Durable data
External transactional database, graph where used, backups with separate custody, restore tests, migration governance, and point-in-time objectives.
Operational patterns
Atlas uses the same identity and policy model across evaluation, production, federation, and edge. The infrastructure changes: production separates durable state, cryptographic custody, trusted time, ingress, recovery, and observation.
Deployment selection
The AIO container provides a fast, coherent evaluation and edge-demonstration footprint. Production Kubernetes and AWS patterns add high availability, separation of duties, external key custody, and independent recovery.
| Pattern | Best fit | State and custody | Availability |
|---|---|---|---|
| AIO container | Evaluation, demonstrations, integration development, constrained single-node field use | Integrated services; configuration can bind external sources | Single-node unless protected by external operational procedures |
| Production Kubernetes | Enterprise and mission control planes requiring service separation and scale | External relational, graph, cache, queue, Vault/KMS/HSM, object storage, and time authorities | Multiple replicas, zones, controlled upgrades, probes, disruption budgets |
| AWS production-shaped | Managed infrastructure, regional operations, automated delivery and evidence | Managed database and load balancing with explicit KMS/HSM, secret, backup, log, and recovery custody | Multi-AZ with optional governed cross-region continuity |
| Federated nodes | Independent organizations or security domains that must exchange bounded identity context | Each node retains local state, issuer trust, policy, keys, audit, and enforcement | Autonomous operation; exchange degrades independently |
| Edge / DDIL | Disconnected, intermittent, low-bandwidth, or mission-forward access decisions | Pre-positioned signed policy, bounded local identity/evidence, queued reconciliation | Local continuity within explicit freshness and risk limits |
Production authority model
A production Atlas deployment names an owner, recovery path, and failure policy for every authority. Services may cache or derive state, but custody remains explicit.
External transactional database, graph where used, backups with separate custody, restore tests, migration governance, and point-in-time objectives.
Vault, KMS, or HSM-backed roots; workload authentication; rotation, revocation, recovery, quorum, and evidence of active key state.
Authenticated time sources and witnesses for token validity, evidence freshness, replay windows, event ordering, and offline decisions.
Managed DNS, certificates, load balancing, DDoS controls, private service paths, mTLS, workload identity, and egress policy.
Metrics, traces, logs, audit outbox, external security monitoring, alert ownership, data minimization, and retention.
Documented RTO/RPO, independent backups, cryptographic restoration, cross-region fencing, game days, and evidence-backed release rollback.
AWS reference shape
A production-shaped AWS topology places public ingress at managed load balancing, keeps workloads in private subnets, externalizes databases and secrets, and records delivery and operational evidence.
Edge and disconnected operations
Edge continuity combines packaging with explicit policy, freshness, and authority limits. Atlas defines which subjects, resources, credentials, evidence, policy versions, and revocation windows are valid locally—and what must stop when a limit is reached.
Minimize replicated identities, attributes, keys, policies, and resources to the local mission.
Bind policy, trust anchors, revocation posture, model status, and configuration to verifiable releases.
Set freshness, replay, risk, rate, session, privilege, and expiration limits for offline decisions.
Verify queued records, resolve authority conflicts, and make post-reconnect decisions observable.
Operational lifecycle
Deployment is complete only when operators can detect drift, rotate authority, recover service and state, revoke a release, and show the evidence.
Validate configuration, dependencies, authority custody, database migrations, trust anchors, time, DNS, certificates, and backup readiness.
Promote signed, immutable artifacts through a controlled wave; bind build, policy, schema, and infrastructure versions to a receipt.
Run protocol, identity, policy, negative, availability, and operational checks through the deployed ingress and authority paths.
Monitor service health and the correctness signals: stale evidence, issuer status, policy divergence, queue lag, failed reconciliation, and authorization anomalies.
Exercise rollback, secret and key rotation, database restore, region isolation, backup custody, and administrative break-glass with review.