Self-hosted service
gna1280072/LeePanel avatar
gna1280072/LeePanel

LeePanel: an SSH-only Linux VPS panel that installs nothing on the server

Linux VPS control panel free software open source

617 stars48 forksRustMIT

At a glance

What is it?
LeePanel is a Tauri and React desktop client that manages Nginx, MySQL, PHP, Redis and Docker over your existing SSH connection. The pitch is zero server-side code; the trade-off is that every action depends on the SSH session holding up.
Who is it for?
Adopt LeePanel if you run a small number of Ubuntu or Debian VPS instances, already keep SSH keys in order, and want panel features without opening 8888 or 8080 to the internet. Skip it if your fleet is mostly CentOS, AlmaLinux or Rocky, or if you need a browser-based panel that several administrators can reach without SSH credentials.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 21 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem LeePanel targets: the panel itself as the attack surface

The README states the motivation directly: traditional Linux and VPS control panels frequently suffer from security vulnerabilities, and LeePanel was built to solve that. The mechanism it proposes is subtraction rather than hardening. A conventional panel installs its own daemon on the server, runs it as root, and exposes a web interface on ports like 8888 or 8080. That daemon is then reachable from the public internet, and a flaw in it means a flaw in the whole machine.

LeePanel moves the panel off the server entirely. It is a desktop application that connects over SSH and issues commands, so the README's comparison table lists only your existing SSH port as exposed. There is no panel process to patch, no panel port to firewall, and no uninstall script to run later: the README says closing the app leaves zero residue.

The audience is therefore narrow and specific. It is for people who administer one or a handful of VPS instances, who already have SSH access working, and who find a browser panel's convenience not worth its exposure. It is not aimed at hosting providers who need to hand panel logins to customers who have no shell account.

How the desktop client reaches your server

The repository layout makes the architecture plain. src-tauri/ holds the Rust side, src/ holds the React and TypeScript frontend, and package.json pins the Tauri 2 plugins the app depends on: plugin-shell, plugin-fs, plugin-dialog, plugin-process, plugin-notification and plugin-updater. The terminal is xterm.js, with the fit, clipboard and web-links addons listed as dependencies. Nothing in that dependency list is a server agent.

So the data flow is one-directional and short. The React UI collects an intent (create a site, restart PHP-FPM, browse a directory), the Rust layer runs the corresponding command over an SSH session, and the result is parsed back into the interface. The README describes SSH password and key authentication with credential storage, multi-server sessions that operate independently without blocking each other, and auto-reconnect when a connection drops.

That last item is doing more work than it appears to. Because the panel has no server-side component, every piece of state it shows you is either read live over SSH or cached locally. The README mentions directory caching for faster file navigation, which is a local cache, not a server one. If the SSH connection is down and auto-reconnect has not yet succeeded, there is nothing on the server answering on the panel's behalf.

Installing LeePanel and creating your first Nginx site

LeePanel ships as a desktop installer rather than a server script. The README points to the GitHub releases page for Windows, macOS and Linux downloads, and lists the installer size as 6 MB or more on each platform. System requirements are Windows 10 or 11 (64-bit), macOS 12 or later on Intel or Apple Silicon, and Linux x64 or arm64 via AppImage. There is no package manager command in the README, so install from the release artifact for your platform.

Building from source is a Vite and Tauri workflow, and package.json defines the scripts. The dev script starts the Vite frontend, and the tauri script invokes the Tauri CLI:

bash
npm install
npm run dev
npm run tauri dev

For a production bundle, the build script runs the TypeScript compiler before Vite, and the test script runs Vitest:

bash
npm run build
npm test

The README does not document which npm scripts produce a distributable installer for each target platform, so check the .github/ workflows in the repository for the release pipeline before assuming a local build matches the published artifact.

Once the app is open, the first real task is adding a server. The README describes SSH password or key authentication with credential storage, so you supply host, port and credentials and the connection is saved for later. From there, the LNMP section of the README covers one-click installation of Nginx, MySQL or MariaDB and PHP-FPM with version selection, followed by start, stop, restart and reload controls. Site management then handles Nginx virtual host creation, per-site PHP version switching, rewrite rules, reverse proxy with WebSocket support, and Let's Encrypt certificates. The README does not give the exact command sequence the app runs for any of these, so treat the first site you create as a check that the resulting Nginx config on disk is what you expected.

What breaks, and when LeePanel is the wrong tool

The README is explicit that all features are currently tested on Ubuntu and Debian, with more distributions described as coming soon. That is a real boundary, not a footnote. A panel that drives Nginx, PHP-FPM, MySQL and Redis through shell commands is encoding assumptions about package names, service unit names, config file paths and default directories. On a distribution outside that pair, individual features may work while others silently write to the wrong path.

The second constraint is the SSH dependency itself. Every operation needs a live authenticated session. A browser panel keeps working when your laptop closes; LeePanel does not, because the laptop is the panel. Scheduled work, monitoring that continues overnight, or anything that must run while no operator is connected has no home here. The README's feature list is all interactive: terminals, file browsers, service controls, database CRUD, Redis key browsing, Docker container lifecycle. There is no scheduler and no alerting described.

The third is credential concentration. The README mentions credential storage for SSH passwords and keys, and package.json includes tweetnacl, a cryptographic library. What the README does not document is where those stored credentials live, how they are encrypted at rest, or what happens to them on a shared workstation. If you are evaluating LeePanel for a team, that is the question to answer before rollout, and the README does not answer it.

LeePanel against a browser-based panel

The obvious alternative is a conventional web control panel installed on the server, the category LeePanel's comparison table argues against. The difference is not cosmetic. A web panel gives you a URL, so any administrator with the URL and an account can log in from any device, including a phone, without SSH keys. It can run background jobs, send alerts, and keep a record of who changed what. LeePanel gives up all of that in exchange for removing the panel daemon, its port, and its root process from the server.

Which one is right depends on what you are protecting against. If your concern is that a panel vulnerability turns into a full server compromise, LeePanel's design removes that path by removing the software. If your concern is operational, multiple administrators, access from anywhere, unattended tasks, the browser panel is the better fit and LeePanel will feel like a step backwards.

There is a middle position worth naming: managing the same server with plain SSH and a text editor. That is free, has no installer, and works on any distribution. LeePanel's value over it is the interface layer, file browsing, database CRUD, Redis key browsing, Docker container controls, and the fact that it does not require you to remember the exact systemctl invocation for PHP-FPM on Debian. If you are comfortable in a shell and rarely touch MySQL or Redis, the panel adds less than the download suggests.

Maintenance, releases and what the MIT licence means here

LeePanel is MIT licensed, which permits commercial use, modification and redistribution provided the copyright notice and licence text are preserved. For a desktop tool you install on your own workstation, the practical implication is that you can fork it, bundle it internally, or ship a modified build without asking permission. The LICENSE file sits at the repository root. This is a description of the licence terms, not legal advice; if you plan to redistribute a modified build, read the LICENSE file yourself.

The release cadence is visible: v1.0.21 on 2026-08-18, v1.0.22 on 2026-08-21, v1.0.23 on 2026-08-23, and the last push to main was on 2026-09-10. Three releases inside six days followed by a quieter period suggests the project is still moving but not on a fixed schedule. package.json carries version 1.0.23, matching the most recent release tag, so the frontend version tracks releases rather than drifting.

Upgrade cost is low by design. The app is a desktop binary with a Tauri updater plugin in its dependency list, so upgrades are a download rather than a server migration. The cost that does not disappear is compatibility drift on the server side: when Ubuntu or Debian changes a package name or a service unit, the panel's command layer has to follow, and that is where the maintenance burden actually lives. There is no documented rollback path in the README if an upgrade misbehaves, so keeping the previous installer around is the cheap insurance.

Editorial conclusion

Adopt LeePanel if you run a small number of Ubuntu or Debian VPS instances, already keep SSH keys in order, and want panel features without opening 8888 or 8080 to the internet. Skip it if your fleet is mostly CentOS, AlmaLinux or Rocky, or if you need a browser-based panel that several administrators can reach without SSH credentials. Before trusting it, verify one thing on a throwaway server: that the version-selection install path for Nginx, MySQL and PHP actually produces the service versions you asked for.

Frequently asked questions

Does LeePanel install anything on my server?

No. The README states that all operations are performed via SSH commands from your local machine, with no panel code installed on the server and no extra ports exposed. Closing the desktop app leaves no panel process behind.

Which Linux distributions does LeePanel support?

The README says all features are currently tested on Ubuntu and Debian, and that more distributions are coming. Other distributions are not documented as supported.

What can LeePanel manage on the server?

The README lists an SSH terminal, SFTP file management, Nginx, MySQL or MariaDB, PHP-FPM, Redis, Docker, firewall rules and Let's Encrypt SSL certificates. It also covers Nginx virtual hosts, reverse proxy with WebSocket support, and per-site PHP version switching.

How large is the LeePanel installer?

The README lists the installer as 6 MB or more on Windows, macOS and Linux. It describes the app as a lightweight cross-platform desktop client built with Tauri 2 and React.

Official sources

  1. gna1280072/LeePanel on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/gna1280072-leepanel.svg)](https://hysenlabs.com/projects/gna1280072-leepanel)