Roadmap · STYGION Panel
Everything we are building, in the open
No dates, no promises we cannot keep. Just what we are thinking about, what we decided to do, what somebody is working on today, and what is already out.
Last thing out A project can be renamed, cards and all 3 weeks ago
Exploring
5Ideas we keep turning over. None of it is a promise.
Panel rewritten from zero
Parked on 30 August 2026. The rewrite was deployed once and almost nothing worked; the code is archived and will be taken from a piece at a time. The panel stays on the 0.2.0 line, the one that runs in production.
First release is self-host, no billing
Parked with the rewrite on 30 August 2026. Panel 0.2.0 already has billing, so this decision waits until there is a release to make it about.
Built one working piece at a time
Parked with the rewrite on 30 August 2026. It stays as the rule for work on 0.2.0: one piece, finished, proven in production, and only then the next.
Teams, roles and permissions
A finer permission matrix beyond the three coarse levels the panel already ships.
Scoped keys for automation and AI
Keys with limited scope (server / capabilities), revoke and audit. Never more rights than the key owner has.
Planned
16Decided. Waiting for its turn.
What your servers really run at, shared
The panel already watches its servers. This lets an operator, if they choose, contribute what those servers actually keep — tick time at the player counts they really carry — to the public performance page. It is the check on everything measured in a load test: a lab number nobody meets in production is a lab number. What leaves carries the pack's mod list, the machine class and the numbers, and nothing that names a server or a person.
Connect the panel without typing a code
Press Connect, a browser opens on the page that already knows which panel is asking, and one button finishes it. Reading a code out stays only for a machine with no browser at all.
Recreate must put a server back the way it found it
`Service.Recreate` deletes the container and builds a new one with `podman create`, which leaves it stopped — a server that was running before a Startup-tab save is down after it, and nothing in the UI says so. Recreate should remember whether it was running and start it again, and say so loudly when it cannot. Changing an environment variable is the only way to hand a server a new token, so this meets everybody who edits a running server's settings.
Issue the admin MCP key from the panel
The Application API page can only say the key is missing and send somebody to an env file and a restart. It should carry a button that issues one — the admin MCP that reaches the whole panel — and a second that revokes it. Shown once, the way a key is shown. No file to edit, no restart.
Mounts
Share one host directory across several servers — a modpack, a map set, a bundle of plugins — instead of every server keeping its own copy. The panel's administrator decides which paths on the machine may be mounted at all; a server's owner picks from those and says whether it is read-only. It is the one feature that lets data out of the host and into a container, so it does not ship without an allowlist and an entry in the activity log. Removed from the panel's tabs on 30 August 2026, where it had no backend and led to a placeholder — a tab must not advertise what does not exist.
Machines announce themselves
The panel finds another machine on the network by itself and offers to adopt it. Nothing gets typed in.
Actions across a selection
Restart, update, limit change and console command reach a hundred servers as easily as one.
Move in from another panel
Servers, eggs, users and ports come over from a running Pterodactyl or Pelican in a single run, with a preview first.
Command palette (Ctrl+K)
Servers, actions and the terminal are one keystroke away from anywhere in the panel.
Server metrics
Continuous CPU and RAM sampling per server with a sparkline chart in the cockpit.
Continuous health watch
The panel watches the servers and itself continuously, not once a night, and speaks up the moment something breaks.
Support bundle
A diagnostics bundle for a ticket in one click, sensitive values redacted.
Operator terminal
The terminal docked to the right of the panel: a shell on the machine and inside the server container; an agent drives the same session over MCP — one audit trail.
Server backup — download & upload the whole database
Download a server’s entire database as a backup, and upload it back the same way.
Signed updates (minisign)
Self-update hardening: minisign-sign the tarball + verify with an embedded public key. sha256 is the current gate; add once the keypair + CI secret exist.
Wails desktop shell (Windows/macOS)
Native desktop around the Go core (Wails 2 + SvelteKit, no Rust). Model: embedded-server webview — the Wails window opens the existing frontend talking to the in-process Go HTTP server on localhost (minimal refactor). Powers the Windows/macOS install in the release workflow.
Building
0Somebody has their hands on it right now.
Nothing here
Done
31Built and out. Newest at the top.
The light theme is readable, and a page holds its shape while it loads
Every status colour — the green of a running server, the amber of a warning, the red on a delete button — was tuned for the dark theme and drawn unchanged on the light one, where several of them were barely legible and one was effectively invisible. They now have their own values on light, measured rather than guessed. Lists no longer print a grey word where a table is about to be: the space is held in the shape of what is coming, so nothing jumps when the answer lands. Switching between sections moves rather than cuts.
Asking whether you mean it looks like the panel, not like the browser
Deleting a server, dropping a database or restoring over live files used to ask through the browser's own grey box. Now it asks in the panel's own dialog, in a sentence that says what actually happens rather than "Are you sure?" — and for what cannot be undone, the name gets typed out before the button turns on. Escape closes it from anywhere, the page behind it stays still, and focus comes back to the button that opened it.
The whole panel in English
The panel mixes two languages on one screen today: a Czech heading over a card that says "Subscription — active", "Linked", "Plan", "Last checked". The Application API screen is entirely Czech; Updates beside it is almost entirely English. This is not a missing translation — it is two decisions at once, and a reader cannot tell which one is ours. The panel is sold outside the Czech Republic, so the language is **English, the whole panel, with no exceptions** — every label, message, empty state and error. Not bilingual, not a switch: one language, until localisation is a real feature with a design of its own. Until then a mixed screen is worse than either clean answer. That includes what the panel writes away from the screen — the `[stygion] …` console lines, audit entries and API error responses.
Panel support goes into the one queue
Writing to us from inside the panel lands in the same queue as everything else, filed under the STYGION ID the panel is licensed to. Nothing to set up: if the panel is linked, it can write. The reply arrives in that account, and the panel links straight to it.
Real Panel screenshot on /core
Marketing dashboard shot from a running instance (devdata has a seeded DB with 2 servers). Blocked by the auth gate (login required) + offline server status without podman. Best captured from a deployed/Linux instance. /core meanwhile uses an honest terminal visual.
Server users and access
Done on 30 August 2026 (0.3.5). A server can be shared with other accounts, and a permission is named after the thing it opens — the same eleven words the tabs are called: console, command, power, files, backups, schedules, databases, network, startup, settings, activity. Enforced at one gate on every route; deleting a server and the Users tab stay owner-only, because somebody who can grant themselves more has all of it. SFTP answers to the same permission as the file manager. A stranger gets 404, not 403. A shared server appears on the dashboard of whoever it was shared with, and the panel hides the tabs and buttons that would only answer 403.
Seven days to try it
Done on 30 August 2026. The week runs from the day of the install, not the day somebody got round to linking an ID — otherwise it is spent on the setup wizard. It needs no network at all: it is a fact the panel holds itself.
Local accounts, licence on the side
Done on 30 August 2026. The accounts stay the panel's own and the licence rides alongside them on a STYGION ID. A pairing code in Settings → Subscription, seven free days from the install, fourteen days of grace when we cannot be reached. It locks exactly one thing: creating a new server.
The panel is drivable over MCP
Done on 30 August 2026. The panel has its own MCP surface at /mcp/v1: servers, console, files, backups, schedules, databases, ports, eggs, nodes, activity, the updater and the licence. A tool calls the same service the panel does — no back doors — and whatever is not wired into an install is not advertised at all.
Live console (WebSocket)
Done on 30 August 2026. The console belongs to the server, not to whoever is looking: one reader lives as long as the container and feeds a buffer viewers only read from — so opening the page is instant, nothing is lost while nobody watches, and ten viewers cost what one does. Start prints what it is launching; Stop and Kill announce themselves when pressed; a failed action is written into the console. The connection reconnects on its own and does not duplicate the scrollback when it does. Commands travel down a pipe the panel owns, so they survive a panel restart — `podman attach` closed a server's input for good, however it ended.
An uploaded file does not stop the server
Done on 30 August 2026. Under rootless podman the server now runs as root inside its own namespace — and that root *is* the panel user who owns the files. Ownership lines up by construction, for an upload and after an install alike, and there is no chown to run over SSH anywhere.
Multi-node and capacity
More machines, allocation, health — after a solid single-node core.
Web installer Linux (alfa live)
Shipped, and finished on 30 August 2026: the installer asks for a domain, takes a certificate through Caddy, opens the firewall, installs podman when no engine is present, verifies the downloaded tarball against its .sha256 before unpacking it, and generates the MCP key. It can run a second instance on one machine, uninstall itself, and install from a file for a machine with no internet.
Self-update + channel selector (servers untouched)
Panel self-updates from Release Control: channel selector (alfa/beta/release), signature verify, binary swap + restart — managed servers keep running.
Release workflow + updater
A tag builds five platforms with the embedded frontend and attaches the update manifest the panel consumes.
Updater: progress modal + auto-refresh after restart
Done on 30 August 2026. The dialog holds from the confirmation to "version X is running": downloading, verifying the checksum, restarting. The page then comes back on its own. No percentage bar — the update is one server-side call, so there are no honest percentages, and inventing them would be worse than showing none.
Safe self-update: health-check + auto-rollback
Verify the new build boots before committing; auto-restore the previous version on a crash loop so an update can never take the Panel down.
Panel update keeps servers running
When the Panel updates and restarts, running servers and services keep going uninterrupted.
Discord beside the panel
A panel account links to Discord — the operator's and everybody else's alike. The operator then points a bot at a channel and it says what happens to the server on its own: planned maintenance, a crash, an update that finished. People hear it where they already are instead of watching a panel for it.
Your own backup plan, your own storage
Everyone sets their own schedule and destination for their server. It is encrypted before it leaves, and a restore is rehearsed from time to time.
Read the modpack from the file
An uploaded archive reveals its loader, game version and required Java on its own. The panel turns that into a plan, shows it and runs it.
Server reinstall
The egg's install runs again into the existing files in one click, with a confirmation and live progress in the console.
Egg catalog and import
Built-in eggs with typed installs, plus Pelican egg JSON import and export including install scripts.
Host tuning
The kernel values game servers need (map count, open files, listen backlog) apply in one click — with a backup and a way back.
Port allocations
Extra ports beside the primary one — the container publishes them on its next start, the panel guards collisions.
Managed databases
One-click MySQL database and user provisioned for a server; the password stays sealed until the operator reveals it.
Activity feed
The audit log as the machine's diary — panel actions, installs, terminal commands and agent work in one trail.
Scheduled tasks (cron)
Timing server actions — restarts, backups, commands — via a cron expression.
Startup editor
The startup command, stop command and variables are editable right in the panel; changes apply on the next start.
Encrypted backups with retention
One-click server backup, encrypted, with configurable retention and a guarded restore.
File manager and SFTP
Browse, read and write server files in the panel plus SFTP access keyed to panel accounts.