Skip to content

System Architecture

FINOS CALM

Auto-generated

Rendered from docs/architecture/calm/architecture.json by the CALM CLI (calm template). Do not edit this file by hand — edit the architecture JSON or the Handlebars template at docs/architecture/calm/templates/mermaid/system.md.hbs and regenerate with make calm-diagrams.

A single Mermaid flowchart LR of every node in the CALM architecture and the connections between them. connects and interacts relationships become arrows (the protocol, when defined, labels the arrow); deployed-in / composed-of containers become subgraphs.

Note: nodes whose name includes "(planned, Phase 1B/C/D)" are not yet implemented in the repo — the diagram shows the target architecture so contributors and users have one canonical picture.

flowchart LR
    actor-sandbox-user["Sandbox User"]
    system-mediatore["mediatore"]
    service-mediatore-user-api["User API (bearer)"]
    service-mediatore-sandbox-api["Sandbox API (SPIFFE mTLS)"]
    service-mediatore-watcher["Claim Watcher"]
    service-mediatore-sts["STS"]
    data-asset-claim-store["Claim Store"]
    data-asset-sts-signing-key["STS Signing Key"]
    service-kubernetes-api["Kubernetes API Server"]
    system-banlieue["banlieue Control Plane"]
    service-spire-server["SPIRE Server (downstream)"]
    service-spire-root["SPIRE Root Server (desired state)"]
    network-identity-cluster["Identity Cluster (desired state)"]
    network-management-cluster["Management Cluster"]
    system-sandbox-vm["Sandbox VM (pool member)"]
    service-spire-agent["SPIRE Agent (in guest)"]
    service-guest-agent["mediatore-guest"]
    service-sandbox-workload["Jailed Workload"]
    network-sandbox-segment["Sandbox Network Segment"]
    subgraph sg_system-mediatore [System Mediatore]
        service-mediatore-user-api
        service-mediatore-sandbox-api
        service-mediatore-watcher
        service-mediatore-sts
        data-asset-claim-store
        data-asset-sts-signing-key
    end
    subgraph sg_system-sandbox-vm [System Sandbox Vm]
        service-spire-agent
        service-guest-agent
        service-sandbox-workload
    end
    subgraph sg_network-sandbox-segment [Network Sandbox Segment]
        system-sandbox-vm
    end
    subgraph sg_network-management-cluster [Network Management Cluster]
        system-mediatore
        service-kubernetes-api
        system-banlieue
        service-spire-server
    end
    subgraph sg_network-identity-cluster [Network Identity Cluster]
        service-spire-root
    end
    service-spire-server -->|mTLS| service-spire-root
    actor-sandbox-user -->|HTTPS| ecosystem-idp
    actor-sandbox-user -->|HTTPS| service-mediatore-user-api
    service-mediatore-user-api -->|HTTPS| ecosystem-idp
    service-mediatore-user-api -->|HTTPS| service-kubernetes-api
    service-mediatore-watcher -->|HTTPS| service-kubernetes-api
    system-banlieue -->|HTTPS| service-kubernetes-api
    service-mediatore-watcher -->|mTLS| service-spire-server
    service-spire-agent -->|TLS| service-spire-server
    service-guest-agent -->|mTLS| service-mediatore-sandbox-api
    service-sandbox-workload -->|mTLS| service-mediatore-sandbox-api
    service-sandbox-workload -->|HTTPS| ecosystem-downstream-api
    actor-sandbox-user --> data-asset-claim-store

Source: nodes and relationships in architecture.json.