VorticPanel

Reference

Files and ports

Controller

Path What
/opt/panel/dist/ The panel
/opt/panel/dist-server/controller.mjs The controller
/opt/panel/dist-agent/panel-agent.mjs The node agent, served to nodes at /agent/panel-agent.mjs
/etc/panel/controller.env Settings
/etc/systemd/system/panel.service The service. It runs as the panel user, can only write in /var/lib/panel, makes files only that user can read, and can’t reach 169.254.169.254 (the cloud metadata service)
/etc/systemd/system/panel-backup.timer, panel-backup.service The hourly copy of the database and secret key, by /usr/local/sbin/panel-backup
/var/backups/panel/ Hourly and daily copies of the database and secret.key, and a copy taken before each upgrade. See Backing up the controller.
/var/lib/panel/panel.db The database. Back it up.
/var/lib/panel/secret.key The encryption key. Back it up, separately.
/var/lib/panel/images/ Images the controller hands to its nodes, such as a Windows Server build. Only nodes can download them.
/opt/panel/*.old The version before the last upgrade, for going back by hand
/usr/local/sbin/panel-backup Takes those copies; run it by hand for one now
/etc/panel/backup.env Optional: PANEL_BACKUP_RSYNC, somewhere off the server to copy them to
/etc/caddy/Caddyfile HTTPS for the panel’s address, and the earlier addresses nodes may still use. Written by the installer; an older one is kept as Caddyfile.before-panel.

Logs: journalctl -u panel.

Node

Path What
/opt/panel-agent/panel-agent.mjs The agent
/etc/panel-agent/agent.json Controller address, node ID and credential (root only)
/var/lib/panel-agent/images/ Cached OS templates
/var/lib/panel-agent/seeds/ Cloud-init seed images
/var/lib/panel-agent/state/ Undelivered task results and backup manifests
/var/lib/panel-agent/migration_ed25519 Its SSH key for moves and imports
/var/lib/libvirt/images/ Server disks, for directory (qcow2) storage
/etc/systemd/system/panel-agent.service The service, running as root
/etc/systemd/system/panel-firewall.service Loads the servers’ firewall (/var/lib/panel-agent/state/firewall.nft) when the node starts, before libvirt starts any server. The agent adds it itself.

Logs: journalctl -u panel-agent. To take all of this off a machine, see Uninstalling the agent.

On the node, servers are libvirt domains named after their server ID (srv_…), so virsh list, virsh dominfo srv_… and friends work as usual. The firewall is the nftables table bridge panel (nft list table bridge panel).

A GPU container host also has /etc/docker/daemon.json, /etc/cdi/nvidia.yaml and panel-nvidia-cdi.service; see the files it adds.

Ports

From To Port For
Browsers Reverse proxy TCP 443 (and 80 for redirects and certificates) The panel, API and consoles
Reverse proxy Controller TCP 8080 on loopback Everything, including WebSockets
Nodes Reverse proxy TCP 443 The agent connection and console streams
Controller PowerDNS TCP 8081, usually loopback Pushing zones
Controller Your SMTP server TCP 587 (or 465, 25) Email
Controller Webhook URLs TCP 443 Webhooks
Node Node TCP 22 on the management network Moving servers. The disk and memory go through the SSH connection, to ports 49152–49215 on the target’s loopback only.
Node Node UDP 4789 on the management network Private networks (VXLAN)
Nodes Backup storage TCP 443 (S3) or 22 (SFTP) Backups
Nodes Source hypervisors TCP 22 Copying servers during imports

Nothing needs to be open to the nodes from the internet.

WebSocket paths

Path Used by
/agent/v1/connect Each node’s connection
/agent/v1/console/… A node’s side of a console session
/console/v1/… The browser’s side of a console session

Every word has to appear. ↑ ↓ to move, Enter to open.