Webcore

WEBCORE PANEL ARCHITECTURE

A control plane built above the servers.

Webcore Panel separates platform administration, hosting-node operation and WordPress site access so each layer can expose the right controls without making every user a fleet administrator.

CONTROL PLANEWebcore PanelFleet · accounts · placement · DNS · operations
NODEHosting NodeAgent · Nginx · Apache · PHP-FPM · MariaDB
NODEHosting NodeAgent · Nginx · Apache · PHP-FPM · MariaDB
NODEDedicated NodeScoped Panel access · SSH · WP-CLI
Site layer: WordPress · Git · WP-CLI · cache · staging · backups · malware
Control PlaneNode AgentHosting NodesSite SSH/SFTPSite LayerWP-CLIRBACIsolation

FOUR ACCESS LAYERS

Infrastructure capability does not imply unrestricted access.

The architecture separates the organisation operating the platform, account-level administrators, explicitly scoped dedicated-node operators and users responsible only for individual WordPress sites.

01

Platform

Fleet, provisioning, placement, global DNS, migrations, updates and platform-wide administration.

02

Account

Manage authorised sites, users and entitled workflows without inheriting fleet-wide permissions.

03

Dedicated node

Explicitly assigned operators can receive node-level Panel controls and SSH for infrastructure dedicated to them.

CONTROL PLANE

Operate the fleet from one place.

The Panel maintains identity, management endpoints, runtimes, site counts, node state, shared-pool membership, capacity, accounts, DNS and platform operations. Capacity-aware placement uses the eligible fleet and current state when placing new shared workloads.

Webcore Panel Hosting Nodes fleet view

NODE ENROLMENT

Bootstrap once. Manage through the platform afterwards.

A clean Ubuntu host can be provisioned from the Panel. Temporary bootstrap access establishes the Webcore node stack, authenticated agent relationship and management TLS; routine platform operations then use that managed relationship.

This does not prevent an infrastructure owner or authorised dedicated-node customer from having SSH access to infrastructure they are entitled to administer.

Webcore Panel node provisioning workflow

HOSTING NODE

The application stack stays local to the workload.

Nginx, Apache, PHP-FPM, MariaDB and the Webcore Agent run on the hosting node. Supported service state and recovery controls are surfaced to the control plane while WordPress traffic remains independent of the Panel request path.

Webcore Panel hosting stack services

REQUEST PATH

The control plane is not in front of the website.

A normal visitor request reaches the hosting node directly. The Panel operates the environment but does not proxy normal WordPress traffic.

01Visitor
02NginxCache hit can end here
03Apache
04PHP-FPM
05WordPress + DB

SITE LAYER

WordPress tools follow the site.

WordPress management, Git deployment, WP-CLI, Nginx page cache, Redis object cache, staging, backups, SSL, files, scheduled tasks, logs, diagnostics and malware protection belong to the application operating layer.

WP-CLI and enabled site SSH/SFTP are site capabilities, available independently of node-administration permissions.

Webcore Panel WordPress site overview

DEDICATED NODE ACCESS

Site access and server administration stay separate.

Developer SSH/SFTP uses public keys and exposes only the enabled site in a managed filesystem environment. It requires platform, node and site approval. Infrastructure administration is a separate responsibility with separately scoped access.

Dedicated-node access does not grant visibility of unrelated nodes, other tenants or the wider control plane.

Webcore Panel Developer SSH and SFTP policy and connection details

TENANCY & RBAC

Scope the interface to responsibility.

Platform Admins operate the platform. Account administrators work within their account scope. Site administrators can be restricted to selected sites, while node permissions and site-migration entitlement are granted separately where required.

Webcore Panel Users and Access

TRUST BOUNDARIES

Different credentials for different responsibilities.

Provisioning access

Temporary bootstrap access is used only to establish a managed node and is removed after provisioning.

Control-plane management

Routine fleet operations use the authenticated node agent and management TLS.

Dedicated SSH

Authorised operators may use SSH on dedicated nodes without receiving fleet-wide Panel access.

Site command line

WP-CLI is a WordPress/site capability and can be provided independently of general node SSH.

WEBCORE PANEL

One platform, with control at the right layer.

Webcore Panel provides the WordPress operating model while infrastructure owners retain control of their servers, network and customer relationship.