System Architecture¶
Auto-generated
Rendered from docs/architecture/calm/architecture.json by the CALM
CLI (calm template). Do not edit this file by hand — edit the
architecture JSON or the Handlebars template at
docs/architecture/calm/templates/mermaid/system.md.hbs and regenerate
with make calm-diagrams.
A single Mermaid flowchart LR of every node in the CALM architecture
and the connections between them. connects and interacts
relationships become arrows (the protocol, when defined, labels the
arrow); deployed-in / composed-of containers become subgraphs.
Note: nodes whose name includes "(planned, Phase 1B/C/D)" are not yet
implemented in the repo — the diagram shows the target architecture so
contributors and users have one canonical picture.
flowchart LR
actor-sandbox-user["Sandbox User"]
system-mediatore["mediatore"]
service-mediatore-user-api["User API (bearer)"]
service-mediatore-sandbox-api["Sandbox API (SPIFFE mTLS)"]
service-mediatore-watcher["Claim Watcher"]
service-mediatore-sts["STS"]
data-asset-claim-store["Claim Store"]
data-asset-sts-signing-key["STS Signing Key"]
service-kubernetes-api["Kubernetes API Server"]
system-banlieue["banlieue Control Plane"]
service-spire-server["SPIRE Server (downstream)"]
service-spire-root["SPIRE Root Server (desired state)"]
network-identity-cluster["Identity Cluster (desired state)"]
network-management-cluster["Management Cluster"]
system-sandbox-vm["Sandbox VM (pool member)"]
service-spire-agent["SPIRE Agent (in guest)"]
service-guest-agent["mediatore-guest"]
service-sandbox-workload["Jailed Workload"]
network-sandbox-segment["Sandbox Network Segment"]
subgraph sg_system-mediatore [System Mediatore]
service-mediatore-user-api
service-mediatore-sandbox-api
service-mediatore-watcher
service-mediatore-sts
data-asset-claim-store
data-asset-sts-signing-key
end
subgraph sg_system-sandbox-vm [System Sandbox Vm]
service-spire-agent
service-guest-agent
service-sandbox-workload
end
subgraph sg_network-sandbox-segment [Network Sandbox Segment]
system-sandbox-vm
end
subgraph sg_network-management-cluster [Network Management Cluster]
system-mediatore
service-kubernetes-api
system-banlieue
service-spire-server
end
subgraph sg_network-identity-cluster [Network Identity Cluster]
service-spire-root
end
service-spire-server -->|mTLS| service-spire-root
actor-sandbox-user -->|HTTPS| ecosystem-idp
actor-sandbox-user -->|HTTPS| service-mediatore-user-api
service-mediatore-user-api -->|HTTPS| ecosystem-idp
service-mediatore-user-api -->|HTTPS| service-kubernetes-api
service-mediatore-watcher -->|HTTPS| service-kubernetes-api
system-banlieue -->|HTTPS| service-kubernetes-api
service-mediatore-watcher -->|mTLS| service-spire-server
service-spire-agent -->|TLS| service-spire-server
service-guest-agent -->|mTLS| service-mediatore-sandbox-api
service-sandbox-workload -->|mTLS| service-mediatore-sandbox-api
service-sandbox-workload -->|HTTPS| ecosystem-downstream-api
actor-sandbox-user --> data-asset-claim-store
Source: nodes and relationships in architecture.json.