Define the operating scope
Include Route Endlets, Service Endlets, identity services, machine-state signals in a representative operating scope.
Continuously validated nodes · Briefing
Admit machines and workloads only after identity and state satisfy policy, then continuously reassess participating nodes.
Primary capability
EdgeControl
Operational outcome
Restrict fabric participation to machines and workloads that satisfy the defined identity and state policy.
Include Route Endlets, Service Endlets, identity services, machine-state signals in a representative operating scope.
machine identity and state → policy evaluation → fabric admission or denial → continuous reassessment → revocation when policy is no longer satisfied
Determine whether admission, continuous reassessment, and revocation behave as defined for representative compliant and noncompliant nodes.
Outcome readiness
Give network, security, and operational teams one service path to review and one decision to make.
Inputs
Route Endlets, Service Endlets, identity services, machine-state signals, admission policy, EdgeControl
Path
machine identity and state → policy evaluation → fabric admission or denial → continuous reassessment → revocation when policy is no longer satisfied
Evidence
validation evidence, authorization decisions, policy release, key release, route participation, re-attestation, and revocation events
Quick answers
Route Endlets, Service Endlets, identity services, machine-state signals, admission policy, EdgeControl
Restrict fabric participation to machines and workloads that satisfy the defined identity and state policy.
Determine whether admission, continuous reassessment, and revocation behave as defined for representative compliant and noncompliant nodes.
Continue the evaluation path
Determine whether admission, continuous reassessment, and revocation behave as defined for representative compliant and noncompliant nodes.
Continue to Architecture