Using your own web server
Most people can skip this page. The installer sets up HTTPS for you with Caddy.
Read on if the server already runs nginx (or another web server) for something else. Install with --no-proxy, and then put your web server in front of the panel:
bash vorticpanel-0.1.0/install.sh --no-proxy --domain panel.example.com
The panel listens on 127.0.0.1:8080, without TLS. Your web server has to:
- forward everything for the panel’s domain to
http://127.0.0.1:8080 - pass WebSocket upgrades: nodes and consoles use them, on
/agent/v1/connect,/agent/v1/console/…and/console/v1/… - send the visitor’s address in
X-Forwarded-For
nginx, step by step
1. Install nginx and Certbot (for the free certificate):
apt-get install -y nginx certbot python3-certbot-nginx
2. Create the site’s file, /etc/nginx/sites-available/panel. This opens it in the nano editor:
nano /etc/nginx/sites-available/panel
Paste this in, change panel.example.com to your domain, then save with Ctrl+O, Enter and Ctrl+X:
map $http_upgrade $connection_upgrade {
default upgrade;
'' close;
}
server {
listen 80;
server_name panel.example.com;
client_max_body_size 2m;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
# Backup downloads stream for as long as they take.
proxy_buffering off;
proxy_read_timeout 1h;
}
}
3. Switch the site on, check the configuration, and reload nginx:
ln -s /etc/nginx/sites-available/panel /etc/nginx/sites-enabled/panel
nginx -t && systemctl reload nginx
nginx -t should say syntax is ok and test is successful.
4. Get the certificate. Certbot adds HTTPS to the file you made, and redirects http to https:
certbot --nginx -d panel.example.com --redirect
Check: https://panel.example.com shows the sign-in page with a valid certificate. Certbot renews the certificate on its own.
Caddy
What the installer writes to /etc/caddy/Caddyfile, if you’d rather set Caddy up yourself. Caddy gets the certificate and passes WebSockets without anything else:
panel.example.com {
reverse_proxy 127.0.0.1:8080
}
Then systemctl reload caddy.
A proxy on another machine
The panel only believes X-Forwarded-For from addresses in PANEL_TRUSTED_PROXIES (just this machine, by default). If the proxy is on another machine, add its address to /etc/panel/controller.env and restart the panel:
PANEL_TRUSTED_PROXIES=10.0.0.5
Without it, sign-in limits, IP allowlists and the audit log see the proxy’s address instead of the visitor’s.