AI AdminPanel Documentation

Features Overview

AI Admin Panel brings deployment, service management, and hosting administration into a self-hosted panel. Availability depends on your edition, permissions, configuration, and server resources. See Licensing for the Free, Power User, and Web Host editions.

Deployment Methods

MethodWorkflowBefore deploying
TemplateChoose an available catalog card, configure, review, deployCheck requirements and Coming Soon status
GitProvide a repository and build configurationCheck repository access and the detected build method
AI-poweredAnalyze a project URL and generate deployment configurationConfigure Panel AI and review the generated configuration
ComposeSupply Docker Compose YAMLReview images, volumes, ports, and security mode

Start with First Deploy, or read the Deployment guides for the individual workflows.

Template Catalog

Browse AI Services, Databases, DevTools, and Web Apps, or search by name. Examples include Ollama, LibreChat, PostgreSQL, n8n, Uptime Kuma, and WordPress. Coming Soon cards are previews, not deployment options. The unfiltered catalog in this version shows the first result page; use search or a category to find entries outside that page. Source manifests, listed cards, and deployable entries are different inventories. See Template Overview.

Service Management

  • Service status, application links, resource usage, logs, and deployment progress
  • Start, stop, restart, redeploy, and removal actions, subject to permissions
  • Customer assignment, plans, and resource controls for hosting workflows
  • Domain routing through Traefik and certificate automation with configured DNS

A running container is not proof that the application is ready; open its URL and check its own setup requirements. See Domains and DNS.

Identity and Hosting Administration

Keycloak provides OIDC sign-in. Roles, permissions, organization scope, and edition controls determine access to customer and service management. The server resolves each request's permissions from the caller's role memberships for the organization being acted on, and API keys never exceed their owner's current access. Accounts below the platform level, such as resellers and organization Admins, can only use routes whose handlers check that the target belongs to them; everything else is reserved for platform administrators. Today that covers their own organization, its users, projects and role assignments, the customers they created (and only those), those customers' services and secrets, and their account and API keys. On a customer's service a reseller can view it, start, stop, restart, redeploy and delete it, edit its environment, rotate its secrets, move the service between its own customers, and manage its webhook and its existing domains, each only with the matching permission. A suspended customer's services are read-only to it. Lists show only the caller's own part of the tree: the organization list and tree, projects, services and their metrics summary, the audit log and its export, the activity feed, the dashboard, metering and subscriptions. Customers' things count only for customers below the reseller. Metering reports configured resource limits, not measured consumption: the total for an organization and everything below it, or, for platform administrators, for the whole panel. A reseller's dashboard shows no host CPU, memory or disk figures: the host cards are not drawn, and the template deployment page says that server capacity is not shown for the account.

The audit log shows a reseller, or a customer organization's admin, the events that are about its own organization and the organizations below it, whoever did them: its own staff, the hosting provider's staff, or the system (backups, deployments, secret rotation). Each event keeps the organization it was about when it happened, so it stays in the right tenant's log after the service, the customer or the user is deleted. Free-form details are never shown outside the platform. Who acted is shown only when that person belonged inside the reader's own organization tree at the time. Otherwise the actor column reads Identity not shown and the entry carries no user, email, IP address or browser. That label has two causes: the actor was outside your organization tree (for example the hosting provider's staff acting on your account), or the event was recorded before the panel started storing where actors belong. Filtering by actor only finds entries whose actor you are shown, and the CSV export follows the same rules.

History from before that upgrade is attributed only where the panel can prove which tenant it was about: events about a customer, a subscription or an API key, and events that recorded their tenant when they were written. Older events about a service, a backup or a backup schedule stay visible to platform administrators only, because a service can be moved between customers and nothing recorded where it was at the time.

Creating services (raw Compose, Git or a catalog template), changing resource limits, suspending services, adding domains, backups beyond viewing, AI model routes, the terminal, changing subscriptions and panel-wide settings stay with platform administrators until those get their own checks. Only a platform administrator can suspend or unsuspend an organization (the default Reseller role still holds organizations.suspend, currently without effect on those two actions). An Admin of a reseller or customer organization can terminate organizations below its own, never its own organization; the default Reseller role cannot terminate. The Web Host edition adds reseller-oriented organization and plan features. Read Customer Management and Service Plans for the operator workflows.

AI and GPU Support

Configure Panel AI separately from the AI sources used by deployed applications. The panel can use local inference or configured external providers. See How AI Works.

The AI Models overview and instance detail show model and hardware status. Deployment forms offer GPU selection on detected GPU hosts. NVIDIA acceleration requires a working host driver and NVIDIA Container Toolkit; detecting a card does not prove a model is using it. See Installation.

Backups, Notifications, and Updates

  • Backup and Restore: service backup workflows, with storage options depending on edition and configuration
  • Notifications: configured channels for operational alerts
  • Updates: release checks, manual apply, and optional scheduled updates with a host updater

A backup is useful only if you can restore the corresponding data, configuration, and secrets. Panel updates and application data recovery are separate operations.

Security and Infrastructure

The installer provisions PostgreSQL, Valkey, Traefik, Keycloak, OpenBao, Ollama, LiteLLM, and the panel. Templates offer Secure, Advanced, and Raw deployment modes with different controls. Use Secure unless the workload needs an explicitly reviewed exception. These controls do not establish complete network isolation between tenants; deployed services can share proxy networks.

Managed secrets use OpenBao by default; installation secret files and encrypted configuration also require protection. HTTPS depends on DNS, challenge reachability, and certificate issuance. Self-hosting gives control over placement, while licensing, updates, and configured external integrations can still make outbound connections.