Skip to main content

Private Data Plane Management Models

WSO2 Cloud - Integration Platform manages the full lifecycle of your integrations, from development through deployment. The data plane is the runtime environment where those integrations run. When you use a private data plane, you own and control that environment, which introduces a choice: how much of the infrastructure and platform management do you want to own?

WSO2 supports three management models for private data planes, ranging from fully WSO2-managed to fully customer-managed. Each model defines a shared responsibility boundary across infrastructure provisioning, Kubernetes management, platform component operations, and security monitoring.

WSO2 fully managed (infrastructure and PDP in WSO2 subscription)

In this model, WSO2 owns the cloud subscription and manages all infrastructure and platform components on your behalf. You are responsible only for creating and managing your integrations. WSO2 fully managed private data planes are supported on Azure, AWS, and GCP.

TaskTask descriptionResponsibleAccountableConsultedInformed
Subscription prerequisitesCreate subscriptions, check quota and service limits, run the compatibility prerequisite scriptWSO2WSO2Customer (if required)Customer (if required)
Remote access for installationProvide owner accessWSO2WSO2WSO2WSO2
Network managementObtain customer backend CIDR for VPN/peering, check end-to-end connectivityWSO2/CustomerWSO2/CustomerCustomerCustomer
Firewall rules and access controlSet up firewall and required rules depending on the security tierWSO2WSO2CustomerCustomer
Infrastructure provisioningProvision bastion and Kubernetes clustersWSO2WSO2Customer (if required)
Kubernetes cluster managementManage Kubernetes versions, increase node pool sizeWSO2WSO2CustomerCustomer
Infrastructure monitoringSet up alertsWSO2WSO2Customer (if required)
DNS management for platform systemManage DNS infrastructure and SSL certificates for platform system componentsWSO2/CustomerWSO2/CustomerCustomerCustomer
Platform system components deploymentSet up PDP agents via HelmWSO2WSO2
Platform system components managementUpgrade, patch, and debug versionsWSO2WSO2Customer (if required)
Platform system components monitoringSet up continuous 24x7 monitoring and provide monthly uptime reportsWSO2WSO2Customer
Platform system security monitoringBasic tier: CSPM, security patches, supply chain security, security incident management. Standard/premium tier: adds runtime security alerts, SIEM alerts, compliance adherenceWSO2/CustomerWSO2/CustomerWSO2/CustomerWSO2/Customer
Integration creation and deploymentCustomerCustomerCustomerCustomer
Integration managementCustomerCustomerCustomerCustomer
Integration monitoringCustomerCustomerCustomerCustomer
Integration logsCustomerCustomerCustomerCustomer

WSO2 fully managed (infrastructure and PDP in customer subscription)

In this model, the customer owns the cloud subscription, but WSO2 still manages infrastructure provisioning and all platform operations. You provide access to your subscription and own the integrations that run on it.

TaskTask descriptionResponsibleAccountableConsultedInformed
Subscription prerequisitesCreate subscriptions, check quota and service limits, run the compatibility prerequisite scriptCustomerCustomerWSO2
Remote access for installationProvide accessCustomerCustomerWSO2WSO2
Network managementObtain customer backend CIDR for VPN/peering, check end-to-end connectivityWSO2/CustomerWSO2/CustomerCustomerCustomer
Firewall rules and access controlSet up firewall and required rules depending on the security tierWSO2/CustomerWSO2/CustomerCustomerCustomer
Infrastructure provisioningProvision bastion and Kubernetes clustersWSO2WSO2CustomerCustomer
Kubernetes cluster managementManage Kubernetes versions, increase node pool sizeWSO2WSO2CustomerCustomer
Infrastructure monitoringSet up alertsWSO2WSO2Customer (if required)
DNS management for platform systemManage DNS infrastructure and SSL certificates for platform system componentsWSO2/CustomerWSO2/CustomerCustomerCustomer
Platform system components deploymentSet up PDP agents via HelmWSO2WSO2Customer
Platform system components managementUpgrade, patch, and debug versionsWSO2WSO2Customer (if required)
Platform system components monitoringSet up continuous 24x7 monitoring and provide monthly uptime reportsWSO2WSO2Customer
Platform system security monitoringBasic tier: CSPM, security patches, supply chain security, security incident management. Standard/premium tier: adds runtime security alerts, SIEM alerts, compliance adherenceWSO2/CustomerWSO2/CustomerWSO2/CustomerWSO2/Customer
Integration creation and deploymentCustomerCustomerCustomerCustomer
Integration managementCustomerCustomerCustomerCustomer
Integration monitoringCustomerCustomerCustomerCustomer
Integration logsCustomerCustomerCustomerCustomer

Customer self-managed (WSO2 provides installation script and updates)

In this model, the customer owns the subscription and manages all infrastructure and platform operations. WSO2 provides the installation script, Helm charts, and ongoing updates, and is available for consultation. This model offers the highest level of customer control.

TaskTask descriptionResponsibleAccountableConsultedInformed
Subscription prerequisitesCreate subscriptions, check quota and service limits, run the compatibility prerequisite scriptCustomerCustomerWSO2WSO2
Remote access for installationProvide owner accessCustomerCustomerWSO2
Network managementObtain customer backend CIDR for VPN/peering, check end-to-end connectivityCustomerCustomerWSO2WSO2
Firewall rules and access controlSet up firewall and required rules depending on the security tierCustomerCustomerWSO2WSO2
Infrastructure provisioningProvision bastion and Kubernetes clustersCustomerCustomerWSO2WSO2 (if required)
Kubernetes cluster managementManage Kubernetes versions, increase node pool sizeCustomerCustomerWSO2WSO2 (if required)
Infrastructure monitoringSet up alertsCustomerCustomerWSO2
DNS management for platform systemManage DNS infrastructure and SSL certificates for platform system componentsCustomerCustomerWSO2
Platform system components deploymentSet up PDP agents via HelmCustomerCustomerWSO2
Platform system components managementUpgrade, patch, and debug versionsCustomerCustomerWSO2
Platform system components monitoringSet up continuous 24x7 monitoring and provide monthly uptime reportsCustomerCustomerWSO2
Platform system security monitoringBasic tier: CSPM, security patches, supply chain security, security incident management. Standard/premium tier: adds runtime security alerts, SIEM alerts, compliance adherenceWSO2/CustomerWSO2/CustomerWSO2/CustomerWSO2/Customer
Integration creation and deploymentCustomerCustomerCustomerCustomer
Integration managementCustomerCustomerCustomerCustomer
Integration monitoringCustomerCustomerCustomerCustomer
Integration logsCustomerCustomerCustomerCustomer

What's next