Architecture Guardrails
The Architecture Guardrails define the key boundaries and principles that guide the design, implementation, and evolution of solutions across the Computational Sciences Center of Excellence (CS-CoE). They ensure cohesion, interoperability, compliance, and sustainability across the REDs’ digital landscape while enabling innovation and agility.
|
This is section is in DRAFT state and Work In Progress. The content is subject to active discussion and may change. If you have feedback or want to contribute you may join our architecture slack channel or send an email to our Architecture Catalyst Council. |
Core Technology and Integration
-
API & Integration: API-first design, new internal API projects within CS CoE must use Gravitee API Gateway
-
DISCUSS: ?Event & Messaging: ?? Event Platform for asynchronous integration and data sharing
-
Identity & Access Management: User facing applications leverage SSO provided by PingFederate.
-
Project Based Access Management (PBAC/PBAM):
Hosting
-
Usage of Roche standard infrastructure offerings for on-premise and cloud (Roche Cloud Platform (RCP))
-
The preferred RCP cloud provider for the CSCoE is AWS.
Governance & Compliance
-
An Architecture Review must be done by all new or significantly modified systems which:
-
Have a substantial relevance and impact on the landscape (e.g. new registration systems, platforms)
-
Deviate from the reference as described in this document
-
-
Decision Transparency: The Architecture team must document decisions in the Architecture Decision Records (ADRs)
-
Computerized systems must perform a Security and Risk Assessment IRM.
-
Register your solution in ACT if you require the option to test application compatibility on client machines.
-
New applications requiring infrastructure from Global Informatics, must be registered in ITSM Service Now.
-
Artifacts of Business Information and Architecture must be captured in the Architecture Master Repository (AMR).
-
Adhere to local compliance rules for user-facing applications, e.g. in Germany the works council approval is required before making a new tool available to employees.
Data, Security & Privacy
-
Data Classification: Define and protect data according to Roche privacy and data-handling policies.
-
Application defines and uses a terminology which is accessible (recommended terminology server is RTS)
-
FAIR principles are applied.
-
Audit & Monitoring: Systems must support auditability and operational visibility.