Features

Everything you need to run a production server

Each module is independent, permission-aware and audited. Privileged changes always go through the typed agent and are validated before they are applied.

Websites & Nginx

Static, PHP, reverse-proxy and Node.js sites with Nginx configs generated from controlled templates.

  • Domains, aliases, redirects, custom headers and upload limits
  • Every change runs nginx -t first — a failing config never replaces the last known-good one
  • Per-site config history with rollback
  • Per-site PHP-FPM pools and PHP versions
server_name example.com www.example.com;
listen 443 ssl http2;
# generated by Pushpendra Panel — validated with nginx -t

Node.js apps & Git deploy

Push to a branch and ship: fetch → install → build → health check → atomic switch, with one-click rollback.

  • GitHub, GitLab, Bitbucket or any Git remote via deploy keys
  • Signed webhooks with replay protection
  • npm, pnpm or yarn; apps run as their own unprivileged user under systemd
  • Build logs, commit info and previous releases kept for rollback
push main → fetch a1b2c3d → npm ci → npm run build
→ GET /health 200 → switch release → reload ✓

Databases

MySQL/MariaDB first, PostgreSQL as a separate adapter — each database with its own least-privilege user.

  • Create databases and users, rotate passwords
  • Import, export, size visibility, backup and restore
  • Database ports stay bound to localhost by default

DNS & nameservers

Manage zones and records through an API-driven authoritative DNS backend, with your own branded nameservers.

  • A, AAAA, CNAME, MX, TXT, CAA, SRV and NS records with validation
  • Zone templates for websites, mail and verification records
  • Change history and zone export; reverse-DNS mismatch detection

Mail hosting

Postfix, Dovecot and Rspamd with mailboxes, aliases, forwarding and quotas.

  • Automatic MX, SPF, DKIM and DMARC records
  • Per-domain and per-mailbox sending limits to reduce abuse
  • Health checks for hostname, PTR, SPF, DKIM, DMARC and TLS

SSL certificates

Free Let’s Encrypt certificates with automatic renewal, or upload your own.

  • HTTP-01 for normal domains, DNS-01 for wildcards
  • Renewal retries and expiry alerts
  • Private keys never appear in logs or API responses

Web application firewall

ModSecurity-compatible WAF with the OWASP Core Rule Set, per site.

  • Detection-only and blocking modes
  • Per-site exclusions for false positives, with expiry and audit trail
  • Security events with sensitive fields redacted

Firewall & SSH hardening

One consistent UI over the OS firewall, with lock-out protection for the active admin.

  • Only 80/443 public by default; restrict the panel port to trusted IPs
  • Temporary rules that expire automatically
  • SSH status: root login, password auth, allowed users and keys

Backups & restore

Scheduled backups of files, databases and configuration to local disk or S3-compatible storage.

  • Retention policies with automatic pruning
  • Encrypted remote backups
  • Restore preview that shows exactly what will be overwritten

Multi-user workspaces

Give clients and teammates exactly the access they need — nothing more.

  • Workspace roles: owner, developer, viewer and custom
  • Resources are isolated per workspace with Linux-level separation
  • Temporary memberships that expire automatically

File manager & logs

Browse, edit, upload and unzip files inside your workspace root — never outside it.

  • Path-traversal protection and tenant isolation
  • Nginx, application, deployment and WAF logs in one place
  • Sensitive files require stronger permissions and are audited

Monitoring, cron & audit

Server resources, service health, scheduled jobs and a complete audit trail.

  • CPU, RAM, disk, network and service health on the dashboard
  • Cron jobs with run-now, history, exit codes and bounded logs
  • Append-only audit log of every privileged action