#Server list & details
#Server list (/[locale]/servers)
| Column | Source | Notes |
|---|---|---|
| Server name | Central link (name) | Click → details |
| IP | OSS facts.public_ip (cached on the link) OSS API | null → "could not determine" (OSS rule) |
| OS | OSS facts.os (cached) | |
| Panel version | OSS /health.version (cached) | Badge "update" if below the latest supported Assumption |
| Status | Link status (online / offline / unauthorized / outdated / connecting) | From the background check |
| Sites | Application count (cached, per server) | Expensive. Refreshed by the background job Missing |
| Last seen | last_seen_at | Relative time via next-intl |
| Health | Disk/RAM/CPU warning from the last live sample | Assumption thresholds |
Search: name, IP. Filters: status, provider, OS, version. Sort: name, created, last seen (V7 sorted only by name/created). Pagination: server-side (V7 default 12 per page, per_page validated). All Missing on the Central API.
Concept Demo UI only: status chips with counts (All · Healthy · Warning · Offline), table on desktop and cards on mobile, "Add Server" primary button.
#Server details (/[locale]/servers/:id/...)
Everything below is served live by the server's OSS API through Central (the browser calls sa-central-api-2, which proxies to OSS with the server's key). Only areas the OSS API supports are listed. OSS API (checked in API_REFERENCE.md @ e60c6bd7)
#Core sections (first release)
| Section | OSS endpoints | OSS permission |
|---|---|---|
| Overview | GET /server/facts, GET /server/metrics/live (poll 2–5 s), GET /server/metrics/history (24 h, 5 min), GET /server/processes, DELETE /server/processes/{pid}, GET /server/capabilities | dashboard |
| Applications | GET/POST /applications, GET/PUT/DELETE /applications/{id}, /sidebar, /deploy, /provision, /process/{action}, /enable, /disable, /site-type, /web-root, GET /applications/port-check + per-app areas (domains & SSL, deployment, env, files, PHP, workers, logs, backups, security, staging, clone…) | application + app_* |
| Databases | GET /databases/engines, POST /databases/engines/{engine}, GET/POST /databases, GET/DELETE /databases/{id}, PUT /databases/{id}/application, GET /databases/untracked, POST /databases/adopt, connections | database |
| System users | GET/POST /system-users, GET/DELETE /system-users/{id}, PUT …/password, PUT …/sudo, PUT …/shell, PUT …/ssh, SSH keys, GET /system-users/shells | system_user |
| Services | GET /services, POST /services/{service}/config-test, PUT /services/{service} (start/stop/restart/reload, start-on-boot) | service |
#Later sections (all available in OSS)
| Section | OSS endpoints | Permission |
|---|---|---|
| Firewall | /firewall, /firewall/rules, /firewall/toggle, presets | firewall |
| Cron jobs | /cronjobs, presets | cronjob |
| Backups | /backups, /backup-targets, per-app backup target, restores | backup |
| Git & Backup storage accounts | Secrets live on the panel, not in Central. The form is in Central and the token is pushed to one or many servers; Central keeps only a note (name, provider, which servers). V8 requirement Phase 5 — see FE: Integrations | git, storage |
| PHP | /php, versions, ini, extensions, ionCube | php |
| Node.js | /node, versions, default, npm | node |
| Fail2ban | /fail2ban, install, bans | fail2ban |
| Settings | /settings (general, swap, reboot, security, updates, redis, reboot schedule) | setting |
| Logs | /logs, /logs/{key} | logs |
| Disk cleaner | /disk-cleaner, schedule, runs | disk_cleaner |
| Server activity | GET /server/activity-log (shows Central actions as "central") | activity_log |
| Server sync | /server/sync | sync |
| WP Toolkit / Log Monitoring (paid add-ons) | /central/addons/... (Central-only) | add-on licence |
#Navigation inside a server
Tabs are shown based on (a) the user's Central permission for that area, (b) GET /server/capabilities (e.g. no database engine installed → empty state with "Install"), and (c) the server's status (offline → only Overview with the unreachable state).
#Behaviour rules
- Live data, no cache in Central (R5), except the small cached copy used by the list (decision D-11).
- Poll live metrics only while the tab is visible. Stop polling on blur or unmount.
- OSS errors keep their meaning: 422
errors→ form fields; 403 → permission state; 404 → "no longer exists on the server"; 500 withreference→ show the reference; 429 → back off. - OSS timestamps are
DD-MM-YYYY HH:mm:ss+_human. The frontend formats with next-intl from the raw value. The proxy should pass the raw value through Assumption. - Long jobs (provision, deploy, add-on runs) are polled (OSS returns a run/status). Show progress, never block the page.
- Every mutation writes a Central audit entry with the real user, because OSS logs it as the machine account.