OIOpen Industrial Automation

Cloud-first engineering with explicit industrial boundaries

Phase 1 proves a deterministic reference process, browser operator experience and engineering evidence chain. It is a platform foundation, not a substitute for certified controllers, qualified field hardware or competent commissioning.

Architecture

Automation Project Model
->
Deterministic control core
->
HTTP simulation boundary
->
HMI and Engineering Studio

The project model carries stable asset, signal, recipe, alarm and requirement identities. Control behaviour is independently testable. The service publishes only a bounded state and role-checked command interface.

Automation Project Model

DomainPhase 1 content
AssetsTanks, pumps, agitator and heater
SignalsLevel, temperature, flow, conductivity and speed
RecipesProduction and clean-in-place phase procedures
EvidenceRequirements, tests, risks and release records

Verification

Unit, integration and browser tests are joined by model, traceability, security, container and Bicep gates. Each release produces a machine-readable manifest and SPDX-style software bill of materials.

Cybersecurity

The HTTP service limits command bodies, applies browser security headers and checks roles at the server boundary. No credentials are stored. MQTT and OPC UA ports are not published. Azure templates compile without login or deployment.

Safety boundary

Certified safety remains independent. Emergency stops, guards, interlocks, pressure protection, hazardous-energy isolation and safe motion require separately engineered hardware and physical validation.

Cloud delivery

GitHub is the control plane. Codespaces provides browser development. Actions provides repeatable CI. Container images are GHCR-ready. Azure Container Apps infrastructure is declared but remains undeployed until a separate cost and security approval.