Nexeed
    • Introduction
    • User manual
      • KPIs in the Global Production Overview module
      • Global production overview
        • Overview: Map Tab
        • Overview: Comparison tab
        • Overview: Favorites Tab
        • Configuration of Global Production Overview module
    • Developer documentation
      • Concepts
      • Getting started
      • How-to
        • Registering GPO as a new Multitenant Access Control module
        • Requesting an access token
        • Work with data publisher messages
    • Operations manual
      • Overview
      • System Architecture and Interfaces
      • System Requirements
        • Global Production Overview
      • Migration from Previous Versions
      • Setup and configuration
        • Helm Configuration
        • smc/global-production-overview
        • Setting up the replication
        • Service-to-service configuration
        • Recommendations
      • Start and Shutdown
      • Regular Operations
      • Failure Handling
      • Backup and Restore
      • Logging and Monitoring
      • Known Limitations
    • API documentation
      • HTTP API
      • Event API
    • Glossary
Global Production Overview
  • Industrial Application System
  • Core Services
    • Block Management
    • Deviation Processor
    • ID Builder
    • Multitenant Access Control
    • Notification Service
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • Global Production Overview
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Product Setup Management
    • Part Traceability
    • Process Quality
    • Setup Specs
  • Execution
    • Line Control
    • Material Management
    • Order Management
    • Packaging Control
    • Rework Control
  • Intralogistics
    • Stock Management
    • Transport Management
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
    • Maintenance Management
    • Tool Management
  • Enterprise & Shopfloor Integration
    • Archiving Bridge
    • Data Publisher
    • Engineering UI
    • ERP Connectivity
    • Gateway
    • Information Router
    • Master Data Management
    • Orchestrator

Nexeed Learning Portal

  • Global Production Overview
  • Operations manual
  • Setup and configuration
  • Recommendations
preview 2026.01.00

Recommendations

Data security

TLS (Transport Layer Security) is used to secure communication between clients (browsers) and Global Production Overview services. By default, TLS is enabled for all Global Production Overview services.

Global Production Overview does not encrypt any communication between client and application itself. The server certificates need to be handled in the Nexeed IAS Gateway. Keep in mind that the browser being used needs to trust the given CA (certification authority) as well in order to be able to communicate with Global Production Overview services.

TLS can be disabled by configuration. Do not consider this for production purposes!

Service meshes

Service meshes are state-of-the-art technology to secure all communication within and between Kubernetes clusters. They typically intercept and redirect traffic to/from the Pods using proxy containers injected into the application Pods. These proxies can then secure communication between Pods using mTLS. In such scenarios, the service mesh control plane manages the complex and error-prone certificate management for the various mTLS connections, while being transparent to the actual application workloads.

The installation and configuration of a service mesh is the responsibility of the cluster operator and is not part of the NEXEED IAS installation process. A service mesh can be used to secure communication between Global Production Overview services and NEXEED IAS modules running in the same cluster.

GPO requires communication between pods for clustering purposes and may therefore require mTLS configuration to be set to permissive in service meshes like istio.Please note that GPO requires communication between pods for clustering purposes and may therefore require mTLS configuration to be set to permissive in service meshes like istio.

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2025, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses