panelOwl docs 1.15.0

Security model

The design goal is that a compromised panel web application cannot become a compromised server, and that one client cannot reach another client's data.

Two processes, one narrow interface

No shell, no templates with holes

Client isolation

Admin web UI

The admin UI (port 2087) is a separate process running as minipanel-admin, a third caller the helper recognises by uid and restricts to an explicit allowlist: account list/show/create/modify/suspend/unsuspend/password reset/quota, the client actions inside an account ("Manage"), certificate retry, backup run/list, health checks and the audit log. Account termination is on the list since 1.7 but the helper demands a valid authenticator code of the admin for it and always writes a 30-day archive first. Restores, rebuilds and admin management are not on the list and remain panelctl-only. Admin logins live in their own table, require TOTP, share the lockout rules below, and every action carries the admin's name into the audit log.

Webmail and phpMyAdmin

Roundcube and phpMyAdmin run in their own PHP-FPM pool as the Unix user minipanel-apps, which is deliberately not in the www-data group (that group can connect to every client's PHP socket): it cannot read client homes, cannot reach client PHP pools and cannot reach the helper socket. They are served only on the server hostname, never on client domains. phpMyAdmin allows cookie logins of client database users only (root refused, no arbitrary servers, system databases hidden); both apps' failed logins feed fail2ban with the real client address.

Authentication

Audit and secrets

Network exposure

Only these ports are open: 22 (SSH), 25 (SMTP in), 80/443 (sites), 465/587 (mail submission), 993/995 (IMAPS/POP3S), 8443 (panel). MariaDB, PHP-FPM, Rspamd, Redis and the helper socket are local only.