Reference architecture
A high-level view of how Foundation capabilities fit together.
The Foundation layer is not a single component. It is a platform architecture made of several cooperating domains.
Architecture view
Capability domains
| Domain | Main role | Example components |
|---|---|---|
| Network | Expose, publish, and route traffic | Gateway API (Envoy Gateway), infrastructure load balancer, External DNS |
| Security | Authenticate, authorize, and protect secrets | Keycloak, OpenFGA, OpenBao, cert-manager |
| Inference | Run production model workloads | KServe, vLLM, KAI Scheduler, Envoy AI Gateway |
| Workflow engines | Execute event-driven and durable processes | Argo Events, Temporal |
| Data plane | Store operational state and artifacts | CloudNativePG, PgAdmin, Rook-Ceph or external S3-compatible storage |
| Tenant lifecycle | Reconcile tenant identity, namespace, quota, storage, and database resources | BSQAI Tenant Operator, PlatformTenant |
| Observability | Collect and explore platform signals | Grafana, Prometheus, Loki, Alloy, Tempo |
| Delivery | Move artifacts and desired state into the cluster | Git repository, OCI registry, Argo CD |
Design intent
This architecture allows BullSequana AI to keep infrastructure concerns explicit and reusable. Higher layers can then consume Foundation services without rebuilding the same operational patterns for each product area.