ZefiraZEFIRA Docs Changelog Donate GitHub ↗

Configuration

Environment variables and panel settings.

Environment variables

Set in /opt/zefira/.env (installer-managed, mode 600) or exported before start:

VariableDefaultPurpose
ZEFIRA_ADMIN_USERNAMEadminFirst-run admin (lowercased, validated)
ZEFIRA_ADMIN_PASSWORDrandomFirst-run password, one-time: auto-scrubbed from .env on first boot (random if empty)
ZEFIRA_DOMAIN—Public domain baked into configs & links
ZEFIRA_PORT8000Panel listen port (systemd unit)
ZEFIRA_SUB_PORT443Port in VLESS/VMess/Trojan/SS links
ZEFIRA_HY2_PORT8443Port in Hysteria2 links
ZEFIRA_WG_PORT51820WireGuard endpoint port
ZEFIRA_DNS1.1.1.1DNS in WireGuard configs
ZEFIRA_OVPN_PORT / ZEFIRA_OVPN_PROTO1194 / udpOpenVPN endpoint
DATABASE_URLSQLitemysql+pymysql://… or postgresql+psycopg2://… (MySQL: use utf8mb4 charset, or emoji notes break inserts)
SUBSCRIPTION_PATH/subSubscription URL prefix
ZEFIRA_SESSION_TTL28800Login session lifetime, seconds (clamped to 5 min – 7 days, default 8h)
ZEFIRA_TRUSTED_PROXIESemptyCIDRs allowed to send X-Forwarded-For. 0.0.0.0/0, multicast and overly-broad ranges (< /8 v4, < /32 v6) are refused/ignored. Example: 127.0.0.1
ZEFIRA_ALLOW_UPDATE10 disables the in-panel updater entirely
ZEFIRA_ALLOW_CUSTOM_REPO01 allows ZEFIRA_UPDATE_REPO/BRANCH overrides (default: pinned to mrlurix/zefira-panel@main)
TG_BOT_TOKEN / TG_CHAT_IDemptyTelegram notifications

Panel settings

Settings → Server / Hosts edits domain, ports, DNS, WireGuard public key, REALITY SNI list, obfuscation and CDN options live (no restart). L2TP/IPsec, Cisco AnyConnect and SOCKS5 each have their own port field; their credentials are generated per user (L2TP also gets a per-user IPsec PSK) and delivered as config text files plus dashboard cards — SOCKS5 additionally ships as socks5:// links and a Clash proxy. Settings → Tunnel sets the public URL and trusted proxies — the latter decides whose X-Forwarded-For is believed for rate limiting and audit logs.

Every server setting, by its stored name

The same values are readable and writable through GET/PUT /api/settings, and they are what a backup or a hand-edited row contains. Use these names, not the labels on the page.

KeyDefaultWhat it changes
domainemptyPublic host baked into every link and config
sub_port443Port written into VLESS / VMess / Trojan / Shadowsocks links
hy2_port8443Port written into Hysteria2 links
wg_port51820WireGuard endpoint port
wg_pubemptyYour WireGuard public key; without it the panel keeps the one it generated
dns1.1.1.1Resolver pushed into WireGuard configs
ovpn_port / ovpn_proto1194 / udpOpenVPN endpoint, and whether it is UDP or TCP
l2tp_port1701L2TP/IPsec port (credentials are generated per user)
cisco_port443Cisco AnyConnect port
socks5_port1080SOCKS5 port, also emitted as socks5:// links and a Clash proxy
reality_port443REALITY listener port
reality_sniwww.yahoo.com,www.samsung.com,www.microsoft.comComma-separated SNI list, rotated across the generated links
reality_pubemptyREALITY public key; the matching private key is stored encrypted and reveal is audit-logged
obfuscated_hostemptyDecoy host that replaces your domain inside the configs (leave empty to use the real domain)
per_user_subdomain0Prefixes a per-user hash so two customers' configs are not correlatable. Needs a wildcard DNS record, and it is skipped on IP literals — a prefixed IP resolves nowhere
cdn_enabled0Turns on CDN SNI spoofing
cdn_sniemptyThe CDN domain shown as TLS SNI while traffic still goes to your obfuscated host
block_direct_ip0Answers 403 to panel and API requests that arrive on a raw IP. Turn it on only once the domain works — while testing it locks you out of your own panel
Ports are not opened for you. Every port in this table needs a firewall rule, and behind nginx the client-facing ones need a stream or TCP/UDP pass in your vhost — the nginx site the installer writes proxies the panel port only.

HTTPS / SSL

Issuing from the panel needs root for certbot (sudo on PATH). The certificate is stored, not deployed: your nginx vhost keeps the paths from install time, so point ssl_certificate at the new files and reload nginx yourself. Easier: let step 7 of the installer issue and wire everything.
Behind Nginx the panel honors X-Forwarded-Proto from localhost/trusted proxies, so cookies get the Secure flag and HSTS is emitted.

Data locations

PathContent
/opt/zefira/.envSecrets (600)
/opt/zefira/instance/zefira.dbSQLite database (600)
/opt/zefira/instance/secret.keyJWT + encryption master key (600) — lose it and encrypted secrets become unreadable
/opt/zefira/instance/ca.key / ca.crtOpenVPN certificate authority