Panel Pairing
You are enrolling the Panel as a client of a Core. Mint the ticket on the Core first — actana pair new — then spend it here.
Two doors to the same form:
- A Panel with no Cores yet opens straight into the first-run wizard — there is nothing else to show. The wizard carries the install commands for a machine that has no Core yet, and this same pairing form.
- A Panel with a fleet: Settings (gear icon) → Cores → Add a Core.
Address, then fingerprint, then code
Enter the Core address the Panel can actually dial:
- Compose, Panel and Core on one network:
core:8443— the service name; the Core publishes no host port, the Panel reaches it over the compose network. - Metal, or a Core the Panel reaches by name:
host:8443— an entry of that Core'sACTANA_PUBLIC_HOST, a SAN on its server certificate.
Check fingerprint before anything secret is typed. The Panel dials with nothing trusted and sends nothing. It shows the CA fingerprint that machine presented; compare it against the CA fingerprint line of the handout. A mismatch stops — the code fields are not shown, and the code is not sent. Why the fingerprint exists.
Only after they match do Session and Pairing code appear. The session id is part of the ticket, not optional. Then the eight-character code — hyphen and case are yours to get wrong. The name in this Panel is optional; empty falls back to the endpoint host.
After a 200, the Core appears in Fleet. The credential is sealed on the Panel server; the browser never sees the private key.
Address already registered
If this Panel already has a Core at that endpoint, pairing refuses before spending the code — you get the registry's sentence, not a spent ticket.
That matters after actana token regenerate. Rotation does not move the endpoint, so a second Add a Core at the same address is refused until you remove the Core (Settings → Cores → Remove Core), then mint a fresh code and add it again. actana core pair is different: it replaces the stored credential in place.
What the Panel must reach
The Panel dials the Core, never the reverse. If 8443 is unreachable from the Panel host, the fingerprint check fails and nothing is paired. In compose, that path is the service name on the compose network, not localhost on your laptop.