Panel Link

The panel link is the single multiplexed WebSocket between an authenticated browser tab and the Panel. Browsers cannot hold mTLS client certificates, so they never dial a Core. Every live byte they see arrives over this socket.

One panel link per Panel session (one tab). It carries coreId-tagged frames for all Cores at once: PTY streams, events, mutations, dial statuses. Framing mirrors the core link — same shapes, replay-by-cursor, reconnect semantics. The Panel is the router: browser frames fan out to the right core link; Core events fan back stamped with coreId.

Server rendering covers first paint. The panel link carries everything live after it. The Panel UI holds no connections to Cores and no fleet state beyond view preferences.

Proxy

The Panel speaks plain HTTP on port 7420. TLS is your proxy. That proxy must upgrade WebSockets — the panel link is one — and set X-Forwarded-Proto: https, or the Panel issues a session cookie the browser will send over plain HTTP.

None of that touches the core link. Core-link mTLS is minted by the Core. Your proxy does not terminate or renew it.

Tabs

A tab that reloads is a new socket for the same Operator looking at the same pane. The tab presents a Panel tab id on upgrade so Session drive (which of this Panel's tabs holds the keyboard) survives the reload. That id authenticates nothing and reaches no Core.

Two of this Panel's tabs on one Session are one human with two tabs. The Panel is a single Core client; it holds a Session lock once for all of its tabs. Which tab drives is settled inside the Panel and never crosses the core link.

See also

Built by Qcentic