Desktop mode
Spread complex work across windows
Drag, minimize, maximize, and use a real taskbar. Monitoring, clusters, terminals, and AI can stay open together while you investigate.

KPanel / Built for real Linux hosts
Desktop and Classic modes share one control plane. System, websites, Docker, files, clusters, and an AI assistant work against the same real host state—with two-way interoperability with kejilion.sh.

01 / TWO MODES
Keep the directness of a classic panel or open a desktop-style multitasking workspace. You are choosing an interface—not a separate system.
Same account · Same Agent · Same host state · No resource migrationDesktop mode
Drag, minimize, maximize, and use a real taskbar. Monitoring, clusters, terminals, and AI can stay open together while you investigate.

Classic mode
A familiar sidebar, clear sections, and dense information make routine checks and consecutive configuration fast.


02 / OPERATIONS WORKSPACE
The lightweight assistant understands host and container state already available to KPanel. It uses bounded tools for queries, analysis, and proposals—without making you assemble a separate agent platform.
Human approval by defaultChoose your modelUse OpenAI-compatible, Anthropic, and Gemini providers with independent sessions.
Fixed tool boundariesNormal actions use structured arguments. Writes require approval; high-risk actions always require it.
Proposals, not privilegeMemory and workflow changes are proposed by AI and approved by the administrator.


Cluster + history
Observe KPanel nodes and lightweight read-only nodes, then review host and container metrics over time.

Diagnostics workspace
Keep historical metrics, route latency, and diagnostic scripts together so the investigation remains continuous.
03 / BUILT FOR OPERATIONS
Start with one host and connect more when needed. Every surface is organized around real resources, explicit state, and traceable actions.
Inspect CPU, memory, disk, network, connections, and container history, with 30-day raw and up to 12-month hourly retention.
Connect full KPanel nodes or observe low-resource servers through outbound-HTTPS, read-only lightweight nodes.
Multiple providers, models, and sessions. Ask against panel state and act through reviewable structured tools.
Manage domains, certificates, reverse proxies, and site state while recognizing configuration that already exists on the host.
Move continuously from containers to files, processes, terminal sessions, and system settings.
Discover kejilion.sh and third-party apps, then use system diagnostics to find common configuration and network issues.
04 / REAL HOST, CLEAR BOUNDARIES
KPanel does not lock resources inside a private abstraction. Scripts, SSH, Compose, and panel-created resources remain mutually visible, while privileged capabilities are separately authorized, time-bounded, and audited.
Web/API runs unprivileged and normal work goes through a structured Agent. Host terminal access is a separately authorized, lifecycle-bounded root PTY.
Login rate limits, CSRF protection, session controls, and optional TOTP protect the administration surface.
Critical actions leave audit records, while resource configuration uses versions for comparison and rollback.
05 / DEPLOY
KPanel is designed for a single-administrator server. The installer validates the environment and prepares dependencies; review the platform matrix and security guidance before production use.
Other Debian, Ubuntu, RHEL, Arch, and openSUSE paths are implemented but admitted progressively through the support matrix. Alpine / OpenRC is not a formal install target.
bash <(curl -sL kejilion.sh) app kpanelRun as root. Review the repository and platform support matrix before installing.
Back up existing configuration first, then protect the management endpoint with HTTPS and access controls.
OPEN SOURCE / AGPL-3.0-only
Enter through the familiar Classic panel or unfold a complete workspace in Desktop mode. Both always point to the same real host.