DRAFT: Network Pattern

Tags azure Pattern

Purpose

The Network Pattern defines the approved reference architecture for networking and connectivity within University-managed technology environments.

This pattern describes how workloads, platforms, enterprise services, shared services, integrations, and external systems communicate through approved networking architectures.

The pattern provides a common networking architecture supporting workload hosting, service integration, operational support, scalability, and platform sustainability.

Applicable standards, workload classifications, data classifications, and obligations determine the networking controls implemented within this architecture.

Use Cases

This pattern applies when:

  • Deploying applications
  • Deploying databases
  • Deploying platform services
  • Deploying integrations
  • Deploying shared services
  • Connecting workloads to enterprise services
  • Connecting workloads to external systems
  • Connecting workloads within Landing Zones
  • Providing networking capabilities for hosted workloads

This pattern does not define:

  • Network security requirements
  • Firewall requirements
  • Ingress requirements
  • Egress requirements
  • Private endpoint requirements
  • Encryption requirements
  • Monitoring requirements
  • Connectivity approval processes
  • Technology-specific implementation requirements

Pattern Application

The Network Pattern provides a common networking architecture for University-managed workloads.

Innovation Workloads

Innovation workloads may implement simplified networking architectures appropriate for experimentation, evaluation, pilot initiatives, and research activities.

Enterprise Workloads

Enterprise workloads implement the Network Pattern using the standard enterprise networking baseline.

Regulated Workloads

Regulated workloads implement the Network Pattern using additional architectural constraints, workload-isolation requirements, and obligation-specific extensions.

Design Principles

Network as Shared Infrastructure

Networking capabilities support multiple workloads through reusable and centrally managed architecture components.

Connectivity by Design

Network architectures are intentionally designed to support workload communications, integrations, platform services, enterprise services, and external systems.

Boundary-Based Architecture

Network architectures establish logical boundaries between workloads, platforms, enterprise capabilities, and external systems.

Composable Architecture

Network architectures are assembled from reusable components supporting multiple workload classifications and hosting patterns.

Shared-Service Integration

Network architectures support consumption of approved enterprise services without requiring duplication of network capabilities within each workload environment.

Extensibility

The Network Pattern supports workload-specific and obligation-specific networking extensions without requiring duplication of the common networking architecture.

Logical Architecture

Workload
        |
        +-- Applications
        +-- Databases
        +-- Platform Services
        +-- Integration Services
        |
        v

Network Architecture
        |
        +-- Workload Connectivity
        +-- Shared Service Connectivity
        +-- Enterprise Connectivity
        +-- External Connectivity
        |
        v

Enterprise Services
        |
        +-- Identity Services
        +-- Monitoring Services
        +-- Governance Services
        +-- Management Services
        +-- Automation Services

        and/or

External Systems

Network Architecture Components

Network Boundary Component

Provides the logical boundaries used to separate workloads, platforms, shared services, enterprise services, and external connectivity domains.

Workload Connectivity Component

Provides communication architecture supporting interaction between workload applications, data platforms, services, and integrations.

Shared-Service Connectivity Component

Provides communication architecture supporting interaction between workloads and approved shared enterprise services.

Enterprise Connectivity Component

Provides communication architecture supporting interaction between workloads and enterprise technology services.

External Connectivity Component

Provides communication architecture supporting interaction between workloads and approved external systems, cloud services, vendors, researchers, partners, and collaborators.

Routing Component

Provides communication and traffic-routing architecture supporting workload, enterprise, shared-service, and external communications.

Network Monitoring Integration Component

Provides integration with monitoring, audit, operational, investigation, and governance services.

Communication Models

Application-to-Application

Applications communicate with other applications through approved workload communication paths.

Application-to-Data

Applications communicate with databases, storage platforms, and data services through approved workload communication paths.

Platform-to-Workload

Platform services communicate with workloads to provide identity, monitoring, governance, management, security, automation, and operational capabilities.

Workload-to-Enterprise Service

Workloads communicate with approved enterprise services through enterprise communication paths.

Workload-to-Shared Service

Workloads communicate with approved shared services through shared-service communication paths.

Workload-to-External Service

Workloads communicate with approved external services through approved external communication paths.

Integration Communication

Integrations communicate with applications, services, data platforms, enterprise services, and external systems through approved integration communication paths.

Network Boundaries

Workload Boundary

The workload boundary contains workload resources, services, integrations, and workload-specific communications.

Platform Boundary

The platform boundary contains shared hosting, operational, governance, identity, monitoring, automation, and management capabilities.

Shared-Service Boundary

The shared-service boundary contains reusable enterprise capabilities supporting multiple workloads.

Enterprise Boundary

The enterprise boundary contains centrally operated services supporting multiple technology environments.

External Boundary

The external boundary represents communication with systems outside University operational control.

Connectivity Integration

Identity Integration

The Network Pattern provides communication paths supporting enterprise identity services, authentication processes, workload identities, and federated trust relationships.

Monitoring Integration

The Network Pattern provides communication paths supporting monitoring, telemetry, logging, reporting, investigation, and audit capabilities.

Governance Integration

The Network Pattern supports communication with governance, inventory, compliance, operational, and management capabilities.

Shared-Service Integration

The Network Pattern supports communication between workloads and approved enterprise shared services.

Landing Zone Integration

Landing Zones implement this pattern through approved hosting architectures and reusable network components.

Operational Responsibilities

Network Engineering

Network Engineering owns enterprise network architecture, routing architecture, connectivity architecture, and reusable network capabilities.

Platform Engineering

Platform Engineering owns cloud-networking architecture, reusable deployment components, Landing Zone networking integration, and onboarding automation.

Information Security

Information Security provides security requirements consumed by network implementations and participates in architecture reviews and investigations.

Enterprise Service Providers

Enterprise service providers own connectivity and networking requirements associated with enterprise identity, monitoring, governance, automation, management, and shared-service capabilities.

Workload Teams

Workload teams own workload-specific communication requirements, connectivity requirements, integration architecture, and workload operational support.

Automation Pattern

Network architectures should be implemented through approved platform automation whenever practical.

Automation may support:

  • Network provisioning
  • Workload onboarding
  • Enterprise-service integration
  • Shared-service integration
  • Monitoring integration
  • Identity integration
  • Landing Zone integration
  • Network configuration validation
Network Definition
        |
        +-- Workload Connectivity
        +-- Enterprise Connectivity
        +-- Shared Service Connectivity
        +-- External Connectivity
        |
        v

Reusable Network Components
        |
        v

Landing Zone or Workload Deployment
        |
        v

Integrated Network Architecture

Network automation components should be reusable across multiple hosting patterns, workload classifications, and platform products.

Reference Architecture Outcomes

A workload implementing this pattern should provide:

  • Workload connectivity
  • Enterprise-service connectivity
  • Shared-service connectivity
  • External-system connectivity
  • Defined architectural boundaries
  • Identity-service integration
  • Monitoring-service integration
  • Governance-service integration
  • Repeatable onboarding
  • Reusable network architecture
  • Operational supportability
  • Support for workload and obligation-specific extensions

Exceptions

Exceptions to this pattern must follow approved architecture governance and information security exception processes.

Approved exceptions must be periodically reviewed and must not be treated as permanent architecture patterns.