Airlock as a Service Knowledge Base

Manage IAM configuration across different environments (staging)

Airlock SaaS allows you to create multiple tenants, each of them being either a production or non-production service level tenant.

We recommend to start with a non-production service level tenant, to start configuring and trying out any new tenant. Once fully configured, we suggest to create a production service level tenant, add the necessary production secrets and key pairs, download your configuration from your non-production service level tenant and upload and activate it in your new production service level tenant.

Later on, when you want to update your production service level tenant, we recommend to thoroughly configure and try out your updated config in a non-production service level tenant again, before uploading your adjusted config to the production service level tenant.

Things to consider

  • Ensure that all secrets and key pairs are configured and having the right values, when setting up your production service level tenant.

  • Do NOT use any placeholder values like TBD in any secret, key pair or your IAM configuration.

  • Ensure that a Redis State Repository is used for your production service level tenant. For non-production service level tenants, an in-memory state repository must be used.

  • If mTLS is configured, ensure that the right client and server certificates as well as SAN and private keys are used.