VorticPanel

Installation

Using your own web server

Most people can skip this page. The installer sets up HTTPS for you with Caddy.

Read on if the server already runs nginx (or another web server) for something else. Install with --no-proxy, and then put your web server in front of the panel:

bash vorticpanel-0.1.0/install.sh --no-proxy --domain panel.example.com

The panel listens on 127.0.0.1:8080, without TLS. Your web server has to:

  • forward everything for the panel’s domain to http://127.0.0.1:8080
  • pass WebSocket upgrades: nodes and consoles use them, on /agent/v1/connect, /agent/v1/console/… and /console/v1/…
  • send the visitor’s address in X-Forwarded-For

nginx, step by step

1. Install nginx and Certbot (for the free certificate):

apt-get install -y nginx certbot python3-certbot-nginx

2. Create the site’s file, /etc/nginx/sites-available/panel. This opens it in the nano editor:

nano /etc/nginx/sites-available/panel

Paste this in, change panel.example.com to your domain, then save with Ctrl+O, Enter and Ctrl+X:

map $http_upgrade $connection_upgrade {
    default upgrade;
    ''      close;
}

server {
    listen 80;
    server_name panel.example.com;

    client_max_body_size 2m;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection $connection_upgrade;
        # Backup downloads stream for as long as they take.
        proxy_buffering off;
        proxy_read_timeout 1h;
    }
}

3. Switch the site on, check the configuration, and reload nginx:

ln -s /etc/nginx/sites-available/panel /etc/nginx/sites-enabled/panel
nginx -t && systemctl reload nginx

nginx -t should say syntax is ok and test is successful.

4. Get the certificate. Certbot adds HTTPS to the file you made, and redirects http to https:

certbot --nginx -d panel.example.com --redirect

Check: https://panel.example.com shows the sign-in page with a valid certificate. Certbot renews the certificate on its own.

Caddy

What the installer writes to /etc/caddy/Caddyfile, if you’d rather set Caddy up yourself. Caddy gets the certificate and passes WebSockets without anything else:

panel.example.com {
	reverse_proxy 127.0.0.1:8080
}

Then systemctl reload caddy.

A proxy on another machine

The panel only believes X-Forwarded-For from addresses in PANEL_TRUSTED_PROXIES (just this machine, by default). If the proxy is on another machine, add its address to /etc/panel/controller.env and restart the panel:

PANEL_TRUSTED_PROXIES=10.0.0.5

Without it, sign-in limits, IP allowlists and the audit log see the proxy’s address instead of the visitor’s.

Every word has to appear. ↑ ↓ to move, Enter to open.