• Concept
  • Version ยท 6.0
  • Create

Review your scope and infrastructure

Last updated: September 29, 2026

Infrastructure

Infrastructure requirements are a critical consideration for any automation initiative.

Below is a sample infrastructure diagram to help your teams understand the architecture generally involved when automating database schema changes.

An infrastructure diagram with eight numbered components. Two Git repositories, one for Liquibase changelogs and SQL scripts and one for pipeline configuration files, feed a CI/CD automation system and a build agent that has Liquibase installed on it. The agent reads from an optional artifact repository and a credential manager, and deploys through an approval gate to the development, QA, and production databases.

Sample infrastructure checklist

Your organization can use this checklist when scoping out the necessary components for your implementation. Each row matches a numbered component in the diagram above.

#

Component

Connection identifiers

Permissions required

1

Git source code repository for SQL scripts

Repository URL, user

Read, write, delete

2

Git source code repository for automation scripts

Repository URL, user

Read, write, delete

3

CI/CD automation system

URL or hostname, user

Read, write, delete on automation code, pipelines, and variables

4

CI/CD build automation agent

Hostname, administrator user, agent runner user

Administrator user requires sudo access. Agent runner user requires read, write, and delete within its home directory. Liquibase is installed here

5

Artifact repository (optional)

URL or hostname, user

Read and write on a specific folder

6

Credential manager

URL or hostname, connection details

Read on the database credentials and on the Liquibase Secure license key, both stored in environment variables for use in the pipeline

7

Development database

JDBC URL, username

Read, write, delete on all schemas and objects that Liquibase will manage

8

Target databases

JDBC URL, username

Read, write, delete on all schemas and objects that Liquibase will manage

Download the sample infrastructure checklist as a PDF

A checklist table with a row for each of the eight numbered components in the infrastructure diagram, and columns for the connection identifiers and the permissions each one needs.

It is recommended that the Liquibase implementation team work together to complete the recommended planning outlined in this guide. That way, you will have all the credentials, permissions, and prerequisites required to progress quickly toward your implementation goal.

Checklist rows that stall implementations

Four rows on the checklist are the ones that stall implementations, because each depends on a request to someone outside the team.

  • The build agent needs a network path to every target database. This is the most common surprise, because the agent usually sits in a different network segment than the workstation the DBA tested the connection from. Confirm it before you commit to a date.

  • Each database platform has its own connection requirements. Check yours in Connect databases, and confirm the platform, version, and Java version against System requirements before you order anything.

  • The credential manager choice shapes the pipeline. Liquibase reads secrets from environment variables, from your CI/CD tool's own secret store, or through a secrets management extension. See Liquibase secrets management extensions and Connect your database.

  • The database accounts need the right grants. Several platforms have a grants guidance page of their own in Connect databases. Ask for the accounts early; grants are usually the slowest approval in the list.

Note what is out of scope for the first pass as deliberately as what is in it. Legacy databases nobody wants to touch, the reporting warehouse, the vendor-managed application. Writing them down as "not now" stops them being reopened every week.

What the server adds to your checklist

Liquibase Secure 6.0 adds Liquibase Secure server to this picture. Plan for these components alongside the pipeline items above:

  • A host for Liquibase Secure server: an on-premises server, a private cloud VM, a VPN-protected host, or an internal Kubernetes cluster, with Docker 24+ and Docker Compose v2.

  • A network path from every machine that runs Liquibase to the server, over HTTPS in production. Reporting is non-blocking: if the server is unreachable, deployments still complete.

  • Browser access to the web application URL for everyone who reviews operations, and an API token for each user who connects their runs.

  • The server distribution bundle and container image registry URL, provided by your Liquibase account team.

For what you deploy and how the components communicate, see What is Liquibase Secure server?.

Summary

Addressing these components can help you create a comprehensive and effective Liquibase implementation plan that minimizes risks and maximizes the benefits of using the tool for database change management.

Once you have planned your implementation, you should be ready to start building. The rest of this guide covers the following setup phases: