Platform Provides
- Networking & mTLS
- Identity & SSO
- Logging
- Monitoring
- Runtime Security
- Backup & Restore
- Policy & Compliance
UDS Core provides a shared platform layer — networking, identity, observability, security, and backup — so application teams can focus on mission logic rather than infrastructure plumbing. This page clarifies the ownership boundary between the two layers. See our interactive architecture diagram for a visual overview.
Platform Provides
Application Teams Own
The Package CR is the contract between layers:
When an app needs a policy exception, the team creates an Exemption CR — keeping exceptions explicit, auditable, and separate from the Package CR.
See Core CRDs for details on both CRs.
Consistency
Same security, networking, and observability baseline for every application.
Compliance
Platform-wide controls enforced uniformly, simplifying authorization.
Speed
Teams declare intent, not infrastructure details — ship faster.
Upgradability
Platform and app workloads upgrade independently.