FAQ
Questions that cut across the sections. Each answer links to the page with the detail.
General
Is CORE the same as Kubernetes?
No. CORE runs on k0s and deploys with pure kustomize, without Helm. It adds its own operators, the
ClientInstance tenant API, the security spine, the agent fleet and the console. See
Architecture.
Do the apps depend on CORE?
No. FACE, PULSE, LUNA and FORGE do not import CORE, and each carries a test that fails if it does.
Code more than one of them runs lives in shared libraries (store, ui, inference, mesh,
security, ml).
How do I sign in?
With Google (when GOOGLE_CLIENT_ID is set) or with a username and password (when
CONSOLE_ADMIN_PASSWORD is set), at your installation’s own console URL. Your address must be on
CONSOLE_ALLOWED_EMAILS or in CONSOLE_ALLOWED_HD: with neither set, every Google sign-in is
refused. There is no Microsoft or other identity provider in the console code. See
Getting started.
Which models does CORE use? Does it call a hosted AI service?
It calls no hosted model. The inference plane is sovereign, and mistral.rs is the only engine.
Every model call goes through cmd/modelrouter, the one admission queue in front of the engines. See
Models and inference.
Does CORE send my data anywhere? CORE dials a tenant source in one place only: Intelligence › Resolve, and only when an admin runs one of its four actions (Test, Explore, Read access patterns, Map estate). Reads never dial. Agents registered in the Atlas workspace are metadata: CORE never calls, polls or sends data to one. See Resolve.
DevEx
How long does a coding session take?
Budget in decode time, not wall-clock intuition. The coder tier decoded at about 4.2 tokens per second
on the target server, so a 40-turn session is roughly an hour. core session start defaults to
--max-turns 40, --timeout 2h and --turn-timeout 15m. See Coding sessions.
Can I stop a running session?
There is no core session stop. A run ends when it finishes, or at --max-turns, --timeout or
--turn-timeout. Sessions persist under ~/.core/sessions/<id>, and core session resume <id>
continues one with a new instruction.
Why does the curator’s daily run succeed but publish nothing?
The curator is dry unless the Actions variable CURATOR_CRON_DRY_RUN is the literal string false.
Unset means dry, and a dry run finishes green. See Agent fleet.
Why are reviews slow and one at a time? The model plane serves one request at a time on the CPU text engine, so reviews are serialised. See Review pipeline.
DataEx
Does CORE scan my data every day? The data governance agent runs daily, but it reads no rows and no values. It assesses data quality and PII exposure only from the structure and counts that Resolve’s Explore recorded. A source nobody explored is reported unassessable, with the reason. See Data governance.
Why does my runner show offline when it is connected?
Running work on a self-hosted runner arrives in rollout step 6. Until then an active, connected
runner is still refused as runner_offline, with the detail “connected; dispatch arrives in rollout
step 6”. See Runners.
What is the difference between findings and judgements? A finding is a claim made by an agent or an assessment platform. A judgement is CORE’s own verdict on a finding that an external platform submitted: concur, dissent, or unable to judge. Unable-to-judge is never shown as agreement. See Judgements.
Why does the judge always report unable to judge?
Its docket can only be filled through POST /api/judgement/submissions, which needs
CORE_JUDGEMENT_INGEST_TOKEN. Nothing in the deployed manifests provides that token, so as deployed
the docket stays empty. That is the design working, not a fault.
Intelligence
Where do the Intelligence pages come from? They are a page-for-page Flutter port of the partner product Atlas, over CORE’s own data and CORE’s own in-process gRPC-web services. See Intelligence.
Why are most rules “Shadow” in a new workspace? The rules reconciliation calls a rule Shadow when the engine runs it but no governance decision declares it. In a fresh workspace nobody has decided anything yet, so most rules are Shadow. See Rule governance.
FORGE
Is FORGE a separate site?
No. FORGE is served inside CORE at /forge/, under CORE’s sign-in. There is no FORGE domain and no
FORGE login. FORGE has not been deployed yet. See FORGE.
Who runs CI for a forged repository?
CORE does, centrally. Forged repositories carry no CI of their own and no App credentials. CORE
posts the result as the core/ci commit status. See Central verification.