Runtime topology
One public Edge. Everything else stays behind it.
Edge is the only Clearplane container exposed to the host and the outside world. It accepts traffic on ports 80 and 443, then reaches applications and the control plane through separate networks.
Runtime boundary
Public request path
Traffic enters once.
Applications publish no host ports for Clearplane traffic. They join the services network and receive matched requests from Edge.
| Container | Networks | Host ports | Responsibility |
|---|---|---|---|
| Edge | internal · services | 80 · 443 | Public ingress, TLS, policy, routing |
| Core | internal · egress | None | Configuration, persistence, management API |
| UI | internal | None | Browser management application |
| ContainerProxy | internal | None | Read-only container-runtime boundary |
Network wiring
Separate paths, narrow membership
Three networks keep each job in its lane.
clearplane-internal
Edge, Core, UI, and ContainerProxy communicate here over internal HTTPS on port 8443 with exact-identity mTLS. The bridge is marked internal.
Edge · Core · UI · ContainerProxyclearplane-services
Edge shares this network with application containers so it can discover and proxy them. Core, UI, and ContainerProxy do not join it.
Edge · application containersclearplane-egress
Core uses this dedicated outbound path without joining the services network. Other Clearplane containers are not members.
Core onlyUI and API exposure
Protected like any other route
Management also enters through Edge.
UI and Core publish no host ports. When management access is enabled, ordinary protected routes on Edge expose the browser UI and API on the same public host and origin.
/Routes to UI over clearplane-internal.
/api/{**catch-all}Routes to Core /external/{**catch-all}.
/api/ws/*SignalR upgrades use the API route.
/internal/*Never routed publicly.
Discovery boundary
The runtime socket stops here
Edge never receives container-runtime access.
- 01ContainerProxy reads metadata.
ContainerProxy alone holds the read-only runtime socket and exposes an allowlisted internal API.
- 02Core reconciles ownership.
Core combines validated container labels with configuration owned through the UI and API.
- 03Edge receives one revision.
Core sends a coherent configuration revision. Edge validates the complete candidate and keeps the last valid configuration when a candidate fails.
Configure from the UI, API, or Docker labels.
Each resource keeps its owner while Core projects one configuration to the public Edge.