m-uising-box panel

Features

What the panel manages, grouped the way the sidebar is. All of it lives in one binary and one SQLite file.

Lines

A line is inbound protocol + port → exit. Protocols: Hysteria2 (with port hopping), AnyTLS, TUIC, Trojan, VLESS (Reality / Vision), VMess, Shadowsocks including the 2022 ciphers, plus SOCKS, HTTP and Mixed. Transports: WebSocket, gRPC, HTTPUpgrade, HTTP. Each line can be deployed to all servers or a chosen subset. Quick-add presets fill in a free port and sensible options; every save is dry-run through sing-box and port-checked against the panel, other lines and other processes on the box.

Upstreams

Where traffic exits when it should not go direct: VLESS, VMess, Trojan, TUIC, Hysteria2, Shadowsocks and SOCKS outbounds, importable from share links. One-click latency test, scheduled health checks with failure/recovery alerts, and Cloudflare WARP set up from inside the panel. Health is measured on the servers that actually use the upstream: each one checks only what its own lines need, the upstream row shows every server's latency side by side, and alerts name the server that cannot reach it. Changing an upstream hot-swaps the outbound without restarting the data plane.

Users

Plans

Templates for quota, duration, devices, speed and line assignment. Apply on create, on renewal or when extending. Resellers get their own plans, separate from yours.

Rules

Temporary speed limits layered on top of a user's own. Schedule: chosen weekdays and a time window in the panel time zone, crossing midnight allowed. Burst: X GB within the last N minutes limits the user for M minutes, lifts automatically and applies again on the next burst; a user can be under several rules at once, each independent. Targets are all users, every user of a reseller, or individual users. The master evaluates rules and syncs them to every node; several hits resolve to the strictest, and the default "tighten only" never exceeds the user's own limit. Changes reach live connections immediately, no reconnect needed. The user list shows "Limited"; the landing page never does.

Resellers

Give a reseller a set of lines plus a traffic quota, a device pool, a bandwidth pool and an expiry. Per-user limits are up to the reseller; the pools cap what all of their users can do at the same time. They get their own panel (default port 2054, path /dl) where they create users and plans, set their own landing-page title, notice and contact, and optionally enable two-factor login. All usage rolls up to the reseller; when the reseller is over budget, expired or disabled, every user of theirs is cut off at once. Reseller users are never mixed into your own user list.

Subscriptions

Servers

One master, any number of nodes. The master pushes lines, upstreams, users and credentials every 5 seconds and pulls back traffic deltas and online IPs; nodes only forward. Per-server traffic ratio, per-server deployment of lines, connection tracking across servers. See Multi-server.

Certificates

Let's Encrypt via HTTP-01 or Cloudflare DNS-01 with DNS and port pre-checks, automatic renewal and hot reload without a restart. No domain? Self-sign with one click. Bring your own certificate files too.

Operations

Security

Two-factor login (TOTP), login rate limiting per IP, sessions scoped per role, reseller isolation enforced server-side, checksum-verified downloads for the installer and the updater, no telemetry. Config changes never bypass validation.

External API

A token-authenticated HTTP API for creating and updating users, reading usage and fetching subscription links — for shops, bots and automation. Documented in docs/API.md.