DocumentationBuild. Deploy. Operate.
DocsConcepts

Core Concepts

On this page 9 sections

QSCS has a small vocabulary. Once these terms click, the rest of the documentation reads quickly.

Node

A single QSCS process running on a host. Every node has a stable UUID and a short 8-character tag derived from it (used in logs and the configuration file).

Cluster (Domain)

A named group of nodes that serve the same set of origins. spookydocs or europe-edge are typical cluster names. In configuration files and CLI commands the cluster name is sometimes called the domain, these two words mean the same thing.

Master & Thin Client

Inside a cluster, exactly one node is the master. All other nodes are thin clients. The master holds the real backend addresses for each origin; thin clients proxy through the master. See Master & Thin Clients for details.

Origin

A virtual hostname that QSCS serves (for example example.com or www.example.com) along with the backend address that should answer for it (for example 127.0.0.1:80). See Origins & the Implicit-Origin Model.

Backend Address

The real server that answers an origin's requests. On the master, this is the actual web server (commonly 127.0.0.1:80 for a co-located nginx). On a thin client, the backend address is rewritten to point at the master's QSCS port instead.

HEADLESS Mode

When QSCS detects that a backend address has failed several times in a row, it marks that origin degraded and switches to HEADLESS mode: it keeps serving cached responses for that origin until probes show recovery. See HEADLESS Mode.

Control Plane

A small HTTPS service that hands out cluster membership, licenses, and the master designation. Nodes contact it on first start, when subscribing to a cluster, and occasionally to refresh state. Nothing on the live request path goes through the control plane.

Identity Gate

Per-request authentication that lives in the substrate rather than the browser. Instead of cookies or bearer tokens, every authenticated request carries an ed25519 signature produced by a small WebAssembly module loaded on the page; QSCS verifies the signature against a public key registered at login. The private key never leaves WASM memory and the tuple (UUID, nonce) is single-use, so there is no stealable credential and no replay window. See Identity Gate for the full model.

Cache & Wire Modes

For each request, QSCS marks the response with an X-QSCS-Mode header describing what happened:

ModeMeaning
fullFetched from origin; full body returned.
incrementalOrigin produced a delta against what the caller already had.
nochangeCache validated against origin; body unchanged.
headlessOrigin unreachable; cached body returned.
Need a hand with your deployment?Contact support ↗Back to top ↑