---
title: "Architecture"
url: "https://control.actana.ai/docs/architecture"
description: "The wire-level design: Panel vs Core, the Singular UI, and the links every client uses."
updated: 2026-09-01T09:02:49+00:00
---

Actana Control detaches the UI from the work. The **Panel** is one self-hosted web service: Operator login, a Core registry, and a live router. Each **Core** is a daemon on a machine that has your code. It owns projects, tasks, sessions, SQLite, and PTYs. The Panel holds no task-shaped state.

One Panel drives many Cores. The Panel dials; Cores never dial back. Default Core port is `8443`. Every Core is remote — even one on the Panel's host. The same components render every Session and Project regardless of which Core owns the data. That is the **Singular UI**.

Writes land on the Core as [core-link](/docs/architecture/core-link) frames, not REST. File bytes use HTTPS `/v1/...`, not that socket. The browser never talks to a Core: it holds one [panel link](/docs/architecture/panel-link). The Panel is a Core client like the CLI and `@actana/sdk`.

```mermaid
flowchart LR
  UI[Panel UI] -->|panel link| Panel[Panel]
  Panel -->|core link wss mTLS| C1[Core A]
  Panel -->|core link wss mTLS| C2[Core B]
  Panel -.->|HTTPS /v1 files| C1
  Panel -.->|HTTPS /v1 files| C2
```

## See also

- [Core link](/docs/architecture/core-link) — `wss` mTLS, bearer `auth` frame, event cursor.
- [Panel link](/docs/architecture/panel-link) — one multiplexed WebSocket per browser tab.
- [Write path](/docs/architecture/write-path) — Core is the source of truth.
- [Filesystem](/docs/architecture/filesystem) — file bytes cross HTTPS, not the core link.
