V8 Central — Product & Technical Spec
  1. Docs
  2. Modules
  3. Server list & details

#Server list & details

#Server list (/[locale]/servers)

ColumnSourceNotes
Server nameCentral link (name)Click → details
IPOSS facts.public_ip (cached on the link) OSS APInull → "could not determine" (OSS rule)
OSOSS facts.os (cached)
Panel versionOSS /health.version (cached)Badge "update" if below the latest supported Assumption
StatusLink status (online / offline / unauthorized / outdated / connecting)From the background check
SitesApplication count (cached, per server)Expensive. Refreshed by the background job Missing
Last seenlast_seen_atRelative time via next-intl
HealthDisk/RAM/CPU warning from the last live sampleAssumption thresholds

Search: name, IP. Filters: status, provider, OS, version. Sort: name, created, last seen (V7 sorted only by name/created). Pagination: server-side (V7 default 12 per page, per_page validated). All Missing on the Central API.

Concept Demo UI only: status chips with counts (All · Healthy · Warning · Offline), table on desktop and cards on mobile, "Add Server" primary button.

#Server details (/[locale]/servers/:id/...)

Everything below is served live by the server's OSS API through Central (the browser calls sa-central-api-2, which proxies to OSS with the server's key). Only areas the OSS API supports are listed. OSS API (checked in API_REFERENCE.md @ e60c6bd7)

#Core sections (first release)

SectionOSS endpointsOSS permission
OverviewGET /server/facts, GET /server/metrics/live (poll 2–5 s), GET /server/metrics/history (24 h, 5 min), GET /server/processes, DELETE /server/processes/{pid}, GET /server/capabilitiesdashboard
ApplicationsGET/POST /applications, GET/PUT/DELETE /applications/{id}, /sidebar, /deploy, /provision, /process/{action}, /enable, /disable, /site-type, /web-root, GET /applications/port-check + per-app areas (domains & SSL, deployment, env, files, PHP, workers, logs, backups, security, staging, clone…)application + app_*
DatabasesGET /databases/engines, POST /databases/engines/{engine}, GET/POST /databases, GET/DELETE /databases/{id}, PUT /databases/{id}/application, GET /databases/untracked, POST /databases/adopt, connectionsdatabase
System usersGET/POST /system-users, GET/DELETE /system-users/{id}, PUT …/password, PUT …/sudo, PUT …/shell, PUT …/ssh, SSH keys, GET /system-users/shellssystem_user
ServicesGET /services, POST /services/{service}/config-test, PUT /services/{service} (start/stop/restart/reload, start-on-boot)service

#Later sections (all available in OSS)

SectionOSS endpointsPermission
Firewall/firewall, /firewall/rules, /firewall/toggle, presetsfirewall
Cron jobs/cronjobs, presetscronjob
Backups/backups, /backup-targets, per-app backup target, restoresbackup
Git & Backup storage accountsSecrets live on the panel, not in Central. The form is in Central and the token is pushed to one or many servers; Central keeps only a note (name, provider, which servers). V8 requirement Phase 5 — see FE: Integrationsgit, storage
PHP/php, versions, ini, extensions, ionCubephp
Node.js/node, versions, default, npmnode
Fail2ban/fail2ban, install, bansfail2ban
Settings/settings (general, swap, reboot, security, updates, redis, reboot schedule)setting
Logs/logs, /logs/{key}logs
Disk cleaner/disk-cleaner, schedule, runsdisk_cleaner
Server activityGET /server/activity-log (shows Central actions as "central")activity_log
Server sync/server/syncsync
WP Toolkit / Log Monitoring (paid add-ons)/central/addons/... (Central-only)add-on licence

Tabs are shown based on (a) the user's Central permission for that area, (b) GET /server/capabilities (e.g. no database engine installed → empty state with "Install"), and (c) the server's status (offline → only Overview with the unreachable state).

#Behaviour rules

  • Live data, no cache in Central (R5), except the small cached copy used by the list (decision D-11).
  • Poll live metrics only while the tab is visible. Stop polling on blur or unmount.
  • OSS errors keep their meaning: 422 errors → form fields; 403 → permission state; 404 → "no longer exists on the server"; 500 with reference → show the reference; 429 → back off.
  • OSS timestamps are DD-MM-YYYY HH:mm:ss + _human. The frontend formats with next-intl from the raw value. The proxy should pass the raw value through Assumption.
  • Long jobs (provision, deploy, add-on runs) are polled (OSS returns a run/status). Show progress, never block the page.
  • Every mutation writes a Central audit entry with the real user, because OSS logs it as the machine account.
ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-03 12:35 UTC