# Reference architecture (/docs/foundation/reference-architecture)



The Foundation layer is not a single component. It is a platform architecture made of several cooperating domains.

## Architecture view [#architecture-view]

<Mermaid
  chart="flowchart TD
    U[&#x22;Users and client systems&#x22;] --> DNS[&#x22;External DNS&#x22;]
    DNS --> LB[&#x22;Load balancer or cloud ingress&#x22;]
    LB --> GW[&#x22;Gateway API&#x22;]

    GW --> ID[&#x22;Identity and Access&#x22;]
    ID --> KC[&#x22;Keycloak&#x22;]
    ID --> FGA[&#x22;OpenFGA&#x22;]
    ID --> BAO[&#x22;OpenBao&#x22;]

    GW --> RUN[&#x22;Foundation Services&#x22;]
    RUN --> INF[&#x22;Inference&#x22;]
    RUN --> WF[&#x22;Workflows&#x22;]
    RUN --> DATA[&#x22;Operational Data&#x22;]
    RUN --> TEN[&#x22;Tenant lifecycle&#x22;]

    INF --> KS[&#x22;KServe&#x22;]
    INF --> VLLM[&#x22;vLLM&#x22;]
    INF --> KAI[&#x22;KAI Scheduler&#x22;]
    INF --> AIGW[&#x22;Envoy AI Gateway&#x22;]

    WF --> AE[&#x22;Argo Events&#x22;]
    WF --> TMP[&#x22;Temporal&#x22;]

    DATA --> PG[&#x22;CloudNativePG&#x22;]
    DATA --> PGA[&#x22;PgAdmin&#x22;]
    DATA --> OBJ[&#x22;S3-compatible object storage&#x22;]

    TEN --> PT[&#x22;PlatformTenant resource&#x22;]
    PT --> TENOP[&#x22;BSQAI Tenant Operator&#x22;]
    TENOP --> KC
    TENOP --> PG
    TENOP --> OBJ
    TENOP --> NS[&#x22;Tenant namespaces and quotas&#x22;]

    RUN --> OBS[&#x22;Observability&#x22;]
    OBS --> GRAF[&#x22;Grafana&#x22;]
    OBS --> PROM[&#x22;Prometheus&#x22;]
    OBS --> LOKI[&#x22;Loki&#x22;]
    OBS --> ALLOY[&#x22;Alloy Gateway and agents&#x22;]
    OBS --> TEMPO[&#x22;Tempo&#x22;]

    GIT[&#x22;Git repository&#x22;] --> CD[&#x22;Argo CD&#x22;]
    REG[&#x22;OCI registry&#x22;] --> CD
    CD --> APPS[&#x22;common, coreai, inference, and proai&#x22;]
    APPS --> RUN"
/>

## Capability domains [#capability-domains]

| Domain           | Main role                                                                    | Example components                                                      |
| ---------------- | ---------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| Network          | Expose, publish, and route traffic                                           | Gateway API (Envoy Gateway), infrastructure load balancer, External DNS |
| Security         | Authenticate, authorize, and protect secrets                                 | Keycloak, OpenFGA, OpenBao, cert-manager                                |
| Inference        | Run production model workloads                                               | KServe, vLLM, KAI Scheduler, Envoy AI Gateway                           |
| Workflow engines | Execute event-driven and durable processes                                   | Argo Events, Temporal                                                   |
| Data plane       | Store operational state and artifacts                                        | CloudNativePG, PgAdmin, Rook-Ceph or external S3-compatible storage     |
| Tenant lifecycle | Reconcile tenant identity, namespace, quota, storage, and database resources | BSQAI Tenant Operator, `PlatformTenant`                                 |
| Observability    | Collect and explore platform signals                                         | Grafana, Prometheus, Loki, Alloy, Tempo                                 |
| Delivery         | Move artifacts and desired state into the cluster                            | Git repository, OCI registry, Argo CD                                   |

## Design intent [#design-intent]

This architecture allows BullSequana AI to keep infrastructure concerns explicit and reusable. Higher layers can then consume Foundation services without rebuilding the same operational patterns for each product area.
