Notice
This functionality is currently limited to partners. Your partner can support you in migrating your on-premises installation to Airlock as a Service.
Initial analysis
Before migrating a tenant’s Airlock IAM instance from an on-premises installation to Airlock as a Service, obtain the following information and materials:
The current Airlock IAM configuration and version. The configuration can be downloaded from the Config Editor in the Airlock IAM Adminapp.
Access to the required secrets and key pairs.
The tenant’s network requirements, including whether Airlock IAM must be accessed using TLS or mTLS — for mTLS, all required client and server certificates, associated private keys, and subject alternative names.
Verifying version compatibility
Before proceeding, verify that Airlock as a Service supports the version of the on-premises Airlock IAM installation.
Notice
Airlock as a Service supports Airlock IAM 8.4 and later.
Recommendation
Upgrade the on-premises Airlock IAM installation to the latest Airlock IAM version supported by Airlock as a Service to ensure continued support.
For instructions on upgrading the tenant IAM version, see Upgrade the Tenant IAM version.
Setting up the organization and tenant
In the Airlock Console, create an organization for the customer if one does not already exist.
Create a new tenant with a non-production service level.
Apply the required Airlock-as-a-Service-specific configuration variables and settings.
Upload the configuration as a ZIP file under Configuration >> IAM Config files.
Activate the configuration by clicking Activate tenant in the Operation section.
Wait for the activation to complete successfully.
If activation fails, review the logs to identify the cause.
Thoroughly test the deployed Tenant IAM instance.
-
To integrate an on-premises Airlock Gateway using mTLS:
Clone the Back-end Group used for the existing on-premises IAM instance.
Clone the Mapping used for the existing on-premises IAM instance.
-
Associate the cloned Mapping with the cloned Back-end Group.
➔ This setup allows you to switch your virtual hosts quickly between the Tenant IAM instance on Airlock as a Service and the existing on-premises Tenant IAM instance.
-
Create the required mTLS certificates.
Add the certificates to the Back-end Group on the on-premises Gateway.
Add the corresponding certificates and private keys to the tenant settings in the Airlock Console.
Verify that Airlock Gateway can reach the tenant IAM instance on Airlock as a Service.
Associate the virtual hosts with the new Mapping, replacing their existing associations with the old Mapping.