21PacketsContact Us
Mining

Confidential site services · Architecture

Map the service path for confidential site services.

Run approved proxy, telemetry, controlled jump-host, and confidential workloads without separate fixed-function appliances.

validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path. Evaluation evidence includes Endlet lifecycle, service identity, access policy, workload state, telemetry, protected paths, and revocation.Mining · Service EndletConfidential site servicesVerified service path and review points01ValidatedService Endlet02Approved serviceprofile03Local proxy,controlledjump-host,04Protected fabricpathEvaluation evidenceEndlet lifecycle · service identity · access policyEach control point and result is verified against the selected environment.

Primary capability

Service Endlet

How it works

Trace the protected service path from admission to evidence.

Consolidate approved site services under one identity, policy, and lifecycle model.

01

Establish identity and scope

Identify site edge compute, Service Endlets, proxy and controlled jump-host workflows, telemetry; validate participating Endlets before admission.

02

Build the protected service path

validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path

03

Capture decision evidence

Review Endlet lifecycle, service identity, access policy, workload state, telemetry with the responsible teams.

Architecture flow

Trace the protected service path and its control points.

01

validated Service Endlet

02

approved service profile

03

local proxy, controlled jump-host, telemetry, or confidential execution

04

protected fabric path

Inputs

site edge compute, Service Endlets, proxy and controlled jump-host workflows, telemetry, confidential workloads, central services

Path

validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path

Evidence

Endlet lifecycle, service identity, access policy, workload state, telemetry, protected paths, and revocation

Quick answers

Confidential site services FAQs

Which technical path should the team review?+

validated Service Endlet → approved service profile → local proxy, controlled jump-host, telemetry, or confidential execution → protected fabric path

Which evidence should reviewers collect?+

Endlet lifecycle, service identity, access policy, workload state, telemetry, protected paths, and revocation

Who should review the architecture?+

site operations, platform engineering, network operations, OT security

Continue the evaluation path

Evaluate confidential site services with a representative scope.

Determine whether selected site services can run locally with controlled access, observable state, and centralized lifecycle governance.

Continue to Evaluation