# Pomerium OSS + LogTo in k3s (Traefik)

**URL:** <https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372>\
**Category:** Support\
**Tags:** k8s\
**Created:** [May 8, 2024, 10:13am UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372 "2024-05-08T10:13:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![IngwiePhoenix](https://avatars.discourse-cdn.com/v4/letter/i/ecb155/32.png) [@IngwiePhoenix](https://discuss.pomerium.com/u/IngwiePhoenix)\
**Post date:** [May 8, 2024, 10:13am UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372/1 "2024-05-08T10:13:01Z")

</div>

## What happened?

I have recently installed [LogTo](https://logto.io) into my cluster and configured a few basics. Right now, my k3s cluster is not exposed to the public - I want to figure out authentication and authorization beforehand.

The grand idea is:

- Local network can always access everything (`192.168.1.0/24` at home and `100.64.0.0/24` via Headscale/Tailscale VPN)
- Friends on a certain Discord Server (Guild) can access resources shared to them as “group” - this should be handled through LogTo.
- A generic Login I can use - already exists in LogTo.

## What did you expect to happen?

While reading through the Helm Chart values, I was somewhat confused as to how I should configure Traefik. So, I have it _and_ cert-manager set up to use Let’s Encrypt with my domain (`*.birb.it`) through DNS challenge - so, everything in the cluster that wants a cert, can get one. No problem.  
But what I struggled with is figuring out how to properly configure Promerium as an auth middleware for Traefik.

There is a [ForwardAuth middleware in Traefik](https://doc.traefik.io/traefik/middlewares/http/forwardauth/) - but I couldn’t figure out how to bind that, Promerium and OIDC creds from LogTo, together into the Helm values.

## How’d it happen?

Nothing has happened _yet_ 🙂

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): None installed yet; prepwork!
- Server Operating System/Architecture/Cloud: Linux, arm64, k3s v1.29.3+k3s1

## What’s your config.yaml?

I will be using k3s’ `HelmChart` API object, which embeds the `values.yaml`.

## What did you see in the logs?

```logs
None, yet.

```

## Additional context

I am still sort-of new to kubernetes; the only auth-proxy I ever used was based on Caddy ([caddy-security aka. authp](https://github.com/greenpau/caddy-security)) and I used it’s Discord integration back then to set things up. But, I am trying to get away from my salad of docker-compose deployments and migrate to k3s across all my servers. So, I need authN/-Z - and I want to use Promerium as the layer inbetween where this feature is not available in the app itself (i.e. i2pd’s dashboard) or to generally secure certain resources away to only be reachable in the first place by users that really should (projects in alpha state or alike).

Thank you and kind regards,  
Ingwie

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [May 9, 2024, 1:09pm UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372/2 "2024-05-09T13:09:29Z")

</div>

Pomerium no longer supports forwardauth with traefik. It’s designed to be an edge proxy. For Kubernetes we have an ingress controller which will automatically convert ingress definitions to Pomerium routes. The ingress controller works with k3s.

> **[Pomerium Ingress Controller for Kubernetes | Pomerium](https://www.pomerium.com/docs/deploy/k8s/ingress)**
>
> The Pomerium Kubernetes Ingress Controller is Pomerium’s official, open-source controller for Kubernetes environments. Pomerium's Ingress Controller builds secure access to Kubernetes Services by enforcing access control policies based on user...

---

<div class="post-metadata">

**Author:** ![IngwiePhoenix](https://avatars.discourse-cdn.com/v4/letter/i/ecb155/32.png) [@IngwiePhoenix](https://discuss.pomerium.com/u/IngwiePhoenix)\
**Post date:** [May 9, 2024, 2:03pm UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372/3 "2024-05-09T14:03:38Z")

</div>

Ohh I see! So I would have to somehow configure Traefik (ingress) → Pomerium (ingress) → ?

---

<div class="post-metadata">

**Author:** ![calebdoxsey](https://avatars.discourse-cdn.com/v4/letter/c/7bcc69/32.png) [@calebdoxsey](https://discuss.pomerium.com/u/calebdoxsey)\
**Post date:** [May 9, 2024, 6:34pm UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372/4 "2024-05-09T18:34:12Z")

</div>

This may be possible but its tricky to configure. Ideally traefik isn’t used at all. Is there a feature from traefik that you need?
