m-uising-box panel

Getting started

One command installs the panel and the embedded sing-box core as a systemd service. Five minutes later a user can import a subscription.

1. Install

Any systemd Linux on amd64 or arm64 (Debian 11+ / Ubuntu 20.04+ recommended), as root:

bash <(curl -fsSL https://raw.githubusercontent.com/Maoyangui/m-ui/main/deploy/install.sh)

The script downloads the latest release, verifies it against the SHA256SUMS published with the same release, installs /usr/local/bin/m-ui, creates the systemd service and starts it. The database lives in /etc/m-ui/m-ui.db. Nothing else is installed — no Docker, no Node, no external database.

Not sure yet? Append --dry-run to the same command: it prints what would be installed where, which files it writes and the default ports, and changes nothing.

Coming from a legacy panel? Run the installer with --import /path/to/old.db to bring lines, upstreams, users and settings across in one go — ports, credentials and the subscription path are kept, so existing clients keep connecting without a refresh. To move only users onto lines you already rebuilt, use Users → Import from legacy panel.

2. First login

A banner stays at the top until the default password is changed — do that on the Admin page first. Port, path and credentials can also be changed later from the SSH menu (m-ui). The UI is available in English and Chinese; switch at the bottom of the sidebar.

3. Certificate

Most protocols need TLS. You have two equally supported options:

You haveDo thisResult
A domain pointing at the serverCertificate → Issue: Let's Encrypt via HTTP-01 (port 80 reachable) or Cloudflare DNS-01 (API token, no port 80). Renews itself.Real certificate, no client warnings.
Only an IPCertificate → Self-sign, one click.Works everywhere; subscriptions automatically tell clients to allow the insecure certificate. Add a domain later and switch.

The Quick Start card on the dashboard treats both as "certificate ready". A domain is a recommendation, not a prerequisite.

4. Create a line

A line is inbound protocol + port → where traffic exits (direct, or an upstream you add later). On the Lines page use Quick add — Hysteria2, AnyTLS, VLESS + Reality, Trojan, Shadowsocks 2022 or VMess + WS come with sane defaults and a free five-digit port already filled in. Ports are checked against other lines, the panel and anything else listening on the server before the save is accepted.

Every save is dry-run through sing-box. If the config does not parse you get the reason and nothing changes on the running data plane.

5. Create a user

On the Users page, Add user: name, optional quota, expiry, device limit and speed limits, and which lines they can use. Credentials for every protocol are generated for you. The first user's detail drawer opens automatically with the subscription links and QR code.

6. Hand out the subscription

Each user has one subscription address in three formats:

Opened in a browser, the same address is a landing page: usage, expiry, one-tap import buttons, QR code and client downloads. Users can also generate a temporary share link there if you allow it. When a subscription is exhausted, expired or disabled, the browser shows a short explanation and your contact details instead of a blank 404.

Tested automatically

Every change to the installer or the Go code runs the install-test workflow on fresh GitHub-hosted machines: the official one-line installer, the service coming up, the panel answering on port 2053, a second install as the upgrade path, a deliberately broken release that must be rolled back automatically, then uninstall. The list below is generated from the latest completed run, not written by hand.

Latest run: 2026-09-28, commit 1672891 (log). Anything not listed has not been tested.

Upgrade

Click the update arrow next to the version number in the sidebar (the panel checks GitHub Releases every 6 hours), or run the install command again, or pick "Update" in the m-ui SSH menu. Only the binary is replaced; database, certificates and settings stay where they are. If the new version fails to start, the previous binary is restored automatically (a pre-upgrade backup is kept under /etc/m-ui/backups/).

Uninstall

bash <(curl -fsSL https://raw.githubusercontent.com/Maoyangui/m-ui/main/deploy/install.sh) --uninstall

Stops and removes the service and the binary; /etc/m-ui (database, certificates, backups) stays, so a later install picks everything up again. Add --purge to delete it too. The m-ui SSH menu's uninstall does the same and asks about the data directory. Nothing else is touched: m-ui never modifies an existing sing-box, Xray, Docker or nginx on the machine.

Next: add more servers · see everything else the panel does · FAQ