Skip to main content

Configuration (.env)

All settings of the panel, generated from example.env. Copy that file to .env and adjust it. Email settings are made in the admin interface (Settings), not here.

Proxmox connection​

SettingExample / defaultDescription
PVE_URLhttps://pve.example.com:8006Proxmox VE
PVE_TOKEN_IDpanel@pve!panelsee above
PVE_TOKEN_SECRET00000000-0000-0000-0000-000000000000see above
PVE_VERIFY_TLStrueKeep true in production. Either use a trusted cert or point PVE_CA_FILE at /etc/pve/pve-root-ca.pem copied from your cluster.
PVE_CA_FILE–see above
PVE_POOLcustomersPool that customer servers live in; servers customers create are added to it

Panel, ports and security​

SettingExample / defaultDescription
INITIAL_ADMIN_EMAIL–First administrator, created on first start only if no accounts exist yet (for setups without a terminal, e.g. a NAS). Remove the password afterwards.
INITIAL_ADMIN_PASSWORD–see above
INITIAL_ADMIN_REQUIRE_2FAfalsesee above
PANEL_PUBLIC_URLhttps://panel.example.comThe addresses browsers use; callbacks are /api/auth/oidc/callback
ADMIN_PUBLIC_URLhttp://localhost:3001see above
PORT3000Customer panel
HOST0.0.0.0see above
ADMIN_PORT3001Admin interface: its own server and port. Default is local-only; reach it through an SSH tunnel or VPN. Only set ADMIN_HOST=0.0.0.0 behind a firewall.
ADMIN_HOST127.0.0.1see above
JWT_SECRETchange-meLong random string: node -e "console.log(require('crypto').randomBytes(48).toString('hex'))"
COOKIE_SECUREtrueSet to false only for local development over plain http
DB_PATH./data/panel.dbsee above

Sign-in: passwords, passkeys and single sign-on​

SettingExample / defaultDescription
PASSKEYS_ENABLEDtruePasskeys (fingerprint, face, device PIN, security key). They need a domain name over https (or localhost); set PANEL_PUBLIC_URL / ADMIN_PUBLIC_URL for your domains.
PASSWORD_LOGIN_CUSTOMERtruePassword sign-in per portal. Turning one off requires OIDC for that portal.
PASSWORD_LOGIN_ADMINtruesee above
OIDC_ENABLEDfalse
OIDC_ISSUERhttps://login.example.com/realms/example
OIDC_CLIENT_ID–
OIDC_CLIENT_SECRET–
OIDC_PORTALScustomer,adminWhich portals show the single sign-on button
OIDC_BUTTON_LABELSign in with single sign-onsee above
OIDC_SCOPESopenid email profilesee above
OIDC_ALLOWED_DOMAINS–Only these email domains may link or be created (empty = any)
OIDC_REQUIRE_VERIFIED_EMAILtrueFirst link by email only when the provider says it's verified
OIDC_AUTO_CREATEfalseCreate unknown users as customers (no rights until an admin grants them)
OIDC_TRUST_IDP_MFAtrueSkip the panel's own 2FA when the provider confirms multi-factor sign-in (amr)
OIDC_USE_PARautoPushed Authorization Requests: auto (when offered), always, never

Customer networks​

SettingExample / defaultDescription
CUSTOMER_NETWORKSfalsePrivate network per customer (see the documentation, "Customer networks"). When enabled, every server a customer creates joins that customer's own SDN VNet.
SDN_ZONEpanelsee above
CUSTOMER_NET_PREFIX10.100Customers get .1.0/24, .2.0/24, ... (up to 254 customers)
CUSTOMER_NET_DNS1.1.1.1see above
CUSTOMER_BLOCKED_NETS10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,100.64.0.0/10,169.254.0.0/16Destinations customer servers may NOT reach: your LAN, management and any other internal networks behind the Proxmox host. The public internet stays reachable. If CUSTOMER_NET_DNS is inside these ranges, DNS to it is allowed automatically.

WireGuard VPN​

SettingExample / defaultDescription
VPN_ENABLEDfalseVPN access through a central WireGuard gateway (see the documentation, "VPN access"). Needs CUSTOMER_NETWORKS=true.
VPN_GATEWAY_VMID–VMID of the gateway VM prepared with docs/vpn/setup-gateway.sh
VPN_ENDPOINTvpn.example.com:51820What customers' WireGuard apps connect to: your public DNS name or IP + UDP port
VPN_NET_PREFIX10.101Customer N's devices get .N.x (must match the setup script)
VPN_MAX_DEVICES10see above

Tailscale​

SettingExample / defaultDescription
TAILSCALE_ENABLEDfalseTailscale: customers can connect servers to their OWN Tailscale account (see the documentation, "Tailscale"). Works with or without the WireGuard VPN.

Windows and guest agent​

SettingExample / defaultDescription
WINDOWS_OOBE_TIMEOUT_MINUTES15Windows: how long Windows may sit at its setup (welcome) screens before a server creation fails with a hint that the template's unattend.xml is incomplete
AGENT_UNRESPONSIVE_SECONDS180How long the QEMU guest agent in a server may stop answering (e.g. while an installer runs) before a panel job gives up. Short stalls are waited out.

Limits​

SettingExample / defaultDescription
MAX_SNAPSHOTS3Plan limits

Branding and versions​

SettingExample / defaultDescription
SHOW_VERSION_TO_CUSTOMERStrueShow the panel version to signed-in customers (sidebar and Account page). Only the number; commit, build date and update status stay in the admin interface.
UPDATE_CHECKtrueUpdate check: the admin interface asks GitHub (at most every 6 hours) whether a newer release exists. Set to false to never contact GitHub.
PANEL_NAMEPVE PanelProduct name shown on the sign-in pages, in the sidebar and in page titles
BRANDING_DIR–Folder with own OS icons (os-windows.svg, os-linux.png …); default data/branding

Server expiry​

SettingExample / defaultDescription
EXPIRY_CHECK_SECONDS300Server expiry (configured per customer/server in the admin interface): how often the panel checks expiry dates, in seconds. 0 = never automatically ("Check now" only).

Docker​

SettingExample / defaultDescription
PANEL_IMAGEghcr.io/sebastianflint/pve-panel:latestUsing the ready-made image (deploy/docker-compose*.yml). Optional: the default is ghcr.io/sebastianflint/pve-panel:latest; set a release to pin it, e.g. ghcr.io/sebastianflint/pve-panel:1.2.0 (optional)
PANEL_DOMAINpanel.example.comDocker with automatic HTTPS (docker compose --profile https): the public DNS name