<?xml version="1.0"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "JATS-journalpublishing1.dtd"[]>
<article xml:lang="en" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" dtd-version="1.2" article-type="research-article">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">IJPDS</journal-id>
<journal-title-group>
<journal-title>International Journal of Population Data Science</journal-title>
<abbrev-journal-title>IJPDS</abbrev-journal-title>
</journal-title-group>
<issn pub-type="epub">2399-4908</issn>
<publisher>
<publisher-name>Swansea University</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.23889/ijpds.v11i5.3743</article-id>
<article-id pub-id-type="publisher-id">11:5:3743</article-id>
<article-id pub-id-type="pii">S2399490821037435</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Population Data Science</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>CR8TOR: Research Object Crates for provisioning reproducible infrastructure in Kubernetes-native federated Trusted Research Environments</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Harding</surname><given-names initials="M">Mike</given-names></name><xref ref-type="aff" rid="affil-1"><sup>1</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Thomas</surname><given-names initials="A">Alwin</given-names></name><xref ref-type="aff" rid="affil-2"><sup>2</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Nair Sudhar</surname><given-names initials="S">Saurav</given-names></name><xref ref-type="aff" rid="affil-2"><sup>2</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Vardhan Chandrabalan</surname><given-names initials="V">Vishnu</given-names></name><xref ref-type="aff" rid="affil-3"><sup>3</sup></xref></contrib>
<aff id="affil-1"><label>1</label><institution>Lancaster University, Lancaster, United Kingdom</institution></aff>
<aff id="affil-2"><label>2</label><institution>Lancashire Teaching Hospitals NHS Foundation Trust, Preston, United Kingdom</institution></aff>
<aff id="affil-3"><label>3</label><institution>Lancashire Teaching Hospitals NHS Foundation Trust, Preston, United Kingdom; Lancaster University, Lancaster, United Kingdom</institution></aff>
</contrib-group>
<pub-date date-type="pub" publication-format="electronic"><day></day><month></month><year></year></pub-date>
<pub-date date-type="collection" publication-format="electronic"><year></year></pub-date>
<volume>11</volume>
<issue>5</issue>
<elocation-id>3743</elocation-id>
<permissions>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by-nc-nd/4.0/">
<license-p>This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.</license-p>
</license>
</permissions>
<self-uri xlink:href="https://ijpds.org/article/view/3743">This article is available from the IJPDS website at: https://ijpds.org/article/view/3743</self-uri>
<abstract>
<p>Orchestration of infrastructure and data resources for research on sensitive data in Trusted Research Environments (TREs) is complex and time-consuming, with fragmented processes for data governance, identity management, disclosure checks, and resource provisioning. Research Object Crates (RO-Crates) aim to make metadata and analytical outputs FAIR (findable, accessible, interoperable, reusable), but current approaches neither record infrastructure requirements in RO-Crates nor use them for automated provisioning. CR8TOR addresses this challenge by extending standardised metadata models (Five-Safes RO-Crate) to take an active role in creating project-dependent infrastructure. Built on the Kubernetes Operator pattern within K8TRE (a Kubernetes-native, cloud-agnostic TRE implementation), CR8TOR demonstrates how contextual project information modelled in RO-Crate-like schemas can provide machine-readable representations of research resource requirements. By extending the Kubernetes API with custom resource definitions (CRDs), these resource descriptions sit alongside traditional research object metadata while maintaining FAIR principles, acting as computable units that can be recreated when required. CR8TOR supports automated data ingress from external sources, project governance controls, data provenance tracking, and on-demand reconciliation of project resources including analytics workspaces, user accounts, and access/network policies. Deployed across cloud and on-premises infrastructure supporting multi-institution collaborations, the same declarative models can be shared across deployments, enabling reproducible and portable research settings. This work demonstrates how provisionable metadata may strengthen methodological foundations of federated research by allowing TRE infrastructure specifications—including workspace configuration, controlled access rules, and project-specific identities—to be described, shared, and reproduced with clarity, consistency, and automation, ultimately lowering operational costs while improving governance and reproducibility.</p>
</abstract>
</article-meta>
</front>
</article>