The challenge
- Provisioning control and worker nodes with the exact CPU, RAM and storage Maximo demands on Azure, while keeping costs predictable and elastic.
- Configuring pull secrets, resource quotas, operator subscriptions and cluster-wide settings to meet IBM Maximo's deployment requirements precisely.
- Correct storage class selection and PVC sizing were critical to avoid data loss, I/O bottlenecks or misalignment with MAS 9.0 prerequisites.
- Retrieving and applying IBM entitlement keys and Container Registry credentials without exposing secrets in plaintext.
- Hardened access controls, encrypted traffic, VPN tunnels and network segmentation were required across both the OpenShift cluster and the Maximo tiers.
Solution architecture
Azure Red Hat OpenShift (ARO)
Managed OpenShift on Azure provides the container orchestration layer with a built-in SLA, automated patching and Azure AD integration for identity.
Ansible control plane
A dedicated controller node runs all provisioning playbooks, with vault-encrypted secrets and role-based task separation for auditability.
IBM Maximo Application Suite operators
MAS and its dependencies (MongoDB, Db2, Kafka, App Connect) are deployed as OpenShift Operators managed through the Operator Lifecycle Manager.
Network and access
All cluster traffic is routed through an internal load balancer. External access is restricted to VPN-authenticated clients, with no public API endpoints exposed.
Monitoring and observability
Azure Monitor, the built-in Prometheus and Grafana stack and custom dashboards give real-time visibility into cluster health, MAS performance and capacity.
What Cloudlit delivered
Infrastructure automation with Ansible
End-to-end playbooks provision the ARO cluster on Azure, configure networking, apply security policies and deploy MAS, all idempotently.
Right-sized cluster provisioning
3 control nodes (12 vCPU, 48 GB RAM, 360 GB storage each) and 3 worker nodes (228 vCPU and 1,298 GB RAM in total) sized precisely to MAS 9.0 requirements.
IBM licensing integration
Automated workflows retrieve and inject the IBM entitlement licence and Container Registry pull secret as Kubernetes secrets, never in plaintext.
Persistent storage configuration
Storage classes, persistent volume claims and reclaim policies aligned with MAS 9.0 data integrity and performance specifications.
Layered security
Internal load balancers, Azure Firewall rules, site-to-site VPN, SSL/TLS certificates, pod-level RBAC and cluster network policies form the defence posture.
Results
- Automated provisioning and standardised configuration ensured compute and storage were used efficiently.
- Automated setup cut deployment time significantly, enabling faster onboarding of new environments.
- Precise sizing and Azure elastic scaling minimised waste while meeting all performance requirements.
- Load balancers, firewalls and SSL certificates protect the cluster and the Maximo suite against threats.
- A standards-based foundation ready to scale Maximo with additional nodes, IoT and analytics.