m-uising-box panel

Frequently asked questions

Short answers; the README's Feature guide has the long ones.

Before you install

Will it break the sing-box, Xray or other panel already on the server?

No. m-ui runs its own sing-box core inside the m-ui process; it never installs, stops or edits a system-wide sing-box or Xray, their configuration files, or another panel. The only thing shared with them is ports — pick free ones for your lines (the new-line form already does) and they coexist.

Does it need Docker, Node or a database server?

No. The installer puts one static Go binary at /usr/local/bin/m-ui, an SQLite file at /etc/m-ui/m-ui.db and one systemd unit. No Docker, no Node, no nginx, no MySQL or PostgreSQL.

Exactly which files does the installer write?

/usr/local/bin/m-ui, the directory /etc/m-ui/ (database, cert/, backups/) and /etc/systemd/system/m-ui.service. Nothing else. Append --dry-run to the install command to print this plan for your machine without changing anything.

Will it conflict with nginx, Caddy or another web server?

Not by default: the panel listens on 2053, subscriptions on 2056, the reseller panel on 2054. Port 80 is only needed briefly if you issue a certificate with HTTP-01; use Cloudflare DNS-01 or a self-signed certificate if 80 is taken.

Does uninstalling delete my data?

Not unless you ask. install.sh --uninstall (or the SSH menu) removes the service and the binary and keeps /etc/m-ui, so installing again picks up your users, lines and certificates. Add --purge to delete the data directory too.

Can I try it without a server?

Yes. The live demo is the real panel interface running on sample data in your browser: no login, no backend, changes reset on refresh. It is built from the same frontend files as the release, so what you see is what you install.

Setup

Do I need a domain?

No. Certificate → Self-sign gives you TLS on the server IP in one click, and subscriptions automatically tell clients to allow the insecure certificate. A domain lets you issue a Let's Encrypt certificate and removes that warning — recommended, not required.

Which ports must be open?

Panel 2053/tcp, subscription 2056/tcp, reseller panel 2054/tcp if enabled, plus every line's port (TCP or UDP depending on the protocol). HTTP-01 certificate issuance also needs 80/tcp; Cloudflare DNS-01 does not. A node's panel port only needs to be open to the master's IP.

Can I change the panel port or path?

Yes, in Settings, or from the SSH menu (m-ui) if you locked yourself out. Paths work with or without the trailing slash. Ports are validated before saving so the panel cannot restart onto a port already used by a line or another program.

What are the system requirements?

Linux amd64 or arm64 with systemd; Debian 11+ / Ubuntu 20.04+ recommended, Rocky / CentOS and other systemd distributions work too. The installer needs systemd, so Alpine (OpenRC) is not supported by it. Root for installation. The panel itself is happy on 1 vCPU / 1 GB. The platforms CI actually exercises are listed under Tested automatically.

Why does the new-line form already have a port?

It picks a free five-digit port that no other line, the panel or any other process on the server is using, and binds it once to be sure. You can change it; conflicts are rejected on save.

Users and subscriptions

The subscription shows my host name instead of the title I set.

Set Settings → Subscription → Profile title (resellers set theirs in their own panel). Clients like nextin and sing-box re-read it on every refresh. Shadowrocket and Clash Verge name a subscription when it is added and never rename it — use the landing page's one-tap import button (it carries the title) or have the user delete and re-add.

How is a device counted?

By distinct source IP, across all servers. A phone on Wi-Fi and the same phone on mobile data are two IPs. The limit is enforced centrally by the master, so 3 means 3 in total.

Can users share a subscription temporarily?

If you enable sharing, the landing page offers a temporary share link that uses a second credential set. Revoking it disconnects only the borrower, immediately, while the owner stays connected; usage, devices and expiry still count against the owner. The share link opens a trimmed landing page (import buttons, links, QR codes, nodes, your notice and purchase button) that never shows the owner's usage or expiry.

What do users see when their subscription runs out?

In a browser: their normal landing page with a status card on top (expired, traffic used up, or disabled — read from the panel), their links and QR codes unchanged, your notice and contact details, and a purchase / renew button if you set a purchase link (resellers can set their own). Only a link that matches no user gets the “invalid link” page. Clients get a plain 404 while the user is disabled.

Can subscription addresses avoid exposing user names?

Yes. Untick Settings → Subscription → Use user name as subscription URL; new users then get a random 32-character token. Existing users keep their current address either way.

Multi-server

Do nodes need their own certificate?

Yes, each node issues its own (self-signed is fine). Lines are pushed with the master's TLS settings and each node serves them with its own certificate files.

What if the master goes down?

Nodes keep forwarding with the configuration they have. Subscriptions served by the master are unavailable until it returns; nodes can also serve subscriptions if you point users at them.

What happens when a node goes offline?

The master marks it offline on the Servers page (and sends a Telegram alert if you configured the bot); the other servers keep working. Lines that live only on that node are unreachable until it returns. On reconnect the master pushes the full snapshot again and continues the traffic counters from the stored cursor, so nothing is double-counted.

Is traffic double-counted when a node reconnects?

No. Nodes keep monotonic counters and the master stores a cursor per node, so only the delta is added. See Multi-server.

Resellers

The new reseller cannot log in.

A new reseller has no password. On the reseller panel they enter the name, leave the password empty and click Log in; the panel then asks them to set one. The first-login window can be reset from the master.

Can a reseller see my users or lines?

No. Resellers see only their own users and plans and only the lines you granted. Scoping is enforced on the server, not in the UI.

Operations

How do updates work? Will I lose data?

The sidebar shows an arrow when GitHub has a newer release. One click downloads the archive, verifies it against the release's SHA256SUMS, replaces the binary and restarts. The database, certificates, backups and settings are untouched. The installer does the same when run again. Since v0.4.9 every update is a transaction: the previous binary is kept, a pre-upgrade backup is written first, and if the new version does not answer within 90 seconds the previous binary (and, if needed, that backup) is restored automatically and the panel tells you so.

What is in a backup?

The database (checkpointed so it is consistent) and the certificate files, as one zip. Restore from the panel; the migration wizard moves a whole installation to a new server.

Can I migrate from a legacy panel?

Yes — the importer reads the compatible legacy database format and keeps ports, credentials, panel path and subscription addresses, so existing clients continue without a refresh. Run the installer with --import /path/to/old.db, or use Users → Import to move only users.

Does m-ui send any telemetry?

No. Outbound connections are only the ones you configure (ACME, Cloudflare, WARP, Telegram) and a version check against GitHub Releases every 6 hours.

Where do I ask questions or report bugs?

Questions and ideas: GitHub Discussions. Confirmed bugs: an issue using the form. Please redact tokens, UUIDs and subscription URLs from logs.