Size XL - Sonatype IQ - AWS Cloud-Native Reference Architecture

Size XL - Sonatype IQ - AWS Cloud-Native Reference Architecture

This Sonatype IQ Server extra-large reference architecture describes the recommended infrastructure specifications for deploying a large-scale high-availability IQ Server environment in AWS using cloud-native services. It supports environments with 20,000–80,000 onboarded applications and an expected throughput of approximately 405 evaluations per hour per node, or approximately 29,160–38,880 evaluations per day total.

This reference architecture is designed for enterprise-scale production environments that require maximum evaluation throughput, large onboarding capacity, resilient infrastructure services, and operational scalability.

Infrastructure Specifications

This architecture includes the following layers:

Compute Layer (IQ Server)

The compute layer hosts the IQ Server application cluster and processes application evaluations, policy evaluations, reports, and related user activity.

This layer meets the following specifications:

Four IQ Server nodes:

JVM configuration per node:

Example AWS instance types:

This architecture uses four IQ Server nodes deployed behind a load balancer to provide application-level high availability, increased aggregate evaluation throughput, and operational headroom for enterprise-scale workloads.

Typical deployment patterns include the following:

Database Layer (Aurora PostgreSQL)

The database layer stores IQ Server application metadata, policy data, configuration information, and operational state.

This layer meets the following specifications:

Aurora PostgreSQL is required at this tier to support enterprise-scale workloads, resilient database operations, and automatic failover capabilities.

Storage Layer (Amazon EFS)

Amazon EFS provides shared persistent storage for IQ Server application data, reports, logs, and scan-related content across all IQ Server nodes.

This layer meets the following specifications:

Elastic throughput is required for this architecture because large-scale concurrent evaluation workloads and reporting operations may generate sustained storage throughput demands across multiple nodes.

Network and Security

This architecture uses load-balanced high-availability connectivity across multiple IQ Server nodes.

Typical deployment patterns include the following:

Apply standard network security practices, including the following:

Limitations

This architecture has the following limitations:

Deploying this Architecture

You can quickly deploy this reference architecture using Sonatype's IQ Terraform configuration for AWS deployments. This automates the creation and configuration of all required AWS resources, including networking, compute, storage, and security components.

For full deployment details, see the README that accompanies the provided Terraform.