Control Panel Management
On this page 5 sections
The Control Panel is the source of truth for platform-managed cluster state. It updates a versioned configuration snapshot instead of asking operators to keep every node configuration file aligned by hand.
Domains and clusters
A domain is a cluster of nodes that serves one or more origins. Add or remove nodes in the domain tile, then select the node that can reach the real application backend as master. The selected fallback receives SecondaryMaster=true in its next configuration snapshot.
- Control PanelConfiguration revision
- Master and replicasPoll every 20 seconds for a newer snapshot
- Apply the configurationWrite complete
qscs.conf, restart once, resume service
Master and fallback roles
- The master owns direct origin revalidation and the master lease.
- Replicas use the master as their implicit upstream and retain a local replicated cache.
- The fallback candidate monitors master routes and can request promotion only after sustained failure and control-plane approval.
- Lease fencing prevents an old master from continuing to act as primary after the topology changes.
Origin controls
| Control | Use it for | Effect |
|---|---|---|
| Persist cache | Warm restart resilience and low-latency anonymous content. | Writes eligible anonymous cache entries to local persistence and replicates their state through the cluster. |
| Timeout | Origins that need a specific connection budget before HEADLESS fallback. | Stores a whole-second HeadlessTimeout. Disabled uses the default detector behaviour. |
| Identity gate | Browser or API routes that require a verified QSCS identity. | Unsigned requests are stopped before the application backend. |
| Backend address | The host-local application route used by the master. | Use the complete local path router where one exists. Do not point directly at a container port if nginx adds redirects, prefixes, or headers. |
Health and telemetry
Each node sends a heartbeat approximately every minute to MonitoringHost, alongside bounded external and substrate traffic batches. Nodes also send hourly latency probes and health transitions. The Nodes tile reads this monitoring heartbeat, so a node can be healthy even if it has received no public requests recently.
Origin health is not inferred from one node. A HEADLESS alert identifies the reporting node when available and reflects whether any registered reporting route has entered the configured failure state. A cached public page may remain available during an origin outage by design.
Operational checks
# Applied configuration and role
sudo journalctl -u qscs -n 80 --no-pager
# Local public listener
curl -i -H "Host: example.com" http://127.0.0.1:8080/
# Service state
systemctl status qscs --no-pager