Deployment Requirements

Immuta comprises three core services (Secure, Discover, and Detect) that rely on PostgreSQL and Elasticsearch to store their states. The illustration below shows the relationships among these services.

The Immuta Enterprise Helm chart (IEHC) (represented by the yellow box above) does not deploy PostgreSQL or Elasticsearch, so you must deploy and manage them separately.

Although Immuta recommends using Elasticsearch because it supports several new Immuta features and services, you can deploy Immuta without Elasticsearch. The table below outlines the Immuta features supported with and without Elasticsearch and the dependencies you must deploy and manage yourself.

Immuta with Elasticsearch
Immuta without Elasticsearch

Immuta Detect

Audit of Immuta and data platform events

Legacy audit

(Until October 2024)

Immuta Monitors

Sensitive data discovery

For guidance on how to configure the IEHC to deploy Immuta with or without Elasticsearch, see one of the guides below:

For more information about legacy features and services no longer enabled in the recommended deployment of Immuta, see the Legacy features and services section.

Version requirements

Kubernetes versions

Kubernetes distribution
Kubernetes versions

Elastic Kubernetes Service (EKS)

1.25 - 1.29

Azure Kubernetes Service (AKS)

1.27 - 1.29

Google Kubernetes Engine (GKE)

1.26 - 1.29

Red Hat OpenShift

1.25 - 1.29

SUSE Rancher Government (RKE2)

1.25 - 1.29

SUSE K3s - For evaluation purposes only

1.25 - 1.29

Metadata database (PostgreSQL)

PostgreSQL incompatibilities

Immuta is not compatible with PostgreSQL abstraction layers, such as Amazon Aurora.

  • PostgreSQL 15.0 or newer

  • The pgcrypto extension must be enabled

Elasticsearch

  • Elasticsearch v7 API or newer

  • OpenSearch compatible with Elasticsearch v7 API or newer

OpenSearch user

The user provided during the install must have the following permissions:

  • cluster:monitor/health

  • indices:data/write/bulk*

  • indices:data/write/bulk

  • indices:data/read/search

  • indices:admin/exists

  • indices:admin/create

  • indices:admin/delete

  • indices:admin/settings/update

  • indices:admin/get

  • indices:data/write/delete/byquery

  • indices:data/write/index

  • indices:admin/mapping/put

  • indices:data/write/bulk

  • indices:data/write/bulk*

Follow OpenSearch documentation to create the user and add permissions, or see the Setting up OpenSearch permissions knowledge base article.

Cache (Redis/Memcached)

Built-in cache

The IEHC manages its own Memcached deployment inside the cluster. The key-value cache can optionally be externalized post installation.

  • Redis 7.0 or newer

  • Memcached 1.6 or newer

Infrastructure recommendations

Kubernetes distribution
Ingress
External metadata database
External Elasticsearch

Amazon Elastic Kubernetes Service (EKS)

AWS Load Balancer Controller

Azure Kubernetes Service (AKS)

Azure Application Gateway Ingress Controller

Google Kubernetes Engine (GKE)

GKE Ingress Controller

Red Hat OpenShift

OpenShift Ingress Operator

SUSE Rancher Government (RKE2)

Ingress NGINX Controller

SUSE K3s - For evaluation purposes only

Traefik

Legacy features and services

Some legacy services and features are no longer enabled in the recommended configuration of the IEHC. The table below lists these features and provides links to documentation that outlines how to enable them in Immuta.

Feature
Immuta Enterprise Helm chart configuration

Legacy audit

Set each of the following secure.extraEnvVars in your immuta-values.yaml file to false:

  • FeatureFlag_AuditService

  • FeatureFlag_detect

  • FeatureFlag_auditLegacyViewHide

Data platforms

Policies

  • Masking with format preserving masking (unless using the Snowflake integration)

  • Masking with k-anonymization

  • Masking using randomized response (unless using the Snowflake integration)

Next step

Follow the Getting started guide to install Immuta.

Last updated