Controller settings
The controller reads its settings from the environment, usually /etc/panel/controller.env through the systemd unit. Each one can also be given as a command-line flag, which wins over the environment.
| Variable | Flag | Default | What it does |
|---|---|---|---|
PANEL_PUBLIC_URL |
--public-url |
none | The address people use, e.g. https://panel.example.com. The address only, no path. Used for email links, the node install command, secure cookies, refusing other sites, the console’s WebSocket address and passkeys. |
PANEL_FORMER_URLS |
--former-urls |
none | Comma-separated addresses the panel had before, e.g. http://203.0.113.4. Nodes still set up for one are told to switch to PANEL_PUBLIC_URL, which they do by themselves. The installer sets it when the panel moves, and --forget-old-addresses clears it. See Moving to a domain. |
PANEL_LISTEN |
--listen |
127.0.0.1:8080 |
Host and port to listen on. Put a TLS proxy in front. |
PANEL_DATA_DIR |
--data-dir |
./data |
Where panel.db and secret.key live |
PANEL_UI_DIR |
--ui-dir |
./dist |
The built panel |
PANEL_AGENT_DIR |
--agent-dir |
./dist-agent |
The built node agent, handed to new nodes |
PANEL_IMAGES_DIR |
--images-dir |
<data dir>/images |
OS images the controller serves to its own nodes at /images/<file>, such as a Windows template built on a node. Only nodes can download them. |
PANEL_TRUSTED_PROXIES |
--trusted-proxies |
loopback |
Comma-separated addresses or ranges whose X-Forwarded-For is believed |
PANEL_SECRET_KEY |
<data dir>/secret.key, made on first start |
Base64 key that encrypts saved credentials and backup keys | |
PANEL_STOP_WAIT |
--stop-wait |
120 |
Seconds a stop or restart waits for running jobs to finish |
PANEL_LOG_REQUESTS |
--log-requests |
off | 1 logs every request. Tokens in links are left out. |
PANEL_DEMO |
--demo |
off | 1 runs the demo world, with its own demo.db, instead of a real install |
PANEL_PDNS_URL |
--pdns-url |
none | PowerDNS’s API, e.g. http://127.0.0.1:8081, to serve customers’ zones and reverse DNS. You can instead connect PowerDNS in the panel, at Network → Reverse DNS → PowerDNS; when these variables are set, they win and the panel page shows them read-only. |
PANEL_PDNS_KEY |
--pdns-key |
none | Its API key (api-key in pdns.conf). Required with PANEL_PDNS_URL. |
PANEL_PDNS_SERVER |
--pdns-server |
localhost |
PowerDNS’s server ID |
Without PANEL_PUBLIC_URL, cookies aren’t marked Secure and the controller warns at start.
Settings errors
The controller refuses to start when a setting is wrong, and says why:
| Message | Fix |
|---|---|
PANEL_LISTEN has to end in a port, like 127.0.0.1:8080 |
Add the port |
PANEL_PUBLIC_URL is the address only, like https://panel.example.com |
Remove any path |
PANEL_PDNS_URL is set, so PANEL_PDNS_KEY has to be too |
Add the key from pdns.conf |
Node agent
The agent on each node reads:
| Variable | Default | What it does |
|---|---|---|
PANEL_AGENT_INSECURE |
off | 1 lets enroll use a plain http:// controller address. For labs only. |
PANEL_AGENT_ETC |
/etc/panel-agent |
Where its credential is kept |
PANEL_AGENT_ROOT |
/var/lib/panel-agent |
Where its images and state are kept |
Everything else
Branding, email, sign-in policy, customer features and limits are set in the panel, under Platform settings. Regions have their own page, Fleet → Regions.