# Using Pomerium with a backend service that is using Google SSO

**URL:** <https://discuss.pomerium.com/t/using-pomerium-with-a-backend-service-that-is-using-google-sso/134>\
**Category:** Support\
**Tags:** idp\
**Created:** [July 4, 2022, 7:49pm UTC](https://discuss.pomerium.com/t/using-pomerium-with-a-backend-service-that-is-using-google-sso/134 "2022-07-04T19:49:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ulfox](https://avatars.discourse-cdn.com/v4/letter/u/ea5d25/32.png) [@ulfox](https://discuss.pomerium.com/u/ulfox)\
**Post date:** [July 4, 2022, 7:49pm UTC](https://discuss.pomerium.com/t/using-pomerium-with-a-backend-service-that-is-using-google-sso/134/1 "2022-07-04T19:49:27Z")

</div>

## Issue Description

We have deployed Pomerium and up to now everything works great!  
There is one configuration we are currently struggling with, which is displayed below

Additional Information:

- We have **IngresOne** : [ingressOne.somedomain.com](http://ingressOne.somedomain.com)
- We have **IngresTwo** : [ingresTwo.somedomain.com](http://ingresTwo.somedomain.com)
- We have a **Backend** service that:
  - Is configured to use **Google SSO**
  - After **authenticating** via SSO it **redirects** users to **IngressOne**

- We have a **Pomerium** deployment that:
  - Is configured to use Google SSO
  - We have a **Pomerium IngressTwo that acts as a proxy for IngressONe**

### Architectural Diagram

#### Before Pomerium

```auto
 +-------------+ +---------+
 | Ingress One |=---> | Backend | # Ingress One is not publicly accessible
 +-------------+ +----+----+
                           |
                           |
                           | # Before Pomerium
     +------------+ |
     | Google IdP |--------+
     +------------+  

```

#### After Pomerium

```auto

     +------------+
     | Google IdP |--------+
     +------------+ |
                           |
                           | # After Pomerium
                           |
 +-------------+ +----+-----+ +-------------+ +---------+
 | Ingress Two |=---> | Pomerium |=---> | Ingress One |=---> | Backend |
 +-------------+ +----------+ +-------------+ +---------+

```

- Pomerium successfully redirects the user to the Backend, that is `IngressTwo -> IngressOne`
- The backend does not understand the identity header that we pass via Pomerium
- After Pomerium authorizes the user, the user can login using the backends **sign-in** button.
  - Doing so, will redirect the user to **IngressOne** which is not publicly accessible

Redirect Information

```auto
GET .../auth?client_id=redacted.apps.googleusercontent.com&...&redirect_uri=<<IngresOne>>...

```

#### Pomerium Annotations

```auto
cert-manager.io/issuer: letsencrypt-prod
ingress.pomerium.io/pass_identity_headers: "true"
ingress.pomerium.io/policy: '[{"allow":{...}}]'
ingress.pomerium.io/secure_upstream: "true"

```

#### Cookies Info

##### Pomerium

```auto
	_pomerium=<redacted>; csrf_token_<redacted>; ory_kratos_continuity=<redacted>

```

##### Backend

```auto
	csrf_token_<redacted> ory_kratos_continuity=<redacted>; ory_kratos_session=<redacted>; m…lbn<redacted>

```

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): 0.17.3
- Server Operating System/Architecture/Cloud: EKS(1.21.12)

## Helm Configuration

```auto
authenticate:
  ingress:
    annotations:
      cert-manager.io/issuer: "${letsEncryptIssuer}"
    tls:
      secretName: authenticate.${clusterName}.aws.metrika.co-tls
  existingTLSSecret: pomerium-tls
  idp:
    provider: "${provider}"
    clientID: "${clientID}"
    clientSecret: "${clientSecret}"
    serviceAccount: "${serviceAccount}"
  proxied: false

proxy:
  existingTLSSecret: pomerium-tls

databroker:
  existingTLSSecret: pomerium-tls
  storage:
    connectionString: rediss://pomerium-redis-master.pomerium.svc.cluster.local
    type: redis
    clientTLS:
      existingSecretName: pomerium-tls
      existingCASecretKey: ca.crt

authorize:
  existingTLSSecret: pomerium-tls

redis:
  enabled: true
  auth:
    enabled: false
  usePassword: false
  generateTLS: false
  tls:
    certificateSecret: pomerium-redis-tls

ingressController:
  enabled: ${ingressController}

ingress:
  enabled: false

config:
  sharedSecret: "${sharedSecret}"
  cookieSecret: "${cookieSecret}"
  rootDomain: ${clusterName}.${domain}
  existingCASecret: pomerium-tls
  signingKey: "${signingKey}"
  generateTLS: false 
  generateSigningKey: false

```

## Backend Ingress Configuration

```auto
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    cert-manager.io/issuer: letsencrypt-prod
    ingress.pomerium.io/pass_identity_headers: "true"
    ingress.pomerium.io/policy: '[{"allow":{"or":[...]}}]'
    ingress.pomerium.io/secure_upstream: "true"
  name: sso-backend-0
  namespace: pomerium
spec:
  ingressClassName: pomerium
  rules:
  - host: <redacted>
    http:
      paths:
      - backend:
          service:
            name: backend-0
            port:
              number: 443
        pathType: ImplementationSpecific
  tls:
  - hosts:
    - <redacted>
    secretName: backend-0-pomerium.tls

```

## What did you expect to happen?

We did not expect but we wish to find a solution for this. We understand that it is not a pomerium limitation.

### Question

- We have an a application that authenticates with google sso. Can we use Pomerium in front of that application

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [July 4, 2022, 10:08pm UTC](https://discuss.pomerium.com/t/using-pomerium-with-a-backend-service-that-is-using-google-sso/134/2 "2022-07-04T22:08:15Z")

</div>

Do you need to maintain both ingresses?

Can you just keep one ingress that is publicly accessible and modify the redirect url of your backend application to use it?

The users would still need to click (sign in) button of your application if it cannot be modified to consult the Pomerium assertion JWT, but as original Google cookies are not stripped, they would likely not need to enter their password again.

---

<div class="post-metadata">

**Author:** ![ulfox](https://avatars.discourse-cdn.com/v4/letter/u/ea5d25/32.png) [@ulfox](https://discuss.pomerium.com/u/ulfox)\
**Post date:** [July 5, 2022, 12:08pm UTC](https://discuss.pomerium.com/t/using-pomerium-with-a-backend-service-that-is-using-google-sso/134/3 "2022-07-05T12:08:33Z")

</div>

Hi Denis,

We will update the client to redirect to the Pomerium ingress. We tested that on a dev env and it is working.

Thank you!
