Master domain
The master domain is the domain you open the panel on, and it is the system’s “master server address”. When the other two domains are not set, subscription links and Agent communication use it too.
Where it is used
Section titled “Where it is used”Set it in System Settings → “System” tab → Master Server URL, as scheme + domain (or IP and port), for example https://panel.example.com. When left empty, the address you are currently visiting is used.
Once saved, it is used for:
- The Agent install command generated when adding a server, and the address Agents connect back to (when no report domain is set).
- Subscription links (when no subscription domain is set).
- The report link of the “Client IP allowlist” in personal settings.
- Places that need to know “who the master is”, such as the passkey RP ID and certificate detection.
If the domain you are visiting over HTTPS differs from the one set here, the panel shows a “Master Domain Mismatch” prompt and can switch it to the current domain in one click.
Enabling HTTPS
Section titled “Enabling HTTPS”Pick one:
| Method | Best for | Notes |
|---|---|---|
| Certificates → “Deploy certificate to master” | Most cases | The master installs and manages Nginx itself. Afterwards the subscription and report domains can be configured from the panel in one click |
| Your own Nginx / Caddy | You already have a reverse proxy, or share the host with other sites | Follow the deployment tutorial; the subscription and report domain configs shown by the panel can be copied as-is |
| Cloudflare Tunnel | The master has no public entry, or you do not want to open ports | Cloudflare provides HTTPS |
See Certificates for issuing and deploying certificates.
Configuration examples
Section titled “Configuration examples”The examples assume the master domain is panel.example.com, the master listens on the default port 12889 (replace it if you changed PORT), and the reverse proxy runs on the same host. The master domain must allow every path and support WebSocket (live panel refresh relies on it, and so do Agent connections when no report domain is set).
Put the certificate under /usr/local/nginx/cert/panel.example.com/ (or use your own path) and save as, for example, /usr/local/nginx/servers/panel.conf:
server { listen 443 ssl; listen [::]:443 ssl; http2 on; server_name panel.example.com;
ssl_certificate /usr/local/nginx/cert/panel.example.com/fullchain.pem; ssl_certificate_key /usr/local/nginx/cert/panel.example.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3;
# Restoring backups, uploading a logo, etc. need a larger request body client_max_body_size 512m;
location / { proxy_pass http://127.0.0.1:12889; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $http_connection; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto https; proxy_connect_timeout 60s; proxy_send_timeout 600s; proxy_read_timeout 600s; }}
# Reject unknown domains: only one default_server on 443; skip it if you already have oneserver { listen 443 ssl default_server; listen [::]:443 ssl default_server; ssl_reject_handshake on;}proxy_http_version 1.1and theUpgrade/Connectionheaders are all required, otherwise the WebSocket handshake fails.X-Real-IP/X-Forwarded-Forlet the master see the real client IP for login rate limiting, the client IP allowlist and so on. The master trusts these headers automatically when the proxy is on the same host (or a private network); when the proxy is on another public server, add its IP to theMMWX_TRUSTED_PROXIESenvironment variable or the “Trusted proxies” setting.
Run /usr/local/nginx/sbin/nginx -t to check, then systemctl reload nginx.
Caddy issues and renews certificates and handles WebSocket and the X-Forwarded-* headers automatically. Add to /etc/caddy/Caddyfile:
panel.example.com { reverse_proxy 127.0.0.1:12889}To use an existing certificate, add tls /path/to/fullchain.pem /path/to/privkey.pem inside the site block. Run caddy validate --config /etc/caddy/Caddyfile, then systemctl reload caddy. Caddy only answers the domains written in the Caddyfile, so no extra “reject unknown domains” site is needed.
Disabling public access
Section titled “Disabling public access”After enabling Disable public access in the “System” tab and restarting the master, it only accepts requests coming through a reverse proxy:
- The master listens on
127.0.0.1only, so IP + port access stops working. This is for a reverse proxy on the same host; Docker port mappings and cross-server proxies do not work with it. - When the Master Server URL is
https://, requests whose Host is not the master domain are redirected (307) to the master domain. Exceptions:- subscription paths on the subscription domain;
- Agent communication paths on the report domain (WebSocket cannot follow redirects, so they must be let through);
- requests from the host itself (127.0.0.1).