Size L - Sonatype IQ - Azure Cloud-Native Reference Architecture

Size L - Sonatype IQ - Azure Cloud-Native Reference Architecture

This Sonatype IQ Server large reference architecture describes the recommended infrastructure specifications for deploying a high-availability IQ Server environment in Microsoft Azure using cloud-native services. It supports environments with 10,000–19,999 applications and an expected throughput of approximately 310 evaluations per hour per node, or approximately 14,880–22,320 evaluations per day total.

This reference architecture is designed for production environments that require high availability, increased evaluation capacity, and resilient managed infrastructure.

Infrastructure Specifications

This reference architecture defines a high-availability IQ Server deployment supported by Azure-managed infrastructure services.

This architecture includes the following layers:

Compute Layer (IQ Server)

The compute layer hosts the IQ Server application cluster and processes application evaluations, policy evaluations, reports, and related user activity.

This layer meets the following specifications:

Three IQ Server nodes:

JVM configuration per node:

Example Azure instance types:

This architecture requires a high-availability IQ Server deployment. IQ Server nodes should be deployed behind a load balancer and distributed across availability zones where possible.

Database Layer (Azure Database for PostgreSQL)

This layer meets the following specifications:

Zone redundancy is required at this tier to support production availability and reduce the risk of database downtime caused by zone-level failures.

Storage Layer (Azure Files)

Azure Files provides persistent shared storage for IQ Server operational data, reports, logs, and scan-related content across all IQ Server nodes.

This layer meets the following specifications:

ZRS is required for this architecture because it replicates storage data across multiple Azure availability zones within a region.

Network and Security

This architecture uses load-balanced high-availability connectivity across multiple IQ Server nodes.

Typical deployment patterns include the following:

Apply standard network security practices, including the following:

Limitations

This architecture has the following limitations:

Deploying this Architecture

You can quickly deploy this reference architecture using Sonatype's IQ Terraform configuration for Azure deployments. This automates the creation and configuration of all required Azure resources, including networking, compute, storage, and security components.

For full deployment details, see the README that accompanies the provided Terraform.