# Kubernetes - Ingress - Multiple IDP?

**URL:** <https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155>\
**Category:** Support\
**Tags:** idp, k8s\
**Created:** [September 15, 2022, 6:05pm UTC](https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155 "2022-09-15T18:05:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![darwiner](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@darwiner](https://discuss.pomerium.com/u/darwiner)\
**Post date:** [September 15, 2022, 6:05pm UTC](https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155/1 "2022-09-15T18:05:02Z")

</div>

## What happened?

Hey there,

I’ve gone through the Kubernetes Quickstart document and have been able to successfully setup Pomerium with an integration in place with Okta.

Everything seems to be working as I would expect it to, being able to filter by email/domain/group and so on.

Now, that settles the first use case I have, in the case there’s an application that I needs to auth via one IDP (Okta) at:

- [app1.example.com](http://app1.example.com) (this is an ingress)

The second use case though, is if I have another application running in the same k8s cluster that needs to auth via another IDP (such as Auth0) at:

- [app2.example.com](http://app2.example.com) (this is another ingress)

Is there a way to put this in place? Considering the “global” pomerium resource setup in k8s points to a specific IDP? Would there be some sort of way to creating multiple ones? And have different ingress configs point to differing pomerium configs, depending on the idp that needs to be used, or something along those lines?

## What did you expect to happen?

Would, for example, multiple pomerium pods be able to run different IDP configs? And each ingress using a pomerium class would need to specificy which pomerium needs to be used…?

## How’d it happen?

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): pomerium/ingress-controller:sha-5294279
- Server Operating System/Architecture/Cloud: GKE 1.22

## What’s your config.yaml?

N/A

---

<div class="post-metadata">

**Author:** ![darwiner](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@darwiner](https://discuss.pomerium.com/u/darwiner)\
**Post date:** [September 15, 2022, 6:09pm UTC](https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155/2 "2022-09-15T18:09:18Z")

</div>

I should note that I’ve also seen this open GH issue that seems to ask about this specific case also: [authenticate: support multiple identity providers · Issue #1403 · pomerium/pomerium · GitHub](https://github.com/pomerium/pomerium/issues/1403)

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [September 17, 2022, 3:50am UTC](https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155/3 "2022-09-17T03:50:07Z")

</div>

You need deploy two instances of Pomerium into your cluster.

The following has to be changed compared to vanilla installation. Assuming you name your installations `one` and i.e. `two`:

1. Namespace: `pomerium` =\> `pomerium-one`
2. Global settings: `global` =\> `global-one`
3. Databases MUST be distinct.
4. Controller name: `pomerium.io/ingress-controller` =\> `pomerium.io/ingress-controller-one`
5. `IngressClass`: `pomerium` =\> `pomerium-one`
6. Authenticate URLs should be distinct - i.e. `https://authenticate-one.corp.com`

You may use `kustomize` that is part of `kubectl` to create a variation of the installation: create a folder `pomerium-one` with the following two files:

**`kustomization.yaml`**

```auto
namespace: pomerium-one
bases:
  - https://raw.githubusercontent.com/pomerium/ingress-controller/main/deployment.yaml
patchesStrategicMerge:
  - deployment.yaml
patches:
  - target:
      kind: IngressClass
      name: pomerium
    patch: |-
      - op: replace
        path: /metadata/name
        value: pomerium-one
      - op: replace
        path: /spec/controller
        value: pomerium.io/ingress-controller-one

```

and **`deployment.yaml`** :

```auto
apiVersion: apps/v1
kind: Deployment
metadata:
  name: pomerium
  namespace: pomerium
spec:
  template:
    spec:
      containers:
        - name: pomerium
          args:
            - all-in-one
            - --pomerium-config=pomerium-one
            - --update-status-from-service=$(POMERIUM_NAMESPACE)/pomerium-proxy
            - --metrics-bind-address=$(POD_IP):9090
            - --name=pomerium.io/ingress-controller-one

```

From that directory, run `kubectl apply -k .` and it should deploy an installation for `pomerium-one`. Now repeat the same for `pomerium-two`, and create secrets and appropriate global configurations.

Now you may start assigning `spec.ingressClass` `pomerium-one` and `pomerium-two` to the `Ingress` objects to make them use different Pomerium installations (and identity providers).

---

<div class="post-metadata">

**Author:** ![darwiner](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@darwiner](https://discuss.pomerium.com/u/darwiner)\
**Post date:** [September 23, 2022, 1:33pm UTC](https://discuss.pomerium.com/t/kubernetes-ingress-multiple-idp/155/4 "2022-09-23T13:33:16Z")

</div>

Thank you for these very detailed instructions! This works out exactly as one would expect and each pomerium deployment is handling a different idp.
