Keyfactor Command Servers

Keyfactor Command includes several features that provide different platform capabilities:

In many Windows server installations, the Keyfactor Command Management Portal, Windows Services, Web API, and Orchestrator Service API roles are collocated on a single server (or pair of servers if redundancy is desired). Both physical and virtual servers are supported.

In Kubernetes installations, containers are created for each of these roles and managed with a Helm chart. Redundancy is handled using Kubernetes clusters.

Tip:  See Install: Select Components for related information.

For a high availability (HA) solution using the same roles on all nodes, note that the following conditions apply:

  • All servers must point to the same Keyfactor Command SQL database.

  • All servers must use the same encryption methodology (see Application-Level Encryption).

  • Keyfactor recommends that the Keyfactor Command Service be configured to run all services on each node. This allows the service to manage the jobs most efficiently—the service will check out jobs via a locking mechanism that will enforce that any jobs are running on only one service at a time. However, you do have the option to manually tune the jobs on the servers if desired (such that server A always does jobs 1, 2 and 3 and server B always does jobs 4, 5 and 6).

  • Review load balancing rules and configuration, if applicable. Load balancing configuration is beyond the scope of this guide.

Keyfactor does not recommend installing any Keyfactor Command components on a CA or on a SQL server in a production environment.

As you plan for Keyfactor Command, you need to decide upon an architecture for the implementation and prepare servers with sufficient resources accordingly. See System Requirements for more information about planning for servers with sufficient resources to support the planned roles.

Licensing

The Keyfactor Command product is licensed by component. Your license for Keyfactor Command may not include all the features described in this guide. If you choose to add additional components to your Keyfactor Command license in the future, these features can generally be configured without the need to reinstall Keyfactor Command.

License files have an extension of cmslicense and are signed to prevent tampering.