Roadmap

Planned Releases, Current Priorities & Long-Term Direction Outlined

PanelConfig development is organized around foundation, PCAdmin, PCUser, PCCLI, API, integrations, installer, documentation, security, polish, and release packaging

Available

34 current platform items already represented in the product direction.

In Progress

11 active content, trust, documentation, API, PCCLI, and polish priorities.

Planned

28 practical operator improvements planned for future releases.

Future / Review

19 items being evaluated carefully before commitment.

Product Direction

Roadmap By Area

Roadmap items show product direction, active priorities, and upcoming platform work.

Core Platform

6 items
Available

PCAdmin Operator Dashboard

Provider-side dashboard for reviewing accounts, services, usage indicators, security signals, release state, and operational records from the administrator surface.

Available

PCUser Customer Dashboard

Customer-facing dashboard for domains, websites, DNS, email, databases, SSL, files, FTP, backups, cron jobs, logs, and support-oriented hosting tasks.

Available

Shared Audited Records

Operational records are kept around jobs, service events, security events, login history, API requests, file operations, and account activity so teams can review what happened later.

Future

Multi-Server Inventory

Track multiple servers, nodes, roles, health status, service state, and account placement from a provider-level inventory view.

Future

Node Management Model

Introduce node registration, node health, job assignment, and safer multi-node operation once single-server workflows are mature.

Future

Container and VM Runtime Direction

Review deeper runtime isolation models for providers that want container, VM, or bare-metal account strategies.

Databases

2 items
In Progress

Postgresql Management

Database and user management for PostgreSQL alongside MySQL, with pgAdmin linking

Available

Database and Database User Records

Database resources, database users, and grants are present for customer hosting and provider review workflows.

Websites

4 items
Planned

One-Click Application Installs

Guided installers for popular PHP applications with version tracking per website

Available

Website and Document Root Records

Website records, document roots, runtime settings, redirects, subdomains, logs, and application-related records are present in the platform direction.

Available

Subdomain Management

Subdomain records are available as part of the website and domain workflow for customer hosting operations.

Available

Redirect Management

Redirect records are available for common website routing and domain transition workflows.

Backups

4 items
Planned

Remote Backup Destinations

S3-compatible, SFTP, and FTP remote targets with per-account retention policies

Available

Backup Records

Backup and restore records are available for tracking backup jobs, restore decisions, schedules, and operational backup history.

Planned

Backup Verification Workflow

Add verification records that prove a backup archive exists, can be read, and matches expected account resources.

Planned

Restore Preview Mode

Add restore previews that show affected files, databases, email, DNS, and account settings before a restore is started.

PCAdmin

5 items
Available

Admin User Management

Provider operators can review and manage users from PCAdmin while preserving role-aware access boundaries.

Available

Hosting Account Records

Hosting account records are available for provider workflows including ownership, status, domains, limits, and related hosting resources.

Available

Package Management Records

Package and plan-style records support hosting account limits, product organization, and provider-facing account assignment.

Planned

Dedicated Reseller Operations Page

Add a focused reseller management area for reseller accounts, customer ownership, package visibility, and provider oversight.

Planned

Dedicated Metrics Page

Build a provider metrics page over existing usage and health records so operators can review pressure trends without searching multiple modules.

Platform

1 items
Under Review

Container Runtime Profiles

Optional isolated runtime profiles per website for teams that want container-level separation

Domains and DNS

2 items
Available

Domain Management

Domain records and DNS zone resources are available across the panel and API foundations for provider and customer workflows.

Available

DNS Zone and Record Management

DNS zones and records are represented as first-class resources so A, MX, TXT, SPF, DKIM, DMARC, and related records can be reviewed and documented.

SSL

2 items
Available

SSL Certificate Records

SSL certificates and SSL order records are available for tracking certificate status, provider information, and operational SSL workflows.

Planned

ACME Failure Assistant

Add guided SSL troubleshooting for DNS mismatch, HTTP challenge failure, rate limits, and expired authorization states.

Email

3 items
Available

Email Account Records

Email account records are available alongside aliases, forwarders, filters, routing, and authentication records for hosting-provider mail workflows.

Available

Email Authentication Records

SPF, DKIM, and DMARC concepts are represented so providers can document and review mail authentication requirements.

Planned

Mail Delivery Diagnostics

Add better diagnostics for SPF, DKIM, DMARC, MX records, mailbox quota, routing, and service state.

Files and FTP

2 items
Available

FTP Account Records

FTP account records are available to support scoped file access and customer file-management workflows.

Available

File Operation Records

File operations can be represented as reviewable operational records instead of invisible file actions.

Automation

2 items
Available

Cron Job Records

Cron job records are available as part of the customer and provider automation surface.

Available

Job Queue Records

Job records support background work and auditable operations across tasks that should not run as uncontrolled web requests.

PCCLI

5 items
Available

PCCLI Command Entrypoint

The cli/pc entrypoint provides a server-side command interface for selected read, health, job, SSL, backup, repair, and service workflows.

In Progress

More PCCLI Command References

Expand documentation and internal planning for account, DNS, SSL, backup, service, job, and troubleshooting command coverage.

Planned

Expanded Account Lifecycle Commands

Add safe PCCLI coverage for creating, inspecting, suspending, unsuspending, package-changing, and reviewing hosting accounts with audit records.

Planned

Expanded DNS Command Coverage

Add PCCLI commands for DNS zone creation, record edits, zone export, and rebuild workflows after validation and audit handling are in place.

Planned

Expanded Backup Command Coverage

Add command coverage for scheduled backups, remote backup queues, verification, restore planning, and storage review.

API

10 items
Available

API Token Management

API tokens and token request records provide the foundation for programmable access and integration workflows.

Available

Read-Oriented API Resources

The current API v1 folder contains many read-oriented JSON resources for accounts, domains, DNS, websites, email, databases, backups, security, services, health, and jobs.

In Progress

API Write-Scope Planning

Plan write endpoint behavior, token scope enforcement, idempotency, audit logging, and job handoff before exposing broader mutation endpoints.

Planned

Write Endpoint Coverage for Accounts

Expose carefully scoped account creation, suspension, unsuspension, package changes, and limit updates through the API after permission enforcement is ready.

Planned

Write Endpoint Coverage for DNS

Expose DNS record creation, update, and deletion through the API with validation, audit logs, and safer error messages.

Planned

Write Endpoint Coverage for SSL

Expose SSL request, renewal, and retry workflows through queued API operations instead of long-running web requests.

Planned

Centralized Scope Enforcement

Add a single scope-checking layer for API endpoints so stored token scopes are consistently enforced across resources.

Planned

Idempotency Support

Add idempotency keys for sensitive automation requests so billing systems and deploy scripts can safely retry without duplicating work.

Future

Webhook Delivery System

Add outbound webhooks with signing, retry handling, delivery logs, and event filters for automation systems.

Future

Openapi Expansion

Expand OpenAPI output to cover current and future resources with examples, error formats, pagination, and scope requirements.

Security

9 items
Available

Security Center Records

Security events, login history, firewall rules, IP blocks, WAF rules, malware scan records, and audit logs are represented as provider-reviewable records.

Available

Command Allowlist Foundation

Server-side command handling is structured around allowlisted command patterns instead of arbitrary command input.

Available

Rate-Limited Login and API Paths

The application includes rate-limit helpers used around login and API request flows to reduce repeated abusive attempts.

Available

CSRF-Protected Forms

Form submission flows use CSRF validation helpers to protect state-changing web actions.

In Progress

Security Page Transparency Update

Explain authentication, CSRF, prepared statements, audit logs, command allowlists, token handling, file safety, and responsible disclosure without fake certification claims.

Planned

Two-Factor Authentication

Add TOTP-based two-factor authentication with recovery codes and role-aware enforcement for owner and operator accounts.

Planned

Security Review Reports

Add downloadable provider review reports covering failed logins, API activity, high-risk changes, malware findings, and firewall activity.

Future

Advanced Policy Engine

Review configurable policies for password rules, API token age, failed login response, operator approvals, and high-risk change control.

Under Review

Responsible Disclosure Policy Workflow

Under review: a more formal vulnerability reporting workflow, triage notes, and public security update process.

Installer

3 items
Available

Installer Page and Records

The installer surface and installation records provide a foundation for self-hosted setup, install state, checks, and reinstall safety.

In Progress

Post-Install Operator Checklist

Document first-login, hostname, DNS, firewall, SSL, backup, email, and security checks after installation.

Under Review

One-Command Update Channel

Under review: a controlled update command that can verify package integrity, show release notes, and stop before risky changes.

Documentation

6 items
Available

Documentation Portal

The documentation portal uses database-backed categories and articles for product, operator, API, and PCCLI guidance.

Available

Blog and Product Writing

The blog system supports categorized product and operations writing for providers, agencies, resellers, developers, and server administrators.

In Progress

Complete Operator Documentation Library

Expand beginner-to-advanced guides for PCAdmin, PCUser, PCCLI, API, security, installation, troubleshooting, and provider workflows.

In Progress

API Documentation Accuracy Pass

Keep API docs aligned with the actual available endpoint files, token behavior, request logging, and rate limiting so developers can trust the examples.

In Progress

PCCLI Documentation Accuracy Pass

Document current PCCLI commands separately from planned command families and keep command examples aligned with cli/pc behavior.

Under Review

Video and Operator Walkthroughs

Under review: guided walkthroughs for installation, DNS, SSL, email authentication, backup restore, and PCCLI automation.

Release and Update System

3 items
Available

Changelog Records

Changelog records are stored in the database and displayed publicly so releases can be explained with operational detail.

Available

Release Audit Records

Release audit records provide a place to track packaging and readiness checks before a release is shipped.

Planned

Release Update Workflow

Improve package update flow with checks, release notes, rollback notes, and readiness validation before updates are applied.

Public Website

2 items
Available

Pricing and Install Pages

Public pricing and install pages explain PanelConfig plans, installation direction, and setup expectations.

Available

Status and Security Pages

Public status and security pages exist to explain availability boundaries, incident communication, and security practices with clear trust and communication practices.

UI/UX

1 items
In Progress

Public Website Trust Content

Improve changelog, roadmap, status, security, documentation, blog, and API pages so reviewers understand the product maturity and current boundaries.

Status

1 items
In Progress

Credible Status Content

Show service records and incident history clearly while avoiding fake uptime numbers or external monitoring claims that the code does not support.

Roadmap

1 items
In Progress

Transparent Public Roadmap

Publish a structured roadmap that separates available, in-progress, planned, future, and under-review work.

PCUser

1 items
Planned

Customer Usage Page

Add a dedicated PCUser usage page over account, disk, inode, bandwidth, website, email, and backup usage records.

Integrations

6 items
Planned

Integrations Hub

Create an integrations hub for DNS providers, backup targets, security tools, app installers, billing systems, and deployment workflows.

Planned

Cloudflare DNS Workflow

Add provider integration direction for domain verification, zone discovery, and DNS record synchronization.

Planned

Remote Backup Provider Workflow

Add S3-compatible, SFTP, FTP, or provider-specific remote backup destinations with retention controls.

Planned

Billing System Connection Guide

Document and later expose safer account provisioning patterns for WHMCS, HostBill, Blesta, and custom provider portals.

Under Review

Security Provider Integrations

Under review: event export and response workflows for external security tools without sending unnecessary customer data.

Under Review

Backup Provider Integrations

Under review: backup provider connectors with destination tests, retention records, and restore validation.

DNS

1 items
Planned

DNS Propagation Helper

Add DNS troubleshooting helpers that explain authoritative nameservers, resolver delay, stale records, and SSL dependency.

Server Health

1 items
Planned

Resource Pressure Timeline

Create historical views for CPU, RAM, disk, load, inode usage, and account pressure so providers can spot issues early.

Templates

1 items
Planned

Template Library

Create a managed library of hosting templates, website recipes, security baselines, and application profiles.

Support

1 items
Planned

Provider Onboarding Workflows

Add guided onboarding tasks for new providers: install review, hostname, DNS, SSL, packages, first account, backup policy, and security review.

Reseller Operations

1 items
Future

White-Label Reseller Branding

Support per-reseller branding, panel domains, customer-facing identity, and scoped customer ownership where the provider model requires it.

Compliance and Trust

1 items
Future

Evidence Export Packs

Add exportable audit evidence packs for providers that need customer-facing operational proof without claiming external certification.

Marketplaces

1 items
Future

Application Installer Marketplace Direction

Review a provider-managed app catalog with controlled versions, install tasks, updates, and rollback notes.

Analytics

1 items
Future

Customer Experience Analytics

Review customer-facing analytics for support tickets, failed operations, restore requests, SSL issues, and common self-service friction.

Billing System Connections

3 items
Under Review

WHMCS Provisioning Module

Under review: a safe WHMCS workflow that creates accounts through approved API paths and tracks job outcomes without direct database writes.

Under Review

HostBill Provisioning Module

Under review: HostBill-oriented provisioning, suspension, unsuspension, and package-change flows using scoped API tokens.

Under Review

Blesta Provisioning Module

Under review: Blesta-friendly account lifecycle integration with clear error handling and audit visibility.