Secure and Extensible Platform Architectures for Enterprise Network Orchestration
Main Article Content
Abstract
Products related to enterprise network orchestration are expanding to include heterogeneous infrastructure, automation operations, use of third parties and programmable interfaces and have become a core conflict between extensibility, operationsecurity. An example of recommended safe and scalable platform design in this paper is one that imposes definite boundaries of trust between the users, services, devices adapters, automation processes and execution platforms. The architecture separates the central control plane, integration and execution territory and is based on workload identity, policy enforced access, least privilege access, intent checking, managed secret use, auditing (tamper evidenced), and software provenance checking. The versioned APIs are event based interfaces and narrow adapters to ensure extensionality without the need to use unconstrained plug-in and database dependency. Other functions that are incorporated in the proposed architecture are pre-execution policy-enforcement, capability based isolation, managed failure and continuity checking of extension behavior. A framework assessment looks at the effectiveness of authorization, component isolation, supply-chain integrity, audit completeness, policy enforcement and safe failure behavior in representative orchestration scenarios. This discussion shows that extensible does not mean compromising the platform security in the event they are managed as independent managed capabilities whose authority, data access and resource consumption are well delimited. The article lays down a viable constructionist base of architecture.