Skip to content

Files and ports ​

Where the Panel and the Node keep things on disk, which ports they listen on, and the environment variables that change either. Everything not listed here, from admins and settings to users and certificates, lives in the panel's database and is managed from the panel.

Panel files ​

PathWhat
/opt/nexora-panel/nexora-panelthe program
/opt/nexora-panel/nexora-panel.previousthe program before the last update, kept for a rollback
/opt/nexora-panel/config.jsonthe database connection, and nothing else
/var/opt/nexora/nexora.dbthe SQLite database (with -wal and -shm files beside it while the panel runs)
/var/opt/nexora/bin/node binaries the panel hands to node installers
/var/opt/nexora/sub-themes/subscription page themes
/var/opt/nexora/presets/your own preset catalogue files, added to the built-in presets
/var/opt/nexora/backups/backup archives and pre-restore snapshots (readable by root only)
/var/opt/nexora/rulesets/the panel's copies of rule-set files it hands to nodes; safe to clear, the panel downloads them again
/etc/systemd/system/nexora-panel.servicethe service

Copying the database files while the panel runs is not a backup. Use the panel's own backup (Backup and restore), which takes a consistent copy without stopping anything.

config.json looks like this:

json
{ "db": { "driver": "sqlite", "dsn": "/var/opt/nexora/nexora.db" } }

With PostgreSQL, driver is postgres and dsn is the connection string. max_open_conns sets the size of the connection pool; leave it out unless the PostgreSQL server is shared with other programs.

In Docker ​

Each panel stack keeps what must outlive the container next to its compose file:

PathWhat
./datathe SQLite database (the PostgreSQL stack uses a named volume)
./backupsbackup archives
./binnode binaries
./rulesetsrule-set copies; safe to clear
./sub-themessubscription page themes

Node files ​

PathWhat
/opt/nexora-node/nexora-nodethe program
/opt/nexora-node/config.jsonthe control port's address and the certificate paths, nothing else
/var/opt/nexora/certs/ssl_cert.pemthe node's own certificate
/var/opt/nexora/certs/ssl_key.pemits private key
/var/opt/nexora/certs/panel_ca.pemthe panel's certificate, the only one the node accepts
/var/opt/nexora/cache/rule sets and other files the panel pushed; safe to delete, the panel sends them again
/etc/systemd/system/nexora-node.servicethe service

Everything a node serves is sent by the panel and held in memory. A restarted node serves nothing until the panel sends its configuration again, which takes seconds. The certificates are the only files on a node worth backing up.

In Docker, the node keeps ./certs and ./cache next to its compose file.

When the panel and a node share a server, /var/opt/nexora holds both: the database, bin, backups and the rest are the panel's, certs and cache are the node's. See Panel and node on one server.

Ports ​

PortWhoWhat
a random high TCP portpanel (script install)the panel's web interface, API and subscriptions. The installer picks a free one and prints it
2095 TCPpanel (Docker)the same, pinned in the compose file
62050 TCPnodethe control port. Only the panel can use it; allow it from the panel's address alone
the inbounds' portsnodewhat your users connect to, chosen in the panel
5432 TCP, local onlyPostgreSQL (with --postgres)the database, reached by the panel on 127.0.0.1

The panel's port can be changed in the setup wizard and later on the settings page, or with nexora-panel config set web_listen_port. Both the panel and the node listen on IPv6 and IPv4 at once, and fall back to IPv4 on a server with IPv6 switched off.

Environment variables ​

Panel ​

VariableEffect
NEXORA_DB_DRIVERsqlite or postgres
NEXORA_DB_DSNthe database connection: a file path for SQLite, a connection string for PostgreSQL
NEXORA_DB_MAX_OPEN_CONNSthe database connection pool size
NEXORA_WEB_LISTENpin the listen address (IP:PORT). The panel then ignores the address saved in its settings, and the setup wizard cannot change it. The Docker stacks use this

These override config.json. nexora-panel run -listen IP:PORT pins the address the same way as NEXORA_WEB_LISTEN.

Node ​

VariableEffect
NEXORA_NODE_LISTENthe control port's address, [::]:62050 by default
NEXORA_NODE_CERTthe node's certificate file
NEXORA_NODE_KEYits private key file
NEXORA_NODE_CLIENT_CAthe panel's certificate file
NEXORA_STATE_DIRthe directory for certs and cache, /var/opt/nexora by default

These override the node's config.json. The node installer also reads NEXORA_INSTALL_TOKEN in place of --token.

Text and images under CC BY 4.0.