Files and ports
Controller
| Path | What |
|---|---|
/opt/panel/dist/ |
The panel |
/opt/panel/dist-server/controller.mjs |
The controller |
/opt/panel/dist-agent/panel-agent.mjs |
The node agent, served to nodes at /agent/panel-agent.mjs |
/etc/panel/controller.env |
Settings |
/etc/systemd/system/panel.service |
The service. It runs as the panel user, can only write in /var/lib/panel, makes files only that user can read, and can’t reach 169.254.169.254 (the cloud metadata service) |
/etc/systemd/system/panel-backup.timer, panel-backup.service |
The hourly copy of the database and secret key, by /usr/local/sbin/panel-backup |
/var/backups/panel/ |
Hourly and daily copies of the database and secret.key, and a copy taken before each upgrade. See Backing up the controller. |
/var/lib/panel/panel.db |
The database. Back it up. |
/var/lib/panel/secret.key |
The encryption key. Back it up, separately. |
/var/lib/panel/images/ |
Images the controller hands to its nodes, such as a Windows Server build. Only nodes can download them. |
/opt/panel/*.old |
The version before the last upgrade, for going back by hand |
/usr/local/sbin/panel-backup |
Takes those copies; run it by hand for one now |
/etc/panel/backup.env |
Optional: PANEL_BACKUP_RSYNC, somewhere off the server to copy them to |
/etc/caddy/Caddyfile |
HTTPS for the panel’s address, and the earlier addresses nodes may still use. Written by the installer; an older one is kept as Caddyfile.before-panel. |
Logs: journalctl -u panel.
Node
| Path | What |
|---|---|
/opt/panel-agent/panel-agent.mjs |
The agent |
/etc/panel-agent/agent.json |
Controller address, node ID and credential (root only) |
/var/lib/panel-agent/images/ |
Cached OS templates |
/var/lib/panel-agent/seeds/ |
Cloud-init seed images |
/var/lib/panel-agent/state/ |
Undelivered task results and backup manifests |
/var/lib/panel-agent/migration_ed25519 |
Its SSH key for moves and imports |
/var/lib/libvirt/images/ |
Server disks, for directory (qcow2) storage |
/etc/systemd/system/panel-agent.service |
The service, running as root |
/etc/systemd/system/panel-firewall.service |
Loads the servers’ firewall (/var/lib/panel-agent/state/firewall.nft) when the node starts, before libvirt starts any server. The agent adds it itself. |
Logs: journalctl -u panel-agent. To take all of this off a machine, see Uninstalling the agent.
On the node, servers are libvirt domains named after their server ID (srv_…), so virsh list, virsh dominfo srv_… and friends work as usual. The firewall is the nftables table bridge panel (nft list table bridge panel).
A GPU container host also has /etc/docker/daemon.json, /etc/cdi/nvidia.yaml and panel-nvidia-cdi.service; see the files it adds.
Ports
| From | To | Port | For |
|---|---|---|---|
| Browsers | Reverse proxy | TCP 443 (and 80 for redirects and certificates) | The panel, API and consoles |
| Reverse proxy | Controller | TCP 8080 on loopback | Everything, including WebSockets |
| Nodes | Reverse proxy | TCP 443 | The agent connection and console streams |
| Controller | PowerDNS | TCP 8081, usually loopback | Pushing zones |
| Controller | Your SMTP server | TCP 587 (or 465, 25) | |
| Controller | Webhook URLs | TCP 443 | Webhooks |
| Node | Node | TCP 22 on the management network | Moving servers. The disk and memory go through the SSH connection, to ports 49152–49215 on the target’s loopback only. |
| Node | Node | UDP 4789 on the management network | Private networks (VXLAN) |
| Nodes | Backup storage | TCP 443 (S3) or 22 (SFTP) | Backups |
| Nodes | Source hypervisors | TCP 22 | Copying servers during imports |
Nothing needs to be open to the nodes from the internet.
WebSocket paths
| Path | Used by |
|---|---|
/agent/v1/connect |
Each node’s connection |
/agent/v1/console/… |
A node’s side of a console session |
/console/v1/… |
The browser’s side of a console session |