Size XL - Sonatype IQ - Azure Cloud-Native Reference Architecture

Size XL - Sonatype IQ - Azure Cloud-Native Reference Architecture

This Sonatype IQ Server extra-large reference architecture describes the recommended infrastructure specifications for deploying a large-scale, high-availability IQ Server environment in Microsoft Azure using cloud-native services. It supports environments with 20,000–80,000 applications and an expected throughput of approximately 405 evaluations per hour per node, or approximately 29,160–38,880 evaluations per day total.

This reference architecture is designed for enterprise-scale production environments that require maximum evaluation throughput, large onboarding capacity, resilient infrastructure services, and operational scalability. The XL profile represents the largest Azure cloud-native deployment profile for IQ Server and recommends AKS for Kubernetes-based orchestration at this scale.

Infrastructure Specifications

This reference architecture defines a high-availability IQ Server deployment supported by Azure-managed infrastructure services.

This architecture includes the following layers:

Compute Layer (IQ Server)

The compute layer hosts the IQ Server application cluster and processes application evaluations, policy evaluations, reports, and related user activity.

This layer meets the following specifications:

Four IQ Server nodes:

JVM configuration per node:

Example Azure instance types:

This architecture requires a high-availability IQ Server deployment. At this scale, AKS is recommended to support Kubernetes-based orchestration, multi-node deployment, workload management, and operational consistency.

Database Layer (Azure Database for PostgreSQL)

This layer meets the following specifications:

Storage Layer (Azure Files)

Azure Files provides persistent shared storage for IQ Server operational data, reports, logs, and scan-related content across all IQ Server nodes.

This layer meets the following specifications:

Network and Security

This architecture uses load-balanced high-availability connectivity across multiple IQ Server nodes.

Typical deployment patterns include the following:

Apply standard network security practices, including the following:

Limitations

This architecture has the following limitations:

Organizations requiring geographic redundancy or disaster recovery across Azure regions should supplement this architecture with additional disaster recovery planning and regional replication strategies.

Deploying this Architecture

You can quickly deploy this reference architecture using Sonatype's IQ Terraform configuration for Azure deployments. This automates the creation and configuration of all required Azure resources, including networking, compute, storage, and security components.

For full deployment details, see the README that accompanies the provided Terraform.