Architecture Design
This topic introduces ZCF's design objectives, product architecture, and technical advantages, explaining how ZCF establishes a unified, composable, and evolutionary infrastructure management architecture built upon cloud platform, storage, container, and networking capabilities.
Design Objectives
From Cloud Platform to Unified Infrastructure Management
Enterprise private cloud construction typically begins with cloud platforms and compute virtualization. As business scale expands, capabilities such as distributed storage, container platforms, and software-defined networking gradually integrate into the infrastructure system, respectively supporting data services, application runtime, and network services.
While infrastructure capabilities continuously expand, management entry points, identity authentication, asset views, and operational data often become fragmented across disparate systems. Infrastructure teams must switch among multiple interfaces to perform access, routine inspection, troubleshooting, and daily operations.
Therefore, enterprises no longer require isolated enhancements within a single resource domain; instead, they need a management architecture capable of organizing cloud resources, storage, containers, and networking—among other infrastructure capabilities—into coherent relationships within a unified platform, enabling consistent access, integration, observability, and maintenance paths for all capabilities.
ZCF as the Response
Built on ZStack Cloud, ZCF dynamically composes infrastructure components—including ZStack ZStone, ZStack Zaku, and ZStack ZNS—to deliver comprehensive infrastructure capabilities spanning cloud resources, storage, containers, and networking. On this foundation, ZCF provides global capabilities including a Unified Portal, Unified Authentication, Cloud Federation, and Observability-driven operations—orchestrating user access, component integration, runtime data aggregation, and management plane operations into a continuous workflow, enabling diverse infrastructure capabilities to collaborate seamlessly within a unified architecture.
This architecture supports both greenfield ZCF deployments and incremental adoption and evolution of existing ZStack Cloud environments—preserving current workloads and resource models.
Product Architecture
The ZCF product architecture is as follows:

ZCF's product architecture comprises four layers: Infrastructure Capabilities, Unified Management and Control Plane, Service Collaboration Linkage, and Extensibility and Evolution Capabilities.
- Infrastructure Capabilities deliver cloud resources, storage, container services, and networking services.
- The Unified Management and Control Plane provides unified access, Unified Authentication, component integration, observability-driven operations, and management plane lifecycle support.
- The Service Collaboration Linkage establishes integration and coordination between the Unified Management and Control Plane and Infrastructure Capabilities via Cloud Federation—enabling already-deployed and operational infrastructure components to enter unified access, runtime status visibility, and operational data aggregation paths.
- Extensibility and Evolution Capabilities reserve integration points for future ZCF capability and service expansions—for example, enterprise-grade disaster recovery and other architectural evolution directions.
Infrastructure Capabilities
- ZStack Cloud: As the foundational and mandatory platform for the current ZCF, it provides cloud platform and virtualization capabilities, hosting core workloads such as cloud resource management, VM instances, and bare metal resources.
- ZStack ZStone: Provides distributed storage capabilities, delivering data and storage services for the cloud platform and business workloads. In addition to ZStack ZStone, users may select other compatible storage solutions based on their actual environment.
- ZStack Zaku: Provides container and cloud-native capabilities, hosting containerized and cloud-native application workloads.
- ZStack ZNS: Provides network virtualization and foundational network service capabilities, supporting network service scenarios within ZCF.
Unified Management and Control Plane
- Unified Portal: Provides a unified access entry point and navigation experience, integrating ZCF management capabilities and entry points to connected environments.
- Unified Authentication: Provides unified identity authentication, single sign-on (SSO), and foundational access control.
- Cloud Federation: Establishes component integration relationships and maintains connectivity, status, and version boundaries for integrated components.
- Observability: Aggregates asset, monitoring, log, and alert data to form an observability-based operations and analytics view.
- Installation, Deployment, and Lifecycle Management: Supports deployment, initialization, upgrade, and runtime state management of the ZCF management plane.
Service Collaboration Path
- Unified Access: Users access ZCF via the Unified Portal and complete identity authentication through Unified Authentication, achieving consistent access entry points and SSO experiences across supported integrated components.
- Component Access: Administrators connect existing component instances to Cloud Federation, complete connection verification, and establish connection status and component context.
- Data Aggregation: Cloud Federation and component integration provide contextual access for assets, monitoring, logs, and alerts; observability capabilities build upon this to deliver a unified operations view.
- Operational Management: Initial delivery of the ZCF management plane is completed via installation and deployment; lifecycle management then assumes responsibility for subsequent component states and maintenance.
Technical Advantages
- Unified Access and Centralized Operations
ZCF consolidates ingress, authentication, connectivity, and observability-based operations capabilities into a unified management plane. Users can access connected environments through a consistent entry point and view resources, statuses, and risk information within a unified operations dashboard—reducing context switching across disparate portals and tools.
This approach establishes a continuous workflow spanning unified access, centralized operations, and observability-driven analysis—enabling administrators to perform environment onboarding, status inspection, and issue diagnosis using a single, cohesive platform relationship.
- Support for Phased Construction and On-Demand Expansion
ZStack Cloud is the foundational, mandatory platform in the current ZCF architecture, providing cloud resource orchestration and virtualization capabilities. ZStack ZStone, ZStack Zaku, and ZStack ZNS deliver storage, container, and network services respectively, and can be selectively combined based on the user's deployment stage and workload requirements.
This modular combination supports private cloud construction across varying scales and maturity stages. Users may first deploy the core cloud platform, then incrementally integrate corresponding service domains—such as data services, cloud-native applications, or network services—as needs evolve—while retaining unified access and centralized operations within ZCF.
- Smooth Access to Existing Infrastructure Environments
ZCF adopts an 'infrastructure environment first, then connect to ZCF' architectural model. Existing ZStack Cloud environments—or subsequently added storage, container, or network service domains—can establish connectivity via Cloud Federation and seamlessly enter ZCF's unified ingress, resource view, and observability-driven operations chain.
This connectivity model protects existing workloads and resource models, minimizing operational impact when introducing a unified management platform. In practice, rollout scope can be incrementally planned based on version compatibility, network connectivity, capacity constraints, and change windows.
- Observable O&M Integrated into the Unified Management Plane
ZCF incorporates asset management, monitoring, logging, alerting, dashboards, and reporting capabilities into its unified management plane—enabling administrators to monitor infrastructure resource health, capacity trends, and risk indicators from a single view.
This design embeds observability-driven operations as an integral part of ZCF's unified operations workflow—not as isolated, siloed capabilities scattered across multiple entry points. While data coverage scope and metric granularity may vary across service domains depending on product versions and integration depth, the end-to-end operations path remains consistent—facilitating routine inspections, root-cause analysis, and continuous optimization.
