Every play that ran on this machine, from either direction — a button on this page, or _tools/push.py from a workstation. A preview (--check) reports what it would change and changes nothing; it is labelled as one.
| Started | Playbook | From | Took | Result |
|---|
Shape — profile, PHP version, limits, which domains a package includes — comes from the inventory in the repository, and is changed there: _tools/new-site.py adds one, and an edit is a commit and a run of the sites playbook. There is no edit button here on purpose.
A package is a ceiling and never a reservation: the column below is what a site may reach, not what is held for it, and the packages on this machine deliberately add up to more than it has. Workers are enforced by PHP-FPM itself, which will not fork past them; memory and CPU by the kernel, in the cgroup of the site's own FPM master. That master is the unit in the last column, and restarting it drops the requests of this site and of no other.
| Domain | Profile | Package | PHP | Database | TLS | Requests | 5xx | Unit |
|---|
Every site and mail domain this machine holds that no account has been given. A name appears here after the inventory and a run of the sites playbook create it — this page says who it belongs to, never whether it exists.
A zone is built before the registrar is pointed at it, which is what makes the change instant when it happens. Records are published by a dns run; the serial is that run's own clock, so it never goes backwards.
The value is written the way a zone file needs it — a host gets its trailing dot, a TXT string gets its quotes and is split if it is long. What is typed is what is meant, not what the file will say.
| Address | Quota | State | Created | Actions |
|---|
| Source | Delivered to | Actions |
|---|
| Login | May send as | Actions |
|---|
Everything a customer has is keyed by a domain — the site, the mailboxes, the databases, the zone — so this list is what makes all of them theirs.
Read from the snapshot the last run applied, so a site created minutes ago and not yet collected is absent rather than guessed at. The package is the ceiling the kernel holds them to, not a number on a page.
One query per name they own, so there is no lookup here capable of returning somebody else's.
Only zones this panel serves. Ours are in the inventory and are not in this store at all, which is what stops one being handed over by accident.
A password alone is not a sign-in here: the authenticator is confirmed with a code the app produces, and until it is, the account cannot get in. Setting a password again clears the authenticator and the recovery codes — an administrator resetting one is answering "I have lost access", and leaving the old second factor behind would not answer it.
An account and nothing else, for somebody who exists before their site does. The form below this one opens a customer and their first site in one go, and creates the account itself if it is new.
A customer is an account and the names it owns. Everything a customer has is keyed by a domain — the site, the mailboxes, the databases, the zone — so this one list is what makes all of them theirs.
The address is the login, and where a second factor will be sent, so it cannot be at a domain this machine holds: a code delivered to a mailbox here is not a second factor. Nobody signs in with it yet — there is no customer login until the next step.
One form: the customer, their domain, the package it runs on, and the first mailbox. The package is a ceiling the kernel enforces on that site alone — it is what was sold, so it is chosen here rather than left to a default.
A mailbox password is shown once. Provisioning runs on the machine and takes minutes; the site appears below as requested and becomes live when this panel sees it being served.
A public key, as it comes out of id_ed25519.pub. Keys
rather than passwords: there is no secret to hand over, and the file
this writes lives outside the site — a compromised site cannot add
one of its own. The account reaches its own tree and nothing else.
| Type | Ends with | Comment | Added |
|---|
| Domain | Runs | Package | Runs as | Asked for | State | Shape | Files | Actions |
|---|
A new name needs a certificate that covers it, so adding one runs sites, then acme, then sites again. Everything else is one sites run. Until it finishes the machine is still serving the old shape.
since this page opened