ServerAvatarDocs

Server Sync

Scan a server for applications, users, certificates and settings that already exist outside the panel, then add the ones you want it to manage.

OSS Panel normally knows about a thing because it created it. Server Sync is for everything else: a server you installed the panel onto after it was already running sites, or one you migrated from another control panel.

It works in two halves, and the first half changes nothing.

  1. Scan — read the whole server and list what is there but not in the panel.
  2. Add to the panel — write panel records for the items you keep.

Server Sync before the first scan

What it looks for

TypeFound by reading
System usersThe accounts on the box and their home directories
SSH keysauthorized_keys of those users
ApplicationsWeb-server virtual hosts and their document roots
PHP settingsPer-site PHP configuration
PM2 processesProcesses PM2 is keeping alive
WorkersLong-running service units for a site
Database usersAccounts on the installed database engines
CertificatesTLS certificates installed for those sites
Cron jobsCrontabs belonging to those users
Firewall rulesThe server's current rules

The order is a dependency order, not an importance order: an SSH key belongs to a user, a worker belongs to an application. If a parent type is left out, its children are skipped rather than invented.

Scan the server

Press Scan the server. Results stream in as they are found, so a long scan on a busy box shows its work rather than going quiet for minutes.

Read the list. Every row carries a type, a name and a status. Found is an item the panel could add; Skipped is one it has decided to leave alone, with the reason on the row.

A completed scan listing a system user, an SSH key and a skipped application

The summary at the top says it plainly: nothing has been changed on your server. A scan is a read.

Open a row for the evidence behind it. The chevron expands the raw facts the discoverer recorded — for a system user, its uid, home directory, login shell and whether it has sudo.

A system user row expanded to show uid, home path, shell and sudo

Items are also scored for confidence — Confident, Likely, Best guess or Not identified — so an unusual vhost layout is flagged rather than quietly treated as a normal site.

Dismiss anything you do not want. The eye icon on a row drops it from this list and from every future scan. Dismissed items are listed behind the Dismissed button at the top, where you can undo any of them.

Filters above the table narrow by type, and the search box matches on name — both useful on a server with two hundred sites.

Add the results to the panel

Press Add to the panel. The dialog is the last read-only moment: it lists what will be written, by type, with a tick box per type.

The Add these to the panel dialog with System users and SSH keys ticked

Everything found is included except what you dismissed. Unticking a type leaves it out entirely. If you untick a type that others depend on, the dialog says so — "Workers need applications to be added too. Without it, every one of them will be skipped."

Read the warning, then confirm. There is no undo: added items have to be removed one at a time afterwards, from the screens that own them.

Watch the outcomes. Each row changes from Found to Added, Skipped or Failed as it is handled, and the summary counts all three.

The same list after adopting, both rows now marked Added

Failures and skips are listed on purpose. A sync that showed only its successes would be indistinguishable from one that silently missed half the server.

Check the feature's own screen. Anything added is now an ordinary panel record. The system user above appears under System Users like any other — with its password shown as Not set, because the panel adopted the account rather than creating it and never knew the password.

The adopted user listed on the System Users screen

Firewall rules need a decision

Firewall rules are off by default in the add dialog, behind their own switch and their own warning:

Once the panel manages your firewall rules, a later change here can close the port you connect on. Leave this off unless you're sure.

That is not boilerplate. Adopting the rules makes the panel's Firewall screen the source of truth for them, and a subsequent edit there is applied to the server wholesale. Adopt them when you intend to manage the firewall from the panel from now on — not merely to have a tidy list.

What it refuses to adopt

Some things are always skipped, with the reason on the row. The panel's own virtual host is one of them:

This is the panel itself, not a site it can host. Left alone deliberately.

Adopting it would put the panel under its own application management, where a careless delete would take out the panel along with the site.

Running it again

Scan again re-reads the server. Items already in the panel are not offered a second time, and dismissed items stay hidden — so a second scan on an unchanged server finds nothing, which is the correct answer rather than an error.

Re-scanning after you add a site by hand is the normal way to bring it in.

Limits and caveats

  • One run at a time. Starting a scan while one is live is refused.
  • Adding cannot be undone in bulk. Remove items individually from their own screens.
  • A run that dies halfway keeps what it did. Items marked Added are in the panel; the rest were not touched. Scan again to see what is left.
  • A stalled scan is reported, not hidden — the screen says so when a run stops sending progress.
  • Watching needs sync view; starting needs sync manage. A read-only operator can follow a migration without being able to begin one.
  • Server Sync reads what is on the box now. It does not import another panel's database, settings or users.

On this page