Portal Runtime - One Operator DC

Portal Runtime - One Operator DC An architecture diagram generated by Archify. Operator Staff + LF SAs · browser, Vue 3 SPA · Architecture component Operator Staff + LF SAs browser, Vue 3 SPA SSO IdP · Okta / Azure AD / local · Architecture component · Passport SSO IdP Okta / Azure AD / local Passport DC Gateway · portal-xx domain · Operator DC (dcNN-N), one per customer · Kong / GW API DC Gateway portal-xx domain Kong / GW API lf-portal-full-express · SPA static + Express BFF · Operator DC (dcNN-N), one per customer · portalBackend lf-portal-full-express SPA static + Express BFF portalBackend DNO Platform Services · billing, catalog, charging... · Operator DC (dcNN-N), one per customer · ~115 services DNO Platform Services billing, catalog, charging... ~115 services Portal MySQL · sessions, tenants, roles · Operator DC (dcNN-N), one per customer Portal MySQL sessions, tenants, roles Redis · cache · Operator DC (dcNN-N), one per customer Redis cache S3 · docs, assets · Operator DC (dcNN-N), one per customer S3 docs, assets Kafka · portal events · Operator DC (dcNN-N), one per customer Kafka portal events HTTPS SPA + API SSO login SQL cache routes.json proxy assets events Operator DC (dcNN-N), one per customer Legend Backend Database Cloud Security Message bus External

BFF's three jobs

  • • Auth + sessions: Passport (Okta, Azure AD, local), MySQL store
  • • Permission-gated proxy: 1,380 routes to ~115 DNO services
  • • System of record for tenants, views, roles, settings

Access gates

  • • Tenant enables a View, role grants Read/Write keys
  • • Same keys gate menu, route guard, widget, and proxy route
  • • OR semantics at every layer, no inheritance between layers

Scale facts

  • • ~45 feature areas in the Vue SPA (unified/app)
  • • One deployment per operator; ~20 staging + production DCs
  • • DNO backend knows nothing about Portal users or permissions
← Docs home