Your live website, panel fleet and recovery in one place.
Loading…SSH FleetBackup: —
Provider-independent Mission Control.
Your Website and 3x-ui fleet are managed over SSH. Linode API is never used in normal operation; it is available only for explicit one-time import or recovery provisioning.
System Health
—
Waiting for fleet
Managed VPS
0
Manual / one-time imported fleet
Latest Backup
—
Verified recovery point
SSH Health Schedule
3h
No provider API polling
Managed System
Last check: —
Recent Activity
Latest events
VPS Fleet
Add servers manually, or use a Linode API token once to discover the account and map the existing Website / 3x-ui VPSs. The token is not saved after the explicit import session.
Provider independentStable Role + Panel Slot identityDefault SSH profile supported
One-Time Linode Import
Temporary API session only
Manual Fleet
No provider API
You can manage the complete fleet without a Linode token. SSH role detection runs before a node is saved.
Discovered VPS
IP / Metadata
Role
Panel Slot
Default SSH
Custom Password
Domain
Enter a token and click Discover Once only if you want one-time import.
Add / Update VPS Manually
SSH verified before save
Use Default SSH Credentials
Name
Role
IP
Domain
SSH
Health
Actions
Website
Your live website is detected automatically. Future website ZIP updates can be applied here with an automatic full safety backup and the website package's own rollback-capable updater.
Website VPS
Not selected
—
Detected Path
—
prod.db + .env + uploads detected from live server
Domain
—
Cloudflare managed
Safe Website Update
ZIP → verify → safety backup → R13 prep → detached update → health check
Mission Control verifies the original full website ZIP, applies the pinned build hotfix only when the exact known affected R13 source is detected, re-verifies the staged package, creates a full safety backup, then runs the ZIP's own production updater in a detached VPS job. R13/R13.1 University Subdomains packages are supported automatically: wildcard Cloudflare DNS, wildcard HTTPS, shared-domain environment settings and post-update health checks are prepared for you. Database, uploads, posts and encryption keys are preserved; failed builds use the website package's rollback protection.
Drop your latest UNLIMITED DATA full ZIP here — R13 / R13.1 supportedor select the ZIP you received from ChatGPT
No update selected.
3x-ui Panels
SSH-managed panel fleet. Xray auto-restart is installed as a local systemd timer on each panel, so it continues even if the UDMC controller is temporarily offline.
Xray Auto Restart — All Panels
Local panel timers
#
VPS
Domain / IP
Status
Panel
Auto Restart
Last / Next
Actions
Cloudflare DNS
Simple DNS tools from the old Cloudflare Controller, now inside Mission Control.
Cloudflare proxy
Type
Name
Content
Proxy
Modified
VPS-Only Backups
The proven R2 recovery backup engine is preserved: one verified Full System Backup every 30 minutes, local retention plus mandatory Telegram off-server delivery with multipart resume.
Latest Status
—
—
Coverage
—
Website + all configured panels
Copies
—
Controller + Telegram
Next Backup
—
Fixed 30-minute schedule
Backup Verification
—
Loading backup status…
Recovery Points
Latest backups created by the controller
UNLIMITED DATA SHIELD
Provider-independent SSH security audit and host hardening. SHIELD never calls Linode API and never changes a 3x-ui panel webBasePath automatically.
Fleet Coverage
SSH-Based
Configured fleet only
Panel Paths
Audit Only
Never automatically changed
Safety
Backup + Rollback
Before host hardening
Safe Protection: required ports are derived from live host/x-ui state, a complete Full backup is required first, and UFW / Fail2Ban / SSH hardening is protected by rollback snapshots.
Panel path policy: weak or reused paths are reported only. SHIELD does not generate a new path, change 3x-ui webBasePath, update Website XuiPanel.url, or change UDMC Node.WebPath.
Configured Fleet Coverage
Not checked
The audit verifies every configured VPS is reachable over SSH.
Panel Path Audit
Read-only
No panel path will be changed automatically.
Fleet Security Report
Not audited yet
Click Run Full Security Audit. The audit is read-only.
Disaster Recovery
Recovery is always explicitly started by you. No Sentinel, no automatic failover and no saved Secondary Linode token.
Recovery Progress
No recovery running.
A. Manual Recovery Targets
No provider API
Use Default SSH Credentials
Manual Targets
0
No targets added.
B. One-Time Linode Auto-Provision Recovery
Token discarded after session
The token is used only for this explicit recovery session to inspect availability, create replacement VPSs and capture their new IPs. The actual restore, monitoring, backups and SHIELD continue over SSH.
VPS
Role
Region
Type
Image
Availability
Create a plan first. No VPS is created during planning.
Cloudflare DNS is changed only after the Website and every required panel have restored successfully and passed origin health checks. The active VPS Fleet is committed only at the safe final stage.
App Releases
One public compatibility policy for the website and Android app. This page stores no signing key, website secret, VPN credential or admin token.
Android Compatibility Contract
Waiting
Security boundary: The APK contains only the public website origin and client code. Authentication uses the system browser with PKCE; every VPN connection needs a fresh, short-lived, one-use server grant. The dashboard cache is display-only.
Save after the integrated website update is live, then run Check Website Manifest.
Job Logs
Full copyable logs for recovery, backups, website updates and fleet jobs. Logs are saved on the controller VPS so errors remain available after the progress popup closes.
Latest Job
Waiting
Loading logs…
Settings
Provider-independent controller settings. No permanent Linode API token is stored here.
1. Controller + Cloudflare
Persistent integrations
2. Default SSH Credentials
Fleet + Recovery
Nodes marked Use Default SSH Credentials reference this profile, so changing the default here updates those nodes without duplicating password copies.
3. Automatic Full Backups
VPS → Telegram every 30 minutes
4. Web Dashboard Health
Waiting
Normal fleet monitoring is SSH-based every 3 hours. Linode API exists only on the explicit One-Time Import and One-Time Recovery screens.
5. Controller Release Safety
Automatic rollback
Controller updates preserve state, encrypted credentials, fleet mappings and backups. Failed migration/readiness/TLS checks restore the previous release.