🤖 AI Summary
To address challenges in highly regulated environments—including cross-cloud governance complexity, high operational overhead, and prolonged configuration cycles for cloud-native applications (CNAs)—this paper proposes a “batteries-included,” out-of-the-box reference architecture. The architecture tightly integrates policy-as-code, declarative APIs, service mesh, and a compliance metamodel to automatically embed governance capabilities across the application lifecycle while decoupling them from business logic. It introduces the first unified abstraction mechanism for cross-cloud governance elements, enabling lightweight deployment alongside elastic scalability. Experimental evaluation demonstrates substantial reduction in governance configuration time and validates strong adaptability in finance and government sectors—two representative highly compliant domains. The architecture supports agile delivery and automated compliance auditing, thereby filling a critical academic gap in generic CNA governance frameworks.
📝 Abstract
The evolution of cloud computing has given rise to Cloud Native Applications (CNAs), presenting new challenges in governance, particularly when faced with strict compliance requirements. This work explores the unique characteristics of CNAs and their impact on governance. We introduce a comprehensive reference architecture designed to streamline governance across CNAs along with a sample implementation, offering insights for both single and multi-cloud environments. Our architecture seamlessly integrates governance within the CNA framework, adhering to a"battery-included"philosophy. Tailored for both expansive and compact CNA deployments across various industries, this design enables cloud practitioners to prioritize product development by alleviating the complexities associated with governance. In addition, it provides a building block for academic exploration of generic CNA frameworks, highlighting their relevance in the evolving cloud computing landscape.