# Kubernetes Deployment Across Clusters with mTLS

**URL:** <https://discuss.pomerium.com/t/kubernetes-deployment-across-clusters-with-mtls/39>\
**Category:** Support\
**Tags:** k8s\
**Created:** [December 3, 2021, 4:15pm UTC](https://discuss.pomerium.com/t/kubernetes-deployment-across-clusters-with-mtls/39 "2021-12-03T16:15:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/alex/32/9_2.png) [@alex](https://discuss.pomerium.com/u/alex)\
**Post date:** [December 3, 2021, 4:15pm UTC](https://discuss.pomerium.com/t/kubernetes-deployment-across-clusters-with-mtls/39/1 "2021-12-03T16:15:43Z")

</div>

> [@](#):
>
> [**View in #general on Slack**](https://slack.com/archives/CK6SVMPU0/p1638398149043400)
> 
> ![Alex_Zero](https://canada1.discourse-cdn.com/flex031/uploads/pomerium/original/1X/b0cef61e6895e3a9e1857e3a1e30a6f887a1d2a8.png) **@Alex\_Zero:** Hi all. I’m currently planning a deployment of Pomerium on a series of Kubernetes clusters. I’m curious about clarifying a few points:  
> • If I have multiple clusters in a site, what’s the best way to set up Pomerium so it can work as an ingress controller?  
> • Currently I have mTLS enabled for all the infrastructure services in our clusters. Would connections between services now happen through Pomerium? Or directly through Kubernetes load-balancer services?  
> • This is less important, but our organisation has a policy of not trusting any CA except our own internal root CA for some high security internal services. This could cause some issues as for services to be accessible externally via Pomerium they need to have an ACME-trusted certificate. Is it somehow possible to use a different certificate for connections inside and outside the network perimeter?

---

<div class="post-metadata">

**Author:** ![alex](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/alex/32/9_2.png) [@alex](https://discuss.pomerium.com/u/alex)\
**Post date:** [December 3, 2021, 4:16pm UTC](https://discuss.pomerium.com/t/kubernetes-deployment-across-clusters-with-mtls/39/2 "2021-12-03T16:16:04Z")

</div>

(Copied from Slack)

Hello fellow Alex! Let me see if I can help.

- I can’t answer your first question with any authority, but I nominate [@travis](https://pomerium-io.slack.com/team/UK6DGHN68) for that.
- With our [Ingress Controller](https://pomerium.com/docs/k8s/ingress.html) Pomerium’s proxy service can act as the load balancer, so services can connect to each other internally through Pomerium. You can configure Pomerium with mTLS, and you can also define client CA roots on a per route basis. With this, you could achieve the same (actually greater) level of security between internal services. My WIP update of our mTLS guide adds instructions for per-route mTLS CA definition ([preview](https://deploy-preview-2788--pomerium-docs.netlify.app/guides/mtls.html#require-mtls-per-route)).
- You can use `tls_custom_ca` to define custom CAs for specific routes. ([reference](https://pomerium.com/reference/#tls-custom-certificate-authority))

---

<div class="post-metadata">

**Author:** ![travisgroth](https://yyz1.discourse-cdn.com/flex031/user_avatar/discuss.pomerium.com/travisgroth/32/31_2.png) [@travisgroth](https://discuss.pomerium.com/u/travisgroth)\
**Post date:** [December 6, 2021, 4:12pm UTC](https://discuss.pomerium.com/t/kubernetes-deployment-across-clusters-with-mtls/39/3 "2021-12-06T16:12:22Z")

</div>

> [@alex](#):
>
> If I have multiple clusters in a site, what’s the best way to set up Pomerium so it can work as an ingress controller?

An instance of the ingress controller can only work against a single kubernetes API server so you’d be deploying one per cluster.

Additionally, you’d need to run a full Pomerium per cluster as we do not currently support running more than one instance of an ingress controller against a databroker.

> [@alex](#):
>
> Currently I have mTLS enabled for all the infrastructure services in our clusters. Would connections between services now happen through Pomerium? Or directly through Kubernetes load-balancer services?

This is up to you. If you want to proxy through Pomerium for all inter-service traffic, you’ll probably need the Enterprise product for [service account](https://pomerium.com/enterprise/concepts.html#service-accounts) support. There is no requirement for service mTLS to go through Pomerium, however. It depends on your operational and security requirements.

In case it is relevant, Pomerium also supports mTLS when communicating with upstreams though you may not need this if you’re running a mesh service for mTLS.

> [@alex](#):
>
> This is less important, but our organisation has a policy of not trusting any CA except our own internal root CA for some high security internal services. This could cause some issues as for services to be accessible externally via Pomerium they need to have an ACME-trusted certificate. Is it somehow possible to use a different certificate for connections inside and outside the network perimeter?

Pomerium can use a custom CA for upstream connections and this can be completely independent of downstream user facing certificate chains.
