Skip to content
PAUIOps
Open menu

Hosted PAUIOps SaaS · From $15/month

One Center account for servers, domains, and service access.

Register, choose the server capacity you need, and operate live or staging Managers from one hosted workspace—including public domain routes and provider firewall rules.

PAUIOps Center logo

Hosted coordination, local execution

You open Center. Manager acts on the selected server.

PAUIOps hosts the account, subscription, and shared server registry. Each connected Manager remains responsible for authentication, permissions, project data, and operations on its own server.

Request path

3 reachable Managers

Team member

Role + project scope

Hosted PAUIOps Center

Account · plan · active server

LIVE / Singapore

Server A

Manager

Docker · Git · files · system

LIVE / Los Angeles

Server B

Manager

Docker · Git · files · system

STAGING / Manila

Server C

Manager

Docker · Git · files · system

Docker

Git + files

Approved commands

Nothing else to host

From registration to multi-server operations.

Your subscription controls connected-server capacity. The hosted Center workspace keeps every Manager destination distinct and ready to find.

Center account

Register once and use the hosted Center workspace from your browser.

Server-capacity plan

Subscribe for 2, 5, or Unlimited connected Manager servers.

Verified server registry

Use an active Manager admin session to add, test, edit, and organize API or WebSocket destinations.

Environment hierarchy

Search LIVE, STAGING, locations, and hosts, or choose another server when the default is unavailable.

Edge route handoff

Keep the route, server, and access boundary in one operating context.

Center records the public-domain intent and the selected provider target. The assigned Manager performs the privileged Nginx work on its supported Ubuntu host.

Public domain

app.example.com

DNS stays at your provider

Pinned Manager

Global Nginx default

Admin session required

App upstream

127.0.0.1:3000

One URL or balanced pool

Copy the DNS handoff

Center shows the A or CNAME record for the assigned Manager. You publish it deliberately and wait for propagation before certificate issuance.

Open only the service port

Manage inbound provider rules from the selected Compose port, with explicit confirmation before public or all-port access.

Latest Center improvements

Server context now reaches the network edge.

Center keeps its Manager-verified registry and per-server sessions, then carries that context into domain routing, encrypted provider profiles, and published-port firewall access.

Product source review · August 7, 2026

Reviewed against the current Center source. Center registration, sign-in, subscriptions, and billing remain behind the website’s pre-launch gate.

Domain access

Grant developers scoped domain access without administrator-only provisioning.

Administration → Domain Access adds a base-domain catalog and a per-user access mode — none, all, or assigned — enforced identically by Center's domain APIs and the Manager Nginx endpoint.

  • Let "All domains" users pick a registered base domain or enter one manually; keep "Assigned only" users to their base domain with no manual-entry path.
  • Scope non-admin domain records to the authenticated Manager, matching the base domain and its true subdomains, never lookalike suffixes.
  • Surface the current domain scope from Manager's login/auth-status response so Center's navigation and page guards update automatically.

Safety boundary: Domain deletion and access-mode changes remain administrator-only. Every apply request is re-validated against the caller's assigned scope on the Manager side, not just hidden in the UI.

Domains + edge routing

Pin public domains to one Nginx Manager and hand off the exact DNS record.

Center stores domain intent, sends validated apply or delete operations to a globally selected Nginx Manager, and keeps deployment state visible beside the upstream and generated DNS handoff.

  • Choose one enabled server as the global Nginx destination, with the active server used only when no global default exists.
  • Create single-upstream or same-protocol load-balanced routes with certificate email and upload-limit controls.
  • Retry a failed deployment and keep DNS-provider changes explicitly outside Center automation.

Safety boundary: Domain operations require a live administrator session on the assigned Manager. Center records pending, deploying, active, or failed state; DNS publication, propagation, certificate reachability, and rollback remain operator responsibilities.

Hosting provider profiles

Keep firewall targets with each server without returning provider secrets to the browser.

Server Registry can associate AWS EC2, AWS Lightsail, DigitalOcean, Linode, or Proxmox credentials and firewall targets with a Manager destination.

  • Seal stored provider configuration with authenticated AES-256-GCM encryption and server-specific associated data.
  • Expose only safe configured status, credential hints, capabilities, and target metadata after write.
  • Preserve existing secrets during target-only edits and require new credentials when changing providers.

Safety boundary: Center must retain and protect its 32-byte credential-encryption key. Losing or changing the key makes stored provider configurations unreadable; provider tokens still need least privilege and independent rotation.

Service-port firewall access

Manage inbound access from the Compose service that needs it.

From a published service port, an administrator can list, add, edit, or remove inbound rules at the registered provider without leaving the active server context.

  • Use the selected Compose service’s published protocol and port as the rule boundary.
  • Allow validated IP/CIDR sources or deliberately confirm public IPv4 and IPv6 access.
  • Adapt the editor to provider capabilities for source counts, port ranges, protocols, and all-port rules.

Safety boundary: Provider APIs are called server-side through administrator routes. Public-source and all-port rules require deliberate confirmation, but operators must still review the provider result and remove access when it is no longer needed.

Server registry

Manager-verified administration without a second frontend secret.

An authenticated Manager administrator can use Center’s server controls directly. Registry mutations forward the active Manager session for server-side role verification.

  • Search and paginate LIVE or STAGING destinations without a separate unlock panel.
  • Add, test, edit, enable, disable, order, set defaults, or remove registered Managers.
  • Reject cross-origin writes and fail closed when Manager verification is missing, expired, non-admin, or unavailable.

Safety boundary: Center does not treat a browser-only flag as administrator proof; the active Manager must verify the session and admin role.

Endpoint setup

API and WebSocket destinations stay paired without blocking overrides.

When an administrator enters a Manager API URL, Center derives the matching ws:// or wss:// endpoint and keeps it synchronized until the WebSocket field is edited manually.

  • Test a Manager endpoint before depending on it in the server selector.
  • Keep explicit WebSocket overrides unchanged during later API edits.
  • Choose another Manager on the login screen when the default destination is unavailable.

Safety boundary: Every destination remains server-specific; Center still requires the correct TLS, CORS, WebSocket, and Manager authentication configuration.

Project setup

Repository-first project forms derive the safe choices.

Add Project begins with the Git URL, derives a project name and contained clone destination, and asks Manager for remote branches before submission.

  • Auto-select a discovered branch with retry and manual-entry fallback.
  • Block creation while branch discovery is still running.
  • Edit branch settings while keeping the existing clone destination read-only.

Safety boundary: Manager still validates the remote, destination containment, branch, checkout result, conflicts, and active branch before accepting the project.

Cross-server continuity

Keep server context visible while routine actions stay per Manager.

Center exposes active-server context, copyable public IP and repository URLs, Compose published ports, and the same project watcher states provided by the selected Manager.

  • Fetch all remote branches when a repository was cloned with a narrow branch refspec.
  • Propagate a deliberate password change only to other Managers where the user already has a live server-specific session.
  • Report password-update failures per server instead of hiding partial completion.

Safety boundary: Center never reuses one server’s login as proof for another. Cross-server account updates use each destination’s existing bearer session and preserve per-server failure reporting.

All features in every plan

Capacity changes. The Center product does not.

The 2-server, 5-server, and Unlimited subscriptions include the same Center operations experience. Upgrade only when you need room for more connected Managers.

  • Hosted Center access
  • Account-based workspace
  • Manager-verified registry
  • API-to-WebSocket pairing
  • Environment and location groups
  • Search and switch servers
  • Global Nginx destination
  • Domain and DNS handoff
  • Encrypted provider profiles
  • Service-port firewall rules
  • Progressive project setup
  • Separate Manager sessions
  • Server-specific watcher state

Start with the hosted operations center

Create your account, choose a server plan, and connect your Managers.