Size S - Sonatype IQ - Azure Cloud-Native Reference Architecture

Size S - Sonatype IQ - Azure Cloud-Native Reference Architecture

This Sonatype IQ Server small reference architecture describes the recommended infrastructure specifications for deploying a single IQ Server instance in Microsoft Azure using cloud-native services. It supports environments with 500–1,999 applications and an expected throughput of approximately 150–220 evaluations per hour, or approximately 3,600–5,280 evaluations per day.

This reference architecture is appropriate for small-to-medium production environments that require increased evaluation throughput, larger onboarding capacity, and improved infrastructure resilience compared to the XS profile. While this architecture still uses a single IQ Server node, it introduces stronger production recommendations around storage redundancy and database resilience.

Infrastructure Specifications

The architecture includes the following layers:

Compute Layer (IQ Server)

The compute layer hosts the IQ Server application and processes application evaluations, policy evaluations, reports, and related user activity.

This layer meets the following specifications:

Single IQ Server node:

JVM configuration:

Example Azure instance types:

Database Layer (Azure Database for PostgreSQL)

This layer meets the following specifications:

Storage Layer (Azure Files)

Azure Files provides persistent shared storage for IQ Server operational data, reports, logs, and scan-related content.

This layer meets the following specifications:

Network and Security

Typical deployment patterns include the following:

Apply standard network security practices, including the following:

Limitations

This architecture has the following limitations:

Deploying This Architecture

You can quickly deploy this reference architecture using Sonatype's IQ Terraform configuration for Azure deployments. This automates the creation and configuration of all required Azure resources, including networking, compute, storage, and security components.

For full deployment details, see the README that accompanies the provided Terraform.