#FE: Add a server (from backend Phase 8)
Frontend spec for backend Phase 8 — Servers: create & connect — requirements complete 2026-10-06 (Pair 1), not built. V8 requirement The phase the Servers screens had been waiting on since the first draft of this site. It covers six ways to get a server into Central — five of which install the OSS panel — what Central stores about it, and what happens while the install runs.
i18n namespaces: servers.add.*, servers.create.*, servers.connect.*, servers.install.*.
#A. The six ways to add a server
| # | Way | Rules from the backend doc | Frontend notes |
|---|---|---|---|
| 8.1 | Your own cloud account | Uses a provider account from Phase 5 (DigitalOcean, Vultr, Linode, Hetzner, Lightsail). The user picks name, region, size, Ubuntu version and an optional SSH key. Linode needs a root password, Lightsail a zone. Name rules per provider, as V7. OSS is installed | Confirms the wizard this site already specced. Two per-provider quirks must be handled by the form rather than hidden: Linode's extra root password field and Lightsail's zone. "Name rules per provider" means validation differs by provider, so the rules come from the API — never one regex for all five |
| 8.2 | Managed server | Created in ServerAvatar's own cloud account from the admin price list. Credit checks, trial rules, the managed-server limit and hourly billing all come from Phase 6 (6.9–6.10). OSS is installed | Conflict D-36 — the frontend builds no screen for this. Bhavik removed the "Managed server" choice from the wizard on 2026-10-05. It is now specified in two backend phases (6.9 and 8.2), so the difference is more visible, not less. Existing managed servers still work in full |
| 8.3 | Existing server — root password | The user gives IP, SSH port and root password. Central logs in over SSH and runs the OSS installer. Hostinger fixes as V7 (force cleanup moved to 8.7 on 2026-10-06, and is now optional). The root password is used for the install only and not stored (as V7) | "Not stored" is worth saying on the screen, because users hesitate to type a root password into a web form. The Hostinger case this site has carried since 2026-10-03 is now confirmed. Force cleanup is no longer automatic — it is an optional tick-box (8.7), so the wizard must let the user choose it and say plainly what it removes |
| 8.4 | Existing server — install command | Central shows a one-line install command; the user runs it as root. OSS is installed and the server links itself to Central | A copy-the-command screen that then waits. It needs a visible "waiting for this server to call home" state with no deadline promised, because the user may run the command minutes later — and it must survive a page reload |
| 8.5 | Connect an existing OSS panel | In OSS: Settings → Central → Enable, copy the token. In Central: enter the panel URL and token. Checks: HTTPS, health check answers, token accepted, panel not linked to another account, plan limit OK | Matches what this site already documented, with one addition worth the wording: "panel not linked to another account" must be a neutral message — it must not reveal whose account it is |
| 8.6 | Free managed server — "ServerAvatar Lite" | Kept, as V7: an install script registers the server without a ServerAvatar account. The server is attached to ServerAvatar's own accounts (admin-set list) and their plan; the person gets a limited panel login — as V7: 100 apps, 100 databases, with backups, Git, Fail2ban, staging, clone, workers, cloud storage and disk cleaner off. Corrected 2026-10-06: OSS is NOT installed on this type (the phase goal now says so explicitly, and the automatic token rule in 8.10 no longer covers it). Re-installing on the same IP replaces the old free server | Even further outside Central than it first looked (D-41). It has no Central account and no OSS panel — and every server screen in this spec is driven by the OSS API, so Central could not manage one of these even if it wanted to. Whatever the script installs to provide that "limited panel login" is not named in the doc. So there is still nothing to add to the add-server wizard, and now also nothing the server screens could show. Flagged, not invented |
#B. What every way shares
| # | Feature | Rules | Frontend notes |
|---|---|---|---|
| 8.7 | Stack & install options | LEMP, LAMP, OpenLiteSpeed, MERN. No Docker. No database at creation — the user adds a database engine in OSS after the install. Added 2026-10-06: "force cleanup" is an optional choice in every way that installs on a server (8.1–8.4 and 8.6) | Confirms Bhavik's decision that the wizard has no database-engine field; worth a line on the review step so nobody wonders where MySQL went. The new part is a real control to design: force cleanup is a tick-box the user chooses, not something that silently happens, so it needs plain wording about what gets removed — this is the switch that makes an existing server with Apache or MySQL on it usable |
| 8.8 | Checks before creating | As V7: user and owner email verified, plan active and server limit not reached (Phase 7), provider enabled by the admin, IP not already used | Five refusals the wizard must show before the create button rather than after. Two are interesting: it is the owner's email that must be verified too (so a member can be blocked by someone else's unverified email — say whose), and "IP not already used" only applies to the existing-server ways |
| 8.9 | Install progress | Live steps until the install finishes. A failure shows the reason, with Retry or Delete | The progress screen this site already specced, now confirmed: named steps, a real reason on failure, and exactly two recoveries. Safe to leave the page |
| 8.10 | Token — answers Q2 | Narrowed 2026-10-06 to 8.1–8.4: for those the installer creates the Central token and saves it in both OSS and Central automatically (8.6 dropped out, since it gets no OSS). For 8.5 the user pastes it. Stored encrypted; never shown or logged | So the frontend only ever handles a token in one of the five flows that reach Central — 8.5. Everywhere else there is nothing to copy, show or mask — which also means no screen should offer to "view" a server's token |
| 8.11 | What Central stores — answers Q1 | Organization, creator, name, hostname, how it was created, cloud details (provider account, provider server ID, region, size), managed link, stack, status, panel URL, token, last seen. Plus a one-time copy from OSS when the server connects: hostname, public IP, OS, OSS version, stack, CPU, RAM, disk, app count. Name and hostname both start as the OSS hostname. Everything else stays in OSS | The answer this site proposed and the backend accepted: a small cached copy so lists work when a panel is offline. One word matters — the copy is one-time, taken at connect. So IP, OS, CPU, RAM, disk and app count can go stale, and a screen that shows them must either label them as "at connect" or read live values instead. That is exactly the gap Q3 still leaves open |
| 8.12 | Activity log | Who added which server, how and when. Tokens and passwords are never logged | Feeds the organization activity log; "how it was created" makes a useful column |
Who can do it: organization roles with server manage, from Phase 4.
#C. Still open after this phase
The backend listed five things as "not in this phase". Three matter to the screens:
- Refreshing server data — later updates from OSS, offline status and "needs new token" are decided later. This is the heart of Q3, and it leaves the server list's liveliness undefined: the one-time copy from 8.11 is all Central is promised to hold.
- Unclaimed server — "waiting for a decision from higher authority". Close relative of Q13 (an automatic install leaves OSS registration open). Both are about a panel that exists with nobody properly attached, and neither is settled.
- Ubuntu versions — pending decision; OSS supports 22.04, 24.04 and 26.04, and 20.04 is not possible. So the version picker's options come from the API, and the V7-on-20.04 note this site has carried since 2026-10-03 is now confirmed as a real migration blocker.
- Also parked: everything after a server exists (list, server page, power, resize, delete, disconnect, settings, apps, databases) — their own phases — and whether name and hostname can be edited separately.
#Existing users
V7 servers carry over and move to OSS, but how the move works is decided later. So the migration story this site has flagged since the first draft — that a V7 server only becomes manageable once OSS is installed on it — is still unwritten, and D-19 (installing OSS on a live V7 server is untested) still applies.
#What this phase answers
| Was open | Now |
|---|---|
| Q1 Which exact server fields does Central store? | Answered (8.11) — and close to what this site proposed: the link record plus a small one-time copy from OSS (IP, OS, version, stack, CPU, RAM, disk, app count) so lists survive an offline panel. The backend removed Q1 from its own list |
| Q2 How does the OSS token reach Central — pasted, or sent by the installer? | Answered (8.10): both, and which depends on the way in. The installer does it automatically for four ways (8.1–8.4); only "connect an existing panel" asks the user to paste, and the free Lite server has no token at all because it gets no OSS. Exactly the answer this site recommended |
| Which ways of adding a server exist? | Six (8.1–8.6) — and Bhavik's wizard covers four of them. 8.2 Managed server is deliberately absent (D-36) and 8.6 ServerAvatar Lite has no screen anywhere (D-41) |