Platform Management and Operations

This chapter describes the coordination and boundaries of ZCF Platform Management and Operations capabilities, including unified access, identity authentication, component integration, licensing, the Observability and Operations Component, and lifecycle management. The management of VMs, storage volumes, containers, and networking resources, as well as installation and upgrades of infrastructure components themselves, remains the responsibility of the corresponding components.

Unified Portal and identity authentication provide the access foundation. Cloud Federation and Unified Authorization maintain component-integration and license relationships, while the Observability and Operations Component aggregates runtime data into a centralized operations view. The actual data and functional coverage of each capability domain depends on the connected components.

Figure 1. Platform Management and Operations Capability Overview


Unified Access and Identity Authentication

This topic explains how Unified Portal and Unified Authentication provide a foundation for platform access and sign-in. It defines the boundaries of entry points, single sign-on, and access control.

Unified Access Entry

Unified Portal provides the access entry and service navigation for ZCF. It centrally presents platform management capabilities and entry points to connected environments. Administrators can enter the relevant service domain, review environment information, and then perform resource management or operational tasks.

Unified Portal works with components through established integration relationships. Components retain their specialized management capabilities, while Unified Portal provides a consistent entry path and navigation experience without changing the management boundaries of component resources.

Identity Authentication and Access Control

Unified Authentication provides the foundation for user sign-in, single sign-on (SSO), and access control. After authentication, users can access applicable capabilities across connected components that support SSO. User, tenant, and permission configurations collectively determine the accessible management scope.

A typical access process includes entering Unified Portal, completing identity authentication, selecting a target environment or management capability, and performing operations according to granted permissions. SSO coverage depends on the component version, authentication integration method, and configuration. Connecting a component does not automatically grant access to all of its capabilities or resources.

Cloud Federation Management

Cloud Federation connects deployed infrastructure components and ecosystem services to ZCF and maintains the connectivity between the platform and components. It provides the foundation for unified access, resource aggregation, and Observability and Operations. During integration, administrators configure the component type, access address, and connection credentials. The system validates the connection and retrieves applicable version information.

Figure 2. Cloud Federation Environment Integration Relationship


After integration, Cloud Federation maintains component connection and synchronization states and provides resource source and ownership context. Resource synchronization is affected by component interfaces, synchronization methods, and network status. After connectivity is restored, confirm that the view has been updated according to the synchronization state before performing management operations that depend on current resource information.

Existing environments can be connected to ZCF in phases without requiring migration of existing workloads. Before integration, confirm component version compatibility, management network reachability, and the required access credentials.

License and Authorization

License Management uses the License Server to maintain license information and provide the authorization basis for components connected to the licensing system. License pools organize quotas by the applicable license type, and each component consumes licenses according to its own authorized scope and metering rules.

Figure 3. Unified Authorization Relationships


User identity and permissions determine access scope, while product licenses determine usable capabilities and corresponding quotas. Both constrain feature use. The handling of license changes, expiration, or License Server connectivity issues is determined by the applicable version and license requirements.

Observability and Operations

This topic explains how Observability and Operations aggregates runtime data and supports daily investigation. It defines the scope of data sources, timeliness, and analysis.

Data Aggregation and Runtime Views

Observability and Operations aggregates resource, metric, log, and alert information from connected environments. Cloud Federation provides resource and ownership context, while component collection or data integration provides runtime information to form a centralized operations view.

Data coverage, update frequency, and retention periods depend on component integration capabilities, collection configuration, and storage planning. Operational analysis must interpret data timeliness together with connection, collection, and synchronization states. Data that has not been collected cannot be used directly for analysis.

Figure 4. Observability and Operations Component Data Aggregation and Workflow


Capability Primary Content Operational Purpose
Resource viewsResource counts, states, and relationshipsUnderstand resource distribution and identify affected objects
Metric monitoringUtilization, performance metrics, and trendsIdentify abnormal changes and support capacity and performance analysis
Log queriesSearch logs by time, source, and keywordsNarrow the investigation scope and supplement fault evidence
Alert managementAlert rules, notification channels, and handling statesIdentify abnormalities promptly and track issue handling
DashboardsSummaries of key resources and runtime dataSupport routine inspections and runtime status reviews

Alerts and Issue Investigation

Administrators can configure alert rules and notification channels according to monitoring requirements. When an abnormal condition satisfies a rule, the system generates an alert and sends a notification. Operations personnel investigate using the alert object, occurrence time, and resource information, and record the handling status.

During investigation, first confirm the source environment and related objects of the alerted resource, then review metric trends for the affected period and search collected logs for additional evidence. After remediation, verify the result through metric and alert states.

Installation, Deployment, and Lifecycle Management

This topic explains the initial delivery and subsequent lifecycle management of the ZCF management plane. It defines deployment preparation, the basis for upgrades, and the boundary with infrastructure component workflows.

Initial Delivery of the Management Plane

Installation and Deployment completes the initial delivery and baseline initialization of the ZCF management plane, enabling Unified Portal, Unified Authentication, Cloud Federation, License Management, and Observability and Operations to operate. The deployment design must align with the nodes, network, access entry, and infrastructure integration conditions established in environment planning.

This chapter does not repeat installation methods, configuration parameters, or procedures. Installing ZCF does not replace the initial deployment of infrastructure components. For implementation details, see Installation and Deployment.

Lifecycle Management Boundaries

After components and ecosystem services are connected, Lifecycle Management maintains the baseline information and readiness required for later ZCF version upgrades. It provides a management basis for platform upgrade maintenance through ZCF Bundles, version paths, component connection and version states, risk-check results, and history records.

The actual upgrade path, supported upgrade scope, and blocking items depend on target Bundle metadata, component status in Cloud Federation, and page check results. Lifecycle Management does not replace the upgrade workflows of infrastructure components such as ZStack Cloud, ZStack ZStone, ZStack Zaku, and ZStack ZNS.