.png?sv=2026-02-06&spr=https&st=2026-10-09T04%3A35%3A02Z&se=2026-10-09T04%3A46%3A02Z&sr=c&sp=r&sig=2oa45%2BQR2P%2FD0QWnmV98toJtXNtAIXx7AgqAyfXQFes%3D)
Figure 1: Fortanix Armor On-premises Architecture Diagram
The Fortanix Armor on-premises architecture consists of a Kubernetes-based control plane managed by the Fortanix Armor Kubernetes Operator, with UI (user interface) and API endpoints exposed externally. External compute nodes connect using Node Agents, enabling secure workload execution with attestation and centralized policy control.
The Administrator accesses Fortanix Armor using the web-based UI exposed through a configured domain (for example,
https://<onprem-armor-api-url>). All user actions performed through the UIare routed to the Armor API.The Fortanix Armor API serves as the central control plane for the platform. It processes all incoming requests from the UI and external components, manages platform logic, and coordinates operations across internal services.
The Fortanix Armor Kubernetes Operator deploys and manages Fortanix Armor platform components within the Kubernetes cluster, including API services, UI static frontend, and Cassandra database for persistent storage. The deployment is initiated using a Helm chart, which installs the operator and applies the
ArmorPlatformcustom resource that defines the desired Armor configuration. Based on this resource, the operator provisions and maintains the required platform components.External Access and Endpoints - Fortanix Armor exposes separate external endpoints for the UI and API components. Client traffic first reaches a load balancer, which routes requests to the appropriate service:
The UI static frontend is exposed through an ingress controller (For example NGINX), mapped to an ingress IP (for example,
https://armor-static-url:443).The Fortanix Armor API is exposed through a load balancer service, mapped to a separate external IP (for example,
https://onprem-armor-api-url:443).
These endpoints typically use different domains and IP addresses, but both are accessed over HTTPS (port 443).
The Fortanix Armor platform integrates with external services to support identity, attestation, and security workflows. These include:
Attestation services for verifying trusted execution environments.
Identity providers (for example, Microsoft Entra ID) for authentication
Logging and monitoring systems (for example, SIEM platforms).
These integrations are invoked by Armor API services as part of workload execution and platform operations.
The ArmorAPI coordinates communication between internal platform components and external services. It ensures that requests are authenticated, policies are enforced, and (where applicable) attestation results are validated before allowing confidential workloads to execute.
Confidential Computing Manager (CCM) and Key Insight – These are the Fortanix Armor Solutions.
For Fortanix Key Insight detailed on-premises architecture, refer Key Insight Architecture.
For Fortanix CCM detailed on-premises architecture, refer CCM Architecture.