Establish identity and scope
Identify site edge compute, Service Endlets, proxy and controlled jump-host workflows, telemetry; validate participating Endlets before admission.
Confidential site services · Architecture
Run approved proxy, telemetry, controlled jump-host, and confidential workloads without separate fixed-function appliances.
Primary capability
Service Endlet
How it works
Consolidate approved site services under one identity, policy, and lifecycle model.
Identify site edge compute, Service Endlets, proxy and controlled jump-host workflows, telemetry; validate participating Endlets before admission.
validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path
Review Endlet lifecycle, service identity, access policy, workload state, telemetry with the responsible teams.
Architecture flow
Inputs
site edge compute, Service Endlets, proxy and controlled jump-host workflows, telemetry, confidential workloads, central services
Path
validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path
Evidence
Endlet lifecycle, service identity, access policy, workload state, telemetry, protected paths, and revocation
Quick answers
validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path
Endlet lifecycle, service identity, access policy, workload state, telemetry, protected paths, and revocation
site operations, platform engineering, network operations, OT security
Continue the evaluation path
Determine whether selected site services can run locally with controlled access, observable state, and centralized lifecycle governance.
Continue to Evaluation