Reference Architecture Diagram + Narrative (petascale flows + integrity by design)
┌─────────────────────────────────────────────┐
│ ROLES & NODES │
PIs │ Researchers │ Lab Techs │ Sysadmins │ Data Stewards │ Compliance/IRB
└──────────┬──────────┬──────────┬────────────┘
│ │ │
▼ ▼ ▼
┌────────────────────────────────────────────────────────────────┐
│ INSTRUMENTS / LAB SITES / FIELD STATIONS (EDGES) │
│ • Sequencers • Microscopes • Telescopes • Sensors • Rovers │
│ • SD-Branch/SD-WAN (dual underlays; ZTP) │
│ • VRFs/VLANs: Instrument | Compute | Admin | Guest │
│ • Local cache / checksum agent (store-and-forward) │
└───────────────┬───────────────────────────────┬────────────────┘
│ │
DIA / MetroE / IX (NREN peering) │ LTE/5G / SAT (remote)
Internet2/GEANT/APAN where available │ (policy-based failover)
▼ ▼
┌────────────────────────────────────────────────────────┐
│ TRANSPORT / SECURITY FABRIC │
│ SD-WAN overlays ║ MPLS / Waves (10/100/400G) ║ IX │
│ SASE/SSE POPs: ZTNA | SWG | CASB | FWaaS | DLP │
│ (geo/data-sovereignty, collaboration allow-lists) │
└───────────────┬──────────────────────────────┬────────┘
│ │
▼ ▼
┌──────────────────────────────────────┐ ┌──────────────────────────────────┐
│ CAMPUS / REGIONAL HPC CORES │ │ CLOUD ON-RAMPS (DX/ER/GCI)│
│ • Login/HPC gateways • IdP/SSO/MFA │ │ • Cloud HPC Queues • Data Lake │
│ • Schedulers: Slurm/PBS/K8s │ │ • Analytics/AI • Archive tiers │
│ • Storage: Lustre/GPFS/Object │ └───────────────┬──────────────────┘
│ • HSM/KMS • PAM • SIEM/NDR │ │
└───────────────┬───────────┬──────────┘ │
│ │ │
▼ ▼ ▼
┌───────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ COMPUTE NODES │ │ WORKFLOW ORCHESTRATION │ │ DATA LAKE (Hot→Cold) │
│ CPU/GPU/DPUs │ │ Nextflow | Cromwell │ │ Hot: Obj Warm: DW │
│ MPI/Containers │ │ Airflow | Argo/K8s │ │ Cold: Tape | Immutable│
└───────────────────┘ └─────────────────────────┘ └─────────────────────────┘
Integrity / Observability bus ──► NOC/SOC + AIOps (throughput/latency) + ITSM/CMDB + FAIR/GDPR dashboards
Narrative (how high-throughput science stays fast, verifiable, and lawful)
1) Purpose & posture
- Objective: Move, compute, and curate petascale datasets with deterministic throughput, cryptographic integrity, and FAIR/GDPR/IRB compliance across campuses, consortia, and clouds.
- Posture: Zero-Trust everywhere, integrity-by-design (checksums at source, verified at sinks), and data-sovereignty aware routing/storage.
2) Edge & transport (syntax of the pipeline)
- Lab/field edges use SD-Branch/SD-WAN with dual underlays (DIA/MetroE/IX; LTE/5G/SAT for remote), ZTP turn-ups, and VRFs separating instruments/computes/admin/guest.
- NREN peering (Internet2/GEANT/APAN) and/or optical waves (10/100/400G) provide the high-capacity spine; SD-WAN policies steer bulk flows on the fastest/cleanest paths.
3) Access & collaboration controls (semantics preserved)
- SASE/SSE POPs enforce ZTNA (user+device+role+geofence), SWG/CASB/FWaaS/DLP for SaaS/share links, and allow-lists for partner ASNs/labs.
- IdP/SSO/MFA gates HPC gateways and workflow UIs; PAM protects admin functions.
4) HPC cores, schedulers & storage (where meaning is computed)
- HPC cores expose login/gateway nodes into Slurm/PBS/Kubernetes schedulers;
- Storage hierarchy: Lustre/GPFS for scratch, object for hot collaboration, warm DW for curated products, cold tape/immutable for long-term provenance.
5) Workflows & reproducibility
- Orchestrators (Nextflow, Cromwell, Airflow, Argo) bind containers (OCI/Singularity) and environment hashes to jobs; every step emits checksums, manifest files, and provenance metadata (FAIR).
- Container registries are signed; results are stamped with time and input digests for auditability.
6) Cloud burst & data lake (elastic grammar)
- Private on-ramps (DX/ER/GCI) provide pinned, high-throughput links to cloud HPC queues, analytics/AI services, and multi-tier data lakes.
- Policies ensure jurisdictional pinning and cost guards (egress budgets, lifecycle moves Hot→Warm→Cold).
7) Resilience patterns (meaning under stress)
- Link failover: SD-WAN shifts bulk transfers to secondary waves/MPLS; rate-limited DIA/IX is the last resort.
- Store-and-forward: Edge caches queue instrument data; ordered replay reconciles checksums on recovery.
- Burst DR: Jobs resubmitted to cloud queues; data lake replicas mounted read-only to preserve provenance.
8) Security, privacy & evidence (pragmatics)
- HSM/KMS manages keys; WORM/immutable stores secure raw/derived datasets; SIEM/NDR/SOAR automates containment (revoke ZTNA, isolate VRF, rotate tokens).
- FAIR/GDPR/IRB dashboards expose access trails, consent status, and retention clocks; automated DSAR search assists compliance teams.
9) Reference KPIs (science-grade)
- Sustained throughput: ≥80% of link line-rate (100/400G paths).
- End-to-end integrity: 100% checksum match on ingest/landings.
- Failover: <60 s path switch; Job resubmission success: ≥99%.
- DR: RTO ≤4 h (HPC queues) / RPO ≤15 min (lake metadata).
- Compliance: FAIR completeness ≥95%; GDPR/IRB incident MTTR ≤2 h.
10) Minimal BOM (aligned to your matrix)
SD-WAN/SD-Branch; DIA/MetroE/IX; Waves (10/100/400G) / MPLS; SASE/SSE (ZTNA/SWG/CASB/FWaaS/DLP); HPC gateways; Schedulers (Slurm/PBS/K8s); Storage (Lustre/GPFS/Object/Tape+WORM); Cloud on-ramps; Workflow engines; HSM/KMS; PAM; SIEM/NDR/SOAR; AIOps; ITSM/CMDB; FAIR/GDPR dashboards.