JFrog Platform Federation
Subscription Information
The feature is gradually being rolled out to Enterprise+ SaaS subscriptions. To request early access to JFrog Platform Federation, contact JFrog Customer Success.
A JFrog Platform Federation creates and maintains a multisite workspace with uniform JFrog Project, Lifecycle, and Access Control settings.
Platform Federation syncs all the major entities that define your Projects and SDLC process. The result is a “full-stack Federation” that supports users in multiple sites with a uniform platform of record.
Platform Federation is powered by JFrog's next-generation Grid and PFED federation services, and its globally synced workspace forms the basis for further multisite integration, which will eventually sync SDLC, Security, and Governance entities into a globally meshed management layer.
Why JFrog Platform Federation
Project settings embody your organization's structure and business policies: your local and global roles, resource permissions, security settings, and lifecycle stages define user access and resource permissions over the SDLC.
In multisite JFrog subscriptions, these project and lifecycle settings must be consistent across all your sites:
- To support collaboration across sites
- To ensure uniform application of security and access policies
- To support resilience and recovery scenarios between sites.
Automated sync enables the multisite workspace.
JFrog Platform Federation resolves and automates many of the challenging tasks Admins face in creating and maintaining the multisite workspace. Automated sync relieves the Admin burden and eliminates configuration drift.
JFrog Platform Federation provides a consistent management layer of Project and Lifecycle settings. This frees users with large-scale deployments to:
- Extend their deployments with additional sites.
- Use JFrog’s powerful Project and Lifecycle tools to define and manage Security, Distribution, and Governance functions over the SDLC.
What Platform Federation Synchronizes
JFrog Platform Federation automatically syncs project and access controls across all its member sites, including:
These settings become Global Entities maintained by Platform Federation. Changes on any site of the Platform Federation are synced to all member sites.
Use Cases
Platform Federation maintains consistency across all its sites, with uniform workflow, identity, access, and governance settings. This supports applications that require a single coherent Projects/access model.
-
Collaboration - users can access their projects on different sites of the Platform Federation, and receive the same working environment. Security and access control are determined by a uniform set of policies. Changes are fully synced across sites.
-
Failover - Platform Federation ensures that its entities are fully synced between the active site and dormant site.
-
CI/CD - Sites dedicated to specific stages in the SDLC process/business functions share one set of project, user, and application settings.
Automated sync drastically reduces the Admin overhead of the multisite deployment, freeing users with large-scale deployments to:
-
Extend their deployments with additional sites.
-
Use JFrog’s powerful Project and Lifecycle tools to define and manage Security, Distribution, and Governance functions over the SDLC.
How Platform Federation works
A JFrog Platform Federation can be defined within your existing SaaS subscription architecture. Select the member sites to include in the Platform Federation. Platform Federation immediately begins to sync Global Entities between the sites of the Platform Federation.
The Platform Federation topology is a mesh of peers. Updates to Global Entities on any site are synced between all sites. Star topologies are not supported.
Federated services and JFrog Platform Federation
Some federated services complement Platform Federation by syncing additional data types. For example, these federation services continue to operate normally on sites that are added to a Platform Federation:
Access Federation or JFrog Platform Federation? JFrog Platform Federation syncs all the entity types that can be handled by an Access Federation. There are differences between the services:
- Platform Federation forms the basis for JFrog’s continued cross-site integration. The JFrog Grid is built on the new, highly scalable Platform Federation (PFED) service infrastructure. Access Federation uses existing JFrog services to provide 1st-generation multisite syncing.
- JFrog Platform Federation is a comprehensive federated workspace, not a standalone service. Platform Federation syncs all entities to create a uniform multisite Project Federation. In this model, you do not select specific entities to sync, so filtering or mapping options of Access Federation are not supported. Similarly, Platform Federation implements a mesh of peers to create one workspace, and star or chained topologies are not supported.
- The JPD Platform UI provides a dedicated Grid management dashboard to monitor sync events between member sites, including drill-down to individual sync events.
You can preserve Access Federations between sites that are not included in a Platform Federation. See Plan the Platform Federation.
Frequently Asked Questions
Can Self-managed sites join a Platform Federation?
Currently only SaaS endpoints are supported. Upcoming releases will support inclusion of Self-managed sites in Platform Federations in Hybrid deployments.
Can Edge nodes join a Platform Federation?
No. Edge nodes have limited functionality do not use or support the Project-related entities synced by Platform Federation. To sync Access entities on Edge nodes, use the Access Federation service.
Will additional entities be synced?
Platform Federation's meshed management layer is the starting point for further multisite integration. Planned releases will add the following entities:
- Lifecycle Stages
- Curation - Platform Federation will sync the entities currently handled by the standalone Curation Federation service.
- Repositories - instead of individual Federated Repositories, Platform Federation will provision and sync repositories across sites.
How do I manually re-sync if a Platform Federation site goes offline?
The Grid is based on the next-generation PFED federation service, and is designed to minimize manual recovery interventions.
Peer-to-peer entity federation interactions are handled by the PFED service on each site, and continue on other sites when one site is offline. Service messaging uses retry mechanisms, queuing, and self-inventory to identify failures and recover when a site comes back online. There is no need for Admins to schedule manual sync scripts.
Platform Federation is configured on the main site of the SaaS deployment. This site has no special role in syncing Global Entities, and is not a single point of failure for federation operations.
Updated 5 days ago
