Architecture 13 — Research HPC & Data Lake (High-Throughput Science)

Reference Architecture Diagram + Narrative (petascale flows + integrity by design)

                             ┌─────────────────────────────────────────────┐
                             │                ROLES & NODES               │
 PIs │ Researchers │ Lab Techs │ Sysadmins │ Data Stewards │ Compliance/IRB
                             └──────────┬──────────┬──────────┬────────────┘
                                        │          │          │
                                        ▼          ▼          ▼
           ┌────────────────────────────────────────────────────────────────┐
           │        INSTRUMENTS / LAB SITES / FIELD STATIONS (EDGES)        │
           │  • Sequencers • Microscopes • Telescopes • Sensors • Rovers     │
           │  • SD-Branch/SD-WAN (dual underlays; ZTP)                       │
           │  • VRFs/VLANs: Instrument | Compute | Admin | Guest             │
           │  • Local cache / checksum agent (store-and-forward)             │
           └───────────────┬───────────────────────────────┬────────────────┘
                           │                               │
          DIA / MetroE / IX (NREN peering)                 │  LTE/5G / SAT (remote)
          Internet2/GEANT/APAN where available             │  (policy-based failover)
                           ▼                               ▼
              ┌────────────────────────────────────────────────────────┐
              │             TRANSPORT / SECURITY FABRIC               │
              │  SD-WAN overlays ║ MPLS / Waves (10/100/400G) ║ IX    │
              │  SASE/SSE POPs: ZTNA | SWG | CASB | FWaaS | DLP       │
              │  (geo/data-sovereignty, collaboration allow-lists)    │
              └───────────────┬──────────────────────────────┬────────┘
                              │                              │
                              ▼                              ▼
   ┌──────────────────────────────────────┐     ┌──────────────────────────────────┐
   │      CAMPUS / REGIONAL HPC CORES     │     │        CLOUD ON-RAMPS (DX/ER/GCI)│
   │  • Login/HPC gateways • IdP/SSO/MFA  │     │  • Cloud HPC Queues • Data Lake  │
   │  • Schedulers: Slurm/PBS/K8s         │     │  • Analytics/AI • Archive tiers  │
   │  • Storage: Lustre/GPFS/Object       │     └───────────────┬──────────────────┘
   │  • HSM/KMS • PAM • SIEM/NDR          │                     │
   └───────────────┬───────────┬──────────┘                     │
                   │           │                                │
                   ▼           ▼                                ▼
      ┌───────────────────┐   ┌─────────────────────────┐  ┌─────────────────────────┐
      │  COMPUTE NODES    │   │  WORKFLOW ORCHESTRATION │  │  DATA LAKE (Hot→Cold)   │
      │  CPU/GPU/DPUs     │   │  Nextflow | Cromwell     │  │  Hot: Obj   Warm: DW   │
      │  MPI/Containers   │   │  Airflow | Argo/K8s      │  │  Cold: Tape | Immutable│
      └───────────────────┘   └─────────────────────────┘  └─────────────────────────┘

  Integrity / Observability bus ──► NOC/SOC + AIOps (throughput/latency) + ITSM/CMDB + FAIR/GDPR dashboards

Narrative (how high-throughput science stays fast, verifiable, and lawful)

1) Purpose & posture

  • Objective: Move, compute, and curate petascale datasets with deterministic throughput, cryptographic integrity, and FAIR/GDPR/IRB compliance across campuses, consortia, and clouds.
  • Posture: Zero-Trust everywhere, integrity-by-design (checksums at source, verified at sinks), and data-sovereignty aware routing/storage.

2) Edge & transport (syntax of the pipeline)

  • Lab/field edges use SD-Branch/SD-WAN with dual underlays (DIA/MetroE/IX; LTE/5G/SAT for remote), ZTP turn-ups, and VRFs separating instruments/computes/admin/guest.
  • NREN peering (Internet2/GEANT/APAN) and/or optical waves (10/100/400G) provide the high-capacity spine; SD-WAN policies steer bulk flows on the fastest/cleanest paths.

3) Access & collaboration controls (semantics preserved)

  • SASE/SSE POPs enforce ZTNA (user+device+role+geofence), SWG/CASB/FWaaS/DLP for SaaS/share links, and allow-lists for partner ASNs/labs.
  • IdP/SSO/MFA gates HPC gateways and workflow UIs; PAM protects admin functions.

4) HPC cores, schedulers & storage (where meaning is computed)

  • HPC cores expose login/gateway nodes into Slurm/PBS/Kubernetes schedulers;
  • Storage hierarchy: Lustre/GPFS for scratch, object for hot collaboration, warm DW for curated products, cold tape/immutable for long-term provenance.

5) Workflows & reproducibility

  • Orchestrators (Nextflow, Cromwell, Airflow, Argo) bind containers (OCI/Singularity) and environment hashes to jobs; every step emits checksums, manifest files, and provenance metadata (FAIR).
  • Container registries are signed; results are stamped with time and input digests for auditability.

6) Cloud burst & data lake (elastic grammar)

  • Private on-ramps (DX/ER/GCI) provide pinned, high-throughput links to cloud HPC queues, analytics/AI services, and multi-tier data lakes.
  • Policies ensure jurisdictional pinning and cost guards (egress budgets, lifecycle moves Hot→Warm→Cold).

7) Resilience patterns (meaning under stress)

  • Link failover: SD-WAN shifts bulk transfers to secondary waves/MPLS; rate-limited DIA/IX is the last resort.
  • Store-and-forward: Edge caches queue instrument data; ordered replay reconciles checksums on recovery.
  • Burst DR: Jobs resubmitted to cloud queues; data lake replicas mounted read-only to preserve provenance.

8) Security, privacy & evidence (pragmatics)

  • HSM/KMS manages keys; WORM/immutable stores secure raw/derived datasets; SIEM/NDR/SOAR automates containment (revoke ZTNA, isolate VRF, rotate tokens).
  • FAIR/GDPR/IRB dashboards expose access trails, consent status, and retention clocks; automated DSAR search assists compliance teams.

9) Reference KPIs (science-grade)

  • Sustained throughput: ≥80% of link line-rate (100/400G paths).
  • End-to-end integrity: 100% checksum match on ingest/landings.
  • Failover: <60 s path switch; Job resubmission success: ≥99%.
  • DR: RTO ≤4 h (HPC queues) / RPO ≤15 min (lake metadata).
  • Compliance: FAIR completeness ≥95%; GDPR/IRB incident MTTR ≤2 h.

10) Minimal BOM (aligned to your matrix)

SD-WAN/SD-Branch; DIA/MetroE/IX; Waves (10/100/400G) / MPLS; SASE/SSE (ZTNA/SWG/CASB/FWaaS/DLP); HPC gateways; Schedulers (Slurm/PBS/K8s); Storage (Lustre/GPFS/Object/Tape+WORM); Cloud on-ramps; Workflow engines; HSM/KMS; PAM; SIEM/NDR/SOAR; AIOps; ITSM/CMDB; FAIR/GDPR dashboards.