Operational patterns

Start small. Externalize authority as the deployment grows.

Atlas uses the same identity and policy model across evaluation, production, federation, and edge. The infrastructure changes: production separates durable state, cryptographic custody, trusted time, ingress, recovery, and observation.

Deployment selection

Choose the topology by authority and recovery needs.

The AIO container provides a fast, coherent evaluation and edge-demonstration footprint. Production Kubernetes and AWS patterns add high availability, separation of duties, external key custody, and independent recovery.

PatternBest fitState and custodyAvailability
AIO containerEvaluation, demonstrations, integration development, constrained single-node field useIntegrated services; configuration can bind external sourcesSingle-node unless protected by external operational procedures
Production KubernetesEnterprise and mission control planes requiring service separation and scaleExternal relational, graph, cache, queue, Vault/KMS/HSM, object storage, and time authoritiesMultiple replicas, zones, controlled upgrades, probes, disruption budgets
AWS production-shapedManaged infrastructure, regional operations, automated delivery and evidenceManaged database and load balancing with explicit KMS/HSM, secret, backup, log, and recovery custodyMulti-AZ with optional governed cross-region continuity
Federated nodesIndependent organizations or security domains that must exchange bounded identity contextEach node retains local state, issuer trust, policy, keys, audit, and enforcementAutonomous operation; exchange degrades independently
Edge / DDILDisconnected, intermittent, low-bandwidth, or mission-forward access decisionsPre-positioned signed policy, bounded local identity/evidence, queued reconciliationLocal continuity within explicit freshness and risk limits

Production authority model

Move critical authority out of the application container.

A production Atlas deployment names an owner, recovery path, and failure policy for every authority. Services may cache or derive state, but custody remains explicit.

DB

Durable data

External transactional database, graph where used, backups with separate custody, restore tests, migration governance, and point-in-time objectives.

KY

Keys and secrets

Vault, KMS, or HSM-backed roots; workload authentication; rotation, revocation, recovery, quorum, and evidence of active key state.

TM

Trusted time

Authenticated time sources and witnesses for token validity, evidence freshness, replay windows, event ordering, and offline decisions.

IN

Ingress and identity

Managed DNS, certificates, load balancing, DDoS controls, private service paths, mTLS, workload identity, and egress policy.

OB

Observation

Metrics, traces, logs, audit outbox, external security monitoring, alert ownership, data minimization, and retention.

RC

Recovery

Documented RTO/RPO, independent backups, cryptographic restoration, cross-region fencing, game days, and evidence-backed release rollback.

AWS reference shape

Managed services strengthen custody and preserve architectural clarity.

A production-shaped AWS topology places public ingress at managed load balancing, keeps workloads in private subnets, externalizes databases and secrets, and records delivery and operational evidence.

  • Edge and ingressRoute 53, ACM, WAF where required, ALB/NLB or managed Kubernetes ingress.
  • ComputeEKS or controlled container hosts with workload roles, immutable releases, probes, and deployment budgets.
  • StateRDS/Aurora-class PostgreSQL patterns, managed cache where appropriate, object storage, durable queues and external backup custody.
  • CryptographyKMS or CloudHSM-backed authority, Secrets Manager or Vault integration, certificate rotation, and signed release artifacts.
  • OperationsCloudWatch and security integrations, audit exports, release receipts, recovery automation, and cost guardrails.
AWS reference flow
EDGERoute 53 · ACM · WAF
INGRESSLoad balancer
ADMINPrivate operations path
Atlas service plane
Gateway & protocol servicesIdentity & policy servicesSession & governanceEvidence & federation
STATEManaged databases
CUSTODYKMS · HSM · Vault
PROOFLogs · backups · receipts

Edge and disconnected operations

Design the disconnected state before disconnection.

Edge continuity combines packaging with explicit policy, freshness, and authority limits. Atlas defines which subjects, resources, credentials, evidence, policy versions, and revocation windows are valid locally—and what must stop when a limit is reached.

01

Scope

Minimize replicated identities, attributes, keys, policies, and resources to the local mission.

02

Sign

Bind policy, trust anchors, revocation posture, model status, and configuration to verifiable releases.

03

Bound

Set freshness, replay, risk, rate, session, privilege, and expiration limits for offline decisions.

04

Reconcile

Verify queued records, resolve authority conflicts, and make post-reconnect decisions observable.

Operational lifecycle

Production is a maintained state.

Deployment is complete only when operators can detect drift, rotate authority, recover service and state, revoke a release, and show the evidence.

Preflight

Validate configuration, dependencies, authority custody, database migrations, trust anchors, time, DNS, certificates, and backup readiness.

Release

Promote signed, immutable artifacts through a controlled wave; bind build, policy, schema, and infrastructure versions to a receipt.

Verify

Run protocol, identity, policy, negative, availability, and operational checks through the deployed ingress and authority paths.

Observe

Monitor service health and the correctness signals: stale evidence, issuer status, policy divergence, queue lag, failed reconciliation, and authorization anomalies.

Recover

Exercise rollback, secret and key rotation, database restore, region isolation, backup custody, and administrative break-glass with review.