Admin guide
The admin interface (https://<host>:2087) is organized in twelve sidebar sections: Accounts, Websites, Email, DNS, Databases, Access, Backups, Security, Server, Cluster, Migration, Panel. A search box at the top of the sidebar filters the entries. The start page shows node load, disks, service status, counters and the advisor's findings.
Everything the web interface does is also available through the API; a subset is also available through the panel command-line tool on the server (run panel with no arguments for the list). In a cluster the CLI is read-only for shared data: use the web interface or the API instead (see Clustering).
Nodes
A node is one server running the panel. A standalone install is a single node. Hostname, date/time/time zone, IP addresses and an immediate or scheduled reboot are under Server.
- Hostname (Server → Hostname): changing it also checks
/etc/resolv.confand restores it if the rename emptied it. The panel certificate and mail certificate depend on the hostname, so reissue them afterwards. In a cluster, the node's identity is not its hostname and does not change. - Reboot now requires explicit confirmation and is refused on a cluster node (use the coordinated reboot, see Clustering).
- Scheduled reboot: pick a window (for example 03:00-05:00); the node reboots there only when a newer kernel is pending. Off by default.
Services
Server → Services lists the services the panel manages (Apache, nginx, OpenLiteSpeed, Varnish, Postfix, Dovecot, Rspamd, ClamAV, BIND, unbound, Pure-FTPd, cron, MariaDB, PostgreSQL, Prometheus, Grafana, the firewall and the panel itself) with their real state. You can start, stop and restart them.
- The list is closed: the panel only operates the services in its catalog, never arbitrary units.
- Stop is an intention. A service you stop stays stopped: reconciliation and configuration publishes do not restart it. The advisor reminds you while something is stopped on purpose.
- The panel does not restart itself from this screen.
- "Not installed" is distinct from "stopped".
Firewall
The firewall is built on nftables and managed from Security → Firewall, Allowed and Blocked. Each field explains what it does and who it affects.
- Ports: the installer seeds the ports of the services it installed (web, mail, DNS, FTP and its passive range). Add or close others per protocol and range.
- Floor ports: SSH and the two panel ports are always open and cannot be closed from the panel, so you cannot lock yourself out.
- Allowed: addresses that bypass blocks. Put your own address here before tightening anything.
- Blocked: temporary or permanent bans. Bans expire in the kernel; no daemon has to lift them.
- Import CSF: reads a
csf.confand the allow/deny lists so that existing tuning is not lost. - Anti brute-force: repeated failed panel logins from one address are banned at the firewall.
CLI: panel fw-sembrar, fw-aplicar, fw-permitir, fw-denegar, fw-ban, fw-desbanear.
PHP
- Node PHP version (Server → PHP): the version used when a site does not choose its own. With a license, install extra versions from the provider's repository (disabled by default) and choose a version per site (Websites → site → PHP options). Without a license only one version is active.
- Missing version fallback. If you uninstall a version that some site uses, those sites move to the nearest lower installed version, or the nearest higher if none is lower. Their requested version is kept, so reinstalling restores it. The advisor lists affected sites.
- PHP extensions (Access → PHP extensions): a closed catalog per client. Common extensions can be toggled by the client; six risky ones (
ffi,xdebug,pcntl,posix,imap,ssh2) can only be enabled by an admin, client by client, and the page says what each one opens up.imagickruns with a hardened ImageMagick policy; availability depends on the distribution release. - Handler:
panel manejador-php fpm|fcgidshows or sets the node handler. PHP-FPM needs a license; fcgid+suexec is the Free-tier handler. - Each account runs its own PHP-FPM master (per client and version) with
open_basediranddisable_functionsapplied; see Security model.
Web stacks
The public edge on ports 80/443 is one of Apache, nginx or OpenLiteSpeed, chosen per node. Only one process can own those ports; everything behind it (PHP-FPM, containers) listens on loopback.
panel stack # shows the current edge
panel stack nginx # apache | nginx | litespeed
Switching releases the ports, rewrites the sockets and brings up the new edge; if the new edge does not come up the panel rolls back to the previous one. Varnish and Apache-behind-nginx combinations exist in the design (nginx+Varnish+Apache); selecting them from the panel is Coming soon.
Website options available to clients (and enforced in all three edges) are listed in the Client guide.
Plans, resellers and accounts
See Resellers for plans and resellers. Account operations:
- Accounts → New account creates the client, its UNIX user and optionally a first site and plan.
- Suspend cuts service (sites, mail, databases, FTP, cron, containers, console) but the client can still sign in to the panel to see why. Deactivate also blocks panel sign-in. Both are reversible and delete nothing. These actions set a state; repeating them is safe.
- Bulk operations (Accounts) suspend, reactivate or change plans for many accounts at once, authorizing each account separately and reporting what changed, what was already so, and what failed. Filters: suspended, over quota.
- Console (shell) access is off by default; enabling it gives the client an SSH shell inside an isolated jail. SFTP works for every active account.
- Impersonate (Accounts → Impersonate): admins can open a client's panel to troubleshoot; it is audited with both names and requires your own password.
- Reset a user's password / regenerate second factor: available to admins; each requires your own password and closes the target's sessions.
Updates
Panel → Updates and CLI:
panel actualizacion-canal estable https://license.teraservercloud.com/artefactos
panel actualizacion-buscar # is there a newer version?
panel actualizar # apply it
- Three channels: estable (stable), candidata (release candidate) and beta, selectable per node.
- Updates are never applied without you asking. The node first checks it has no drift from its desired state.
- The update is a signed package verified against a key pinned on the node. A different channel's manifest is rejected, and key rotation can only move forward.
- It is applied by a detached process; afterwards the panel must stay up and healthy. If it does not, the node rolls back to the previous version automatically.
- Updates are served to nodes whose license is reporting; a Free node with no license is still served.
Audit log
Security → Audit records who did what, when, from which address and on which resource, including admin actions. It is append-only from the panel's point of view. Entries can be sent off the node, which is the only protection if the node itself is compromised:
panel auditoria-externa # is it sending?
panel auditoria-externa-destino syslog+tls://logs.example.com:6514
panel auditoria-externa-destino - # turn off (this action is itself sent before it stops)
- Format: RFC 5424 syslog with octet-counted framing, which standard rsyslog, Graylog and Splunk understand.
- With
syslog+tls://the server certificate is always verified; there is no switch to skip verification. If your SIEM uses a private CA, upload that CA in the audit page (Security → Audit): it is trusted for that destination only. - Plain
syslog://is accepted for trusted internal networks. - If the destination is down, entries are queued and retried; the advisor warns while sending is stuck.
Metrics
- The node exposes Prometheus-format metrics at
/metricason the admin port, protected by a bearer token you generate in Server → Metrics (shown once; rotate or remove it there). Without a token the path returns 404. This is free in all tiers. - It measures the node and each client's CPU, memory, IO and throttling from its cgroup, service state, and counters. It does not publish per-site series.
- With a License, Server → Metrics stack installs Prometheus and Grafana on the node. Each node runs its own pair and scrapes the others, so every node has the data of the whole cluster. Grafana is reached through the panel (admin only); it has no separate login.
Advisor
Server → Recommendations reads what the panel already knows and lists items that have a concrete action: expired or soon-to-expire certificates, sites served in plain HTTP, stopped services the node needs, backup destinations not running, an empty firewall, clients with free-form server directives enabled, stuck audit export, sites whose requested PHP version is not installed, transfer over 80% of plan. A table with no rows means it checked and found nothing.
Other admin tools
- Logs of the node (Server): mail, web, DNS, firewall and panel logs with search.
- Mail queue (Email): list, requeue or delete queued messages. Every change is audited first.
- Malware scan (Security): detects and reports; it never deletes files.
- WAF (Websites): ModSecurity with the OWASP core ruleset; rule exclusions per site. Needs a License.
- Cloudflare (DNS): see API & integrations.
- Backup destinations (Backups): see the backups section of the Client guide.
- Brand (Panel → Brand): panel name, logo and colors; see Resellers.