Mission Control

Enter your dashboard password.

System Overview

Your live website, panel fleet and recovery in one place.

Loading…SSH FleetBackup: —

Provider-independent Mission Control.

Your Website and 3x-ui fleet are managed over SSH. Linode API is never used in normal operation; it is available only for explicit one-time import or recovery provisioning.

System Health
—
Waiting for fleet
Managed VPS
0
Manual / one-time imported fleet
Latest Backup
—
Verified recovery point
SSH Health Schedule
3h
No provider API polling

Managed System

Last check: —

Recent Activity

Latest events

VPS Fleet

Add servers manually, or use a Linode API token once to discover the account and map the existing Website / 3x-ui VPSs. The token is not saved after the explicit import session.

Provider independentStable Role + Panel Slot identityDefault SSH profile supported

One-Time Linode Import

Temporary API session only

Manual Fleet

No provider API
You can manage the complete fleet without a Linode token. SSH role detection runs before a node is saved.
Discovered VPSIP / MetadataRolePanel SlotDefault SSHCustom PasswordDomain
Enter a token and click Discover Once only if you want one-time import.

Add / Update VPS Manually

SSH verified before save
Use Default SSH Credentials
NameRoleIPDomainSSHHealthActions

Website

Your live website is detected automatically. Future website ZIP updates can be applied here with an automatic full safety backup and the website package's own rollback-capable updater.

Website VPS
Not selected
—
Detected Path
—
prod.db + .env + uploads detected from live server
Domain
—
Cloudflare managed

Safe Website Update

ZIP → verify → safety backup → R13 prep → detached update → health check
Mission Control verifies the original full website ZIP, applies the pinned build hotfix only when the exact known affected R13 source is detected, re-verifies the staged package, creates a full safety backup, then runs the ZIP's own production updater in a detached VPS job. R13/R13.1 University Subdomains packages are supported automatically: wildcard Cloudflare DNS, wildcard HTTPS, shared-domain environment settings and post-update health checks are prepared for you. Database, uploads, posts and encryption keys are preserved; failed builds use the website package's rollback protection.
Drop your latest UNLIMITED DATA full ZIP here — R13 / R13.1 supportedor select the ZIP you received from ChatGPT
No update selected.

3x-ui Panels

SSH-managed panel fleet. Xray auto-restart is installed as a local systemd timer on each panel, so it continues even if the UDMC controller is temporarily offline.

Xray Auto Restart — All Panels

Local panel timers
#VPSDomain / IPStatusPanelAuto RestartLast / NextActions

Cloudflare DNS

Simple DNS tools from the old Cloudflare Controller, now inside Mission Control.

Cloudflare proxy
TypeNameContentProxyModified

VPS-Only Backups

The proven R2 recovery backup engine is preserved: one verified Full System Backup every 30 minutes, local retention plus mandatory Telegram off-server delivery with multipart resume.

Latest Status
—
—
Coverage
—
Website + all configured panels
Copies
—
Controller + Telegram
Next Backup
—
Fixed 30-minute schedule

Backup Verification

—
Loading backup status…

Recovery Points

Latest backups created by the controller

UNLIMITED DATA SHIELD

Provider-independent SSH security audit and host hardening. SHIELD never calls Linode API and never changes a 3x-ui panel webBasePath automatically.

Fleet Coverage
SSH-Based
Configured fleet only
Panel Paths
Audit Only
Never automatically changed
Safety
Backup + Rollback
Before host hardening
Safe Protection: required ports are derived from live host/x-ui state, a complete Full backup is required first, and UFW / Fail2Ban / SSH hardening is protected by rollback snapshots.
Panel path policy: weak or reused paths are reported only. SHIELD does not generate a new path, change 3x-ui webBasePath, update Website XuiPanel.url, or change UDMC Node.WebPath.

Configured Fleet Coverage

Not checked
The audit verifies every configured VPS is reachable over SSH.

Panel Path Audit

Read-only
No panel path will be changed automatically.

Fleet Security Report

Not audited yet
Click Run Full Security Audit. The audit is read-only.

Disaster Recovery

Recovery is always explicitly started by you. No Sentinel, no automatic failover and no saved Secondary Linode token.

Recovery Progress

No recovery running.

A. Manual Recovery Targets

No provider API
Use Default SSH Credentials

Manual Targets

0
No targets added.

B. One-Time Linode Auto-Provision Recovery

Token discarded after session
The token is used only for this explicit recovery session to inspect availability, create replacement VPSs and capture their new IPs. The actual restore, monitoring, backups and SHIELD continue over SSH.
VPSRoleRegionTypeImageAvailability
Create a plan first. No VPS is created during planning.
Cloudflare DNS is changed only after the Website and every required panel have restored successfully and passed origin health checks. The active VPS Fleet is committed only at the safe final stage.

App Releases

One public compatibility policy for the website and Android app. This page stores no signing key, website secret, VPN credential or admin token.

Android Compatibility Contract

Waiting
Security boundary: The APK contains only the public website origin and client code. Authentication uses the system browser with PKCE; every VPN connection needs a fresh, short-lived, one-use server grant. The dashboard cache is display-only.
Save after the integrated website update is live, then run Check Website Manifest.

Job Logs

Full copyable logs for recovery, backups, website updates and fleet jobs. Logs are saved on the controller VPS so errors remain available after the progress popup closes.

Latest Job

Waiting
Loading logs…

Settings

Provider-independent controller settings. No permanent Linode API token is stored here.

1. Controller + Cloudflare

Persistent integrations

2. Default SSH Credentials

Fleet + Recovery
Nodes marked Use Default SSH Credentials reference this profile, so changing the default here updates those nodes without duplicating password copies.

3. Automatic Full Backups

VPS → Telegram every 30 minutes

4. Web Dashboard Health

Waiting
Normal fleet monitoring is SSH-based every 3 hours. Linode API exists only on the explicit One-Time Import and One-Time Recovery screens.

5. Controller Release Safety

Automatic rollback
Controller updates preserve state, encrypted credentials, fleet mappings and backups. Failed migration/readiness/TLS checks restore the previous release.
Working…0%