Technical overview

The IBM Verify Identity Governance - Container consists of a Verify Identity Governance application running on IBM WebSphere Liberty server.

Figure 1. IVIG Container - Main components
IVIG Container Main components

IVIG Container architecture

IBM Verify Identity Governance - Container includes a runtime stack with a full-fledged Verify Identity Governance application coupled with a containerized IBM MQ running on a standard Kubernetes distribution such as MicroK8S, K3S, or RHEL OpenShift.

You can choose to install a containerized IBM Security Verify Directory (ISVD) or connect to your own external LDAP. Similarly, you can choose to install a containerized PostgreSQL or connect to your own external PostgreSQL or IBM DB2.

The IVIG Container deployment builds on the existing framework from ISVG v10.0.2, and includes a new set of Spark pods for Identity Analytics.

At a minimum, a container deployment requires the IVIG and MQ Shared pods.

Typically, one or more of LDAP, PostgreSQL, and the Dispatcher are deployed as pods. If desired, they can also all be run externally.

With the Enterprise or Compliance Licenses, a new Job (risk-start) creates and manages a Spark cluster to implement the new Analytics component.