Skip to main content
The InferCrane console is a separate web application over the same authenticated control API used by the CLI, SDKs, Terraform provider, and terminal workspace. It is not a second backend and never reads PostgreSQL or provider credentials directly.
The hosted console is a company-operated service over the public InferCrane control contracts. The Apache-2.0 core remains CLI-, API-, Terraform-, and terminal-first and does not require an InferCrane account.

What the console covers

  • fleet attention, stable endpoints, and concrete deployments;
  • durable operations with reconnectable timelines and cooperative cancellation;
  • Request Inspector and deterministic Doctor findings;
  • endpoint monitoring for request rate, errors, fallback, TTFT, queueing, latency, and reported token throughput;
  • typed freshness, source, sample count, and availability for every monitoring measurement;
  • Release Guard, benchmark, replay, revision, and replica evidence where available;
  • lifecycle overlays, signed alert policies, sourced FinOps reports, and signed output-quality evidence;
  • provider/runtime capability inventory and secret references;
  • private/gated model-access references and authenticated existing-endpoint discovery;
  • content-free telemetry imports and workload replay history;
  • scoped API-key lifecycle, organization roles, hosted SSO entry, and approval boundaries;
  • a curated Model API shelf with InferCrane rates, capabilities, limits, and availability.
Missing or forbidden evidence remains explicit. A failed optional panel does not make a deployment look healthy, and an unavailable measurement is never rendered as zero.

First-run paths

Create endpoint starts with the application identity the user wants, then asks how it should be served. The primary paths are ordered by intent:
  1. Deploy an open model starts from a reviewed model configuration, exposes only the required serving choices, and keeps runtime, accelerator, region, and scaling under Advanced.
  2. Connect existing inference discovers vLLM, SGLang, LiteLLM, or another compatible endpoint and starts observe-only. The endpoint page then presents a separate, explicit ownership action before InferCrane can route traffic. Promotion changes routing ownership only; it does not grant lifecycle control over the external workload. Saved Baseten, Fireworks, OpenRouter, and generic OpenAI-compatible connections can authenticate the bounded discovery call without putting their bearer credential in the browser or endpoint URL.
  3. Use a Model API selects a hosted InferCrane product, creates one API key, and uses the same OpenAI-compatible endpoint across the catalog. The customer surface shows only the InferCrane rate, capability, limit, and availability contract. Procurement routing, internal offer IDs, credentials, and upstream rate provenance remain inside the control plane. Prepaid reservation happens before a managed request can leave InferCrane.
Teams that want to pay infrastructure vendors directly use the separate Your infrastructure path. Connecting infrastructure does not make that vendor part of the Model API product catalog, authorize spend, or send traffic. Each workflow separates configuration from review. The review step states ownership, billable effects, missing cost evidence, and whether traffic changes before the mutation is submitted. The deployment templates mirror InferCrane’s reviewed curated recipes. They are configuration-only starting points, not benchmark, price, compatibility, or performance claims. The console never chooses hardware or displays a cost estimate without grounded evidence. Deployment operations are durable and remain reattachable after the browser closes. The console navigation keeps stable application identities under Endpoints, lifecycle-managed capacity under Deployments, live evidence under Monitoring, and provider/runtime setup under Settings → Connections. Existing monitoring systems enter through Settings → Observability; identity and policy remain under Settings → Access. Endpoint pages expose task tabs for monitoring, requests, releases, routing, and settings. Deployment pages expose replicas, revisions, autoscaling, benchmarks, and events without turning every capability into a global navigation item. Optional evidence fails locally: a missing benchmark, alert, member directory, or adapter inventory shows an explicit unavailable panel while the rest of the resource stays usable. Unknown values are not converted to zero. The monitoring page queries only the authenticated control API. PostgreSQL request evidence and lifecycle events form the initial local evidence store; OpenTelemetry GenAI semantics define the portable names and dimensions. Runtime-internal metrics remain unavailable until a qualified runtime adapter reports them. GPU utilization, memory, temperature, power, and XID evidence appear when a qualified collector posts a fresh revision-bound snapshot. The UI displays why evidence is absent or stale rather than rendering an unknown value as zero.

Self-hosted interface boundary

The public repository ships the control API, OpenAI-compatible gateway, CLI, Python and TypeScript SDKs, Terraform provider, and terminal workspace. Those surfaces are sufficient to self-operate InferCrane and do not depend on the hosted console. The browser console source is maintained as a separate company-operated service and is not part of the Apache-2.0 repository.

Hosted identity and workspace provisioning

Hosted mode uses Clerk for sign-in, sessions, and organization selection. The Go control plane then independently requires a mapped InferCrane user, organization membership, role/scopes, and active web_console_access entitlement. Configure the Go verifier with the Clerk instance’s HTTPS issuer and public JWT verification key. Use the inline value when the deployment platform stores environment secrets, or the file value when it mounts secrets; never configure both:
When automatic provisioning is enabled, a cryptographically verified Clerk organization receives a dedicated tenant on first use. Its first member is the tenant administrator; subsequent members use the role asserted by Clerk. Provisioning is transactional and idempotent, never remaps an external organization, never changes an existing membership during login, and never restores revoked access. Keep the setting disabled when access must be granted only through the administrative provisioning API. Every protected page and server action resolves a server-side session. Every control API request then repeats authentication, authorization, and tenant ownership checks. Organization IDs supplied only by browser input never establish authority.

Durable work

Closing the browser does not cancel deployment work. Reopen the console or resume from any terminal:
Cancellation is cooperative. Provider cleanup may continue after cancellation is requested or the browser closes.

Terminal equivalent

For headless, low-bandwidth, or incident use, the terminal surfaces remain first-class:
The public Console link opens the hosted product. If an organization is not entitled to a hosted capability, the console shows that boundary explicitly instead of fabricating an available offer. The web workspace’s npm run test:e2e:empty-control-plane journey starts with a new PostgreSQL volume and verifies this first-run flow through the real control API. It is the regression boundary for empty states and browser-to-control-plane wiring; the hosted identity provider and real GPU/cloud boundaries remain separate release qualifications.