headends.md

MK.IO Beam for headends

MK.IO Beam modernizes traditional broadcast and streaming headend workflows with a cloud-connected, software-based approach. Running on standard COTS servers, it delivers cost-effective, portable, and programmable live video processing. Fully integrated with the MK.IO cloud orchestration layer, MK.IO Beam enables centralized control, monitoring, and software lifecycle management.

Its flexible commercial models, including pay-as-you-go, multi-year enterprise licenses, and perpetual licenses ensure streamlined procurement and scalability for any deployment.

Common Workflows

Architecture & Redundancy

Encoding & Processing

Multiplexing

Packaging

Layers

The solution has three main layers:

These three layers are glued together by the common micro-services architecture of all the MediaKind components.

MK.IO Beam for streaming and MK.IO Beam for broadcast use components to address the different processing listed below:

Management Layer

The management layer is the control/command of the whole headend. This is the single-entry point to access all functions of the headend. This interface (UI & API) is designed to:

Configuration, Control and Monitoring

MK.IO Beam for streaming and MK.IO Beam for broadcast benefit from a single entry-point for all operations. MediaKind management and configuration component is the centralized point to configure and command the headend.

It is built upon the following principles:

The management nodes gather all the metrics and logs from the full headend to provide a global health of the system. This monitoring layer provides information on the deployed applications and the infrastructure the headend is running on.

Processing Layer

The processing layer comprises one or multiple components running on any infrastructure. To increase reliability, this layer is designed to be completely independent of the management layer. This independence ensures continuous processing even if the connection with the management layer is lost.

Live Video Service Encoding

MediaKind brings together 25 years of video compression experience to deliver the highest quality, any screen software applications for live video encoding and transcoding. MediaKind's continued investment and focus on the latest compression technologies ensures that the encoding component will efficiently deliver the best picture quality over bandwidth in all encoding environments and networks. This component is ideal for any real-time broadcast application, including IPTV, cable, DTH and Internet TV. As a service-oriented software solution designed to address today’s key technological and operational challenges:

Live Video Service Packaging

The packaging component is a powerful solution designed for the distribution, personalization, and monetization of multiscreen video services. You can also deploy it across your network to drastically reduce the bandwidth, storage or equipment footprint usually required to distribute video services securely to smartphones, tablets, connected TVs, game consoles, PCs, or OTT Set- Top-Boxes. MediaKind architecture is extremely modular and can scale according to your needs. It combines the following key functions:

Reliable Transport (SRT, Zixi, RIST)

Another complexity for broadcast operations is how to send or retrieve the content to/from a headend via private or public IP networks. The integration of SRT, RIST, and Zixi as a component of the MK.IO Beam for streaming and MK.IO Beam for broadcast solutions allows an easy to setup, and secure link for reliably passing data.

Stream Conditioning

The Stream Conditioning can be used with Live Encoder to trigger functions such as SCTE-35 rewrite, animation/text crawling, slate/logo insertion, live-to-file and file-to-live video switching using operation type Video clip.

Viewing Policy Manager

The Viewing Policy Manager is used to configure the ingest of programming events schedules. This has limited functionality in the current version of MK.IO Beam.

Security

Access & Security Configuration

Controller is the single-entry point for any action via the UI or the API. A virtual IP is defined to always redirect the requests to the active controller when the solution is deployed in 1+1 redundancy.

It is possible and recommended to activate the HTTPS connection and to use the API in a secured way to secure the access to the system. By default the user management is activated to access the UI.

Info: This user management can be connected to an LDAP service for better integration in your system.

OS Security

All the products are software products running on Linux operating systems. To ensure the security of the solution MediaKind uses Nessus® vulnerability scanner tool to highlight any security risk. Based on the results, MediaKind regularly (every two months) propose “security packages” to secure the OS the MediaKind products are running on. Each security package will upgrade some of the libraries present on the OS to ensure products are using the secured version of these. Products are tested with these security packages installed to ensure their behavior with the latest libraries. OS should not be upgraded outside of these security packages.