ReferenceEvery page

panel-api(8)

panel interface

Name

panel-api — panel interface

Synopsis

panel-api [-v] [-f file]

Description

panel-api serves the panel's interface and its HTTP API. It is started by panel-masterd(8) and is not ordinarily run by hand.

It holds no privilege. It reaches the system only by asking panel-brokerd(8), and runs as its own unprivileged account. Since 1.92.3 it is also confined with Landlock, on every thread: it may read and write only the files it needs — its database, the web files, its sockets and certificates, the release spool under upgrade_dir and a few more — and nothing else on the machine. Landlock confines files, not the network: it still makes the connections it needs, to the blocklists, the owner list, the other panels, a relay and, since 1.174.0, the download site. On a kernel without Landlock, or with api_unveil = no in panel.conf(5), it runs unconfined and logs a warning saying so at startup.

Since 1.151.0 it also stays connected to a relay the panel joined (Maintenance, Relay), and serves what the relay passes on as any other connection: a browser from outside, only while From outside is on, and the other panels that joined it, for the fleet. See panel-relay(8).

The manual is served under /docs/, from web_dir, to anybody: the pages a browser opens and /docs/help.json, each page's part of it that the ? beside a page's heading shows. It is the manual of the version running.

Requests under /api/m/⟨id⟩ are passed to that module's daemon. Events published by modules are read from their sockets and delivered to browsers over a single stream per session, so the number of connections does not grow with the number of modules.

To a panel it is paired with it answers on the same port, over TLS with pinned keys, under /fleet/v1/. A release uploaded is kept beside the upload spool; once this panel runs it and it is kept, a panel sharing accounts with this one may fetch it there and stage it, to be installed when somebody on that panel agrees.

A phone running the panel's app is paired by signing in to it with an account, and is given a token of its own, once; only its fingerprint is kept. The app swaps the token for an ordinary session at /api/session/device, for session_ttl, and the phone is listed on the Panels page, where it is revoked.

It keeps the household's pause schedules and every fifteen seconds, in the machine's own clock, pauses what they pause and resumes what they no longer do, through panel-brokerd(8), as “(schedule)”; a pause somebody made is left alone. Once a minute it reads what the devices under a daily internet time have sent, counts a minute used for each one that sent 120 packets or more, and pauses those whose time is used up until midnight, as “(allowance)”. Every thirty seconds it takes a closer look: the line's loss and delay as the net module's echoes found them, a name asked of the router's DNS, the uplink's and the home network's cables, and the machine's load, temperature, memory and disks — a disk gone read-only, or one ext4 has counted errors on, among them; the household page, the Status page and Home's Health card show the result, and Activity a problem's start and end.

The options are as follows:

-f file
Read configuration from file.
-v
Print the version and exit.

Files

/var/db/panel/upgrade/spool/release.tar.gz
The release last uploaded or fetched, kept to pass on.
/var/db/panel/upgrade/spool/release.json
Its version, architecture, size and SHA-256.
/var/db/panel/upgrade/spool/fetched.json
What was fetched from another panel, turned down, or failed.

See also

panelctl(1), panel.conf(5), panel-brokerd(8), panel-masterd(8)