JoinGG

Pterodactyl, TCAdmin and Doing Without a Panel

A panel is a delegation tool, not an operations strategy. Which to use depends entirely on who else needs to touch the server.

SweetMask · 7 min read

A control panel turns a server into a web page with a start button. That is worth something, and it is also another internet-facing application with administrative control over your machine, which is worth thinking about before you install one.

Three options in practice: Pterodactyl, TCAdmin, or no panel at all. The right answer depends less on features than on who is going to touch the server.

What a panel is for

Not convenience for you. Convenience for you is systemctl restart, which takes four seconds and needs no maintenance.

Panels earn their place when somebody other than you needs access. A co-owner who should be able to restart the server but not read your SSH key. A moderator who needs the console but not the filesystem. A friend running one game on your box who should not be able to touch the other.

That is the real feature: permissions with a boundary, without handing out shell access. Everything else, the file editor, the start button, the graphs, is a nicer version of something you could already do.

If you are the only person who will ever touch the machine, a panel is a component that can break and be exploited, in exchange for saving you a command you already know.

Pterodactyl

Open source, free, and the default answer for most people now.

What it does well. Everything runs in Docker containers, so one game server cannot see another's files. Permissions are granular and usable. The interface is clean. Multi-node, so one panel can manage servers on several machines. Egg-based configuration means adding a new game is usually a config import rather than a project.

What it costs. It is real infrastructure: a panel, a database, a daemon on every node, and Docker underneath. That is four things to keep patched instead of one. The install is well documented and it is still an afternoon.

Where it hurts. The containerisation that makes it safe also makes it fiddly when a game wants something unusual, and debugging inside a container is a step removed from debugging a process. If you are comfortable on a terminal you will occasionally find it in your way.

Who it suits. Anybody hosting for other people, anybody running several games, and anybody who wants isolation between servers without doing it by hand.

TCAdmin

Commercial, licensed per machine, and the one you meet if you have ever rented from a game host.

What it does well. Enormous game support out of the box, billing integration, and a feature set built for reselling. If your intent is to host servers for paying customers, this is what the industry uses and the reason is that it handles the commercial half.

What it costs. Money, monthly, per machine. For a community server that is a hard sell against a free alternative that does the same job.

Who it suits. Hosting businesses. For a single community it is usually the wrong shape and the wrong price.

No panel

Worth taking seriously rather than treating as the fallback.

What you use instead. systemd for running and restarting, RCON for the console, SSH for files, journalctl for logs, and a cron entry or timer for scheduled restarts.

What you gain. One less internet-facing application. Nothing to patch, nothing to be exploited, no database, no daemon. Everything is a text file you can put in version control.

What you lose. Any ability to delegate. Giving a moderator console access means giving them a shell account, which is a different and larger grant.

Who it suits. A single owner running one or two servers who is comfortable on a terminal. That is more people than the panel-first advice suggests, and Linux basics for game server owners is about a dozen commands rather than a career.

The security half

Whichever you pick, a panel is the most exposed thing on the machine and it is routinely the least maintained.

Keep it updated. Panel vulnerabilities are published and scanned for within days of disclosure. An out-of-date panel is a more likely route in than anything else on a game server.

Put it behind HTTPS with a real certificate. Not optional; the panel takes credentials.

Restrict access if you can. To your own address, or behind a VPN. A panel only three people use does not need to answer the entire internet.

Give sub-users the minimum. The whole point of a panel is bounded access, and defaulting everyone to full permissions throws that away. When somebody leaves the team, revoke it the same day, security basics covers why lingering access is behind most admin-griefing stories.

Do not run the panel and the game on the same address if you can avoid it. An attack on either takes both, and DDoS protection covers why separating them matters.

Choosing

One server, you alone, comfortable on a terminal: no panel. Add systemd, monitoring and backups instead.

One server, you alone, not comfortable on a terminal: Pterodactyl, or a managed host that gives you a panel and takes the operating system away entirely. Choosing a host covers that trade.

Several servers, or several people: Pterodactyl. The isolation and the permission model are the actual reasons, and they are worth the afternoon.

Reselling to customers: TCAdmin, and the licence is a cost of doing business.

The decision that gets made badly is installing a panel because it seems like what you are supposed to do, on a single-server setup that one person administers. That adds a database, a daemon and a web application to protect a workflow that was already two commands long.

What a panel does not solve

Worth stating plainly, because installing one frequently gets treated as having dealt with server administration.

It does not back anything up. Most panels have a backup button that writes to the same disk. That is a copy, not a backup, and it protects against a mistake rather than against the machine. Game server backups covers off-machine and, more importantly, testing a restore.

It does not monitor. A panel shows you the server is down when you open it. Something has to tell you before a player does, monitoring uptime covers the difference, and it is most of the gap between a ten-minute outage and an overnight one.

It does not update the game. The panel updates itself; your server, plugins and configs are still yours to keep current. Updating without breaking things is unchanged by having a panel, except that the panel makes it easier to update carelessly.

It does not secure the machine. SSH keys, a firewall, non-root execution and a changed RCON password are all still required, and the panel is one more thing on that list rather than a replacement for it. Security basics covers the order.

A panel is a delegation tool. Treating it as an operations strategy is how servers end up with a pleasant interface, no backups and an unpatched daemon.

Migrating between them

Both directions happen, and the data moves more easily than people expect.

Worlds, configs and plugin folders are ordinary files. What does not transfer is the panel's own configuration: users, permissions, scheduled tasks and startup parameters all have to be recreated.

The safe sequence is the same as any move — stand the new one up, copy the data with the server stopped, verify with real content rather than by checking it starts, and keep the old one for a week. Moving a server between hosts covers it properly, including the DNS work that has to begin before the move rather than during it.

The question that decides it

Not features. Not price. Who else needs to touch this server, and what should they be able to break?

If the answer is nobody, a panel is a web application you have installed to save yourself two commands, and it is a component that can fail and be exploited.

If the answer is a co-owner, three moderators and somebody who runs the Discord bot, then bounded access is a real requirement and a panel is the only reasonable way to provide it. Handing out shell accounts to five people is not an alternative; it is the same grant with none of the limits.

Everything else on this page follows from that answer. Pterodactyl exists because that answer is common. TCAdmin exists because the commercial version of it is common. And no panel is the right answer far more often than the advice suggests, because a large share of community servers are administered by exactly one person who is already comfortable in a terminal.

Decide that first, then pick the tool.

Whichever way that question comes out, the operational work underneath is the same: something has to restart the server, something has to back it up somewhere else, and something has to tell you when it is down. A panel helps with the first and does nothing about the other two.

One last thing

Whatever you conclude from the above, test it against your own numbers rather than against advice. Every server is a specific game, on specific hardware, with a community in a specific timezone, and general guidance is wrong at the edges for all three reasons.

The measurements that settle most arguments are free and take minutes: the tick budget, the per-core load, the peak-hour shape, and the route from the player furthest away. Owners who take those four regularly make better decisions than owners who read more, and the gap is not close.

Tags
server adminhostingdedicated serverssecuritymaintenance
Share

SweetMask

Published · 7 min read

All articles

Keep reading

Guides

Skyblock Servers, and Why the Format Refuses to Die

A map with a tree and forty blocks of dirt became one of the most played formats in multiplayer Minecraft. What the servers added, and which of the two Skyblocks you are joining.

· 7 min read