Establish identity and scope
Identify field edge compute, Service Endlets, approved workloads, data sources; validate participating Endlets before admission.
Confidential edge services · Architecture
Run approved field services on governed Service Endlets while keeping workload identity, network access, and lifecycle under policy.
Primary capability
Trusted Execution
How it works
Run selected services near field operations while retaining centralized identity, access, and lifecycle control.
Identify field edge compute, Service Endlets, approved workloads, data sources; validate participating Endlets before admission.
validated Service Endlet → approved workload profile → local execution or confidential environment → policy-controlled fabric path → command or cloud service
Review attestation, workload identity, key release, execution state, service reachability with the responsible teams.
Architecture flow
Inputs
field edge compute, Service Endlets, approved workloads, data sources, key services, command or cloud services
Path
validated Service Endlet → approved workload profile → local execution or confidential environment → policy-controlled fabric path → command or cloud service
Evidence
attestation, workload identity, key release, execution state, service reachability, path state, and revocation behavior
Quick answers
validated Service Endlet → approved workload profile → local execution or confidential environment → policy-controlled fabric path → command or cloud service
attestation, workload identity, key release, execution state, service reachability, path state, and revocation behavior
mission system owners, platform engineering, cyber defense, data owners
Continue the evaluation path
Determine whether the selected workload can run at the field edge with the required access policy, observability, and revocation controls.
Continue to Evaluation