AI control · Capabilities · Telemetry · FAQ
English · Polski · Deutsch · Nederlands · Español · Français · Italiano · Português · Українська · العربية · 简体中文
PanelAlpha Engine is software you install on your VPS to host AI-built and vibe-coded projects, websites and open source apps you found online. Once installed, you can connect your own AI agent directly to PanelAlpha Engine and let it handle deployments, maintenance and server management for you. Your server stays organized and under control.
But most importantly, it makes managing your own server/VPS super simple. You don't have to be a sysadmin to self-host anymore!
Out of the box, PanelAlpha Engine gives you and your AI everything you need to run real projects in production:
- Deploy any stack from Git or files
- Instant preview URLs with optional password protection (
project:set-password/ API + MCP;SITE_PASSWORD_AUTH_MODE=custom|basicon nginx-proxy). Uptime monitors need Basic Auth credentials or they see 401 as down. - Staging & Git workflows with separate live and staging environments
- Automatic backups & restore
- External monitoring & built-in visitor statistics
- Project isolation with separate Docker containers
- Firewall & OWASP/WAF protection with per-project access rules
- Domains, SSL, cron, FTP/SFTP, Databases, logs
- Easy Cloudflare integration for DNS, Tunnels and caching
AI has broken software creation out of its old limits. More people can turn ideas into working products, small teams can build much more than before, and open source is booming with projects worth making your own. What has not changed nearly as much is the work required to run it yourself. Most self-hosted tools still expect you to understand and manage Docker, a webserver, certificates, databases, backups, a firewall, and the updates that follow.
PanelAlpha Engine makes managing software in production as easy as AI made building it.
- One command, once. Then you talk to the AI assistant you already use.
- You ask in plain words. The engine builds the project, starts it, gives it HTTPS, and keeps it backed up.
- The AI never gets root. It works through the engine, inside rules you set.
Join the Discord. That is the main place to ask, show what you deployed, and talk to the people who build this.
You need a fresh server running Debian 12/13 or Ubuntu 22.04/24.04/26.04, with at least 2 GB RAM and 1 CPU, and you log in as root over SSH:
curl -fsSL https://get.panelalpha.com/engine | shThat is it. Your server is ready. Custom name, your own TLS certificate, or a server behind NAT: Install options.
At the end of the install the engine asks which assistant you use and prints the exact command to run on your own computer. To connect another one later, run this on the server:
pae connectRun pae connect on the engine server, not on your laptop. The line it prints is what you run on your computer.
Claude Code · Cursor · Codex · Gemini CLI · VS Code / Copilot · Grok · OpenCode · Windsurf · Pi · Hermes · OpenClaw
Using something else? Any assistant that speaks MCP will work: connecting other assistants.
A token with default permissions can delete a whole project. You can hand out a read-only one instead, or take single tools away: decide what the assistant may do.
Open your assistant's chat and say it the way you would say it to a person:
deploy github.com/anna/invoicer to my server
Done. Available at
invoicer.panelalpha.online
Every project gets a free panelalpha.online address the moment it exists. When you are ready, ask for your own domain and the certificate comes with it.
Prefer to do it from the server yourself? Deploy straight from git.
No commands to learn, and no magic phrases either. These are examples of the level of detail worth giving:
| You say | What happens |
|---|---|
Deploy github.com/org/app on this engine. |
A project is created, the stack is detected, the app is built, started and given an address with HTTPS. |
Add shop.example.com to this project and get a certificate for it. |
The domain is attached and Let's Encrypt issues a certificate that renews itself. |
This site does not open. Read the deploy log and fix what you can. |
Your assistant reads the log, checks what the site actually serves, changes your code and tries again. |
Push it to staging first. |
A linked copy with its own address. Push it live when you are happy, in either direction. |
Install WordPress here, admin user anna. |
WordPress installed and ready, with WP-CLI available for everything after that. |
Create a MySQL database for this project and a user for it. |
Database, user and privileges, without you touching SQL. |
Roll back to yesterday's backup. |
The backup is restored, and the current state is saved first, just in case. |
Only let our office reach this internal tool. |
A firewall rule limiting that project to the addresses you name. |
Set up a Cloudflare tunnel for n8n.mydomain.com. |
DNS and the tunnel configured, which is also how you serve a site from a server behind NAT. |
How much traffic did we get last week? |
Usage, logs and limits for that project, and the server as a whole. |
More worked examples: what to ask. The complete list of what your assistant can reach: 199 tools.
Your own tools, AI-built projects or open source software you found online. It does not matter: PanelAlpha Engine just runs it. A few applications get extra care because the general approach would get them wrong: WordPress, Matomo, phpBB, Magento and Passbolt. See the full list.
Giving AI full root access means open ports, random settings, and one project affecting another. PanelAlpha Engine sets the rules:
- Less room for mistakes. The AI works through the engine, not directly on the server.
- A clear structure. Projects, accounts and domains stay organized.
- Project isolation. Each one runs in its own Docker container, with its own limits on disk, memory and CPU, and only the ports it needs open.
What the assistant may do is something you decide before you connect it. Decide what the assistant may do · Security
Deploy is only the beginning. Ongoing management is there from the first install:
- See it online right away. A free
panelalpha.onlinehostname on every project, plus your own domains when you want them. Certificates come from Let's Encrypt and renew themselves. Domains and HTTPS - Build on staging. Go live when ready. A linked copy to break freely, then push live. You can push the other way too, to refresh the test copy with real data. Projects
- Built-in monitoring. Server metrics, per-site logs, Lighthouse reports on demand, and a check every six hours that each site is still serving itself rather than a blank page. Monitoring and logs
- All the essentials covered. Backups on the server and off it, SSL, domains, databases, FTP and SFTP logins, cron jobs and logs. Backups · Databases · Files and access
- A safe space per project. Docker isolation, a firewall, and ModSecurity with the OWASP rules. One broken app cannot take the others down. Security
- Cloudflare in one connection. DNS, tunnels and caching across your projects, including a site on a server behind NAT. Cloudflare
Most first deploys work. The ones that do not are usually a repository problem. Most tools leave you with a stack trace. Here the path is:
- You get a sentence, not a trace. "This project needs PHP 8.2, but it was built with PHP 8.1." "The build ran out of memory." The full output is still underneath if anyone wants it.
- Your assistant takes it from there. It reads the log, looks at what the site is actually serving, fixes what is fixable in your code and deploys again. That work runs on the AI subscription you already pay for, not on API tokens.
- The engine learns from it. An anonymous report goes back to PanelAlpha. One failure on your server might be your repository. The same failure on thirty servers is a bug in detection or in a framework recipe, and that becomes a fix in the next update.
- When the engine is the one that got it wrong, say so and it collects the evidence: ask your assistant to file it, or run
pae telemetry:bug-report <project>.
The whole procedure: when a deploy fails · what the error means.
Telemetry is on after install. Anonymous reports about deploys and later health checks leave the server unless you turn them off. They include the public names of your sites.
- Sent: what kind of application it was, how long it took, the project's limits, and for a failure the stage that broke plus a redacted log tail. A health report only when a site later stops serving itself. A bug report only when you file one.
- Never sent: your source code, project names, tokens, passwords, your server's IP or hostname, private repository names, or anything about the people who visit your sites.
- See a report before you decide:
pae telemetry:statusandpae telemetry:show.
To stop sending:
pae telemetry:disableWhat is collected, what is not, and every way to turn it off: what is collected · how to turn it off.
Why do I even need PanelAlpha Engine?
Because an application is not finished when the code is finished. Your project still needs somewhere to run, not to mention everything required to keep it healthy, reachable and safe. PanelAlpha Engine gives your AI assistant a proper way to handle that entire layer for you. You ask for the outcome you want, and the engine turns it into controlled server operations without giving the AI unrestricted access to the machine.
If you already know Docker, reverse proxies, firewalls and server logs, that knowledge still matters. PanelAlpha is not trying to hide the infrastructure from you or lock you out of it. It gives you a cleaner way to operate it, automate the repetitive parts and let AI take on real work without surrendering control. You can go as deep as you want when something deserves your attention, and skip the routine when it does not.
Do I need my own server?
Yes. PanelAlpha Engine is a tool for AI agents to manage your server. You need a fresh Debian or Ubuntu VPS with at least 2 GB RAM and 1 CPU, that you log into as root over SSH. You start by running the Engine installation on that VPS yourself. What you need
Which AI agents work with PanelAlpha Engine?
Any assistant that can connect to an MCP server with a token. There are step-by-step pages for Claude Code, Cursor, Codex, Gemini CLI, VS Code and Copilot, Grok, OpenCode, Windsurf, Pi, Hermes and OpenClaw, plus anything else that speaks MCP.
What projects can I deploy with PanelAlpha Engine?
The goal is a universal tool for any project. Static sites, WordPress, PHP, Laravel, Node, Next.js, Django, Go, Rust, Java, a plain Dockerfile or a Compose file. Your own tools, projects you built with AI, and open source software you found online. See project types, and if you want to check before committing, ask your assistant to inspect the repository first.
Is it free? What do I pay for?
PanelAlpha Engine is free and open source under the Apache 2.0 license. You pay for your server and your AI subscription, both of which you already have. Debugging a failed deploy runs on your assistant's subscription, not on API tokens.
Can I limit what my assistant is allowed to do?
Yes, and it is worth doing before you paste a token. You can give it a read-only token, allow changes but not deletions, expose only some areas, or deny individual tools such as project_delete. Decide what the assistant may do
What is reported if a deploy fails?
An anonymous summary: the kind of application, the stage that broke, a redacted log tail, and the public names of the sites. Never your source, project names, credentials or your server's identity. You can print a queued report with pae telemetry:show, and turn the whole thing off. Full detail: Telemetry.
Can I use PanelAlpha Engine for shared hosting?
Yes. Every project is a separate account with its own domains, databases, files and limits. Hosting providers have been running thousands of sites on it in production.
The engine got my project wrong. What now?
File a bug report and it gathers the evidence itself. Ask your assistant to file it, or run pae telemetry:bug-report <project> on the server. Use --dry-run first if you want to see exactly what would be sent.
Discord is the main place to reach us. Ask a question, show us what you deployed, share an idea, or simply drop by and see what we are working on. We're right there in the middle of those conversations, and what you raise there can turn into the next thing we build, fix or rethink.
Not really into Discord? Our forum is just as open.
curl -fsSL https://get.panelalpha.com/engine | shAn engine host is a single-purpose machine. The installer replaces the resolver and the firewall, so treat it that way.
Found a vulnerability? Please disclose it privately, never in a public issue. See SECURITY.md, or use manage.panelalpha.com/contact.
PanelAlpha Engine is open source under the Apache License 2.0.
Want to get involved? CONTRIBUTING.md will get you started. Operator documentation is in docs/.
