DocsFleet and multiple servers

Fleet and multiple servers

Manage several ZoPanel servers from one panel: fleet tokens, one-click sign-in, creating accounts on any server, moving websites and a DNS cluster.

When you run more than one ZoPanel server, you can connect them into a fleet. One panel, the controller, shows the status of the other servers, the nodes. From the controller you can sign in to any node with one click, create hosting accounts on it and move websites between servers. Each server keeps running on its own, and a node does not depend on the controller to serve websites.

How it works

  • A node is enrolled with a fleet token (zpf_…) that its own administrator generates.
  • The controller talks to the node over HTTPS on the panel port. The node's certificate must be publicly trusted for its host name, or the controller pins its fingerprint at enrolment.
  • The controller checks every node regularly. A node that fails three checks in a row is reported down once, and reported again when it answers.

Connecting a server

1. On the node: generate a fleet token

  1. Open Settings → System → Central management.
  2. Choose the Access for controllers:
    • Full: sign in, move websites, create accounts. Controllers sign in as their own administrators, which are created on the node the first time they are used.
    • Monitoring only. Controllers only see the status of this server.
  3. Click Generate token and copy it. It is shown only once.

If you restrict panel access by IP on the node, add the controller's IP to Settings → General → Restrict panel access.

Regenerate token creates a new token. Controllers that use the old one lose access until you update them. Disable turns central management off.

2. On the controller: add the server

  1. Open Servers and click Add server.
  2. Enter a Name, the Panel address (for example https://node2.example.com:8888) and the Fleet token.
  3. Click Connect.

If the node uses a self-signed certificate, the controller pins it and shows its fingerprint. Compare it with the certificate on the node. If you later change the node's certificate, use Re-pin certificate on its card. Only do that when you know the certificate was changed. Otherwise the new certificate may come from an impersonation attempt.

Each server card shows whether the server is online, its CPU, RAM and disk use, the number of websites and accounts, uptime and agent status.

Fleet tokens and scopes

Scope Controller can
Full See status, sign in as an administrator, create accounts, receive migrated websites
Monitoring only See status only

The token is stored on the node only as a hash. On the controller it is kept encrypted with the panel's other secrets. API tokens cannot generate fleet tokens or enrol nodes. Those actions require a signed-in administrator.

Single sign-on

On a node's card, click Open panel. The controller asks the node for a one-time sign-in link, valid once for 60 seconds, and opens the node's panel in a new tab.

On the node, you are signed in as a dedicated administrator named after your controller login, prefixed with fl. It has a random password and can only sign in through the controller, which checks your own 2FA. Two people on the controller never share an account on the node, the node's activity log names the person who acted, and no controller ever signs in as the node's own administrators.

Creating accounts on a node

  1. On the node's card, click New account.
  2. Enter the username, password and email, and pick a package. The packages are loaded from that node.
  3. Optionally enter a First website (optional).
  4. Click Create.

The account is created on the node in your name and recorded in both activity logs. The node's license limits apply.

Moving websites between servers

Websites move with everything the application depends on. The account keeps its username and panel password, and the databases keep their names, users and passwords, so wp-config.php and .env files work without changes. The website on the source server is left untouched until you remove it.

You can move websites in two ways:

  • Several at once: on the target server's card in Servers, click Move websites, select the websites and confirm.
  • One website: open the website and, in the Move to another server card on its overview, choose the target server and click Start migration.

Then:

  1. Follow the job log until it finishes. If one website fails, the next one still moves.
  2. Check the website on the target server.
  3. Point DNS to the new server. Certificates are issued again there once the domain resolves.
  4. Remove the website from the old server when you no longer need it.

App Store (Docker) and S3 storage websites cannot be moved this way. Reinstall them on the target. The target must be online with a Full token, and its license limits apply.

The same information travels inside every account backup. An archive made on one server can also be restored on another with Backups → Restore from file.

DNS cluster

If you host DNS on your servers (PowerDNS, installed from the DNS page), you can serve the same zones from several servers. This is set up on the DNS page, in the DNS cluster card, and works separately from the fleet.

On the primary server, which holds the zones:

  1. Under Secondary servers (IPs), list the IPs of the secondaries. They may transfer every zone of this server and are notified of changes (NOTIFY and zone transfer).
  2. Under Cluster key (TSIG), click Generate and copy the key. It is not shown again. Zone transfers are signed with HMAC-SHA256.

On each secondary server:

  1. Under Primary servers, add one line per primary: its IP and this server's nameserver name in the primary's zones, for example 203.0.113.10 ns2.example.com.
  2. Enter the same Cluster key (TSIG).

Secondaries then receive the zones automatically, and the card shows how many zones were received. Deleting a zone on the primary does not delete it on the secondaries.

Good practice

  • Give monitoring-only tokens to dashboards and tools that do not need to change anything.
  • Turn on 2FA for every administrator on the controller. It protects sign-in to all nodes.
  • Keep fleet nodes on publicly trusted certificates (Settings → General → Panel domain & SSL), so pinning is never needed.

← Provisioning API Operations and monitoring →