Skip to content

Architecture

FACE is application code that runs on the Runink platform: a k0s Kubernetes cluster managed by Runink CORE, installed in your environment. The platform supplies the shared services FACE relies on: the model plane, the service mesh and its certificate authority, the object store, and the operators that deploy and configure FACE instances.

    flowchart TB
    U[Browser: FACE cockpit] -->|HTTPS| E[Platform edge<br/>TLS termination]
    E --> CP[FACE control plane<br/>gRPC services]

    subgraph cluster [Your Runink cluster]
      CP <-->|mutual TLS, rotating certificates| M[Mesh peers<br/>replicated configuration]
      CP -->|in-cluster HTTP| MP[Model plane<br/>text · vision · embeddings]
      CP --> S[(Sealed storage<br/>metadata · object store · records)]
      CP -->|mutual TLS| R[Managed runner]
    end

    R --> DS[(Your data sources)]
    CP -->|mutual TLS| SR[Self-hosted runner<br/>in your network]
    SR --> DS2[(Data sources behind<br/>your firewall)]
  

Components

ComponentWhat it does
CockpitThe Flutter web application analysts and operators use. It is served by a small static file server and talks to the backend over gRPC-web on the same origin.
Control planeThe FACE gRPC backend: configuration, fetch orchestration, analysis, twins, compliance, surveillance, and the other services listed in the API reference.
MeshFACE peers replicate configuration (connections, runners, settings) through a raft log carried over mutual TLS, with short-lived certificates issued from the platform’s certificate authority.
Model planeIn-cluster language, vision and embedding models behind an OpenAI-compatible HTTP interface. FACE is a client of it and ships no model server itself.
RunnersThe processes that actually dial a data source. A runner can be managed by the platform or self-hosted inside your own network, so queries run close to the data.
StorageA sealed metadata database, the platform object store, and append-only record logs for sessions, traces and data lineage.

Where your data goes

  • Model calls stay in the cluster. Prompts, retrieved records and model outputs go only to the in-cluster model plane.
  • Outbound calls go only to what you connect. That means your data sources, plus any web, mapping or messaging integrations you explicitly configure.
  • Credentials are separated from configuration. A connection record has no field that can hold a secret. Credentials go to a sealed credential store and are never returned through the API.
  • At rest, data is encrypted under a key-encryption key that the platform provides. FACE refuses to start without it rather than fall back to plaintext.

Details and limits are in Security & trust. Deployment and configuration are in Operating FACE.