V8 Central — Product & Technical Spec
  1. Docs
  2. Product
  3. Product architecture

#Product architecture

#System context

  • The browser only talks to sa-central-api-2. It never calls an OSS panel or a provider directly. Server keys and provider tokens stay on the backend. V8 requirement R5 (common OSS client) · Security
  • sa-central-api-2 holds accounts, organizations, billing, roles and a small link record per server. It calls OSS panels through one shared OSS client (built with the Servers phase, not the Foundation phase — backend update 2026-10-03) that handles auth headers, timeouts, retries, error mapping and secret-free logging. V8 requirement §2.2
  • OSS panels answer with live data. The Central key signs in as a machine administrator account on that panel (CentralSystemGuard). It can use the whole OSS API except creating, changing or deleting panel users and roles. OSS API

#What lives where (V8 rule R5)

Central database (stored)OSS panel (fetched live, never stored in Central)
Users, login data, 2FA, IP whitelist, sessionsServer facts, metrics, processes
Organizations, members, roles, permissionsApplications and everything inside them
Plans, subscriptions, wallet, transactions, invoicesDatabases, system users, services, firewall, cron, backups…
Providers (encrypted tokens)OSS's own activity log ("central" machine account)
A few link fields per server (which ones is still open, Q1)Panel version, health
Blueprints (Central stores them, as V7 did; OSS runs them) OSS APIAdd-on run results
Central audit log, notifications

V8 requirement §2.1

#Request path

#Frontend architecture

LayerChoiceStatus
FrameworkNext.js 16 App Router, JavaScript onlyConfirmed scaffold
UIshadcn/ui primitives in components/ui/ (button, card, dialog, dropdown, input, select, sheet, table, tabs, tooltip, sonner…), Tailwind v4Confirmed scaffold
i18nnext-intl, /[locale]/… routes, messages/<locale>.jsonRequired by project rules. Not installed yet Missing
Formsreact-hook-form + zodzod installed · react-hook-form not installed Missing
TablesTanStack Table v8Not installed Missing
HTTPaxios instance in lib/api/ with interceptorsaxios installed · client not written
StateZustand for cross-component UI state (current organization, sidebar)installed
ChartsRechartsinstalled
Themenext-themesinstalled

Rule for the build: server components by default, "use client" only where state, effects or browser APIs are needed. Every route group gets loading, error and not-found. The frontend is a view layer with no business logic.

#Backend architecture (from the V8 doc)

ConcernDecisionSource
FrameworkLaravel 13V8 requirement Phase 1
DatabaseMariaDB, separate per pair (sv_central / sv_central_2), utf8mb4, strictV8 requirement (currently still SQLite in .env)
Cache / sessions / queueRedis; Horizon queues default, notifications, emailsV8 requirement
API authLaravel Passport: access 15 days, refresh 30 days, personal token 6 monthsV8 requirement
CORSOnly the configured frontend URL; api/*, oauth/*; Authorization headerV8 requirement
LogsDaily, 14 days, never tokens/passwords/AuthorizationV8 requirement
TestsPest for every endpoint; OSS faked with Http::fakeV8 requirement

#Key architectural consequences

ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC