Architecture
FACE is application code that runs on the Runink platform: a k0s Kubernetes cluster managed by Runink CORE, installed in your environment. The platform supplies the shared services FACE relies on: the model plane, the service mesh and its certificate authority, the object store, and the operators that deploy and configure FACE instances.
flowchart TB
U[Browser: FACE cockpit] -->|HTTPS| E[Platform edge<br/>TLS termination]
E --> CP[FACE control plane<br/>gRPC services]
subgraph cluster [Your Runink cluster]
CP <-->|mutual TLS, rotating certificates| M[Mesh peers<br/>replicated configuration]
CP -->|in-cluster HTTP| MP[Model plane<br/>text · vision · embeddings]
CP --> S[(Sealed storage<br/>metadata · object store · records)]
CP -->|mutual TLS| R[Managed runner]
end
R --> DS[(Your data sources)]
CP -->|mutual TLS| SR[Self-hosted runner<br/>in your network]
SR --> DS2[(Data sources behind<br/>your firewall)]
Components
| Component | What it does |
|---|---|
| Cockpit | The Flutter web application analysts and operators use. It is served by a small static file server and talks to the backend over gRPC-web on the same origin. |
| Control plane | The FACE gRPC backend: configuration, fetch orchestration, analysis, twins, compliance, surveillance, and the other services listed in the API reference. |
| Mesh | FACE peers replicate configuration (connections, runners, settings) through a raft log carried over mutual TLS, with short-lived certificates issued from the platform’s certificate authority. |
| Model plane | In-cluster language, vision and embedding models behind an OpenAI-compatible HTTP interface. FACE is a client of it and ships no model server itself. |
| Runners | The processes that actually dial a data source. A runner can be managed by the platform or self-hosted inside your own network, so queries run close to the data. |
| Storage | A sealed metadata database, the platform object store, and append-only record logs for sessions, traces and data lineage. |
Where your data goes
- Model calls stay in the cluster. Prompts, retrieved records and model outputs go only to the in-cluster model plane.
- Outbound calls go only to what you connect. That means your data sources, plus any web, mapping or messaging integrations you explicitly configure.
- Credentials are separated from configuration. A connection record has no field that can hold a secret. Credentials go to a sealed credential store and are never returned through the API.
- At rest, data is encrypted under a key-encryption key that the platform provides. FACE refuses to start without it rather than fall back to plaintext.
Details and limits are in Security & trust. Deployment and configuration are in Operating FACE.