Deployment and Planning Guide#
This articles and documents in this section will help you plan how to launch a digital identity service for your organization. It will hopefully answer many of the "why" questions, not just the "how" questions, setting the stage for what challenges are in scope for Janssen--and where you may need to use other software. It addresses some common questions that don't quite fit into other parts of the Janssen docs.
By covering the key features and designs, hopefully, this guide will help you understand the different deployment options available, when to use each, and how to right-size your Janssen identity services.
The audience for this deployment guide includes technical architects, designers, developers, and Janssen administrators.
Documents in this section broadly cover the following areas of planning:
Overview & Architecture#
Deployment & Infrastructure#
- Deploying Janssen with Kubernetes
- Deploying with a VM cluster
- Deploying on a single VM instance
- Load balancers and HTTP ingress
- DNS security and hostnames
- Database persistence options
- Caching options and session storage
Authentication & Access Control#
- Passwordless authentication and passkeys
- Stepped-up authentication
- Machine-to-machine authentication
- Identity provider discovery (WAYF)
- Using Auth Server as a central authentication service
Identity Governance & Administration#
- Identity Management (IDM)
- Identity Access Governance (IAG)
- Role-based access management (RBAC)
- Delegated user administration
- Self-service password and 2FA credential management
Security & Operational Management#
- Security best practices
- JSON signing, encryption, certificates, and keys
- Managing timeouts
- Benchmarking performance and scalability