EFA consists of core K3s containerized microservices that interact with each other and with other infrastructure services to provide the core functions of Fabric and tenant network automation.

The Fabric Service is responsible for automating the Fabric BGP underlay and EVPN overlay. By default, the EVPN overlay is enabled but you can disable it before provisioning if necessary. The Fabric Service exposes the CLI and REST API for automating the Fabric underlay and overlay configuration.
Underlay automation includes interface configurations (IP numbered), BGP underlay for spine and leaf, BFD, and MCT configurations. Overlay automation includes EVPN and overlay gateway configuration.
The Tenant Service manages tenants, tenant networks, and end points, fully leveraging the knowledge of assets and the underlying Fabric. You can use the CLI and REST API for tenant network configuration on Clos and non-Clos Fabrics.
Tenant network configuration includes VLAN, BD, VE, EVPN, VTEP, VRF, and router BGP configuration on Fabric devices to provide Layer 2-Extension, Layer 3-Extension across the Fabric, Layer 2-Handoff, and Layer 3-Handoff at the edge of the Fabric.
The Inventory Service acts as an inventory of all the necessary physical and logical assets of the Fabric devices. All other EFA services rely on asset data for their configuration automation. The Inventory Service is a REST layer on top of device inventory details, with the capability to filter data based on certain fields. The Inventory Service securely stores the credentials of devices in encrypted form and makes those credentials available to different components such as the Fabric and Tenant services.
The Inventory Service supports the execute-cli option for pushing configuration and exec commands to devices. Examples include configuring SNMP parameters or OSPF configurations. This supports lets you use EFA for SLX-OS commands and push the same configuration to multiple devices.
The Asset Service provides the secure credential store and deep discovery of physical and logical assets of the managed devices. The service publishes the Asset refresh and change events to other services.
The Notification Service sends events, alerts, and tasks to external entities. Notifications sent from EFA are derived from the syslog events received from the devices that EFA manages. Alerts are notifications that services in EFA send for unexpected conditions. Tasks are user-driven operations or timer-based tasks such as device registration or Fabric creation.
The RASlog Service processes syslog messages from devices, processes SNMP traps from devices, and forwards notifications to subscribers.
The Security Service consists of authentication and authorization features that enforce a security boundary between northbound clients and downstream operations between EFA and SLX devices. The service also validates users and their credentials through Role-based Access Control (RBAC) and supports local and remote (LDAP) login.
EFA provides one-touch integration with these ecosystems, providing deep insight into VMs, vSwitches, port groups, and hosts, and the translation of these into IP Fabric networking constructs.