Purpose
The Network Pattern defines the approved reference architecture for networking and connectivity within University-managed technology environments.
This pattern describes how workloads, platforms, enterprise services, shared services, integrations, and external systems communicate through approved networking architectures.
The pattern provides a common networking architecture supporting workload hosting, service integration, operational support, scalability, and platform sustainability.
Applicable standards, workload classifications, data classifications, and obligations determine the networking controls implemented within this architecture.
Use Cases
This pattern applies when:
- Deploying applications
- Deploying databases
- Deploying platform services
- Deploying integrations
- Deploying shared services
- Connecting workloads to enterprise services
- Connecting workloads to external systems
- Connecting workloads within Landing Zones
- Providing networking capabilities for hosted workloads
This pattern does not define:
- Network security requirements
- Firewall requirements
- Ingress requirements
- Egress requirements
- Private endpoint requirements
- Encryption requirements
- Monitoring requirements
- Connectivity approval processes
- Technology-specific implementation requirements
Pattern Application
The Network Pattern provides a common networking architecture for University-managed workloads.
Innovation Workloads
Innovation workloads may implement simplified networking architectures appropriate for experimentation, evaluation, pilot initiatives, and research activities.
Enterprise Workloads
Enterprise workloads implement the Network Pattern using the standard enterprise networking baseline.
Regulated Workloads
Regulated workloads implement the Network Pattern using additional architectural constraints, workload-isolation requirements, and obligation-specific extensions.
Design Principles
Network as Shared Infrastructure
Networking capabilities support multiple workloads through reusable and centrally managed architecture components.
Connectivity by Design
Network architectures are intentionally designed to support workload communications, integrations, platform services, enterprise services, and external systems.
Boundary-Based Architecture
Network architectures establish logical boundaries between workloads, platforms, enterprise capabilities, and external systems.
Composable Architecture
Network architectures are assembled from reusable components supporting multiple workload classifications and hosting patterns.
Shared-Service Integration
Network architectures support consumption of approved enterprise services without requiring duplication of network capabilities within each workload environment.
Extensibility
The Network Pattern supports workload-specific and obligation-specific networking extensions without requiring duplication of the common networking architecture.
Logical Architecture
Workload
|
+-- Applications
+-- Databases
+-- Platform Services
+-- Integration Services
|
v
Network Architecture
|
+-- Workload Connectivity
+-- Shared Service Connectivity
+-- Enterprise Connectivity
+-- External Connectivity
|
v
Enterprise Services
|
+-- Identity Services
+-- Monitoring Services
+-- Governance Services
+-- Management Services
+-- Automation Services
and/or
External Systems
Network Architecture Components
Network Boundary Component
Provides the logical boundaries used to separate workloads, platforms, shared services, enterprise services, and external connectivity domains.
Workload Connectivity Component
Provides communication architecture supporting interaction between workload applications, data platforms, services, and integrations.
Shared-Service Connectivity Component
Provides communication architecture supporting interaction between workloads and approved shared enterprise services.
Enterprise Connectivity Component
Provides communication architecture supporting interaction between workloads and enterprise technology services.
External Connectivity Component
Provides communication architecture supporting interaction between workloads and approved external systems, cloud services, vendors, researchers, partners, and collaborators.
Routing Component
Provides communication and traffic-routing architecture supporting workload, enterprise, shared-service, and external communications.
Network Monitoring Integration Component
Provides integration with monitoring, audit, operational, investigation, and governance services.
Communication Models
Application-to-Application
Applications communicate with other applications through approved workload communication paths.
Application-to-Data
Applications communicate with databases, storage platforms, and data services through approved workload communication paths.
Platform-to-Workload
Platform services communicate with workloads to provide identity, monitoring, governance, management, security, automation, and operational capabilities.
Workload-to-Enterprise Service
Workloads communicate with approved enterprise services through enterprise communication paths.
Workload-to-Shared Service
Workloads communicate with approved shared services through shared-service communication paths.
Workload-to-External Service
Workloads communicate with approved external services through approved external communication paths.
Integration Communication
Integrations communicate with applications, services, data platforms, enterprise services, and external systems through approved integration communication paths.
Network Boundaries
Workload Boundary
The workload boundary contains workload resources, services, integrations, and workload-specific communications.
Platform Boundary
The platform boundary contains shared hosting, operational, governance, identity, monitoring, automation, and management capabilities.
Shared-Service Boundary
The shared-service boundary contains reusable enterprise capabilities supporting multiple workloads.
Enterprise Boundary
The enterprise boundary contains centrally operated services supporting multiple technology environments.
External Boundary
The external boundary represents communication with systems outside University operational control.
Connectivity Integration
Identity Integration
The Network Pattern provides communication paths supporting enterprise identity services, authentication processes, workload identities, and federated trust relationships.
Monitoring Integration
The Network Pattern provides communication paths supporting monitoring, telemetry, logging, reporting, investigation, and audit capabilities.
Governance Integration
The Network Pattern supports communication with governance, inventory, compliance, operational, and management capabilities.
Shared-Service Integration
The Network Pattern supports communication between workloads and approved enterprise shared services.
Landing Zone Integration
Landing Zones implement this pattern through approved hosting architectures and reusable network components.
Operational Responsibilities
Network Engineering
Network Engineering owns enterprise network architecture, routing architecture, connectivity architecture, and reusable network capabilities.
Platform Engineering
Platform Engineering owns cloud-networking architecture, reusable deployment components, Landing Zone networking integration, and onboarding automation.
Information Security
Information Security provides security requirements consumed by network implementations and participates in architecture reviews and investigations.
Enterprise Service Providers
Enterprise service providers own connectivity and networking requirements associated with enterprise identity, monitoring, governance, automation, management, and shared-service capabilities.
Workload Teams
Workload teams own workload-specific communication requirements, connectivity requirements, integration architecture, and workload operational support.
Automation Pattern
Network architectures should be implemented through approved platform automation whenever practical.
Automation may support:
- Network provisioning
- Workload onboarding
- Enterprise-service integration
- Shared-service integration
- Monitoring integration
- Identity integration
- Landing Zone integration
- Network configuration validation
Network Definition
|
+-- Workload Connectivity
+-- Enterprise Connectivity
+-- Shared Service Connectivity
+-- External Connectivity
|
v
Reusable Network Components
|
v
Landing Zone or Workload Deployment
|
v
Integrated Network Architecture
Network automation components should be reusable across multiple hosting patterns, workload classifications, and platform products.
Reference Architecture Outcomes
A workload implementing this pattern should provide:
- Workload connectivity
- Enterprise-service connectivity
- Shared-service connectivity
- External-system connectivity
- Defined architectural boundaries
- Identity-service integration
- Monitoring-service integration
- Governance-service integration
- Repeatable onboarding
- Reusable network architecture
- Operational supportability
- Support for workload and obligation-specific extensions
Exceptions
Exceptions to this pattern must follow approved architecture governance and information security exception processes.
Approved exceptions must be periodically reviewed and must not be treated as permanent architecture patterns.