owned this note
owned this note
Published
Linked with GitHub
---
title: Enterprise AAA Management (FOSS - fosseam)
tags: fosseam, brainstorm
description: Erste Sammlung zum Thema FOSS - EAM
---
# FOSS Enterprise AAA Management (fosseam)
## Upfront
A steht für
- Architecture (meistens)
- Asset (öfters)
- Application (hin und wieder), eher Application Portfolio Mangement
- API (selten)
- ARM (nie ;-)
### Sinn & Zweck von EAM
1. Transparenz herstellen
2. Digitale Souveränität skalieren insb. durch FOSS
3. Kosten- & Ressourcen sparen: re:duce, re:use, re:cycle
4. Informationen für alle Bereiche des IT-Managements bereitstellen
5. Grundlagen für
- die Entwicklung der IT-Strategie und
- das Business-IT-Alignment schaffen
6. Systemlandschaft(en) konsolidieren
7. Planungsinstrumente bereitstellen
8. Best Practices für die Architektur sammeln
9. Einhaltung von Compliance-Anforderungen vereinfachen
### Erster grober Gedankensturm
german:
FOSS-EAM ...
... liefert API Management?
... ist IT-Portfolio Management?
... ist Master-Data Management?
... integriert NoLowCode, BPMN?
... bietet Dependency Management?
... ist im Kern auch Asset-Management?
... braucht Enteprise Data-Catalogues?
... bietet Application Developer Portale?
... benutzt EA-Design/Modellierungs Tools?
... basiert auf sBOM's? (spdx, nist, owasp)
... integriert InfoSec, Release-Flow, DevOps?
... berücksichtigt Standards, like TOGAF, ITIL, COBIT, CMMI...?
... integriert verschiedene Teildisziplinen?
english:
FOSS EAM ...
... provides API management?
... is IT portfolio management?
... is master data management?
... integrates NoLowCode, BPMN?
... offers dependency management?
... is also asset management?
... does Enterprise need data catalogs?
... offers application developer portals?
... based on sBOMs? (spdx,nist,owasp)
... uses EA design/modeling tools?
... integrates InfoSec, release flow, DevOps?
... considers standards like TOGAF, ITIL, COBIT, CMMI...?
... integrates different sub-disciplines?
### Standards
- Corporate Governance: COBIT, COSO, ISO/IEC 38500:2008
- IT Service Management: ISO 20000, ITIL
- InfoSec: ISO/IEC 2700x und IT-Grundschutz-Kataloge
- Projectmanagement: SAFe, PMBOK Guide, IPMA ICB und PRINCE2
- Architecture: TOGAF, Archimate, Zachmann, SysML, C4
- Systemen Development: TickIT und CMMI
### EA Reference-Theories
* TOGAF
* TOGAF's Enterprise Continuum From Common to Specific:
![](https://i.imgur.com/pXwkE78.png)
* [TOGAF aus Sicht von GERAM](https://www.opengroup.org/architecture/wp/saha/TOGAF_GERAM_Mapping.htm)
* TOGAF in Wikipedia [en](https://en.wikipedia.org/wiki/The_Open_Group_Architecture_Framework) [de](https://de.wikipedia.org/wiki/TOGAF)
* Zachman (Meta-Theory):
* Zachman mapped to OMG's MDA:
![](https://i.imgur.com/6CIa8mM.png)
* Zachman vs. TOGAF: [BMC-Article](https://www.bmc.com/blogs/togaf-vs-zachman/)
* Zachman in Wikipedia [de](https://de.wikipedia.org/wiki/Zachman_Framework) [en](https://en.wikipedia.org/wiki/Zachman_Framework)
* [Domain Driven Design & Co](https://hackmd.io/PBJg96nxRtCVrsjEyzmUcg)
## FOSS-Tools (mostly)
### Modelling (Togaf, Archimate, ...)
* [Archi HP](https://www.archimatetool.com/), [Upstream](https://github.com/archimatetool/archi)
* [Modellio](https://www.modelio.org/downloads/download-modelio.html)
* [Visual Paradigm Online, with Freemium](https://online.visual-paradigm.com/)
### Asset-Management
* [Backstage.io](https://backstage.io/), [Upstream](https://github.com/backstage/backstage), [Live-Demo](https://demo.backstage.io), [Plugins](https://backstage.io/plugins)
* [roadie.io](https://roadie.io/), [Upstream](https://github.com/RoadieHQ) - Backstage SaaS
* [GLPI](https://glpi-project.org/), [Upstream](https://github.com/glpi-project), [Lab-Demo](https://lab.r3s.nrw/glpi/front/central.php), [Plugins](https://plugins.glpi-project.org/#/), [Forum](https://forum.glpi-project.org/index.php)
* [Snipe-IT](https://snipeitapp.com/), [Upstream](https://github.com/snipe/snipe-it), [Live-Demo](https://demo.snipeitapp.com/)
### CMDB
CMDBuild
i-doit
iTop
Ralph
Zenos Core (Zenoss Community Edition)
OneCMDB
DATAGERRY
BlueKing CMDB
### Data Management
- [CKAN](https://ckan.org/)
- [Dataverse](https://dataverse.org/)
- [Pimcore](https://de.wikipedia.org/wiki/Pimcore)
- [Keen](https://github.com/keen/keen)
- [Unidata](https://github.com/Unidata)
- [Semarchy xDM](https://www.semarchy.com/)
- [Metabase](https://www.metabase.com/)
### IT-Portfolio Management (NON-FOSS)
* [ABACUS by Avolution](https://www.avolutionsoftware.com/abacus/)
* [ADOIT, BOC-Group, Wien](https://www.boc-group.com/en/adoit/)
* [alfabet, Software AG](https://www.softwareag.com/de_de/platform/alfabet.html)
* [LeanIX, Bonn](https://www.leanix.net/de/produkte/enterprise-architecture-management) siehe: [Slides1](https://de.slideshare.net/leanIX_net/realtime-enterprise-architecture),[Slides2](https://de.slideshare.net/leanIX_net/the-next-big-thing-71851224?next_slideshow=71851224)
* [MapIT - Freeware](https://frankitecture.wordpress.com/my-ea-tool/download-and-install/)
### Application Marketplaces
- [YunoHost - Application Catalog](https://yunohost.org/en/apps)
- [Cloudron - App Store](https://www.cloudron.io/store/index.html)
- [Bitnami - Application Catalog](https://bitnami.com/stacks)
- [Heroku - Add-Ons](https://elements.heroku.com/addons)
- [Snapcraft - The app store for Linux](https://snapcraft.io/)
- [Flathub - Apps for Linux](https://flathub.org/home)
- [F-Droid - FOSS applications for Android](https://f-droid.org/)
### Package Manager
- [List of 32 Package Manager on libraries.io](https://libraries.io/)
- [deb](https://www.debian.org/doc/manuals/debian-reference/ch02.en.html)
- [rpm](http://rpm.org/)
- [Homebrew](https://brew.sh/)
- [scoop](https://scoop.sh/)
- [chocolatey](https://chocolatey.org/)
### PaaS-Solutions
- [YunoHost](https://yunohost.org), [Upstream](https://github.com/YunoHost/yunohost)
- [OpenShift/OKD](https://www.okd.io/), [Upstream](https://github.com/openshift/okd)
- [Portainer](https://www.portainer.io/), [Upstream](https://github.com/portainer/portainer)
- [VirtEngine](https://virtengine.com/), [Upstream](https://github.com/VirtEngine)
- [Cloudify](https://cloudify.co/), [Upstream](https://github.com/cloudify-cosmo)
### API Management
- API Umbrella (NGINX, Ruby)
- Fusio (Apache httpd, PHP)
- Gravitee (Java)
- Kong (NGINX, Lua)
- KrakenD (Go, Martian)
- Tyk (Go)
- Wicked (NGINX, JavaScript, Lua)
- WSO2 (Java, OSGi)
- [traefik](https://traefik.io/) (Go) -> wird bei FIT-Connect genutzt
### Dependency-Management
* REUSE-Spezifikation: https://reuse.software/
* [OSS Review Toolkit, ORT](https://github.com/oss-review-toolkit/ort)
* [Eclipse SW 360, inkl. Fossology](https://www.eclipse.org/sw360/), [15 Min. Fossdem-Talk](https://fosdem.org/2022/schedule/event/how_to_manage_oss_license_obligation_and_sbom_using_sw360_new_features/)
* https://www.fossology.org/
* [DependencyTracker](https://dependencytrack.org/)
* [RenovateBot](https://github.com/renovatebot/renovate)
* https://scancode-toolkit.readthedocs.io/
* https://github.com/aquasecurity/trivy und https://github.com/hadolint/hadolint für Docker-Images
.
.
.
## More ...
### Sammlungen / Anregungen aus dem Matrix-Chat
* [ADOIT Screencast](https://www.youtube.com/watch?v=CzgpZw5iFHA&t=261s)
* [Cloudnative Landscape](https://landscape.cncf.io/)
* [Awesome eGoverment](https://github.com/codedust/awesome-egov-de)
* [Awesome Tech-Radars/Maps](https://codeberg.org/codedust/awesome-tech-maps)
* [Wikimatrix als Feature Compare Lösung](https://www.wikimatrix.org/)
### Weitere Übersichten:
* https://internaldeveloperplatform.org/
* https://linuxpip.org/best-open-source-cmdb-software/
* [Gartner, 2021: Critical Capabilities for Enterprise Architecture Tools via Ardoq](https://content.ardoq.com/gartner-critical-capabilities-for-enterprise-architecture-tools?utm_source=google&utm_medium=cpc&utm_campaign=2021-Search-Global-Gartner-CC&utm_content=enteprise-architecture-tools&utm_term=enterprise%20architecture%20tools&hsa_acc=8848011804&hsa_cam=17561882345&hsa_grp=139444815313&hsa_ad=569457679639&hsa_src=g&hsa_tgt=kwd-488884628072&hsa_kw=enterprise%20architecture%20tools&hsa_mt=b&hsa_net=adwords&hsa_ver=3&gclid=Cj0KCQjw8O-VBhCpARIsACMvVLPzpNxv3e3HoUhHBfwSLKzvGZYIQwDHiRwkbBRTVlQzhQlzX8kxXtMaAhiSEALw_wcB)
* https://socialism.tools/cloudron-yunohost-self-host-app-showdown/
* https://internaldeveloperplatform.org/frameworks/
* https://www.computerwoche.de/a/18-ea-tools-im-vergleich,3066120
* https://www.predic8.de/open-source-api-management-kong-tyk-fusio-umbrella-wso2.htm
* https://www.inform-it.org/open-source-enterprise-architecture-tools/
* https://www.hitechnectar.com/blogs/open-source-master-data-management-tools/
### Barcamp Idee
* Barcamp: https://hackmd.io/rgYMbHW_QaOouOwmPp-jNw
### More Ideas
* Newsletter, Blogpost triggerd by new Releases
* Compare- & Voting-Stuff like stackshare or wikimatrix
* awesome list
* fosseam landscape