Skip to main content

Installing Cyrus Daemon

The Cyrus Panel Daemon runs directly on your host nodes. It handles container lifecycles via Docker, monitors resource utilization, executes server commands, and manages file systems.


System Requirements​

  • Operating System: 64-bit Linux (Ubuntu 20.04+, Debian 11+, AlmaLinux 8+, Rocky Linux 8+, or Arch Linux).
  • Architecture: x86_64 (64-bit).
  • System Utilities: tar and unzip (required for archive extraction, inspection, and packaging).
  • Container Runtime: Docker CE.
  • Kernel: Modern Linux kernel with virtualization support.
  • SSL/HTTPS: All daemon-to-panel communication requires valid SSL certificates or a secure tunnel.

Step 1: Install Dependencies & Docker​

1. Install Required System Utilities (unzip & tar)​

The daemon relies on unzip and tar to extract, inspect, and package server archives safely. Install them for your Linux distribution:

Debian / Ubuntu​
sudo apt update
sudo apt install -y unzip tar curl
Fedora / RHEL / Rocky / AlmaLinux​
sudo dnf install -y unzip tar curl
Arch Linux​
sudo pacman -S unzip tar curl
Alpine Linux​
apk add unzip tar curl

2. Install Docker​

The daemon requires Docker to deploy and manage isolated game server containers.

Install Docker using the official automated script:

curl -sSL https://get.docker.com/ | CHANNEL=stable bash

Enable and start the Docker service:

sudo systemctl enable --now docker

Step 2: Download Cyrus Daemon​

  1. Create the configuration directory for Cyrus Daemon:
sudo mkdir -p /etc/cyruspanel
  1. Download the latest compiled 64-bit binary to your /usr/local/bin directory:
sudo curl -L -o /usr/local/bin/cyrus-daemon "https://github.com/HasenDev/cyrus-daemon/releases/latest/download/cyrus-daemon"
  1. Make the binary executable:
sudo chmod +x /usr/local/bin/cyrus-daemon

Step 3: Create the Node on Cyrus Panel​

Before configuring the daemon on your server, register it in your panel:

  1. Log into your Cyrus Panel as an Administrator.
  2. If you have not created a Location yet:
    • Go to Locations in the admin sidebar.
    • Click Add Location, provide a name (e.g. US-East / Virginia), select its flag, and save it.
  3. In the admin sidebar, navigate to Nodes.
  4. Click Create New Node and fill in the required fields:
    • Name: A descriptive name for the node (e.g. Node-01).
    • Location: Select the location you created.
    • FQDN / Domain: The fully qualified domain name pointing to this node (e.g. node1.example.com).
    • Daemon Port: The port the daemon listens on (default is 8080).
  5. Click Create Node.

Step 4: Auto-Deploy Node Configuration​

  1. On the node overview page in the panel, click the Auto-Deploy Token button.
  2. Copy the generated deployment command, which will look similar to this:
sudo cyrus-daemon configure --panel-url https://cyrus.example.com --token 616a9761563e7aa68bed7a1479799c0ee2471f3c17360113
  1. Run this command on your node server. This automatically generates /etc/cyruspanel/config.json with the required node tokens and credentials.

Step 5: Configure SSL & Networking​

Cyrus Panel enforces HTTPS communication between the panel and daemon. Choose one of the following methods to establish a secure connection:

Cloudflare Tunnels allow you to expose your Cyrus Daemon securely to the internet without opening inbound ports on your firewall or exposing your node's public IP address. SSL is automatically terminated and managed by Cloudflare.

Why Use Cloudflare Tunnels for Nodes?​

  • No Port Forwarding: No need to expose daemon port 8080 to the public internet.
  • Full DDoS Mitigation: All traffic is proxied through Cloudflare's global edge network before reaching your host.
  • Automatic SSL: Cloudflare manages and auto-renews SSL/TLS certificates for your node subdomain.
  • Hidden Origin IP: Completely hides your node's public IPv4 address.

1. Install cloudflared on the Node Server​

Connect to your node server via SSH and install the official Cloudflare tunnel client (cloudflared):

Debian / Ubuntu​
# Add Cloudflare's package signing key
sudo mkdir -p --mode=0755 /etc/apt/keyrings
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /etc/apt/keyrings/cloudflare-main.gpg >/dev/null

# Add repository to apt sources
echo "deb [signed-by=/etc/apt/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list

# Update repositories and install cloudflared
sudo apt update
sudo apt install -y cloudflared
RHEL / Fedora / AlmaLinux / Rocky Linux​
sudo dnf install -y 'https://pkg.cloudflare.com/cloudflared-ascii.repo'
sudo dnf install -y cloudflared
Arch Linux​
sudo pacman -S cloudflared

2. Create a Tunnel in Cloudflare Zero Trust​

  1. Navigate to the Cloudflare Zero Trust Dashboard.
  2. In the left navigation sidebar, go to Networks → Tunnels.
  3. Click Add a tunnel (or Create a Tunnel).
  4. Select Cloudflared as the connector type and click Next.
  5. Enter a tunnel name (e.g. cyrus-node1-tunnel) and click Save tunnel.
  6. Under Install and run a connector, select your server OS (e.g. Debian/Ubuntu 64-bit).
  7. Copy the generated installation command (starts with sudo cloudflared service install ...) and execute it in your node terminal to register and start the daemon connector.
  8. Once the connector status on the webpage changes to Connected with a green status indicator, click Next.

3. Configure Tunnel Routing​

During New Tunnel Creation ("Route tunnel")​
  1. Under the Public Hostname section:
    • Subdomain: Enter your node subdomain (e.g. node1).
    • Domain: Select your registered domain from the dropdown (e.g. example.com).
    • Path: Leave empty.
  2. Under the Service section:
    • Type: Select HTTP.
    • URL: Enter localhost:8080 (or 127.0.0.1:8080).
  3. Click Save tunnel (or Save hostname).
Or Adding to an Existing Tunnel​

If you already have a tunnel created:

  1. Go to Networks → Tunnels and select your tunnel.
  2. Switch to the Published application routes tab.
  3. Click Add a published application route.
  4. Configure the route:
    • Subdomain: node1
    • Domain: example.com
    • Service Type: HTTP
    • URL: localhost:8080
  5. Click Save.

4. Disable Direct SSL in Daemon Configuration​

Because Cloudflare terminates SSL at the edge and communicates with the daemon over local HTTP, direct SSL inside the daemon configuration must be disabled:

  1. Open /etc/cyruspanel/config.json:
sudo nano /etc/cyruspanel/config.json
  1. Set ssl.enabled to false and set api.host to localhost:
{
"api": {
"host": "localhost",
"port": 8080,
"ssl": {
"enabled": false
},
"upload_limit": 100
}
}
  1. Save the file and exit (CTRL+O, Enter, CTRL+X).

5. Update Node Settings in Cyrus Panel​

  1. Go to your Cyrus Panel admin dashboard.
  2. Navigate to Nodes → select your node → Settings.
  3. Set FQDN / Hostname to your Cloudflare Tunnel hostname (e.g. node1.example.com).
  4. Set Daemon Port to 443 (Cloudflare's HTTPS port).
  5. Click Save Changes.

Option B: Direct SSL with Let's Encrypt (Certbot)​

If you are not using Cloudflare Tunnels, point a DNS A Record (DNS-only / unproxied) directly to your node's public IP.

  1. Install Certbot on your node:
sudo apt install -y certbot # Debian/Ubuntu
# or
sudo dnf install -y certbot # RHEL/Rocky Linux
  1. Generate a standalone certificate (make sure port 80 is temporarily open):
sudo certbot certonly --standalone -d node1.example.com
  1. Edit /etc/cyruspanel/config.json:
sudo nano /etc/cyruspanel/config.json

Configure the api.ssl block with your certificate paths:

{
"api": {
"ssl": {
"enabled": true,
"cert": "/etc/letsencrypt/live/node1.example.com/fullchain.pem",
"key": "/etc/letsencrypt/live/node1.example.com/privkey.pem"
}
}
}
Valid Certificate Paths

Ensure the paths pointing to fullchain.pem and privkey.pem are valid and accessible. If the files are missing or unreadable, the daemon will automatically fallback to non-SSL mode.


Step 6: Create a Systemd Service​

Create a systemd service file to keep Cyrus Daemon running in the background and start automatically on system boot.

  1. Create the service unit file:
sudo nano /etc/systemd/system/cyrus-daemon.service
  1. Paste the following configuration:
[Unit]
Description=Cyrus Panel Daemon
After=docker.service
Requires=docker.service
PartOf=docker.service

[Service]
User=root
WorkingDirectory=/etc/cyruspanel
LimitNOFILE=4096
PIDFile=/var/run/cyrus-daemon/daemon.pid
ExecStart=/usr/local/bin/cyrus-daemon start
Restart=on-failure
StartLimitInterval=180
StartLimitBurst=30
RestartSec=5s

[Install]
WantedBy=multi-user.target
  1. Reload systemd, enable the service, and start the daemon:
sudo systemctl daemon-reload
sudo systemctl enable --now cyrus-daemon

Step 7: Verify Status​

Check the status of your daemon service to confirm it is active and running:

sudo systemctl status cyrus-daemon

You can view real-time daemon logs at any time using:

sudo journalctl -u cyrus-daemon -f

Your node should now display a green connected status inside Cyrus Panel!