Skip to content

Architecture

Architecture overview

Omnistrate is an agentic control plane generator that solves the fundamental distribution channel problem for software vendors. This document provides an architectural overview of how Omnistrate generates the private, provider-branded control plane you use to build, distribute, and operate your software across multiple deployment models while maintaining complete control over customer interactions.

The Distribution Channel Problem

Modern software companies face a critical challenge: customers demand deployment flexibility across multiple channels—SaaS, BYOC (Bring Your Own Cloud), on-premises, and AI agent deployments—but building and operating these distribution channels requires years of engineering effort and specialized expertise.

YOUR SOFTWARETRADITIONAL DELIVERY STACKSCOMPLEXITY MULTIPLIESPaaS / SaaSSelf-service customersDedicated platform + operationsBYOCEnterprise customersDedicated tooling + operationsOn-premisesRegulated customersInstaller + separate operationsAI agentsAgent-driven experiencesDedicated platform + operationsDuplicated control planesFragmented operationsSlower product delivery signed installerdisconnected workflow

Each distribution channel requires its own infrastructure management, tenant isolation, billing integration, operational monitoring, and customer interfaces. This complexity multiplies operational overhead and diverts engineering resources from core product innovation.

Omnistrate's Architectural Solution

Omnistrate transforms this paradigm by generating a unified control plane that enables you to build all distribution channels from a single platform. Application deployments run in your cloud account, your customer's cloud account or Kubernetes cluster, or an on-premises environment, depending on the deployment model.

YOUR OMNISTRATE-GENERATED CONTROL PLANEDISTRIBUTION CHANNELSAPPLICATION ENVIRONMENTSBranded experiencePortal · API · CLI · SDKsUnified managementDeploy · operate · meter · governHosted SaaSBYOCAI agentsAir-gappedProvider cloud accountHosted deploymentsCustomer cloud or clusterBYOC deploymentsCustomer data centerDisconnected deployment signed artifact managed executionmanaged executionno live connection

Key Architectural Principles

  1. Customer Infrastructure Deployment: All customer workloads run in their chosen environment (their cloud account, on-premises, or your managed infrastructure)
  2. Centralized Control: Your control plane maintains complete visibility and control over all deployments regardless of location
  3. Unified Operations: Single operational interface for managing deployments across all channels and environments
  4. Customer Ownership: Customers maintain full control over their data and infrastructure while benefiting from your managed experience

Control Plane Architecture

The generated control plane spans three architectural areas: your provider-branded interfaces, Omnistrate-hosted managed services, and account-local execution components. The interfaces and managed services are hosted by Omnistrate. The account-local components do not host the complete control plane; they execute authorized operations near the application infrastructure.

YOUR BRANDED EXPERIENCE · OMNISTRATE HOSTEDOMNISTRATE-HOSTED MANAGED SERVICESACCOUNT-LOCAL EXECUTIONAPPLICATION ENVIRONMENTSCustomer PortalREST APIsCLI + SDKsOperator ConsolePrivate control plane APITENANCYIdentity · accounts · subscriptionsDEPLOYMENTOrchestration · infrastructure · configurationOPERATIONSMonitoring · audit · recoveryFINOPSMetering · billing · reportingAgent / provisionerScoped cloud or cluster identityHosted SaaSProvider accountBYOCCustomer accountBYOC-K8sCustomer clusterAir-gappedCustomer environment least privilegeencrypted control traffic signed installer artifact

The exact account-local component and trust path vary by deployment model. Air-gapped deployments have no live control-plane connection; Omnistrate produces a signed installer artifact that the customer runs inside the isolated environment.

Control Plane Components

Provider-branded interfaces

  • REST APIs: Comprehensive APIs for programmatic access to all control plane functions
  • CLI Tools: Command-line interface for developers and DevOps teams
  • Operator Console: Operational interface for the SaaS provider's teams
  • Customer Portal: Self-service interface for customers to manage their deployments
  • SDKs: Language-specific SDKs for seamless integration

Omnistrate hosts these interfaces and exposes them as part of your private, branded control-plane experience.

Tenant Management

  • Tenant Orchestrator: Manages the complete tenant lifecycle from onboarding to deprovisioning
  • Account Manager: Handles customer account creation, authentication, and access control
  • Subscription Manager: Manages subscription plans, billing cycles, and feature entitlements

Deployment Engine

  • Deployment Orchestrator: Coordinates complex multi-resource deployments across different environments
  • Infrastructure Manager: Provisions and manages cloud resources, networking, and dependencies
  • Configuration Manager: Handles service configuration, secrets management, and environment-specific settings

Operations Center

  • Monitoring & Alerting: Proactive monitoring with intelligent alerting and anomaly detection
  • Logging & Auditing: Centralized logging with comprehensive audit trails for compliance
  • Recovery & Healing: Automated recovery systems that handle failures and maintain high availability

Financial Operations

  • Usage Metering: Accurate tracking of resource consumption and feature usage
  • Billing Engine: Flexible billing with support for multiple pricing models and payment methods
  • Reporting & Analytics: Comprehensive reporting for business intelligence and optimization

Account-Local Execution

  • Agent or Provisioner: Executes authorized lifecycle and infrastructure operations in the applicable provider or customer environment
  • Scoped Identity: Limits the component to the cloud or cluster permissions required by the deployment model

Modular By Design

Omnistrate's architecture is fundamentally modular, giving you the flexibility to choose the right components for each layer of your control plane. This "Choose our Component or Bring Your Own" approach ensures you can leverage existing investments while benefiting from Omnistrate's comprehensive platform capabilities.

Modular Component Options

For each layer of the control plane, you have three flexible options:

1. Omnistrate Provided Components

  • Fully Managed: Zero configuration, automatic updates, and seamless integration
  • Enterprise Ready: Built-in security, compliance, and scalability features
  • Optimized Performance: Purpose-built for control plane operations
  • Unified Experience: Consistent APIs and user experience across all components
  • Best-in-Class: Leverage industry-leading specialized services
  • Existing Investments: Utilize tools your team already knows and trusts
  • Rich Ecosystems: Access to extensive integrations and community support
  • Proven Scale: Battle-tested solutions used by thousands of companies

3. Bring Your Own Components

  • Complete Control: Full customization and control over functionality
  • Legacy Integration: Seamlessly integrate with existing internal systems
  • Compliance Requirements: Meet specific regulatory or security requirements
  • Unique Differentiation: Maintain competitive advantages through custom solutions

Migration and Evolution

The modular architecture supports seamless migration between component types as your needs evolve:

  • Start Simple: Begin with Omnistrate components for rapid deployment
  • Integrate Gradually: Replace components with specialized services as requirements grow
  • Scale Strategically: Move to custom solutions for unique competitive advantages
  • Mix and Match: Use different approaches for different layers based on specific needs

This flexibility ensures that your control plane can evolve with your business without requiring complete rebuilds or migrations.

Next Steps