Dokploy Reimagined — Enterprise-Grade Self-Hosted Cloud PaaS, VPS Orchestrator & Pterodactyl-Class Game Server Control Panel
Deploy any application, manage databases, run high-performance game servers, monitor real-time traffic telemetry, and harden Linux infrastructure—all from one unified, sleek dashboard.
Quick Install • Documentation • Key Features • Game Control Panel • Traffic Analytics • Traffic Security • Host Hardening • Uninstallation • Credits & Attributions
RylixManager is an enterprise-grade reimagining of Dokploy, designed for developers, system administrators, and game hosting providers who require full architectural freedom, high-speed automated installation, native game server orchestration, and deep Linux kernel tuning.
Whether you are hosting web services, managing PostgreSQL/MySQL/Redis clusters, deploying Docker Compose stacks, or running production gaming infrastructure (Minecraft, Rust, Palworld, Counter-Strike 2, Valheim), RylixManager delivers:
- Zero-Lock-in Application Orchestration: Git push deployments, Dockerfile builds, Nixpacks, and Docker Compose with automatic HTTPS.
- Pterodactyl-Grade Game Control Panel: Complete gaming suite with interactive Web TTY terminal, 1-click Mod/Plugin Marketplace, visual MOTD editor, atomic world backup snapshots, and multi-protocol proxy routing.
- Instant Terminal Admin Creation: Configure your master administrator account (Name, Email, Password) directly in the terminal during installation—no blank-slate browser surprises.
- Vercel-Style Traffic Analytics: Real-time traffic volume, visitor geography, edge latency percentiles (p75/p95), status code distributions, User-Agent breakdowns, and live request inspector.
- Built-in Layer 7 Traffic Manager & Traefik Security Deck: OWASP strict headers, DDoS rate limiters, connection caps, and response compression for all domains with 1-click toggles.
- Linux Host OS & Kernel Tuning: Automated sysctl network socket optimization (25MB UDP/TCP buffers), Google BBR congestion control, somaxconn listen backlogs, and Docker daemon log rotation safeguards.
- 100% Unlocked Enterprise Suite: Whitelabeling, Single Sign-On (SSO), Custom RBAC permissions, audit logging, and multi-server management available out-of-the-box with no license keys required.
- Built-in Documentation Deck: Native
/dashboard/docspage embedded directly in the panel.
Run this one-line installer on any clean Linux VPS running Ubuntu 20.04/22.04/24.04, Debian 11/12, Rocky Linux 9, AlmaLinux 9, or Fedora:
curl -sSL https://raw.githubusercontent.com/RishBroProMax/rylixmanager/main/install.sh | sh- Interactive Admin Account Prompt: The terminal will ask you for:
Admin First Name(e.g., John)Admin Last Name(e.g., Doe)Admin Email(e.g., admin@example.com)Admin Password(min 8 characters, confirmed with hidden input) (These credentials immediately become your master login details).
- Fast & Non-Blocking Image Setup: Uses GitHub Container Registry (
ghcr.io) with real-time download progress so your VPS never hangs or freezes. - Automatic Swarm & Network Provisioning: Activates Docker Swarm mode and provisions the
rylix-networkoverlay mesh. - Traefik v3 Reverse Proxy: Deploys reverse proxy on ports 80 & 443 with automated Let's Encrypt SSL.
- Kernel Performance Hardening: Applies
99-rylix-performance.confwith 25MB socket buffers & Google BBR.
Once the installer completes, open your browser and access:
http://<YOUR_SERVER_IP>:3000
Log in immediately using the Email and Password you configured in the terminal!
RylixManager includes a complete, interactive documentation deck embedded directly inside the panel at:
http://<YOUR_SERVER_IP>:3000/dashboard/docs
Accessible from the sidebar navigation, providing guides for Git deployments, game server configurations, custom domain SSL certificates, database clustering, and security tuning.
RylixManager features a dedicated, first-class Game Server Control Panel accessible at /dashboard/game-panel. It replaces the need for separate Pterodactyl or AMP panels by integrating directly with your container infrastructure.
┌────────────────────────────────────────────────────────────────────────┐
│ 🎮 RYLIX GAME CONTROL PANEL │
├─────────────────┬─────────────────┬──────────────────┬─────────────────┤
│ Total Servers │ Online Status │ Active Protocols │ UDP Net Buffer │
│ 12 Active │ 10 Running │ TCP/UDP Bound │ 25 MB (Tuned) │
└─────────────────┴─────────────────┴──────────────────┴─────────────────┘
- Real-Time Hardware Telemetry: Live CPU usage percentage and allocated RAM (MB/GB) counters updated every 4 seconds.
- Interactive Command Input Bar: Execute any administrative console command (
op <player>,whitelist add <user>,say <message>) with instant feedback. - One-Click World Snapshot: Atomic
tar.gzdata backup created on demand before updating mods or restarting. - Pre-Configured Quick Commands: Instant buttons for
save-all,time set day,weather clear,whitelist on, andstatus. - Dual Console Modes: Toggle seamlessly between the real-time Docker Log Stream and full interactive TTY terminal.
- Curated Plugin Catalog: Instant 1-click installation of essential plugins:
- LuckPerms: Modern permissions and group management.
- EssentialsX: Teleports, warps, homes, kits, and economy.
- ViaVersion: Multi-version client compatibility.
- GeyserMC: Bedrock Edition (iOS/Android/Console) cross-play onto Java servers.
- WorldEdit & FAWE: Fast in-game terrain builder and brush tools.
- Vault: Universal economy and permission bridge.
- Chunky: Chunk pre-generation to eliminate exploration lag.
- spark: Diagnostic profiler for tick health, CPU, and RAM allocation.
- SkinsRestorer: Skin restoration for hybrid and offline networks.
- Custom Mod / Plugin Downloader: Input any direct HTTP/HTTPS URL and target directory to download mods directly into the container.
- Installed Plugins Manager: View all
.jar/.csfiles with 1-click deletion.
- Multiplayer Ping Preview: Realistic in-game Minecraft server list ping card rendering server avatar, formatted color text, ping bars, and player count.
- Minecraft Color Palette Picker: Interactive buttons to insert formatting codes (
§0to§f,§lBold,§oItalic,§nUnderline,§rReset). - Visual Gameplay Switches:
- Online Mode: Toggle Mojang authentication or enable offline/cracked clients.
- PvP: Enable or disable player combat.
- Whitelist: Restrict access to approved players.
- Hardcore Mode: Automatically ban players upon death.
- Allow Flight: Allow flying mods and Elytra gliding.
- Numeric Limits: Configure Max Players, View Distance (chunks), Simulation Distance, World Difficulty, and Default Gamemode with 1-click apply.
- Integrated directory browser directly inside the container volume.
- In-browser code editor with syntax highlighting for
server.properties,server.cfg,PalWorldSettings.ini, and YAML files. - File upload, recursive
mkdir -pdirectory creation, and instant download.
- Direct Connect: Copyable
IP:Portaddress for immediate client connection. - DNS SRV Generator: Automatically generates DNS SRV records (
_minecraft._tcp.play.domain.com) so players can connect via domain without typing ports. - Velocity / BungeeCord Proxy Hub: Ready-to-copy proxy forwarding configs (
forwarding-secret, modern BungeeGuard integration). - Playit.gg Tunnel Sidecar: Zero-port-forwarding tunnel generator for servers hosted behind CGNAT or home networks.
Deploy any game server with one click via Docker Compose:
- Minecraft (Java): PaperMC, Purpur, Spigot, Fabric, Forge (
itzg/minecraft-server, Port25565). - Minecraft (Bedrock): Official dedicated Bedrock server (
itzg/minecraft-bedrock-server, Port19132/udp). - Rust: SteamCMD auto-updating server with Oxide/uMod support (
didstopia/rust-server, Port28015/udp). - Palworld: Multi-threaded dedicated server (
thijsvanloef/palworld-server-docker, Port8211/udp). - Counter-Strike 2 (CS2): Source 2 engine with custom map support (
joedrumgoole/cs2-server, Port27015). - Valheim: Dedicated world with crossplay (
lloesche/valheim-server, Port2456/udp). - Terraria: TShock server (
ryansheehan/terraria, Port7777). - ARK: Survival Evolved, Satisfactory, Factorio, Project Zomboid, and Enshrouded.
Accessible at /dashboard/analytics (and upgraded /dashboard/requests), RylixManager includes an edge-level traffic observability suite powered by Traefik JSON telemetry.
┌────────────────────────────────────────────────────────────────────────┐
│ 📈 REAL-TIME TRAFFIC TELEMETRY │
├─────────────────┬─────────────────┬──────────────────┬─────────────────┤
│ Total Requests │ Unique Visitors │ Bandwidth Served │ Avg Edge Latency│
│ 1,482,910 │ 84,219 IPs │ 42.8 GB │ 14.2 ms │
└─────────────────┴─────────────────┴──────────────────┴─────────────────┘
- KPI Summary: Total Requests, Deduplicated Unique Client IPs, Total Bandwidth (formatted in MB/GB), Average Latency (ms), p75 and p95 Edge Latency, and Success/Error Rates.
- Stacked Time-Series Chart: Hourly and daily request volume visualizer with stacked 2xx (Success), 3xx (Redirect), 4xx (Client Error), and 5xx (Server Error) status codes plus latency trend line.
- Top Requested Paths: Ranked endpoints with request share progress bar and average response latency.
- Domain Breakdown: Multi-host traffic volume across all registered applications.
- Hardware & User-Agent Profiling:
- Operating Systems: macOS, Windows, Linux, iOS, Android, and Other.
- Browsers: Chrome, Safari, Firefox, Edge, Opera, and automated HTTP tools (Curl, Postman).
- Device Types: Desktop, Mobile, Tablet, and Automated Bot / Scraper traffic.
- Top Client IPs: Identifies heavy users, web crawlers, or malicious scrapers.
- Real-Time Request Stream: Live request stream with click-to-inspect dialog showing HTTP method, host, path, status, latency, client IP, and User-Agent headers.
- 1-Click Data Export: Download aggregated metrics as JSON or export recent request logs directly to CSV.
Accessible at /dashboard/traffic, RylixManager includes a built-in reverse proxy security deck that protects your web applications and APIs against Layer 7 attacks, clickjacking, MIME sniffing, and bandwidth abuse.
- Strict OWASP Security Headers (
security-headers-strict):Strict-Transport-Security:max-age=31536000; includeSubDomains; preload(Enforces 1-year HSTS).X-Frame-Options: DENY(Eliminates clickjacking attacks).X-Content-Type-Options: nosniff(Prevents MIME-type spoofing).X-XSS-Protection: 1; mode=block(Browser-level XSS filter).Referrer-Policy: strict-origin-when-cross-origin.
- DDoS & Brute-Force Rate Limiter (
rate-limit-standard&rate-limit-strict):- Public Apps: Average 100 req/s, Burst 50 requests per client IP.
- Strict Auth Routes: Average 20 req/s, Burst 10 requests per client IP.
- Connection Flood Shield (
connection-limit-50):- Caps concurrent in-flight HTTP connections to 50 per IP address to thwart slowloris and exhaustion attacks.
- Auto Gzip / Brotli Compression (
auto-compress):- Dynamically compresses text, JSON, HTML, and CSS assets, reducing bandwidth consumption by up to 70%.
- In-Memory Request Buffer (
request-buffer-100mb):- Absorbs and buffers large client payloads safely up to 100MB before proxying upstream.
RylixManager includes automated Linux kernel diagnostics and one-click performance tuning specifically designed for high-concurrency web traffic and low-latency gaming:
# Max socket receive buffer (25MB) - Prevents UDP packet loss for game servers
net.core.rmem_max = 26214400
net.core.rmem_default = 26214400
# Max socket send buffer (25MB)
net.core.wmem_max = 26214400
net.core.wmem_default = 26214400
# High-concurrency listen backlog (Thwarts SYN floods)
net.core.somaxconn = 65535
# System-wide open file descriptors limit (2 Million)
fs.file-max = 2097152
# Virtual memory mapping count for databases & game engines
vm.max_map_count = 262144
# Prioritizes physical RAM over disk swap thrashing
vm.swappiness = 10
# Google BBR TCP Congestion Control (Superior throughput on high-latency links)
net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr{
"log-driver": "json-file",
"log-opts": {
"max-size": "50m",
"max-file": "3"
},
"live-restore": true
}- Log Rotation (
max-size: 50m): Eliminates runaway Docker container log files filling 100% of root disk space. - Live Restore (
live-restore: true): Ensures running containers stay alive even during Docker daemon updates or restarts.
- Create an A Record in your DNS provider (e.g. Cloudflare, Namecheap, Route53):
Type: A Name: panel (or @ for root domain) Value: <YOUR_VPS_PUBLIC_IP> TTL: Auto or 300 seconds - Navigate to Settings → Server Domain inside RylixManager:
- Enter your domain (e.g.,
panel.yourdomain.com). - Enable HTTPS (Let's Encrypt).
- Enter your email address for SSL expiration notifications.
- Click Save. Traefik will issue and provision a Let's Encrypt TLS certificate within 30 seconds.
- Enter your domain (e.g.,
If using Cloudflare with the orange cloud (Proxy enabled):
- Set Cloudflare SSL/TLS encryption mode to Full (Strict).
- Under Network, ensure WebSockets and gRPC are enabled.
- For Game Servers: Game ports (25565, 28015, 8211) cannot pass through standard HTTP Cloudflare proxies. Create a separate unproxied (grey cloud) DNS A record (e.g.
play.yourdomain.com) or use the DNS SRV Record Generator under the Proxy tab.
Symptom: Traefik container fails to start, or installer prints port is already allocated.
Root Cause: A pre-installed web server (Apache, Nginx, or Caddy) or systemd-resolved is holding ports 80/443.
Fix:
# 1. Identify which process is binding the port
sudo lsof -i :80
sudo lsof -i :443
# 2. Stop and disable Apache or Nginx if installed
sudo systemctl stop apache2 2>/dev/null || true
sudo systemctl disable apache2 2>/dev/null || true
sudo systemctl stop nginx 2>/dev/null || true
sudo systemctl disable nginx 2>/dev/null || true
# 3. Restart Traefik
docker restart rylix-traefikSymptom: Domain does not get an HTTPS certificate, browser warns of invalid certificate.
Root Cause: DNS record has not propagated yet, firewall blocks port 80 (required for ACME challenge), or Cloudflare Flexible SSL is causing a redirect loop.
Fix:
- Verify DNS propagation:
dig +short yourdomain.com(Must match your server public IP). - Ensure port 80 is open to the internet (Let's Encrypt validates HTTP-01 on port 80):
sudo ufw allow 80/tcp sudo ufw allow 443/tcp
- Check Traefik error logs:
docker logs rylix-traefik --tail 100
- If using Cloudflare, change SSL mode from Flexible to Full (Strict).
Symptom: Error: This node is not a swarm manager. Use "docker swarm init" or "docker swarm join" to connect this node to swarm and try again.
Root Cause: Docker Swarm state became corrupted or the IP address of the host changed.
Fix:
# Force leave swarm and reinitialize cleanly
docker swarm leave --force
docker swarm init --advertise-addr $(curl -s https://ifconfig.io)
# Recreate overlay networks
docker network create --driver overlay --attachable rylix-network
docker network create --driver overlay --attachable dokploy-network
# Re-run install script to re-deploy services
bash install.shSymptom: Web panel loads infinitely or displays Database error on initial startup.
Root Cause: PostgreSQL is still running migrations or the container ran out of memory.
Fix:
# 1. Inspect PostgreSQL service status
docker service ps rylix-postgres
docker service logs rylix-postgres --tail 50
# 2. Inspect RylixManager service status
docker service ps rylix-manager
docker service logs rylix-manager --tail 50
# 3. If Postgres failed to write data, fix permissions:
chmod 777 /etc/dokploy
docker service update --force rylix-postgresSymptom: Players experience teleportation, rubber-banding, or timeout disconnections on Minecraft, Rust, or Palworld.
Root Cause: Default Linux kernel socket buffers are too small (212KB), causing incoming UDP packets to overflow and get dropped.
Fix:
- Check if Rylix kernel tuning is active:
sysctl net.core.rmem_max # Should return 26214400 (25MB) - If not applied, enforce it manually:
sudo sysctl -w net.core.rmem_max=26214400 sudo sysctl -w net.core.wmem_max=26214400 sudo sysctl -w net.ipv4.tcp_congestion_control=bbr
- Ensure the game server's UDP port is open in your cloud provider firewall (e.g. AWS Security Group, Hetzner Firewall).
Symptom: Deployments fail with write /var/lib/docker/...: no space left on device.
Root Cause: Unused Docker build cache, old images, or unrotated container logs.
Fix:
# 1. Clean all stopped containers, dangling images, and build cache
docker system prune -af --volumes
# 2. Check disk usage per directory
df -h /
du -sh /var/lib/docker/* | sort -hr | head -n 5
# 3. Ensure Docker daemon log rotation is active:
cat /etc/docker/daemon.json
# Should contain "max-size": "50m"Symptom: Game server or database container suddenly dies and restarts; logs show exited with code 137.
Root Cause: Out Of Memory (OOM). The Linux kernel killed the process to prevent system freeze.
Fix:
- Add a swap file if your VPS has 2GB–4GB of RAM:
sudo fallocate -l 4G /swapfile sudo chmod 600 /swapfile sudo mkswap /swapfile sudo swapon /swapfile echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
- For Minecraft servers, allocate explicit Java memory in the compose environment variables:
environment: - MEMORY=4G - INIT_MEMORY=2G
Symptom: Docker Swarm fails to initialize inside a Proxmox LXC container.
Root Cause: LXC containers need nesting and keyctl enabled to run Docker Swarm overlay networks.
Fix:
- On the Proxmox Host: Open LXC container Options → Features and enable:
- ✅ Nesting
- ✅ keyctl
- In the LXC configuration file (
/etc/pve/lxc/<ID>.conf), add:lxc.apparmor.profile: unconfined lxc.cgroup2.devices.allow: a lxc.cap.drop: - RylixManager installer automatically detects Proxmox LXC and applies
--endpoint-mode dnsrr.
| Enterprise Feature | Proprietary Cloud PaaS | RylixManager Self-Hosted |
|---|---|---|
| Whitelabeling & Custom Branding | 🔒 $499/mo | ✅ Included Free |
| Audit Logs & Activity Trail | 🔒 Enterprise Only | ✅ Included Free |
| Custom RBAC & Permission Policies | 🔒 Enterprise Only | ✅ Included Free |
| Single Sign-On (SSO / SAML / OIDC) | 🔒 Enterprise Only | ✅ Included Free |
| Multi-Server VPS Orchestration | 🔒 $29/server | ✅ Unlimited Free |
| Automated S3/R2 Database Backups | 🔒 Paid Addon | ✅ Included Free |
| Integrated Game Control Panel | ❌ Not Supported | ✅ Native Built-In |
| Edge Traffic Telemetry & Analytics | 🔒 $20/domain | ✅ Native Built-In |
| Port | Protocol | Purpose | Access Level |
|---|---|---|---|
3000 |
TCP | RylixManager Web Control Deck | Public / Admin |
80 |
TCP | Traefik Reverse Proxy (HTTP & ACME Challenge) | Public |
443 |
TCP / UDP | Traefik Reverse Proxy (HTTPS & HTTP/3 QUIC) | Public |
22 |
TCP | SSH Server Access | Admin Only |
| Port | Protocol | Purpose | Game / Engine |
|---|---|---|---|
25565 |
TCP | Primary Client Connection | Minecraft Java Edition |
25575 |
TCP | Remote Console (RCON) | Minecraft Java Edition |
19132 |
UDP | Primary Client Connection | Minecraft Bedrock Edition |
28015 |
UDP | Game Traffic & Queries | Rust Dedicated Server |
28016 |
TCP | Remote Console (RCON) | Rust Dedicated Server |
8211 |
UDP | Dedicated Server Port | Palworld Dedicated Server |
27015 |
TCP / UDP | Game Traffic & Query Port | Counter-Strike 2 (CS2) |
2456–2457 |
UDP | Game Traffic & Queries | Valheim Dedicated Server |
7777 |
TCP | Game Port | Terraria (TShock) |
27015–27020 |
UDP | Game Traffic | ARK: Survival Evolved |
16261 |
UDP | Game Client Port | Project Zomboid |
All persistent state (database, secrets, Traefik dynamic configs, and game volumes) is stored in /etc/dokploy. To create a complete backup archive:
sudo tar -czvf rylix-full-backup-$(date +%F).tar.gz /etc/dokploy- Transfer the backup file to your new server:
scp rylix-full-backup-*.tar.gz root@<NEW_SERVER_IP>:/root/
- On the new server, extract the archive before running the installer:
sudo tar -xzvf /root/rylix-full-backup-*.tar.gz -C / - Run the installer to reconnect services:
curl -sSL https://raw.githubusercontent.com/RishBroProMax/rylixmanager/main/install.sh | sh
All configurations, users, and game volumes will be restored seamlessly.
To safely uninstall RylixManager, Traefik, and associated services:
curl -sSL https://raw.githubusercontent.com/RishBroProMax/rylixmanager/main/uninstall.sh | shPrompts interactively to preserve or purge data. Stops Swarm services, removes overlay networks, and cleans up Docker secrets.
curl -sSL https://raw.githubusercontent.com/RishBroProMax/rylixmanager/main/uninstall.sh | sh -s -- --purge-data --forceTo update your RylixManager installation to the latest stable release:
bash install.sh updateOr execute directly through Docker Swarm:
docker service update --image ghcr.io/rishbropromax/rylixmanager:latest --force rylix-managerRylixManager is a reimagined edition of Dokploy.
We extend our deepest respect, admiration, and gratitude to:
- Mauricio (@siumauricio) — The visionary creator and lead architect of Dokploy.
- The Entire Dokploy Community & Open-Source Contributors — For building an exceptionally elegant, resilient, and developer-friendly PaaS foundation.
- Pterodactyl-Class Gaming Control Panel: Integrated dedicated game server orchestration (Minecraft, Rust, Palworld, Valheim, CS2) with live Web TTY, 1-click mod marketplace, and atomic world backups.
- Linux Kernel & Network Tuning: Automated host optimization applying 25MB high-throughput UDP/TCP buffers, Google BBR congestion control, and connection backlogs.
- Interactive Terminal Admin Setup: Instant administrator creation directly during installation for seamless first login.
- Built-in Native Documentation: Complete offline-capable docs deck embedded at
/dashboard/docs. - 100% Free & Unlocked: Enterprise RBAC, audit logging, and whitelabeling permanently unlocked under the MIT License.
RylixManager is open-source software licensed under the MIT License. All enterprise modules and features are permanently free and open for self-hosted community operators.