Rendered folder index
Section overview
Folders and articles are both available in the left browser. This panel promotes actual notes first.
Security Architecture
Canonical hub for security architecture: identity, policy enforcement, secrets, and platform hardening.
Scope
In scope
- Identity, access, and governance: WP-07 Identity and Access Management (IAM)
- Security posture hardening: WP-06 Security Posture and Hardening
- Trust and secret services: WP-03 Trust and Secret Services
Out of scope
- Network cabling and physical fabric details (see Network Architecture)
Current target direction (while ADR-012 and ADR-015 are draft): Keycloak-centered IAM and SSO with policy enforcement as a platform default.
Key Concepts
- IAM baseline: Smart Access.
- Admission policy enforcement: Automation.
- Secrets and certificates: Secrets Management and Public Key Infrastructure.
- Zero-trust posture: ZTNA
Related Decisions (ADRs)
- ADR-012 SSO (Single Sign-On) for OpenShift and Hosted Services (draft)
- ADR-015 Keycloak IAM architecture (draft)
Principles Coverage
- Security by Design - controls are embedded in platform defaults.
- Least Privilege - access is constrained to minimum required permissions.
- Observability by Default - security posture remains measurable.
Supporting Facts
- Smart Access
- Federated Authentication
- Identity Governance and Administration
- OPA Gatekeeper
- OpenBao (SBB)
Key Sources
Diagrams
- Delivery dependency and sequencing views: Workpackage Dependencies.
Mapping Views
- DC 3.0 capability-to-solution mapping for this domain: DC 3.0 Building Block Lens.
Next Steps
- Capture security investigations in
10-topics/platform/until a dedicated10-topics/security/stream is created. - Update security architecture notes under
20-architecture/security/. - Add security ADRs under Platform ADRs.
- Keep security facts current in
40-facts/.