Skip to content

Architecture Flows

FINOS CALM

Auto-generated

Rendered from docs/architecture/calm/architecture.json by the CALM CLI (calm template). Do not edit this file by hand — edit the architecture JSON or the Handlebars template at docs/architecture/calm/templates/mermaid/flows.md.hbs and regenerate with make calm-diagrams.

Each business flow defined in the CALM architecture is rendered below as its own Mermaid flowchart TD — one diagram per flow, linking the transitions in sequence order. Three flows are modelled today:

  • Create a VirtualMachine — the happy path from kubectl apply to Ready=true.
  • Swap a VirtualMachine's backend — the canonical least-touch demonstration: change one field, the controller rebuilds the infra.
  • Delete a VirtualMachine — finalizer-gated teardown that guarantees no backend leaks.

Claim a sandbox and act as the user

The happy path from login to a delegated downstream call: login, claim, bind, subject fetch, jail, token.

flowchart TD
    t1["1. User logs in; receives a token with aud = mediatore."]
    t2["2. POST /v1/claims; mediatore validates the token and derives the subject."]
    t3["3. mediatore creates the VirtualMachineClaim with spec.subject."]
    t4["4. banlieue binds a Ready, already-attested pool member."]
    t5["5. The watcher creates the claim's registration entry under the bound node's agent ID."]
    t6["6. The in-guest agent fetches the subject, creates the sb- user and starts the jail."]
    t7["7. The workload trades its claim SVID for a short-lived, audience-scoped token."]
    t8["8. The workload calls the downstream API on the user's behalf."]
    t1 --> t2 --> t3 --> t4 --> t5 --> t6 --> t7 --> t8

Source: flow flow-claim-to-token in architecture.json.

Release and cut-off

Any of four independent cut-offs stops the sandbox acting as the user; this is the ordered normal release.

flowchart TD
    t1["1. DELETE /v1/claims (or the TTL fires). The store row is revoked: /v1/token refuses immediately."]
    t2["2. The SPIRE entry is deleted; the workload's SVID stops within the agent sync interval."]
    t3["3. The VirtualMachineClaim is deleted (or its deletion observed)."]
    t4["4. banlieue destroys the member, vTPM included; the guest agent tears down the jail and user regardless."]
    t1 --> t2 --> t3 --> t4

Source: flow flow-release-cutoff in architecture.json.