A focused operations console and customer self-service portal for GenieACS.
Monitor ONTs, manage network topology, configure multi-vendor devices, and give customers a safe view of their own connection from one lightweight service.
Installation · CLI · Configuration · Security
SkyGenPanel is a management layer for GenieACS deployments. It combines an operator-facing panel on port 5890 with an isolated customer portal on port 5891. SQLite works out of the box, while MySQL can be selected and migrated to later from the interface.
| Operator console | Customer portal |
|---|---|
| Fleet health, faults, optical signal, temperature, and registration trends | ONT health, optical signal, uptime, and connected-device visibility |
| ONT, OLT, ODC, and ODP topology management with a network map | Permanent Customer IDs bound to SoftwareVersion and PPPoE identity |
| Multi-vendor WAN, WiFi, credential, and virtual-parameter configuration | Safe SSID and WiFi password changes for the authenticated customer's ONT |
| Runtime SQLite-to-MySQL migration and deployment controls | No WAN or administrative credential exposure |
- Dedicated operator and customer listeners served by one application.
- First-run setup wizard for the initial administrator account.
- Fast Vite and React interface with responsive light and dark themes.
- GenieACS fault visibility and dependency-light dashboard charts.
- Network topology editor with Google Maps and OpenStreetMap-compatible providers.
- Automatic Customer ID generation that can be enabled or disabled in Settings.
- Encrypted recovery of the last WiFi password changed through the customer portal.
- Automatic Linux dependency and Node.js installation during both first install and CLI updates.
| Operator panel | Customer portal |
![]() |
![]() |
| Secure access to fleet operations and GenieACS management. | Isolated self-service access for each authenticated customer. |
The production installer targets Linux systems running systemd. It supports:
- Debian and Ubuntu
- Fedora, RHEL, Rocky Linux, and AlmaLinux
- Arch Linux
- openSUSE
Git, native build tools, and the latest Node.js 22 release are installed automatically when required. An existing Node.js 22.22 or newer installation is reused.
Run as a regular user:
curl -fsSL https://raw.githubusercontent.com/skydashnet/genieacs-panel/main/deploy/install.sh | sudo bashRun from an existing root shell:
curl -fsSL https://raw.githubusercontent.com/skydashnet/genieacs-panel/main/deploy/install.sh | bashAfter installation:
- Operator setup:
http://localhost:5890 - Customer portal:
http://localhost:5891
Both listeners bind to 127.0.0.1 by default. This is suitable for a reverse proxy or a Cloudflare Tunnel running on the same host. Use skygenpanel expose only when another trusted machine must reach the service directly, and protect the ports with a firewall.
| Command | Description |
|---|---|
skygenpanel update |
Fetch the latest source, rebuild the application, and restart the service |
skygenpanel expose |
Bind the panel and customer portal to 0.0.0.0 |
skygenpanel unexpose |
Return both listeners to 127.0.0.1 |
skygenpanel restart |
Restart the system service |
skygenpanel start |
Start the system service |
skygenpanel stop |
Stop the system service |
skygenpanel status |
Show service and endpoint status |
skygenpanel logs [N] |
Follow the latest log lines; defaults to 100 |
skygenpanel reset-password <user> [password] |
Reset an operator password; prompts securely when the password is omitted |
When cloudflared runs on the SkyGenPanel host, publish two HTTP services:
| Public hostname | Origin service |
|---|---|
panel.example.com |
http://127.0.0.1:5890 |
portal.example.com |
http://127.0.0.1:5891 |
TLS terminates at Cloudflare, so the local origin URLs intentionally use HTTP. Keep Universal SSL active for the zone and wait for its edge certificate to reach Active before forcing HTTPS redirects.
Environment configuration lives in backend/.env; see backend/.env.example.
| Variable | Purpose |
|---|---|
APP_HOST |
Operator panel bind address |
APP_PORT |
Operator panel port; defaults to 5890 |
PORTAL_HOST |
Optional customer portal bind address |
PORTAL_PORT |
Customer portal port; defaults to 5891 |
JWT_SECRET |
Stable application secret used for sessions and encrypted WiFi credential recovery |
PORTAL_JWT_SECRET |
Optional independent customer-session secret |
CORS_ORIGINS |
Explicitly allowed browser origins |
DATA_DIR |
Optional persistent application data directory |
TRUST_PROXY |
Set to 1 only when requests arrive through a trusted direct proxy |
The GenieACS URL and optional MySQL connection are managed from the Settings interface rather than environment variables. Runtime database configuration is stored in DATA_DIR/db-config.json.
Open Settings → Database as an administrator to:
- Inspect the active database configuration.
- Test a MySQL connection.
- Migrate existing application data.
- Switch the running application to the new database.
The migration includes device installation profiles, related customer accounts, and encrypted customer WiFi credentials.
git clone https://github.com/skydashnet/genieacs-panel.git
cd genieacs-panel
npm run install:all
npm run dev:backend
npm run dev:frontendUseful project checks:
npm run check:backend
npm run lint
npm run typecheck
npm run buildBuild and run the production bundle locally:
npm run build
npm start- Backend: Node.js, Express 5, Knex, SQLite, MySQL, and JWT.
- Frontend: Vite, React, React Router, TypeScript, and Tailwind CSS.
- Deployment:
systemd, hardened service boundaries, automatic dependency installation, and an update-safe CLI. - Integration: GenieACS NBI with typed task values and multi-vendor parameter discovery.
The operator and customer APIs use separate listeners. Administrative routes are not mounted on the customer portal port.
- Role-based operator access with bcrypt password hashing and separate access and refresh tokens.
- Customer sessions stored in
HttpOnly,SameSite=Strictcookies. - Customer actions resolve the target device exclusively from the authenticated account.
- Saved WiFi passwords protected at rest with authenticated AES-256-GCM encryption.
- Password values revealed only through an authenticated, rate-limited request.
- Same-origin mutation checks, strict CSP, security headers, and request-size limits.
- Dedicated rate limits for login, portal API access, WiFi mutations, and password reveals.
- Session revocation after operator password changes and logout.
- Loopback-only listeners by default.
- Hardened
systemdunit with restricted write paths andNoNewPrivileges.
Keep JWT_SECRET stable across reinstallations and container replacements. Changing it invalidates existing sessions and makes previously encrypted WiFi credentials unreadable.
docker build -t skygenpanel .
docker run \
-p 5890:5890 \
-p 5891:5891 \
-v skygenpanel-data:/var/lib/skygenpanel \
-e DATA_DIR=/var/lib/skygenpanel \
-e JWT_SECRET="$(openssl rand -hex 48)" \
skygenpanelSkyGenPanel is available under the MIT License.
For support, email support@skydash.net or open a GitHub issue.

