Installing Cyrus Daemon
The Cyrus Panel Daemon runs directly on your host nodes. It handles container lifecycles via Docker, monitors resource utilization, executes server commands, and manages file systems.
System Requirements
- Operating System: 64-bit Linux (Ubuntu 20.04+, Debian 11+, AlmaLinux 8+, Rocky Linux 8+, or Arch Linux).
- Architecture:
x86_64(64-bit). - System Utilities:
tarandunzip(required for archive extraction, inspection, and packaging). - Container Runtime: Docker CE.
- Kernel: Modern Linux kernel with virtualization support.
- SSL/HTTPS: All daemon-to-panel communication requires valid SSL certificates or a secure tunnel.
Step 1: Install Dependencies & Docker
1. Install Required System Utilities (unzip & tar)
The daemon relies on unzip and tar to extract, inspect, and package server archives safely. Install them for your Linux distribution:
Debian / Ubuntu
sudo apt update
sudo apt install -y unzip tar curl
Fedora / RHEL / Rocky / AlmaLinux
sudo dnf install -y unzip tar curl
Arch Linux
sudo pacman -S unzip tar curl
Alpine Linux
apk add unzip tar curl
2. Install Docker
The daemon requires Docker to deploy and manage isolated game server containers.
Install Docker using the official automated script:
curl -sSL https://get.docker.com/ | CHANNEL=stable bash
Enable and start the Docker service:
sudo systemctl enable --now docker
Step 2: Download Cyrus Daemon
- Create the configuration directory for Cyrus Daemon:
sudo mkdir -p /etc/cyruspanel
- Download the latest compiled 64-bit binary to your
/usr/local/bindirectory:
sudo curl -L -o /usr/local/bin/cyrus-daemon "https://github.com/HasenDev/cyrus-daemon/releases/latest/download/cyrus-daemon"
- Make the binary executable:
sudo chmod +x /usr/local/bin/cyrus-daemon
Step 3: Create the Node on Cyrus Panel
Before configuring the daemon on your server, register it in your panel:
- Log into your Cyrus Panel as an Administrator.
- If you have not created a Location yet:
- Go to Locations in the admin sidebar.
- Click Add Location, provide a name (e.g.
US-East/Virginia), select its flag, and save it.
- In the admin sidebar, navigate to Nodes.
- Click Create New Node and fill in the required fields:
- Name: A descriptive name for the node (e.g.
Node-01). - Location: Select the location you created.
- FQDN / Domain: The fully qualified domain name pointing to this node (e.g.
node1.example.com). - Daemon Port: The port the daemon listens on (default is
8080).
- Name: A descriptive name for the node (e.g.
- Click Create Node.
Step 4: Auto-Deploy Node Configuration
- On the node overview page in the panel, click the Auto-Deploy Token button.
- Copy the generated deployment command, which will look similar to this:
sudo cyrus-daemon configure --panel-url https://cyrus.example.com --token 616a9761563e7aa68bed7a1479799c0ee2471f3c17360113
- Run this command on your node server. This automatically generates
/etc/cyruspanel/config.jsonwith the required node tokens and credentials.
Step 5: Configure SSL & Networking
Cyrus Panel enforces HTTPS communication between the panel and daemon. Choose one of the following methods to establish a secure connection:
Option A: Cloudflare Tunnels (Recommended)
Cloudflare Tunnels allow you to expose your Cyrus Daemon securely to the internet without opening inbound ports on your firewall or exposing your node's public IP address. SSL is automatically terminated and managed by Cloudflare.
Why Use Cloudflare Tunnels for Nodes?
- No Port Forwarding: No need to expose daemon port
8080to the public internet. - Full DDoS Mitigation: All traffic is proxied through Cloudflare's global edge network before reaching your host.
- Automatic SSL: Cloudflare manages and auto-renews SSL/TLS certificates for your node subdomain.
- Hidden Origin IP: Completely hides your node's public IPv4 address.
1. Install cloudflared on the Node Server
Connect to your node server via SSH and install the official Cloudflare tunnel client (cloudflared):
Debian / Ubuntu
# Add Cloudflare's package signing key
sudo mkdir -p --mode=0755 /etc/apt/keyrings
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /etc/apt/keyrings/cloudflare-main.gpg >/dev/null
# Add repository to apt sources
echo "deb [signed-by=/etc/apt/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list
# Update repositories and install cloudflared
sudo apt update
sudo apt install -y cloudflared
RHEL / Fedora / AlmaLinux / Rocky Linux
sudo dnf install -y 'https://pkg.cloudflare.com/cloudflared-ascii.repo'
sudo dnf install -y cloudflared
Arch Linux
sudo pacman -S cloudflared
2. Create a Tunnel in Cloudflare Zero Trust
- Navigate to the Cloudflare Zero Trust Dashboard.
- In the left navigation sidebar, go to Networks → Tunnels.
- Click Add a tunnel (or Create a Tunnel).
- Select Cloudflared as the connector type and click Next.
- Enter a tunnel name (e.g.
cyrus-node1-tunnel) and click Save tunnel. - Under Install and run a connector, select your server OS (e.g. Debian/Ubuntu 64-bit).
- Copy the generated installation command (starts with
sudo cloudflared service install ...) and execute it in your node terminal to register and start the daemon connector. - Once the connector status on the webpage changes to Connected with a green status indicator, click Next.
3. Configure Tunnel Routing
During New Tunnel Creation ("Route tunnel")
- Under the Public Hostname section:
- Subdomain: Enter your node subdomain (e.g.
node1). - Domain: Select your registered domain from the dropdown (e.g.
example.com). - Path: Leave empty.
- Subdomain: Enter your node subdomain (e.g.
- Under the Service section:
- Type: Select
HTTP. - URL: Enter
localhost:8080(or127.0.0.1:8080).
- Type: Select
- Click Save tunnel (or Save hostname).
Or Adding to an Existing Tunnel
If you already have a tunnel created:
- Go to Networks → Tunnels and select your tunnel.
- Switch to the Published application routes tab.
- Click Add a published application route.
- Configure the route:
- Subdomain:
node1 - Domain:
example.com - Service Type:
HTTP - URL:
localhost:8080
- Subdomain:
- Click Save.
4. Disable Direct SSL in Daemon Configuration
Because Cloudflare terminates SSL at the edge and communicates with the daemon over local HTTP, direct SSL inside the daemon configuration must be disabled:
- Open
/etc/cyruspanel/config.json:
sudo nano /etc/cyruspanel/config.json
- Set
ssl.enabledtofalseand setapi.hosttolocalhost:
{
"api": {
"host": "localhost",
"port": 8080,
"ssl": {
"enabled": false
},
"upload_limit": 100
}
}
- Save the file and exit (
CTRL+O,Enter,CTRL+X).
5. Update Node Settings in Cyrus Panel
- Go to your Cyrus Panel admin dashboard.
- Navigate to Nodes → select your node → Settings.
- Set FQDN / Hostname to your Cloudflare Tunnel hostname (e.g.
node1.example.com). - Set Daemon Port to
443(Cloudflare's HTTPS port). - Click Save Changes.
Option B: Direct SSL with Let's Encrypt (Certbot)
If you are not using Cloudflare Tunnels, point a DNS A Record (DNS-only / unproxied) directly to your node's public IP.
- Install Certbot on your node:
sudo apt install -y certbot # Debian/Ubuntu
# or
sudo dnf install -y certbot # RHEL/Rocky Linux
- Generate a standalone certificate (make sure port
80is temporarily open):
sudo certbot certonly --standalone -d node1.example.com
- Edit
/etc/cyruspanel/config.json:
sudo nano /etc/cyruspanel/config.json
Configure the api.ssl block with your certificate paths:
{
"api": {
"ssl": {
"enabled": true,
"cert": "/etc/letsencrypt/live/node1.example.com/fullchain.pem",
"key": "/etc/letsencrypt/live/node1.example.com/privkey.pem"
}
}
}
Ensure the paths pointing to fullchain.pem and privkey.pem are valid and accessible. If the files are missing or unreadable, the daemon will automatically fallback to non-SSL mode.
Step 6: Create a Systemd Service
Create a systemd service file to keep Cyrus Daemon running in the background and start automatically on system boot.
- Create the service unit file:
sudo nano /etc/systemd/system/cyrus-daemon.service
- Paste the following configuration:
[Unit]
Description=Cyrus Panel Daemon
After=docker.service
Requires=docker.service
PartOf=docker.service
[Service]
User=root
WorkingDirectory=/etc/cyruspanel
LimitNOFILE=4096
PIDFile=/var/run/cyrus-daemon/daemon.pid
ExecStart=/usr/local/bin/cyrus-daemon start
Restart=on-failure
StartLimitInterval=180
StartLimitBurst=30
RestartSec=5s
[Install]
WantedBy=multi-user.target
- Reload systemd, enable the service, and start the daemon:
sudo systemctl daemon-reload
sudo systemctl enable --now cyrus-daemon
Step 7: Verify Status
Check the status of your daemon service to confirm it is active and running:
sudo systemctl status cyrus-daemon
You can view real-time daemon logs at any time using:
sudo journalctl -u cyrus-daemon -f
Your node should now display a green connected status inside Cyrus Panel!