# Pomerium HTTP proxy mode + Azure AKS

**URL:** <https://discuss.pomerium.com/t/pomerium-http-proxy-mode-azure-aks/119>\
**Category:** Community Showcase\
**Created:** [May 23, 2022, 12:15am UTC](https://discuss.pomerium.com/t/pomerium-http-proxy-mode-azure-aks/119 "2022-05-23T00:15:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![ms1111](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@ms1111](https://discuss.pomerium.com/u/ms1111)\
**Post date:** [May 23, 2022, 12:15am UTC](https://discuss.pomerium.com/t/pomerium-http-proxy-mode-azure-aks/119/1 "2022-05-23T00:15:28Z")

</div>

## Using the pomerium-cli proxy command with Azure AKS

I wanted to put in a plug for the new `pomerium-cli proxy` command that was [added in 0.17.3](https://github.com/pomerium/cli/pull/56). (Related to [#1837](https://github.com/pomerium/pomerium/issues/1837)).

The new proxy command allows `kubectl` and `helm` to access a private Azure Kubernetes Service cluster through Pomerium.

### Pros / Cons

Pomerium has its own full-fledged solution for [authenticating access to Kubernetes clusters](https://www.pomerium.com/docs/k8s/) using a service account for impersonation, but I didn’t want to replace AKS’s Azure AD integration. I wanted to layer on Pomerium as an extra network level protection rather than replacing AKS authorization entirely.

## Configs

Pomerium config:

```yaml
routes:
  - from:tcp+https://examplecluster-12345678.pomerium.example.com:8000
    # For "to", use the API server address from the Azure portal, adding "tcp://" and ":443"
    to: tcp://examplecluster-12345678.hcp.exampleregion.azmk8s.io:443
    policy:
      - allow:
          or:
            - groups:
                has: "examplegroup"

```

The port `:8000` in the `from` clause is a bit of a hack, [explained in the pull request](https://github.com/pomerium/cli/pull/56#:~:text=Currently%20there%20seems%20to%20be%20a%20bug%2C%20most%20likely%20in%20envoy%2C%20that%20prevents%20tcp%20tunnels%20with%20frontend%20port%20443%20to%20work.%0AThis%20PR%20just%20have%20a%20hardcoded%20rewrite%20of%20port%20443%20to%20port%208000%20when%20setting%20up%20the%20tunnel%2C%20which%20is%20not%20ideal). From the client’s perspective it will be port 443.

Launch the proxy:

```shell
pomerium-cli proxy --proxy-domain pomerium.example.com --pomerium-url https://pomerium.example.com

```

Test with curl first. When you run this, `pomerium-cli` should open your browser to authenticate to Pomerium. You should then get a 401 unauthorized back from the AKS cluster:

```auto
curl -k --proxy http://127.0.0.1:3128 https://examplecluster-12345678.pomerium.example.com

{
  "kind": "Status",
  "apiVersion": "v1",
  "metadata": {
    
  },
  "status": "Failure",
  "message": "Unauthorized",
  "reason": "Unauthorized",
  "code": 401
}

```

That’s a good sign, since it’s coming from Kubernetes.

Set up your `~/.kube/config` as usual using `az aks get-credentials`. To route traffic through the proxy, edit `~/.kube/config` and find your `cluster:` entry.

```yaml
clusters:
- cluster:
    certificate-authority-data: ...
    server: https://examplecluster-12345678.hcp.exampleregion.azmk8s.io:443
  name: examplecluster

```

Make the following changes:

- change `server` to your internal Pomerium `tcp+https` route from the `from` block.
- add `proxy-url` with your local proxy.
- add `tls-server-name` with the real server name.

```yaml
clusters:
- cluster:
    certificate-authority-data: ...
    server: https://examplecluster-12345678.pomerium.example.com:443
    proxy-url: http://127.0.0.1:3128
    tls-server-name: examplecluster-12345678.hcp.exampleregion.azmk8s.io
  name: examplecluster

```

With this configuration, `kubectl get nodes`, `kubectl exec`, `kubectl logs -f`, etc. should all work. Also `helm upgrade`. Each request will be a bit slower than accessing directly or over a VPN, but it works.
