Glossary
Quick reference for terms you’ll see in the UI, docs, and logs. Deeper behaviour: Configuration & Runtime Engine, REST API Reference, Security.
Names and capitalization
| Term | Form | Meaning |
|---|---|---|
| Padas Motion | Title Case | Product line and install SKU. |
| Motion Engine | Title Case (then engine) | Streaming runtime (padas-core tree). Not the product-line name. |
| Padas UI | Title Case on first mention | The operator app; introduce it as Padas UI, the console. |
| console | lowercase | The short name in running prose after Padas UI is introduced. The console is the control plane. |
| control plane | lowercase | Role of the console—not a product or page name. |
| Control Tower | Title Case | One Management screen (live graph / start-stop on the selected Core)—not the whole console. |
| Cores / Core | Title Case | console inventory of engines (Configurations → Cores). Each row is a registered Motion Engine. |
core/, padas-core-*, [core], padas-core.service | monospace | Path, package, TOML table, systemd unit. |
Runtime & Architecture
Core
A Core in the console is a registered Motion Engine instance (host/port). The engine process routes events (StreamRouter), runs tasks and connectors, optional WAL, and serves /api/v1/*. Registry rows live under [api.persistence].config_dir (for example streams.json, tasks.json, connectors.json). Tune paths and limits in padas.toml — see Motion Engine TOML and Configuration & Runtime Engine.
Motion Engine
The streaming runtime inside Padas Motion. Same process as Core in the inventory: there is no separate “pipeline service” per workflow.
Runtime Engine
Synonym for Motion Engine.
StreamRouter
In-process component that buffers and routes events per stream to subscribers (tasks, consumers, WAL). Shared across all pipelines on that engine.
Streams & Processing
Stream
Named channel events flow through inside the engine. Sources publish in; tasks read and write; sinks read out. Optional WAL enables durability and historical reads.
WAL
On-disk write-ahead log for a stream when enabled. Trades disk (and sometimes latency) for crash recovery and replay. If WAL is off for a stream, some query paths may fail — check stream settings and Configuration & Runtime Engine.
Consumer lag
How far a consumer’s offset is behind the stream head. Large lag may push reads toward WAL; tune [core.subscriber.lag] and sink throughput.
Task
Registry object that reads from source stream(s), runs PDL, writes to sink stream(s). Start / stop control execution on the engine after deploy. See Tasks.
Processing task
Task mode: typically one PDL evaluation per inbound event on the hot path (plus window state for aggregates). Distinct from detection rule evaluation.
Detection task
Task mode: multiple saved conditions (queries/rules), evaluated for alerting-style matches.
PDL
Padas Domain Language — pipeline expressions (|-separated stages: parse, filter, eval, aggregate). Full syntax: PDL Reference.
Aggregation
Windowed summarisation (timespan, group_by, …). Emits flat result rows; processing tasks may fan out one downstream event per group when configured.
Watermark
Signal that a time window is ready to flush idle aggregates — ties to [core.task.aggregation.*] and shutdown behaviour.
Replay
Reading past events via stream consume APIs or POST /api/v1/query, bounded by retention and WAL. Operational replay datasets (saved slices for tests) live under Testing.
Connectors & Pipelines
Connector
Source or sink integration: moves data between external systems and streams. Stored in connectors.json; start / stop after deploy.
Source connector
Ingests from outside (syslog, HTTP, Kafka, …) into a stream.
Sink connector
Reads from a stream (or task output path) and delivers outward.
Connector class
Implementation type (http, syslog, kafka, …) — sets config schema and behaviour.
Pipeline
Registry workflow: one source, ordered tasks, one or more sinks. Defined under Configuration; assigned and deployed under Management. See Pipelines.
Operations & Deployment
Assign
Choose which sources, tasks, and sinks belong on a Core (or attach a pipeline to Cores). Saves intent — does not push to the engine by itself.
Deploy
Apply registry changes to the engine so running config matches what you assigned.
Deploy All
Push pending pipeline/deploy updates across the selected Cores (bulk deploy).
Assign and deploy
Save placement and deploy in one step for that Core/pipeline row.
Drift
UI/registry definition no longer matches what’s running — often needs Deploy, restart, or fixing partial file edits.
Monitoring & Testing
Monitoring
Live EPS (events per second), drops, stream/task/connector rows, Query, Monitor, and metrics for the selected Core — shows what’s happening now, not the registry editor. See Monitoring.
Testing
Capture or upload events, run PDL against them on an engine without changing production pipelines. See Testing.
Capture
Saved event slice from Monitoring (or uploads) used as input for Testing.
Security & Identity
Service account token
JSON file on the engine host (service-account.token) used for direct API access (automation, Troubleshooting & Logs → leftover API objects). The token field is sent as Authorization: Bearer to /api/v1/*. The console uses enrollment instead—operators do not paste this token into Cores. See Security.
Enrollment
One-time CLI setup that binds a Motion Engine (or Lookup service) to the console. After enrollment, register engine host and port in Cores only. See Installation — padas-motion.
Operator session
Browser session to Padas UI, the console (HTTP-only cookies after POST /auth/login). Used for operator login and console API authorization—not sent to the engine for normal console workflows. See Users, roles & permissions.
JWT session
Older synonym for operator session; the console issues signed access and refresh tokens in cookies.
Bearer authentication
When [api.auth].enabled, every /api/v1 route requires a valid Bearer header (including /health and /metrics).
Token rotation
The engine can issue a new service-account secret (/api/v1/auth/token/refresh); update automation clients that call the engine directly. The console's enroll credentials are managed separately—see Installation — padas-motion.
Lockout
Too many bad Bearer attempts from one client IP can temporarily block auth — check proxy X-Forwarded-For headers. Details: Security.
API & Runtime Control
REST API
The engine’s /api/v1 HTTP surface (Axum): CRUD and lifecycle for streams, tasks, connectors, query, reload, auth. Handlers use EmbeddedApiState, not a forked CLI per request. See REST API Reference.
Runtime status
GET /api/v1/status (and per-resource …/status) — snapshot of health and resources for triage.
Related pages
Configuration & Runtime Engine · REST API Reference · Security · Monitoring · Testing