Skip to main content

CIVITAS/CORE V2 Glossary

Key terms used across the CIVITAS/CORE V2 platform documentation. Terms written in CamelCase (for example DataStructure) denote Model Management artifact types. Terms in regular spelling (for example Data structure) denote user-facing platform concepts. Where both exist, each entry says how they relate.

A

Apache APISIX
An open-source API gateway for traffic management, security and observability. In CIVITAS/CORE it is used as the centralized entrypoint to route and protect externally exposed APIs.
Apache Kafka
A distributed event streaming platform. In CIVITAS/CORE it is used as the message bus to transport events, models and data in data flows.
Apache NiFi
A stream processing and connector framework. In CIVITAS/CORE it is the pipeline engine for data integration and transformation (see ADR 047) and implements dataset-defined data flows.
API
A programmatic interface that allows external applications to control the platform or access and interact with its payload data. It enables the programmatic management and the structured retrieval and use of data from Datasets.
Related terms: Payload
Architecture Decision Record (ADR)
A document capturing an architecture decision. Each ADR has a stable identifier and short title and is managed through four lifecycle states: Proposed, Accepted, Deprecated and Superseded.
Assignment
Links a Group with a Role within a defined Scope. It determines which permissions apply to which Users and where.
Related terms: Group, Role, Scope, Permission
Authentication
The process of verifying the identity of a User or Client before access is granted. In CIVITAS/CORE, Keycloak authenticates Users and issues JWTs.
Related terms: Authorization, Keycloak
Authorization
The process of deciding whether an authenticated User or Client may perform a given action on a given resource. In CIVITAS/CORE, authorization decisions are made by the Policy Decision Point (OPA) and enforced by the Policy Enforcement Point (APISIX), based on Assignments of Roles to Groups within a Scope.

B

Backend-For-Frontend (BFF)
An architecture pattern where a dedicated backend serves a specific frontend, ensuring that sensitive tokens never reach the client side.
Bundle
A View that renders an artifact together with the (complete) graph of the artifacts it connects to, as one self-contained document. The bundled (embedded $defs) and inlined schema projections are both Bundles.
Related terms: View, Model Artifact

C

Client
An external application or service that connects to the Platform to provide or use data. For example, a software component like Apache Superset acts as a client that consumes and visualizes data of the Platform.
CloudNativePG (CNPG)
A Kubernetes operator for running and managing PostgreSQL clusters. In CIVITAS/CORE it is used to provision and operate Postgres databases.
Configuration Adapter
The component that consumes data models on behalf of platform components that cannot consume them directly, and configures the component accordingly. In the secrets management flow, the Configuration Adapter is the sole component that resolves Vault references into concrete credentials.
Connector
A software building block that can be configured to define how the Platform connects to an external data source or system. It specifies the technical setup required to access or ingest data. Not to be confused with a data space connector (for example Eclipse Dataspace Components), which governs data exchange between data space participants.
Context Broker
A component that manages context information (entities and their state) and exposes it through the NGSI-LD API. Part of the CIVITAS/CORE V2 target architecture (ADR 038); the choice of the broker product is still open.
Related terms: NGSI-LD
CORE Intermediate Representation (CORE-IR)
The JSON-based exchange format between Model Management, UI, registry, Configuration Adapters and downstream generators.
Related terms: CORE URN
CORE URN
The global identity Model Management assigns to every model artifact: a unique, stable and versionable URN that exists independently of storage location, file names or registry technology.

D

Data flow
A process that describes how data moves through the Platform from its source to its final use. It is implemented through pipelines that ingest, transform, and provide data.
Data model
A formal, logical description of the structure, relationships, and constraints of data within a specific domain or project.
Related terms: Data structure
Data pool
A governed, centralized collection of Datasets that are managed together within the Platform. It provides a shared place to organize, discover, and access data, including associated metadata, ownership, and access permissions. With Data pools users can cluster their Datasets according to their organizational structure (e.g., by Departments, Offices).
Related terms: Tenant, Scope
Data sink
A target where data is written or delivered at the end of a data flow. It can represent a persistence layer or another system where data is stored.
Data source
A data-related element that represents the origin of data. It defines how data is connected, accessed, and ingested into the Platform, such as an external database or sensor network.
Data space
A federated data ecosystem where data is shared across organizations in a controlled and secure way. It enables participants to exchange and use data while maintaining data sovereignty. A data space typically contains data from multiple Tenants.
Related terms: Tenant
Data storage
A Pipeline node that persists data inside the Platform so that it can be provided through an API. The Platform offers the Sensor Data storage, which stores sensor data for the SensorThings API, and the Geospatial Data storage, which stores geospatial data in tables for WFS/WMS APIs. The Data storages used in the Pipelines of a Dataset determine which API types the Dataset can offer.
Data structure
A versioned data-related element that defines the schema and organization of data. It specifies how data is structured and interpreted within the Platform.
Dataset
A data-related element that contains processed data and makes it available for consumption. A Dataset is populated via Pipelines and carries Metadata and access permissions.
DataSet (Model Management)
An integration composition: a manifest that references Elements, Mappings, Pipelines, DataSources and DataSinks by URN. Where a DataStructure groups Elements by provenance, a DataSet composes artifacts of all types into a deployable unit. Distinct from the platform's user-facing Dataset object described elsewhere in this glossary.
DataSink
The declaration of an outbound target, such as an HTTP endpoint, whose payload binds to an Element by URN. A DataSink is a stored, versioned artifact with its own CORE URN. For the user-facing concept, see Data sink.
DataSource
The declaration of an inbound data source, such as an MQTT topic or a database query, whose payload binds to an Element by URN. A DataSource is a stored, versioned artifact with its own CORE URN. For the user-facing concept, see Data source.
DataStructure
A stored grouping of Elements. Importing one JSON Schema document (a root, optionally with $defs) creates one DataStructure that references the resulting Elements by URN, as the module and provenance grouping. A DataStructure is a stored artifact, not a View: it carries no content of its own, and its members are fetched individually by URN. For the user-facing concept, see Data structure.

E

Element
The umbrella for a single modeled domain type, such as a Class or an Enumeration. An Element is a JSON Schema 2020-12 document whose $id is a versioned CORE URN. It carries version, name, description and URN.

F

Format
A View that serializes an Element in a chosen representation: JSON Schema or XSD. An Element's format is recorded per version.
FROST-Server
A complete server implementation of the OGC SensorThings API. In CIVITAS/CORE it is used as the SensorThings API broker to store and serve IoT/sensor observations via STA.

G

Group
A collection of individual users who are grouped together so that roles with their permissions can be assigned to them simultaneously within a specific scope.
Related terms: User, Role, Assignment

H

HashiCorp Vault
A secrets management system used as the platform's secrets backend. CIVITAS/CORE supports HashiCorp Vault (BSL) and its API-compatible open-source fork OpenBao. The platform does not implement its own encryption or secret storage.
Related terms: Configuration Adapter

I

Instance
A single, complete, and isolated deployment of the CIVITAS/CORE software environment.
Related terms: Platform

J

JSON Schema
A vocabulary for describing and validating the structure of JSON documents. CIVITAS/CORE uses JSON Schema 2020-12 as the format of Elements.

K

Keycloak
An open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs.

M

Management Portal
The central user interface of the Platform that provides access to all functionalities for managing data, configurations, users, and access. It serves as the main entry point for working with data-related elements.
Mapping
A declarative field mapping from a source Element to a target Element, both referenced by URN. Per target field it describes an operation (for example copy, concat, const or format) over the source payload. A Mapping is a stored, versioned artifact with its own CORE URN.
Metadata
Descriptive information that provides context about a data-related element, such as its name and description.
Model Artifact
Umbrella term for any persistable CORE unit: Element, DataStructure, Mapping, DataSource, DataSink, Pipeline and DataSet. Every artifact has a stable CORE URN identity and is versioned.
Model centricity
A design philosophy where Data models serve as the core foundation for all Platform interactions, especially Data structures and propagation of configuration of internal platform components. It aims to ensure consistency across all services.
Model Management
The part of the platform that defines, versions and stores the data models and integration configuration (the model artifacts) from which the platform is configured. It is implemented by Model Forge, an embedded module of the Portal Backend.

N

NGSI-LD
An Open API and data model specification for context management, published by ETSI. It defines how context information (entities, relationships, and properties) is represented and exchanged.
Related terms: Context Broker

O

Open Policy Agent (OPA)
The platform's authorization service: it evaluates 'who may do what' against the CIVITAS/CORE authorization model. OPA is the platform's central Policy Decision Point (PDP) for API authorization.
Open Source
Software whose source code is published under a license that complies with the Open Source Definition of the Open Source Initiative (OSI), allowing anyone to use, study, modify, and redistribute it. The CIVITAS/CORE V2 platform code is published under the European Union Public Licence (EUPL) 1.2.

P

Payload
The data contained in a Dataset that is made available for consumption. It is exposed through the Dataset's APIs.
Related terms: Dataset, API
Permission
Defines a specific action that can be performed within the Platform. Permissions can apply to system features or data-related elements and determine what Users are allowed to do.
Related terms: Role
Persistence
Systems or processes for data that ensure it is stored durably and remains available beyond individual processes or system restarts.
Pipeline
An automated sequence of steps used to ingest, transform, or provide data within the Platform. Each pipeline defines a specific stage of data processing, such as loading or providing data. Pipelines are defined inside of Datasets.
Related terms: Pipeline (artifact)
Pipeline (artifact)
A data flow graph of nodes and edges that wires DataSources through Mappings into DataSinks. A Pipeline references the participating artifacts by URN and is itself a stored, versioned artifact with its own CORE URN. For the user-facing concept, see Pipeline.
Platform
The CIVITAS/CORE system that enables organizations to manage Users, define access, and work with data-related elements. It provides the foundation for organizing, governing, and making data available within a controlled environment. A running deployment of it is an Instance. Currently, a Platform has exactly one Tenant.
Related terms: Instance, Tenant
Policy Decision Point (PDP)
The component that decides whether a request is authorized. CIVITAS/CORE uses Open Policy Agent (OPA) as its PDP.
Policy Enforcement Point (PEP)
The component that enforces the authorization decision made by the Policy Decision Point. CIVITAS/CORE uses Apache APISIX as its PEP, adopting a centralized, gateway-enforced authorization architecture.

R

Rego
OPA's declarative policy language, used to express authorization rules such as checking role assignments at the most specific scope first.
Related terms: Open Policy Agent
Role
A collection of Permissions that defines what actions can be performed within the Platform. Roles can apply to system features or data-related elements and are assigned to Groups within a specific Scope.
Related terms: Group, Scope, Assignment

S

Saga Pattern
A pattern for coordinating long-running, multi-step operations across several components without a distributed transaction. Each step has a compensating action; if a later step fails, the compensating actions of all previously completed steps are executed in reverse order. In CIVITAS/CORE it is used for provisioning workflows that require sequential, cross-adapter operations.
SASL (Simple Authentication and Security Layer)
A framework defined in RFC 4422 that decouples authentication from application protocols.
Scope
Defines where a Role assigned to a Group applies. It can cover the whole Tenant or be limited to a Data pool or to specific data-related elements.
Related terms: Group, Role, Assignment, Tenant
SCRAM (Salted Challenge Response Authentication Mechanism)
A challenge-response authentication protocol defined in RFC 5802.
Secure Software Development Lifecycle (SSDLC)
CIVITAS/CORE's development process, focused on shipping a secure-by-default product, a transparent supply chain, and high-quality security documentation.
SensorThings API
A standardized API based on the OGC SensorThings API specification for accessing time series and IoT data. It enables structured retrieval and management of observations and related entities.
Related terms: FROST-Server
Software Bill of Materials (SBOM)
A machine-readable inventory of a software artifact's components, generated in CycloneDX format as part of the supply-chain security measures (alongside dependency pinning, vulnerability scanning, signed artifacts, and SLSA-aligned provenance).
Standard API
A predefined, specified API that provides access to data in a consistent and standardized way. It enables Users and external systems to retrieve or store data from e.g. Datasets without custom implementation.
Related terms: SensorThings API, NGSI-LD
Standard component
A reusable, modular, Open Source building block within the CIVITAS/CORE architecture that performs a specific, standardized system function.
Standard roles
A predefined set of roles that can be used immediately when starting with the Platform. They are designed according to data governance principles and cover common responsibilities.
Related terms: Role
Status
A state that indicates the current stage of a data-related element within its lifecycle. It reflects whether the element is in draft, ready, or available. Only data-related elements that have status available can be used in the platform, e.g. Dataset to store and retrieve data.
Learn more: Status Lifecycle

T

Tenant
An isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform.
Related terms: Data pool, Scope, Platform
Transactional Outbox Pattern
A pattern for reliably publishing events after a database change: Entity changes and their corresponding outbox events are persisted in a single database transaction. A separate publisher process reads the outbox table and publishes events to Kafka after the transaction has committed.
Related terms: Saga Pattern, Apache Kafka
Transformation
The process of changing the format, structure, or values of data e.g. to ensure it aligns with the target Data structure or system requirements.
Related terms: Pipeline, Mapping

U

Unified Modeling Language (UML)
A standardized notation used to represent and define Data structures in a visual way. In the Platform, it is used to describe the structure of data.
Related terms: Data structure
Urban Data Platform (UDP)
A platform that integrates urban data from different systems and domains, enabling its collection, management, and reuse. It makes data available for applications and services.
User
A person who signs in to the Platform and works with it, for example in the Management Portal. A User belongs to Groups, and the Roles assigned to those Groups determine what the User may do.

V

Version
A specific state of a versioned Data structure that captures its structure definition. It allows changes to be managed and tracked without overwriting previous definitions.
Related terms: Data structure
View
Umbrella for a read-side projection of stored artifacts, currently Bundle and Format. Views are generated on demand and never stored.
Related terms: Bundle, Format

W

WFS/WMS API
A standardized geospatial API that makes spatial data available through Web Feature Service (WFS) and Web Map Service (WMS). It enables applications to access geographic features and map visualizations from a Dataset. Both are standards of the Open Geospatial Consortium (OGC).

X

XML Schema Definition (XSD)
A W3C language for describing the structure of XML documents. Model Management imports XSD into JSON Schema and can serialize an Element as XSD.
Related terms: JSON Schema, Format

Total terms: 79