Dashboard

v1.5.0
NaiveProxy
Mieru (mita)
Active Users
Server
CPU Usage
Usage—%
Memory
Used
Disk
Used
Username Email Expiry Naive Mieru Hy2 Naive (MB) Mieru (MB) Hy2 (MB) Quota (MB) Quota Last Active Actions
Loading users…
External Panel Access

Expose the panel via a TLS subdomain (https://panel.<domain>/<webBasePath>/), protected by basic auth. The panel always stays on 127.0.0.1:3000; Caddy reverse-proxies to it. The root and any path outside webBasePath show a static stub.


Static HTML served by Caddy at the panel subdomain root and any path outside webBasePath. Separate from the naive fake-site. Edit and save to replace it.

Probe Resistance Secret

Secret token clients present in headers. Unrecognised clients see the fake site instead.

"Bare" matches a known-good reference server. "Secret" requires a special domain to reach the masquerade.
Subscription Domain (Sub-ссылка)

Optional dedicated domain for client subscription links (e.g. https://sub.example.com). Leave empty to serve sub-links from the panel domain. Caddy auto-provisions the TLS certificate.

Point an A-record for this host to this server's IP first, otherwise the TLS certificate cannot be issued.
Server flag / label

Optional emoji/text prefix added to the display name of every config this server hands out (e.g. 🇷🇺 or 🇳🇱 RP). Shown in Shadowrocket, Happ, Karing/NekoBox/Throne, etc. Leave empty for no prefix. Bonus links are not touched — put a flag directly into the bonus link if you want one.

Fake site (masquerade)

The site shown to anyone who opens the server domain in a browser (camouflage for DPI/probes). Enter a full https:// URL to reverse-proxy a real site, or leave empty to serve the built-in default fake site. Changes rebuild Caddy automatically.

Pick a plausible, always-online site. Leave empty to fall back to the built-in fake site bundled with the panel.
NaiveProxy Port

Change the HTTPS port for NaiveProxy. Reloads Caddy only — no service restart.

Changing port will require clients to update their configs.
Mieru Port Range

Change the TCP port range for Mieru. Requires full Mieru restart.

UFW rules will be updated automatically. Clients must download new configs.
Hysteria2 (Hy2)

Hysteria2 — быстрый QUIC/UDP-протокол. Работает поверх UDP и сосуществует с NaiveProxy на TCP/443. Использует общий пул пользователей и сертификат Caddy (второй email не нужен).

Hysteria2 ещё не установлен на этом сервере.

По умолчанию 443/udp (рядом с Naive TCP/443). Можно изменить на 8443 и т.п.

Traffic Obfuscation

Configure Mieru traffic obfuscation pattern and MTU.

UDP Mode (Mieru)

TCP-only is recommended and default. Enable UDP only if your network blocks TCP on Mieru ports. Requires full Mieru restart.

UDP mode restarts Mieru. Test TCP first — it works on most networks.
Каскад / Relay

Настройка relay: трафик идёт через этот сервер (entry) на выходной сервер (exit), а затем в интернет. Mieru использует вариант B (mieru-client + redsocks + iptables) — провайдер видит только этот (entry) сервер.

ℹ Hysteria2 каскадируется автоматически через тот же Mieru-туннель (по владельцу процесса) — отдельный exit-адрес для Hy2 указывать не нужно. Достаточно заполнить Mieru exit ниже и включить эту галочку.

Формат: https://user:pass@host:port (оставьте пустым, чтобы не каскадировать Naive)
Адрес выходной (EU) ноды, где установлен тот же скрипт. Оставьте пустым, чтобы не каскадировать Mieru.
При включении каскада relay будет настроен и запущен (mieru-client + redsocks + iptables) — на это уйдёт до минуты при первой установке.
Cloudflare WARP (egress)

Выводит весь исходящий трафик сервера через Cloudflare WARP, скрывая реальный IP сервера. Режим на весь сервер. Взаимоисключающий с каскадом: активен ровно один из трёх режимов — родной IP / каскад / WARP.

SSH и порт панели НЕ заворачиваются в туннель — доступ к серверу сохраняется. В WARP идёт только исходящий прокси-трафик.
Interface Language

Select web-panel language. Choice is saved in browser.

Panel Password
Backup & Restore

Export a full backup (all users + all settings) to a single file, or restore it on a fresh server. If the new server uses the same domain (just point DNS to it), existing client keys keep working with no changes.

⚠ The backup file contains user passwords in plain text. Store it somewhere safe and never share it.

Link several panels so one subscription link delivers configs from multiple servers. Users are matched across servers by their email. This panel pulls configs from the peer nodes you add below and merges them into each user's subscription.

This server's node token

Give this token to another (main) panel so it can pull this server's configs. Keep it secret — anyone with it can request configs by email. Empty = this server will not answer federation requests.

A token is set. Regenerating replaces it — peers using the old one stop working.
Peer servers (pulled into subscriptions)

Add each other panel by its base URL and that panel's node token. Disabled or unreachable peers are silently skipped — a subscription never breaks.

Checks each peer for DNS / TLS / token problems without changing anything.

Use the peer's SUBSCRIPTION domain (Settings → Subscription Domain on that panel), e.g. https://sub.example.com — NOT its main/fake-site domain. Federation is served there next to /sub.
CPU—%
RAM
NaiveProxy
Mieru
Uptime
User Traffic & Quota
Username Upload (MB) Download (MB) Total Used (MB) Quota (MB) Quota Used Expiry Last Active
Loading…
Select a log above…
Port Status

Click "Run Checks" to begin.

Config Validation

Mita Status
Mita Config (describe)