Core Concepts
On this page 9 sections
QSCS has a small vocabulary. Once these terms click, the rest of the documentation reads quickly.
Node
A single QSCS process running on a host. Every node has a stable UUID and a short 8-character tag derived from it (used in logs and the configuration file).
Cluster (Domain)
A named group of nodes that serve the same set of origins. spookydocs or europe-edge are typical cluster names. In configuration files and CLI commands the cluster name is sometimes called the domain, these two words mean the same thing.
Master & Thin Client
Inside a cluster, exactly one node is the master. All other nodes are thin clients. The master holds the real backend addresses for each origin; thin clients proxy through the master. See Master & Thin Clients for details.
Origin
A virtual hostname that QSCS serves (for example example.com or www.example.com) along with the backend address that should answer for it (for example 127.0.0.1:80). See Origins & the Implicit-Origin Model.
Backend Address
The real server that answers an origin's requests. On the master, this is the actual web server (commonly 127.0.0.1:80 for a co-located nginx). On a thin client, the backend address is rewritten to point at the master's QSCS port instead.
HEADLESS Mode
When QSCS detects that a backend address has failed several times in a row, it marks that origin degraded and switches to HEADLESS mode: it keeps serving cached responses for that origin until probes show recovery. See HEADLESS Mode.
Control Plane
A small HTTPS service that hands out cluster membership, licenses, and the master designation. Nodes contact it on first start, when subscribing to a cluster, and occasionally to refresh state. Nothing on the live request path goes through the control plane.
Identity Gate
Per-request authentication that lives in the substrate rather than the browser. Instead of cookies or bearer tokens, every authenticated request carries an ed25519 signature produced by a small WebAssembly module loaded on the page; QSCS verifies the signature against a public key registered at login. The private key never leaves WASM memory and the tuple (UUID, nonce) is single-use, so there is no stealable credential and no replay window. See Identity Gate for the full model.
Cache & Wire Modes
For each request, QSCS marks the response with an X-QSCS-Mode header describing what happened:
| Mode | Meaning |
|---|---|
full | Fetched from origin; full body returned. |
incremental | Origin produced a delta against what the caller already had. |
nochange | Cache validated against origin; body unchanged. |
headless | Origin unreachable; cached body returned. |