Resources · Architecture

Enterprise architecture for the whole estate

Target-state diagrams and install patterns for a single control plane across APIs, models, MCP tools, and agents—without ripping out systems of record.

1

control plane

Catalog, policy, identity, and GitOps for the whole estate.

4

data planes

API, AI, MCP, and Agent—same PDP and audit trail.

3

install models

SaaS, hybrid, and self-hosted / air-gapped.

N

systems of record

CRM, ERP, ITSM, lakes, and model providers stay put.

Reference architecture

ForgeCrux One: unified control plane

One control plane for your entire AI, MCP, agent, and API estate — catalog, policy, routing, and compliance in a single fabric.

ForgeCrux One: Unified Control Plane Architecture

ForgeCrux One control plane for your entire AI, MCP, agent & API estate

ForgeCruxProbing Deeper, Stacking Precision

Consumer & application layer

End users

Chatbots, apps

Enterprise applications

CRM, ERP

Developers

IDE, SDKs

Microservices

Internal workloads

ForgeCrux SDKs & gateways

Installation & deployment models

SaaS

ForgeCrux managed

Hybrid

Control plane SaaS, data plane VPC / on-prem

Self-hosted

Air-gapped / private cloud

Transformation layer

Protocol translation

Data normalization

Semantic mapping

Payload optimization

ForgeCrux One control plane

Centralized management & registry

Unified catalog

AI, MCP, agents, APIs

Dashboard & policy manager

Configuration database

Orchestration & routing engine

MCP hub & router

Model Context Protocol

AI model switcher & load balancer

Multi-model routing

API Gateway

OAS / GraphQL / gRPC

Agent manager & event bus

Identity, A2A, HITL

API Gateway fabric

Policy, quota, mediation

Agent bus manager

Workflows and events

Security & identity

IAM & zero trust

RBAC, ABAC

DLP & PII masking

API security

OAuth 2.0, mTLS

Audit logging

Governance & compliance

Compliance frameworks

GDPR, CCPA, HIPAA

AI ethics & fairness monitoring

Usage quotas & rate limiting

Performance & drift monitoring

Cost control

Managed AI, MCP, agent & API estate

AI estate

Commercial LLMs

OpenAI, Anthropic, Google

Open-source models

Llama, Mistral

Vector databases

Embeddings APIs

MCP estate

Local MCP tools

ForgeCrux MCP gateways

Remote MCP services

Upstream agents

Agent estate

ForgeCrux agents

Custom agents

Partner agents

Agent registries

API estate

Legacy systems

Third-party SaaS APIs

Internal microservices

Microservices mesh

Enterprise data

Uses, installation, setup, and security—the same operating model as the platform and solutions pages.

Enterprise uses

When teams pull architecture reviews from this library.

  • Target-state design for a unified API + AI + MCP + agent fabric
  • Hybrid and air-gapped placement of control vs data planes
  • Strangler and dual-run patterns off legacy API management
  • Zero-trust MCP and agent identity before production autonomy
  • Governance evidence path from PDP to SIEM and GRC
  • Observability maps spanning all four gateway hops

Installation patterns

Where each box in the diagrams actually runs.

  • SaaS: ForgeCrux-operated control and optional data planes
  • Hybrid: SaaS control, customer VPC/K8s/on-prem data planes
  • Self-hosted: full stack on private Kubernetes with GitOps
  • Coexistence: ForgeCrux northbound, existing ingress southbound
  • Multi-region active-active with config DB replication
  • Disconnected promotion with signed Helm/Terraform artifacts

Setup & review

How an architecture engagement typically proceeds.

  • Map channels, IdP, current gateways, SoRs, and telemetry
  • Choose SaaS, hybrid, or self-hosted for control and data
  • Draw trust boundaries: vault, mTLS join, residency pins
  • Sequence waves: APIs first, then AI, MCP, agents
  • Define SLO, audit, and rollback contracts before cutover
  • Leave with GitOps repo layout and environment topology

Security architecture

Controls that appear on every reference diagram.

  • Identity: SSO for operators, workload identity for planes
  • PDP in path for APIs, completions, MCP tools, and A2A
  • Vaulted credentials—never in agent memory or MCP stdio configs
  • Network: private link, allow lists, sandbox egress for tools
  • Data: classification, DLP, residency, and payload truncation
  • Evidence: immutable decisions, traces, and session replay ACLs

Need a custom architecture review?

Our solutions architects can design SaaS, hybrid, or air-gapped deployments for your estate.