Control Plane
Central management, provisioning, tenant, fleet, and deployment coordination plane.
The Control Plane is the one FaburAI service that knows about every tenant. Its router (control-plane/app/backend/gateway/router.go) mounts a single API group at /api/control-plane, and everything under it is either a public lookup used by tenant-facing SPAs at startup, or gated behind a staff-only middleware group — tenants, the per-tenant IdP credentials handler, fleet, and registry are all staff routes, meaning day-to-day tenant and cluster administration is a FaburAI-operator activity, not something a customer does through this plane. Tenant-scoped routes (cluster listing, tenant Kubernetes cluster registration) sit outside that gate and rely on the handlers themselves to filter by tenant ID.
Its backend modules split cleanly along that job: tenants owns tenant records and their settings; provisioning and clusters create and manage the actual Data Plane deployments a tenant runs on, including the multi-cluster fan-out used when applying configuration changes; fleet and registry track the Kubernetes clusters available to the platform (system-owned or tenant-owned) and basic key/value configuration; secrets provides the encryption service the tenants module uses to store IdP credentials at rest; billing tracks credit and consumption; and docs has no backend of its own — it mounts the shared docsserve package to serve the Control Plane's own copy of the documentation corpus.
Two plain, unauthenticated endpoints exist specifically for Data Planes to talk back to the Control Plane: POST /api/cp/v1/register, which a Data Plane calls on boot, and POST /api/cp/v1/heartbeat, which it calls periodically to report health — the handler tries to match the reporting cluster by cluster ID, then by Kubernetes namespace, then by tenant ID, so a heartbeat still lands even if the caller only knows one of those identifiers. The Control Plane also exposes its documentation corpus to Data Planes over /api/cp/v1/docs-relay, so a Data Plane without its own reachable corpus can proxy documentation reads through the Control Plane instead of carrying a second copy.
In short, the Control Plane is the multi-tenant control surface: it is where tenants, their clusters, and the Data Planes running in those clusters are created, tracked, and administered, while the governance work itself — policies, catalog, enforcement — happens entirely inside each tenant's own Data Plane.

Docs