# Architecture principles whose scope is infrastructure

> 28 records

This index as JSON: https://banes-lab.com/json/api/facets/architecture/scope/infrastructure

## Entries

- [Control Plane](https://banes-lab.com/records/architecture/control-plane.md): Descriptive data about the desired state of a distributed runtime, held in one place and applied to every node through a management interface.
- [Portability](https://banes-lab.com/records/architecture/portability.md): The degree to which software runs on another platform or environment without code changes.
- [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md): The practice of declaring infrastructure in versioned files and provisioning it from them.
- [Standards Compliance](https://banes-lab.com/records/architecture/standards-compliance.md): A rule or precondition that an implementation conforms to the published standard for its protocol, format or domain.
- [Immutable Infrastructure](https://banes-lab.com/records/architecture/immutable-infrastructure.md): An approach in which servers are replaced from a new image for every change, instead of being patched in place.
- [Replaceability](https://banes-lab.com/records/architecture/replaceability.md): The degree to which a component can be swapped for another implementation of its interface without editing its callers.
- [Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md): A design rule that an authentication or policy failure denies access.
- [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md): The degree to which a system keeps operating correctly when some of its components fail.
- [Resilience](https://banes-lab.com/records/architecture/resilience.md): The degree to which a system contains failures, stays stable under stress and recovers.
- [Declarative Configuration](https://banes-lab.com/records/architecture/declarative-configuration.md): A design rule that a system's settings are declared as validated data, and the system configures itself from that data.
- [Monitoring](https://banes-lab.com/records/architecture/monitoring.md): A mechanism that collects metrics about resources and service levels over time and compares them with thresholds.
- [Scalability](https://banes-lab.com/records/architecture/scalability.md): The degree to which a system keeps its throughput and latency as load grows, by adding resources.
- [Horizontal Scaling](https://banes-lab.com/records/architecture/horizontal-scaling.md): A technique for adding capacity by running more stateless instances of a service behind a load balancer.
- [Vertical Scaling](https://banes-lab.com/records/architecture/vertical-scaling.md): A technique for adding capacity by giving one instance more CPU, memory or I/O.
- [Elasticity](https://banes-lab.com/records/architecture/elasticity.md): The degree to which a system's provisioned capacity follows demand up and down automatically.
- [CDN / Edge Caching](https://banes-lab.com/records/architecture/cdn-edge-caching.md): A mechanism that serves cacheable content from servers near the requester, keyed by a fingerprint of the content.
- [Self-Healing Architecture](https://banes-lab.com/records/architecture/self-healing-architecture.md): The ability of a system to detect a failed component from its health signals and restore it without human action.
- [Failover](https://banes-lab.com/records/architecture/failover.md): A mechanism that switches traffic or reads to a standby instance when the active one fails.
- [Redundancy](https://banes-lab.com/records/architecture/redundancy.md): A mechanism that keeps spare instances or capacity for a critical component, spread across failure domains.
- [Auto-Scaling](https://banes-lab.com/records/architecture/auto-scaling.md): The ability to change the number of running instances automatically, between set bounds, from a load metric.
- [Auto-Remediation](https://banes-lab.com/records/architecture/auto-remediation.md): The ability to run a guarded, automated response, such as a restart, a reset and replay or a compaction, when an alert or a health signal shows a failure whose fix is known.
- [RAID Redundancy](https://banes-lab.com/records/architecture/raid-redundancy.md): A technique for spreading data across several disks with mirroring or parity, so the loss of a disk loses no data.
- [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md): A design rule that several independent security controls protect each asset, so one failed control does not expose it.
- [Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md): A design rule that endpoints, ports, features and permissions nothing uses are removed or disabled.
- [Access Control](https://banes-lab.com/records/architecture/access-control.md): A mechanism that evaluates an access policy for each request to a resource and denies the request when the policy does not allow it.
- [Policy Enforcement](https://banes-lab.com/records/architecture/policy-enforcement.md): A mechanism that blocks an action a policy forbids at the point the action is attempted.
- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md): A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.
- [Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md): The ability to check compliance on every change, with automated policy gates and evidence capture.
