> System.Architecture

Designed in layers.
Governed at every level.

KARECTL is built in four layers on a Kubernetes-native foundation, with security, governance and audit enforced at every layer, for operational and research workloads alike.

KARECTL // Architecture Diagram

Four layers, from Infrastructure through Platform Foundation and Core Services to Applications. Each band lists its capabilities. Security, governance and audit apply at every layer.

  1. 01 / Infrastructure

    • Kubernetes
    • On-premises
    • Microsoft Azure
  2. 02 / Platform Foundation

    • Identity & access (Keycloak)
    • Network isolation
    • Certificates & secrets
    • Encrypted storage
  3. 03 / Core Services

    • Observability
    • AI-assisted remediation
    • Provisioning
    • Data & messaging
    • Security as code
    • AI inference (vLLM)
    • Workflow orchestration
  4. 04 / Applications

    • Operational AI applications
    • Research workspaces
    • Federated analysis (DataSHIELD)
    • Agentic research tools (in development)

> Layer Breakdown

01 / Infrastructure

Kubernetes on-premises and on Microsoft Azure. KARECTL is designed to be infrastructure-agnostic, so organisations can choose where it runs.

02 / Platform Foundation

Shared services abstracted from the underlying infrastructure: identity and access management with multi-factor authentication (Keycloak), network routing and isolation, certificate and secrets management, and encrypted storage.

03 / Core Services

Observability and AI-assisted remediation; project and service provisioning; data storage and messaging; security and compliance defined as code, covering policy enforcement, runtime threat detection and configuration scanning; and AI services, including self-hosted model inference (vLLM), LLM observability, workflow orchestration and event-driven scaling.

04 / Applications

Operational AI applications, such as follow-up triage and waiting-list prioritisation, run in their own governed environments. Researchers work in isolated project workspaces with R and Python, JupyterHub notebooks, RStudio, shared code repositories, remote desktops and DataSHIELD for federated analysis. Agentic research tools are in development.

KARECTL_

An AI-conformant platform for governed AI and analytics on sensitive data.

© 2026 Lancashire Teaching Hospitals NHS Foundation Trust. All rights reserved.