Size XL - Sonatype IQ - GCP Cloud-Native Reference Architecture

Size XL - Sonatype IQ - GCP Cloud-Native Reference Architecture

This Sonatype IQ Server extra-large reference architecture describes the recommended infrastructure specifications for deploying a large-scale, high-availability IQ Server environment in Google Cloud Platform (GCP) using cloud-native services. It supports environments with 20,000–80,000 applications and an expected throughput of approximately 405 evaluations per hour per node, or approximately 29,160–38,880 evaluations per day total.

This reference architecture is designed for enterprise-scale production environments that require maximum evaluation throughput, large onboarding capacity, resilient infrastructure services, and operational scalability. The XL profile represents the largest validated GCP deployment profile for IQ Server and uses four IQ Server nodes to support sustained large-scale workloads.

Infrastructure Specifications

This architecture includes the following layers:

Compute Layer (IQ Server)

The compute layer hosts the IQ Server application cluster and processes application evaluations, policy evaluations, reports, and related user activity.

This layer meets the following specifications:

Four IQ Server nodes:

JVM configuration:

Example GCP machine type:

Database Layer (Cloud SQL PostgreSQL)

This layer meets the following specifications:

Storage Layer (Cloud Filestore)

Cloud Filestore provides persistent shared storage for IQ Server operational data, reports, logs, and scan-related content.

This layer meets the following specifications:

Network and Security

Typical deployment patterns include the following:

Apply standard network security practices, including the following:

Limitations

This architecture has the following limitations:

Deploying this Architecture

You can quickly deploy this reference architecture using Sonatype's IQ Terraform configuration for GCP deployments. This automates the creation and configuration of all required GCP resources, including networking, compute, storage, and security components.

For full deployment details, see the README that accompanies the provided Terraform.