# Issue with Cloud Gateway and JDBC globalProvision rule

**URL:** <https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, provisioning, jdbc-connector, rules\
**Created:** [February 13, 2025, 3:02pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927 "2025-02-13T15:02:19Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sonali\_manhas](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sonali\_manhas](https://developer.sailpoint.com/discuss/u/sonali_manhas)\
**Post date:** [February 13, 2025, 3:02pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/1 "2025-02-13T15:02:19Z")

</div>

## Which IIQ version are you inquiring about?

8.4p1

## Please share any images or screenshots, if relevant.

_[Please insert images here, otherwise delete this section]_

## Please share any other relevant files that may be required (for example, logs).

_[Please insert files here, otherwise delete this section]_

## Share all details about your problem, including any error messages you may have received.

We are trying to configure JDBC applications with Cloud Gateway, and we are seeing issues while provisioning. The issue comes up when the Global Provisioning Rule executes, and the rule fails when we try to fetch objects from the IIQ database, through context.getObject… calls.  
Is there an entry in the app XML that can be configured to rectify this behaviour, like (that is used for LogiPlex applications)?

IdentityIQ version: 8.4p1  
CloudGateway version: 8.4p1

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 13, 2025, 3:32pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/2 "2025-02-13T15:32:14Z")

</div>

Hi @sonali_manhas,

When using **Cloud Gateway** , direct database queries via `context.getObject(...)` in provisioning rules may not work as expected because the rule executes in the **Cloud Gateway environment** , which lacks direct access to the **IIQ database**. Here are some possible solutions:

1. **Ensure the rule runs in IdentityIQ**  
Move any logic that uses `context.getObject(...)` to a **Before/After Provisioning Rule** that runs on the **IIQ side** instead of Cloud Gateway.

2. **Use a TaskDefinition**  
If you need database access, consider using a **Rule Task** instead of a **Global Provisioning Rule**. This allows you to retrieve objects **before sending the request to Cloud Gateway**.

3. **Pre-process with an IdentityRequestProvisioningPlan**  
Instead of querying the database within the provisioning rule, gather the necessary information **beforehand** in an **IdentityRequestProvisioningPlan** and pass it as part of the **ProvisioningPlan**.

4. **Enable debugging logs**  
Check if the rule is executing in **Cloud Gateway** by enabling detailed logging in `log4j.properties`:

```auto
log4j.logger.sailpoint.rules=DEBUG  
log4j.logger.sailpoint.provisioning=DEBUG  

```

Let me know if this helps or if you need further clarification! 🚀

---

<div class="post-metadata">

**Author:** ![sonali\_manhas](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sonali\_manhas](https://developer.sailpoint.com/discuss/u/sonali_manhas)\
**Post date:** [February 13, 2025, 3:35pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/3 "2025-02-13T15:35:16Z")

</div>

Thank you for your reply. How can we handle context.search(…) calls?

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 13, 2025, 3:37pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/4 "2025-02-13T15:37:22Z")

</div>

Also, I came across another post mentioning that JDBC applications have the tag:

```auto
<synchronous>true</synchronous>

```

It seems to work similarly to the one used for LogiPlex applications. This might be worth exploring to see if it helps with your issue. Try this, and if it doesn’t work, you can proceed with the suggestions I shared earlier.

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 13, 2025, 3:38pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/5 "2025-02-13T15:38:59Z")

</div>

You’re welcome!

For context.search(…) calls, a similar issue arises when executing the rule in Cloud Gateway, as it does not have direct access to the IdentityIQ database. In such cases, you may need to move the logic that uses context.search(…) to a **Before/After Provisioning Rule** running on the IdentityIQ server, just like with context.getObject(…).

---

<div class="post-metadata">

**Author:** ![sonali\_manhas](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sonali\_manhas](https://developer.sailpoint.com/discuss/u/sonali_manhas)\
**Post date:** [February 13, 2025, 10:08pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/6 "2025-02-13T22:08:22Z")

</div>

> [@angelborrego](#):
>
> `<synchronous>true</synchronous>`

Is this an entry to be added in the app XML? The app XML doesn’t support it when I try to add it.

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 14, 2025, 7:46am UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/7 "2025-02-14T07:46:34Z")

</div>

Try better with:

```auto
      <entry key="synchronous">
        <value>
          <Boolean>true</Boolean>
        </value>
      </entry>

```

---

<div class="post-metadata">

**Author:** ![sonali\_manhas](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sonali\_manhas](https://developer.sailpoint.com/discuss/u/sonali_manhas)\
**Post date:** [February 14, 2025, 1:39pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/8 "2025-02-14T13:39:21Z")

</div>

This entry did not work. 🙁

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 14, 2025, 3:48pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/9 "2025-02-14T15:48:40Z")

</div>

> [@Issue with Cloud Gateway and JDBC globalProvision rule](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/2):
>
> Hi @sonali_manhas, When using Cloud Gateway, direct database queries via context.getObject(...) in provisioning rules may not work as expected because the rule executes in the Cloud Gateway environment, which lacks direct access to the IIQ database. Here are some possible solutions: Ensure the rule runs in IdentityIQ Move any logic that uses context.getObject(...) to a Before/After Provisioning Rule that runs on the IIQ side instead of Cloud Gateway. Use a TaskDefinition If you need dat…

And what about this?

---

<div class="post-metadata">

**Author:** ![sonali\_manhas](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sonali\_manhas](https://developer.sailpoint.com/discuss/u/sonali_manhas)\
**Post date:** [February 14, 2025, 7:45pm UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/10 "2025-02-14T19:45:24Z")

</div>

Adding the required values in the provisioning plan, through the BeforeProvisioning rule works. I can fetch those values in the globalProvisioning rule through the plan.

---

<div class="post-metadata">

**Author:** ![angelborrego](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelborrego/32/21987_2.png) [@angelborrego](https://developer.sailpoint.com/discuss/u/angelborrego)\
**Post date:** [February 15, 2025, 10:34am UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/11 "2025-02-15T10:34:45Z")

</div>

Hi @sonali_manhas,

I’m glad to hear that adding the required values in the **BeforeProvisioning rule** and then retrieving them in the **Global Provisioning Rule** through the **ProvisioningPlan** worked for you.

If this solution resolved your issue, could you mark it as the accepted answer in the forum? This would help others facing similar challenges and also allow me to continue progressing on my journey as a **SailPoint Ambassador**.

Thanks, and let me know if you have any other questions! 😇

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [April 16, 2025, 10:35am UTC](https://developer.sailpoint.com/discuss/t/issue-with-cloud-gateway-and-jdbc-globalprovision-rule/100927/12 "2025-04-16T10:35:13Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
