Reference architecture

A high-level view of how Foundation capabilities fit together.

Agentic Friendly

The Foundation layer is not a single component. It is a platform architecture made of several cooperating domains.

Architecture view

Capability domains

DomainMain roleExample components
NetworkExpose, publish, and route trafficGateway API (Envoy Gateway), infrastructure load balancer, External DNS
SecurityAuthenticate, authorize, and protect secretsKeycloak, OpenFGA, OpenBao, cert-manager
InferenceRun production model workloadsKServe, vLLM, KAI Scheduler, Envoy AI Gateway
Workflow enginesExecute event-driven and durable processesArgo Events, Temporal
Data planeStore operational state and artifactsCloudNativePG, PgAdmin, Rook-Ceph or external S3-compatible storage
Tenant lifecycleReconcile tenant identity, namespace, quota, storage, and database resourcesBSQAI Tenant Operator, PlatformTenant
ObservabilityCollect and explore platform signalsGrafana, Prometheus, Loki, Alloy, Tempo
DeliveryMove artifacts and desired state into the clusterGit repository, OCI registry, Argo CD

Design intent

This architecture allows BullSequana AI to keep infrastructure concerns explicit and reusable. Higher layers can then consume Foundation services without rebuilding the same operational patterns for each product area.

On this page