IT CanvassTalk to an advisor
Installation · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Kubernetes

Running IdentityIQ on Kubernetes: deployments, config maps, secrets and scaling.

Quick answer

On Kubernetes, run IdentityIQ as a Deployment with ConfigMaps and Secrets, an external database, and services for UI and task nodes.

Key takeaways
  • Prerequisites for Kubernetes
  • Step-by-step install path
  • Common pitfalls and fixes
  • Verification after install

Running IdentityIQ on Kubernetes adds orchestration, self-healing and horizontal scaling on top of the containerised deployment. The application runs as a Deployment of pods, configuration lives in ConfigMaps and Secrets, and the database stays external and managed. Kubernetes is powerful here but only pays off once the containerisation fundamentals are solid.

Prerequisites

  • A built, registry-hosted IdentityIQ container image.
  • A Kubernetes cluster and access to deploy.
  • An external managed database reachable from the cluster.

Step by step

  • 1. Push the image to a registry the cluster can pull from.
  • 2. Define a Deployment and a Service for the IdentityIQ pods.
  • 3. Store configuration in ConfigMaps and credentials in Secrets, mounted or injected as environment variables.
  • 4. Point at the external database via the Secret/ConfigMap connection settings.
  • 5. Add readiness and liveness probes so Kubernetes only routes traffic to healthy pods and restarts unhealthy ones.
  • 6. Scale deliberately: separate UI-serving pods from task/background pods, since they have different resource profiles.

Verify

Confirm pods reach ready state, probes pass, the Service exposes the UI, and the app connects to the database. Test that killing a pod results in a clean, automatic replacement.

Kubernetes notes

  • Keep the database out of the cluster, use a managed database service.
  • Use Secrets for credentials, never plain ConfigMaps or image layers.
  • Separate UI and task workloads so batch jobs do not starve interactive pods.
  • Plan how background/task processing is coordinated across replicas.

Common pitfalls

  • Running the database in-cluster without proper persistence.
  • Secrets stored insecurely as ConfigMaps.
  • No probes, so traffic hits pods that are not ready.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What are the prerequisites for Kubernetes?

Frequently asked questions

What does the term Kubernetes refer to in SailPoint?
Running IdentityIQ on Kubernetes adds orchestration, self-healing and horizontal scaling on top of the containerised deployment. The application runs as a Deployment of pods, configuration lives in ConfigMaps and Secrets, and the database stays external and managed.
What is the practical takeaway on Kubernetes?
Confirm pods reach ready state, probes pass, the Service exposes the UI, and the app connects to the database.
What is worth remembering about Kubernetes in practice?
Test that killing a pod results in a clean, automatic replacement.
What tends to go wrong with Kubernetes?
Running the database in-cluster without proper persistence. Secrets stored insecurely as ConfigMaps. No probes, so traffic hits pods that are not ready.
Want this with a live instructor and a lab tenant?
SailPoint Architect training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support