Skip to content

Architecture

QHx architecture diagram. The diagram shows two boxes: cluster control plane and node. Within the cluster control plane box, there are further boxes: blue boxes labelled 'QHx Manager' and 'PKI Server' and 'QHx Notary'. The Node box is divided into two sections by a dotted line: 'node control plane', which contains two blue boxes labelled 'QHx Agent' and 'PKI Agent', and another section 'data plane', containing a blue box 'QHx Agent', plus a grey box labelled 'Workload', which has a stacked effect under it indicating it exists in multiple instances. The 'Node' box also has a stacked box effect under it indicating multiple instances.

Quantum Helix is deployed as a package for standard Kubernetes environments, and is installable as a Helm chart. It comprises multiple components:

  • QHx Manager (qhx-manager)
  • QHx Agent (qhx-agent)
  • QHx Proxy (qhx-proxy)
  • QHx Notary
  • QHx PKI Server (pki-server)
  • QHx PKI Agent (pki-agent)
  • QHx CLI (qhx(1))

The purpose of these components is as follows:

  • The QHx CLI (qhx(1)) facilitates operator management of QHx.
  • The QHx Manager (qhx-manager) acts as a controller-manager and supervises the entire QHx installation.
  • The QHx Agent (qhx-agent) is deployed to each node in a cluster, and provides realisation of QHx networking services on that local node.
  • The QHx PKI Server (pki-server) issues workload-bound credentials, such as X.509 certificates, in cooperation with the PKI Agent on each node.
  • The QHx PKI Agent (pki-agent) is scheduled on every node in a cluster, and performs local supervision and attestation of workloads on a node to the PKI Server so that they can be issued workload-bound credentials.
  • The QHx Proxy (qhx-proxy) provides data-plane intermediation of application-layer traffic within a cluster, and is responsible for transportation of application-layer traffic over post-quantum secure, end-to-end-encrypted, mutually authenticated and workload-bound tunnels.
  • The QHx Notary provides application-level request notarisation and attestation functionality, allowing application-level requests to be augmented with information about workload identity and providence. It is hosted inside a specially configured instance of QHx Proxy.