DRAFT SIR CSS-FD Attachment J-9.pdf
PDF 2 MB Posted
- Attached to
- Draft Screening Information Request (SIR) Common Support Services-Flight Data (CSS-FD) Federal contract opportunity
- Solicitation number
- 693KA8-23-Presolicitation_CSS-FD
About this file
This document provides an overview of the Federal Aviation Administration's cloud architecture and considerations for how the Common Support Services-Flight Data program would integrate within the FAA's cloud platforms. The FAA is establishing the Cloud National Test Bed and Mission Essential Cloud environments within the AWS GovCloud to enable development, testing, and production deployment of NAS programs. The CNTB allows programs to conduct pre-production activities using AWS services and FAA-provided DevSecOps tools. The ME-Cloud and ME-OE production environments will offer infrastructure, platform, and core services to facilitate rapid deployment of systems like CSS-FD. The document outlines relevant interface standards, compute compatibility, integration patterns, and security requirements for CSS-FD to leverage the FAA's cloud platforms and enterprise DevSecOps toolchain. Appendix A provides an initial list of tools available within the CNTB.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DRAFT SIR CSS-FD Sect C.pdf | ||
| DRAFT SIR CSS-FD Sect F.pdf | ||
| DRAFT SIR CSS-FD Sect G.pdf | ||
| DRAFT SIR CSS-FD Attachment J-0.pdf | ||
| DRAFT SIR CSS-FD Attachment J-12.pdf | ||
| DRAFT SIR CSS-FD Sect D.pdf | ||
| DRAFT SIR CSS-FD Sect E.pdf | ||
| DRAFT SIR CSS-FD Sect K.pdf | ||
| DRAFT SIR CSS-FD Sect L.pdf | ||
| DRAFT SIR CSS-FD Attachment J-4.pdf | ||
| DRAFT SIR CSS-FD Sect B.pdf | ||
| DRAFT SIR CSS-FD Attachment J-1.pdf | ||
| DRAFT SIR CSS-FD Attachment J-2.pdf | ||
| DRAFT SIR CSS-FD Sect I.pdf | ||
| DRAFT SIR CSS-FD Attachment J-8.pdf | ||
| Attachment 1 - CSS-FD Draft SIR Vendor Comment Matrix 2023-09-08.xlsx | XLSX spreadsheet | |
| DRAFT SIR CSS-FD Sect H.pdf | ||
| DRAFT SIR CSS-FD Sect M.pdf |
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solicitation # Attachment J-9
Federal Aviation Administration
Common Support Services – Flight Data (CSS-FD)
FAA Cloud Architecture
September 2023
Federal Aviation Administration 800 Independence Avenue, SW
Washington, DC 20591 i
TABLE OF CONTENTS
1 INTRODUCTION
2 FAA CLOUD PLATFORM BACKGROUND
3 FAA CLOUD NATIONAL TEST BED
3.1 CNTB TOOLS AND ACCESS
4 THE FUTURE FAA ME-CLOUD AND ME-OE
5 FAA ME-CLOUD AND ME-OE CONSIDERATIONS FOR CSS-FD
DEVELOPMENT
5.1 CLOUD PLATFORM CONSIDERATIONS
5.2 INTERFACES BETWEEN CSS-FD CONTAINERS AND SERVICES
5.3 COMPUTE FOUNDATION
5.4 INTEGRATION FOUNDATION
5.5 METRICS, LOGGING, AND MONITORING
5.6 SCALING
5.7 SECURITY
APPENDIX A – CNTB INITIAL TOOLS
APPENDIX B – ACRONYMS AND ABBREVIATIONS
TABLE OF FIGURES
Figure 1: AES NAS Reference Architecture with Cloud Services
Figure 2: FAA CNTB Features and Capabilities
Figure 3: CNTB - High-level Network Connectivity
Figure 4: AWS Organizations and Landing Zone Accelerator
Figure 5: AWS Global Network and CNTB Organization
Figure 6: CNTB Accounts Management through AWS
1 INTRODUCTION
This document provides an overview of the Federal Aviation Administration (FAA) Cloud Architecture and describes how tenant programs such as Common Support Service Flight Data (CSS-FD) are envisioned to fit within the cloud solution framework. The following sections provide insight and references which provide context for how the FAA Cloud Platform will be leveraged as CSS-FD is implemented in the National Airspace System (NAS).
2 FAA CLOUD PLATFORM BACKGROUND
The FAA’s vision for an info-centric NAS includes a move toward an agile infrastructure through the evolution of system-wide information management and adoption of cloud-based enterprise architecture. The FAA Enterprise Services Infrastructure Framework (ESIF) provides the methodology to evaluate and identify programs and program components that qualify for movement to the cloud. As part of an info-centric vision for the NAS, the FAA will build on the Next Generation Air Transportation System foundation in operations, supporting infrastructure, and integrated safety management.
To support the allocation of NAS functional capabilities to cloud infrastructure, the FAA leveraged the ESIF cloud-analysis framework to investigate emerging technologies and innovative architecture configurations as candidates for NAS infrastructure modernization.
Cloud computing offers the FAA the potential to reduce development, implementation, and maintenance costs, allowing the agency to efficiently deliver future NAS solutions to aviation stakeholders. To streamline this delivery, the FAA has developed the Automation Evolution Strategy (AES) Technical Architecture, which focuses on serviced-based design and enterprise scope implementation for future services. Planned enhancements and amplification of some of these key concepts have led to the development of an AES layered service-based architecture.
Figure 1 depicts the expected cloud services envisioned to enable AES.
For more information on the FAA AES Implementation Strategy, please see Attachment J-8, AES Technical Architecture.
Figure 1: AES NAS Reference Architecture with Cloud Services
3 FAA CLOUD NATIONAL TEST BED
The FAA Cloud National Test Bed (CNTB) is an Amazon Web Service (AWS) GovCloud Federal Information Security Modernization Act (FISMA) High off-premises cloud computing operating environment. This environment is configured, secured, monitored, operated, and controlled by the FAA. Tenant services, such as CSS-FD, made available in the CNTB include most AWS native services and additional enterprise services, categorized based on function.
From a software development standpoint, the CNTB is used for pre-production activities, while the FAA’s Mission Essential Cloud (ME-Cloud) is a computing environment that enables programs to quickly access, acquire, provision and de-provision infrastructure and platform services in the FAA Mission Essential Operating Environment (ME-OE). See Section 3.2 for more information on the ME-Cloud production environment and the ME-OE.
To facilitate FAA and vendor implementation objectives, the CNTB offers development, testing, and pre-production of FAA system/applications. The CNTB is a secure environment used to identify and resolve code issues, integrate with other systems and services, implement security controls including scans/penetration testing. This environment is used for sustainment, programmatic, and operation technology support for the ME-OE. As such, the CNTB affords the FAA the opportunity to conduct use cases of all systems migrating to the ME-Cloud (i.e., Off- Prem, On-Prem, and Hybrid). Figure 2 provides a summary of CNTB features and capabilities.
Figure 2: FAA CNTB Features and Capabilities
Early CNTB releases include access to services from tenant AWS accounts within an off-premises Commercial AWS – GovCloud. Amazon Workspaces, an AWS virtual desktop, will provide access into the CNTB accounts for early tenants. The CNTB provides access to the FAA William J. Hughes Technical Center (WJHTC) Lab facilities in Atlantic City, N.J. via dual redundant 10Gb/sec AWS Direct Connect links. Sufficient port density is provided to extend connections from the Direct Connect service to any lab within the Technical Center. See Figure 3 for a high-level reference to CNTB network connectivity.
Figure 3: CNTB - High-level Network Connectivity
3.1 CNTB TOOLS AND ACCESS
CNTB tools and services include a mix of AWS native services and third-party enterprise service capabilities. The CNTB also provides additional access into CNTB through Direct Connect ports, which will be available to Atlantic City labs. In addition, the AWS Direct Connect feature connects to the GovCloud and WHJTC. This environment uses the AWS Landing Zone Accelerator (LZA) to apply best practices, AWS environment governance and follow AWS Security Reference Architecture.
From Amazon Workspaces, access to the AWS Console is permitted through AWS Identity Center Single Sign-on (SSO) via internal Keycloak IDP integrated with a managed active directory. Access to additional CNTB resources such as GitLab, OpenShift, Terraform, Vault, etc., is achieved through internal Keycloak IDP and the managed active directory. The use of Amazon Workspaces assures no direct connection between internet and CNTB environments, preventing internal CNTB Uniform Resource Locator (URL’s) or endpoints exposure to the internet. For the virtual desktop user on FAA Mission Support, CNTB applies a Service Control Policy (SCP) that allows only FAA IP addresses. Figures 4 through 6 provide information on general AWS connection structure and CNTB organization.
Figure 4: AWS Organizations and Landing Zone Accelerator
Figure 5: AWS Global Network and CNTB Organization
Figure 6: CNTB Accounts Management through AWS
CNTB Core Services are essential to establishing and operating a production ME-Cloud.
Expected CNTB services are as follows:
• Deployment, Security, Operations (DevSecOps) C/M (OpenShift)
• DevSecOps (GitLab)
• Identity and Access Management
(RH SSO)
• Service Mesh (Consul, RH Istio)
• Secrets Manager (Vault)
• Cloud Service Provider (CSP) Native
Platform as a Service (PaaS)
• Code/containers repositories
• Application Performance Monitoring
• Logging and Monitoring
• Privilege Access Management
• Security Information and Event
Management (SIEM)
• Vulnerability Scanning
• Operations Management
• Governance, Billing
• Service Desk, Ticketing
• Inventory/patch/config management
Refer to Appendix A for information on CNTB initial tools and toolchain.
4 THE FUTURE FAA ME-CLOUD AND ME-OE
The FAA is in the process of migrating to an enterprise-based infrastructure model through a scalable, FISMA High, Off-Prem Cloud Computing Environment. Currently, AWS GovCloud will serve as the CSP for the ME-Cloud architecture. The ME-Cloud enables programs like CSS- FD to quickly access and platform services in the ME-OE – reducing the timeline for programs to deliver services to the NAS. The CNTB, ME-Cloud and ME-OE are distinctly different environments with unique purposes and capabilities:
1. The CNTB serves as the pre-production off-premises cloud computing operating environment.
2. The ME-Cloud environment includes infrastructure, platform, and cloud core services.
These integrated layers facilitate the FAA’s objective to create an infrastructure accessible to the NAS that is interoperable and seamless, where programs can choose to deploy to a cloud computing environment based on program requirements. Key features include:
• Infrastructure services providing compute, memory and storage resources
• Platform services providing common shared tools, capabilities and services (i.e., DevSecOps Toolchain)
• Cloud Core services providing foundational connectivity, security and operations management capabilities.
3. The ME-OE environment is a private [FAA-controlled hardware administration], off-premises government cloud that consists of Efficiency Critical, Essential and Routine system/service assets. Access to the ME-OE is limited to authorized users and is capable of supporting limited IT user activities and real-time Air Traffic Control services.
5 FAA ME-CLOUD AND ME-OE CONSIDERATIONS FOR CSS-FD
DEVELOPMENT
FAA Programs, like CSS-FD, that deploy to the ME-CLOUD/ME-OE, will do so through services and containers in the standard FAA enterprise platform run-time environment. CSS-FD will be a system that runs on a general-purpose FAA software management and infrastructure platform that serves multiple programs and systems (not just CSS-FD). As part of this enterprise platform, CSS-FD would leverage a standardized CI/CD (Continuous Integration / Continuous Delivery) DevSecOps toolchain. Aspects of platform compatibility are highlighted below:
• CSS-FD software compatibility with the enterprise platform for services and containers
• CSS-FD software team utilization of specified tools for CI/CD and DevSecOps.
• CSS-FD utilizes AES architecture to implement a solution that meets the needs of multiple programs and systems.
5.1 CLOUD PLATFORM CONSIDERATIONS
The current referenced CNTB Architecture reflects certain selections and preferences on the part of the FAA. It also leaves room for vendors to recommend alternatives or additional software elements to support CSS-FD. Furthermore, the platform is likely to evolve over time reflecting new technologies and best practices. Generally, the FAA prefers tools and technologies that have the following characteristics:
• Open source
• Well-established
• Industry standard in their field
• Supported by multiple vendors
• Zero or low lifetime license costs
5.2 INTERFACES BETWEEN CSS-FD CONTAINERS AND SERVICES
Many integration protocols rely on elements that are implemented in the underlying platform, for example, message brokers. These protocols not only tie together CSS-FD services, they also may be used to integrate with other FAA systems. Therefore, interface protocol compatibility is an important concern for the FAA. If an interface between CSS-FD containers is used, the FAA will advise on the appropriate protocols for CSS-FD software service containers, unless specifically justified by the vendor and approved by the FAA. Consider the following:
• Synchronous and asynchronous communication, REpresentational State Transfer (REST) Application Programming Interfaces (APIs), etc.
• Asynchronous push-type messaging
• Asynchronous, high-throughput, distributed pull-type messaging
• FAA SWIM services approach when producing or consuming CSS-FD data or functionality to or from other NAS or external systems
5.3 COMPUTE FOUNDATION
The CNTB compute infrastructure provides the foundation for all CSS-FD software services, implying complete compatibility with that infrastructure. A CSS-FD software service may consist of a single container or may be decomposed into multiple containers. If there are multiple containers, these compute platform requirements apply to each. For example, two sub-service containers cannot use a unique and non-compliant interface between them, even if it is not externally exposed.
5.4 INTEGRATION FOUNDATION
Service integration capabilities link CSS-FD services together to function as a complete software system. It is advised that containerized CSS-FD software is compatible with and integrated by these platform capabilities.
5.5 METRICS, LOGGING, AND MONITORING
CSS-FD software features that implement metrics, logging, and monitoring are essential to successful operational deployment of a vital NAS capability. Standardization ensures integration with platform infrastructure as well as operational tools and procedures.
5.6 SCALING
Common infrastructure and container management allows systems to scale dynamically, according to demand, providing both efficiency during low demand and protection against overload during high demand. This also promotes self-healing to compensate for failures.
5.7 SECURITY
CSS-FD as an integrated system and each service within (including the constituent containers) is expected to meet security requirements as they flow down from the Program Requirements Document (PRD). This usually means the satisfaction of certain security controls that apply to the system level in question (application, service, interface, container, base image, etc.).
APPENDIX A – CNTB INITIAL TOOLS
Purpose / Description CNTB DevSecOps Tools
Traffic management, routing rules, service access
OpenShift (NGINX operator, or HAProxy Ingress controller (native), K8s native)
Distributed version control manager (Git) GitLab
Artifact management GitLab, OpenShift
Infrastructure as code tool, provisioning Terraform (HashiCorp)
CI/CD pipelines, version control, deployment patterns OpenShift (Tekton)
Declarative continuous delivery OpenShift (Argo CD)
Build pack provider/Software Bill of Materials (SBOM) GitLab (Cloud Native Buildpacks)
Role based namespace security context inheritance manager OpenShift
Infrastructure resource request management OpenShift, GitLab (Auto Deploy)
Policy engine OpenShift (Kyverno)
Cluster elasticity manager OpenShift (Kubernetes)
Service mesh Consul (Hashicorp), OpenShift (Apigee)
Automated unit test GitLab
Automated runtime function test GitLab (Selenium)
Static code quality and vulnerability scan GitLab CodeQuality, SonarQube plugin
Dynamic/runtime vulnerability scanner GitLab (SAS, DAST, and Dependency container Scanning)
Cloud native (containers) realtime vulnerability scanning
GitLab (SAS, DAST, and Dependency container Scanning), Aqua plugin
Capture and export performance metrics OpenShift (Prometheus), many other plugins (ELK, Datadog)
Cluster performance monitoring, notifications and alerts
Dynatrace (OpenShift plugin), and many other OpenShift plugins
Log retention, monitoring, notifications and alerts
Splunk (OpenShift plugin), and many other OpenShift plugins
Real-time visibility into cloud costs OpenShift (OCM)
Certificate management controller OpenShift (cert-manager, Vault plugin)
Secrets manager Vault (HashiCorp)
Purpose / Description CNTB DevSecOps Tools
User authentication, role based access control (RBAC), separation of duties, least privilege
AWS Identity Center. via Red Hat SSO (Keycloak) Identity and Access Management (IAM) HA with potential for MyAccess FA AD Federation
APPENDIX B – ACRONYMS AND ABBREVIATIONS
Acronym/Abbreviation Definition
AES Automation Evolution Strategy
API Application Programming Interface
ATO Air Traffic Organization
AWS Amazon Web Service
CI/CD Continuous Integration / Continuous Delivery
CSP Cloud Service Provider
CSS-FD Common Support Services – Flight Data
CNTB Cloud National Test Bed
DevSecOps Deployment, Security, Operations
ESIF Enterprise Services Infrastructure Framework
FAA Federal Aviation Administration
FENS FAA Enterprise Network Services
FISMA Federal Information Security Modernization Act
IaaS Infrastructure as a Service
IAM Identity and Access Management
LZA AWS Landing Zone Accelerator
ME-Cloud Mission Essential Cloud
ME-OE Mission Essential Operations Environment
NAS National Airspace System
PaaS Platform as a Service
PPS Ports, Protocols and Services
PRD Program Requirements Document
REST Representational State Transfer
RH SSO Identity and Access Management
SSO Single Sign-On
SWIM System Wide Information Management
SIEM Security Information and Event Management
URL Uniform Resource Locator
WJHTC William J. Hughes Technical Center
| 1 Introduction |
| 2 FAA Cloud Platform Background |
| 3 FAA Cloud National Test Bed |
| 3.1 CNTB Tools and Access |
| 4 The Future FAA ME-Cloud and ME-OE |
| 5 FAA ME-CLOUD AND ME-OE considerations for CSS-FD Development |
| 5.1 Cloud Platform Considerations |
| 5.2 Interfaces between CSS-FD Containers and Services |
| 5.3 Compute Foundation |
| 5.4 Integration Foundation |
| 5.5 Metrics, Logging, and Monitoring |
| 5.6 Scaling |
| 5.7 Security |
| Appendix A – CNTB Initial Tools |
| Appendix B – Acronyms and Abbreviations |
File details come from the government source that posted it. Updated .