Linux

Where Is the Pomerium Config File?

Pomerium reads one config.yaml you point it at, with routes, identity settings, and databroker storage inside.

Last updated

Pomerium has no fixed config path. You hand it a YAML file through the -config flag or the equivalent container setting, and the conventional home for that file on a Linux host is /etc/pomerium/config.yaml.

Everything about access lives in that file: routes, upstream destinations, identity provider details, and which storage backend the databroker uses. Because the path is yours to choose, document it in your deployment notes. Six months later the file's location is the thing nobody remembers.

Where Pomerium stores this, by platform

Linux
/etc/pomerium/config.yaml

Conventional location; the actual path is whatever your -config flag or container mount says. Routes, IDP settings, and databroker storage all live here. Keep secrets in env vars referenced from the file.

Frequently asked questions

How should I manage the config file across environments?

Keep the file in version control and deploy it with your container or systemd unit. Secrets belong in environment variables or a vault, referenced from the file rather than pasted into it.

Sessions vanish after every restart. Is my config broken?

Check the databroker storage backend first. Ephemeral backends lose sessions on restart by design, which looks exactly like a config bug.

Notice an outdated path? Let us know.