Join our Newsletter — 33% off our NHI Course

Pomerium alternatives: where proxy-based access still falls short

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Identity-aware proxies can simplify application access, but teams still need deeper controls for databases, servers, Kubernetes, audit logging, and offboarding across hybrid environments, according to StrongDM. The issue is not access convenience alone, but whether access layers actually hide credentials, enforce least privilege, and preserve revocation control.

Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “Alternatives to Pomerium”.

Key questions

Q: What breaks when proxy-based access is used for infrastructure resources?

A: Proxy-based access often breaks down when teams need consistent control over databases, servers, and Kubernetes rather than just application sign-in.

Q: Why do identity-aware proxies not remove the need for PAM?

A: Identity-aware proxies reduce exposure at the access edge, but PAM is still needed when the underlying resources require privileged actions, session evidence, and strong offboarding.

Q: How do teams know whether an access platform is actually auditable?

A: Teams should look for session-level evidence that can be tied to a specific user, resource, and action.

Practitioner guidance

  • Test offboarding at the resource layer Suspend a user once and verify that database, server, and cluster access actually disappears, not just the front-door session.
  • Map hidden credential paths Inventory where VPN passwords, SSH keys, and database credentials still exist outside the proxy layer and document who can reach them.
  • Require session evidence for privileged access Set a minimum standard for query logs, shell command capture, and kubectl activity before treating an access model as auditable.

Bottom line: Proxy-based access can simplify sign-in, but it does not automatically solve governance for infrastructure resources.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Proxy-based access is not the same thing as governed access. Identity-aware proxies can simplify authentication, but they do not automatically solve credential ownership, entitlement scope, or offboarding across the wider estate. The governance question is whether the access layer merely front-ends applications or actually controls the full lifecycle of access to infrastructure. Practitioners should treat access convenience and access governance as separate problems.

A question worth separating out:

Q: When should organisations choose a proxy model over a full access control plane?

A: A proxy model fits when the main requirement is simpler sign-in to applications and the risk surface does not depend on hidden downstream credentials. A fuller access control plane is better when the organisation needs governance over infrastructure resources, offboarding, and audit trails. The choice should follow the resource type and the revocation model, not the appeal of a simpler access experience.

👉 Read our full editorial: Pomerium alternatives expose the limits of access proxy models


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.