In development

QuroPanel is under active development. Follow the roadmap and join the first public testing group.

QuroPanel
Follow development

Features

Every module, by workspace.

This is the full specified feature set. Status is shown honestly — almost everything is planned, because the software is being built now.

Everything below is specified in detail across the project documentation. Nothing here is claimed as shipped — QuroPanel is pre-1.0.

QuroAdmin

Server and fleet administration

Server overview

Planned
  • Load, CPU, memory, swap, disk and inode use
  • Service status, failed services and restart history
  • Network throughput and active connections
  • RAID and SMART health where the hardware reports it
  • Pending updates and reboot-required state

Account functions

Planned
  • Create, modify, suspend, unsuspend and terminate accounts
  • Change package, owner, primary domain or username
  • Login as customer, with the original actor kept in the audit log
  • Bulk operations and account notes
  • Disk, bandwidth and resource limits per account

Services and runtimes

Planned
  • Nginx, Apache compatibility mode and reverse proxy
  • PHP-FPM pools and a PHP version per domain
  • Node.js, Python, Ruby, Go and Java runtimes
  • MariaDB, MySQL, PostgreSQL and Redis
  • Config validation before every reload, never after

Fleet and clusters

Planned
  • Node roles: web, app, mail, DNS, database, cache, backup
  • Drain, cordon and maintenance mode
  • Capacity planning and workload placement
  • Rolling and canary updates with rollback

QuroReseller

Reseller and master reseller management

Customer management

Planned
  • Create, suspend, unsuspend and transfer customers
  • Change package, reset password, schedule termination
  • Customer 360: services, domains, invoices, tickets, usage
  • Login as customer with a fully audited session

Packages and feature sets

Planned
  • Resource limits: disk, inodes, bandwidth, CPU, RAM, I/O
  • Feature sets kept separate from resource packages
  • Add-ons, upgrade and downgrade paths
  • Overselling policy set by the provider, not the reseller

White-label

Planned
  • Logo, favicon, colours and login screen
  • Customer portal domain and support links
  • Branded email templates and invoices
  • Branded native apps, built from one codebase

Hierarchy

Planned
  • Provider → master reseller → reseller → customer
  • Child resellers within the parent's allocation
  • Ownership tree, usage reports and audit history

QuroControl

Customer hosting control panel

Websites and domains

Planned
  • Addon domains, subdomains, aliases and redirects
  • Document roots, wildcard domains and preview URLs
  • DNS zone editor with record history and rollback
  • SSL status, forced HTTPS and HSTS

Files

Planned
  • File manager with preview, code editor and search-in-files
  • Upload, compress, extract and restore from trash
  • SFTP and SSH keys, scoped per directory
  • Malware status shown against the file that carries it

Databases

Planned
  • MySQL, MariaDB and PostgreSQL
  • Database wizard, users and per-host access
  • phpMyAdmin, Adminer and pgAdmin
  • Connection strings, import, export and repair

Email

Planned
  • Mailboxes, forwarders, aliases and autoresponders
  • Filters, spam settings and quarantine
  • SPF, DKIM and DMARC status with a deliverability score
  • Delivery tracking that names the actual failure reason

QuroCommerce

Billing, orders, domains and provisioning

Catalog and orders

Planned
  • Products, plan variants and configurable options
  • Domain search, transfer or use-an-existing-domain at checkout
  • Coupons, tax, multi-currency and terms snapshots
  • Idempotent checkout with duplicate-payment prevention

Billing

Planned
  • Invoices, credit notes, refunds and partial payments
  • Wallet balance, proration and upgrade credits
  • Dunning ladder, grace periods and late fees
  • A transaction ledger, not a single invoice table

Domains

Planned
  • Register, transfer, renew and auto-renew
  • Multiple registrar accounts with TLD-based routing
  • Auth codes, WHOIS privacy, DNSSEC and glue records
  • Registrar inventory reconciliation

Provisioning

Planned
  • One queueing path from paid order to working service
  • Drivers for QuroPanel, cPanel/WHM, DirectAdmin, Plesk and more
  • Desired-state reconciliation that reports configuration drift
  • Every action queued, idempotent, retriable and audited

QuroDeploy

Git deployment, applications and WordPress

Deployment

Planned
  • GitHub, GitLab and Bitbucket, or a plain SSH repository
  • Branch environments and preview deployments per commit
  • Zero-downtime release with the previous one kept for rollback
  • Deployment approvals before anything reaches production

Build

Planned
  • Framework and package-manager detection
  • Locked-dependency installs in an isolated workspace
  • Secret and dependency scanning before the release goes live
  • Build logs, cache control and failed-build diagnosis

Runtime

Planned
  • Node, Python, PHP, Go, Java and static sites
  • Workers, queues, scheduled jobs and WebSockets
  • Health checks that gate the upstream switch
  • Rootless containers where isolation matters

WordPress

Planned
  • Install, import, clone and stage
  • Transactional updates: snapshot, update, smoke test, roll back
  • Core checksum verification and vulnerability notices
  • Object cache, page cache and scheduled backups

QuroShield

Security, monitoring and incident response

Host and edge

Planned
  • nftables policy generated from structured rules, not raw input
  • CrowdSec behaviour detection with firewall remediation
  • Coraza WAF running the OWASP Core Rule Set
  • Cloudflare WAF, rate limits and origin protection

Detection

Planned
  • ClamAV and YARA for malware and web shells
  • File-integrity monitoring that separates expected deploys from unexplained changes
  • Vulnerability scanning across OS packages and dependencies
  • Secret scanning before a deployment is allowed through

Response

Planned
  • Quarantine, block, suspend or revoke straight from a finding
  • Automated playbooks with a human approval step
  • Incident timeline with the evidence attached
  • Post-incident report and corrective actions

Audit

Planned
  • Immutable audit log: actor, original actor, resource, result
  • Impersonation always recorded against the real administrator
  • Retention policy and external SIEM delivery
  • No passwords or session tokens are ever written to a log

QuroSupport

Tickets, knowledgebase and operations

Helpdesk

Planned
  • Departments, priority, assignment and followers
  • SLA timers with escalation before a breach, not after
  • Canned responses, macros, merge and split
  • Every ticket linked to its service, domain, invoice and server

Knowledgebase

Planned
  • Versioned articles with draft, review and publish
  • Contextual help surfaced inside the panel
  • Public and private articles, reseller-branded

Safe access

Planned
  • Customer-authorised, time-limited support sessions
  • View-only mode and approval-required privileged access
  • A reason is required, and the real actor is always recorded
  • Secret fields stay masked during impersonation

Operations

Planned
  • Incident queue, maintenance tasks and migration queue
  • Backup, payment and provisioning failure queues
  • Public status page updates from the same incident record

Follow the build

The roadmap shows what is specified, what is being built and what is still only planned.

View the roadmap

Contribute

Drivers, integrations, translations and documentation are all places to start.

How to contribute

Report a security issue

Responsible disclosure, with a stated response commitment.

Disclosure policy