ROYALFIRE

platform · 2026

VajraClouds Mission Control

A hosting control panel where the admin surface is the product, not an afterthought.

Role
Platform owner — architecture, dashboard, and the access model
Status
active
Stack
Node.jsExpressDiscord OAuth2FirebasePterodactylPM2 clusterCloudflare

Most hosting panels bolt administration on afterwards, behind a separate admin login that nobody remembers the password to. I built this one so that the operations surface is the product.

What it does

Fifteen operational views behind a single authenticated session, grouped into Mission Control, Hosting & Cloud, Bot Fleet, Support & Vault, and Security & Config. Node monitoring, client servers, a client user database, ticket analytics, a transcript vault, audit logs, root node control, and staff role management all live behind the same permission model.

Identity is Discord OAuth2 with identify guilds email. There is no local password to leak, phish, or forget, because there is no password. Session state lives in a signed cookie, and the application runs as a PM2 cluster behind Cloudflare.

The part that mattered most

Role-based access control is the actual design constraint. Every route declares the permission it needs and the middleware enforces it server-side, so hiding a tab in the UI is never what keeps a user out. Permissions are per-staff-member and editable without a redeploy.

There are also invariants that the system refuses to violate. Server deletion is fail-closed: it requires the server to be explicitly suspended, the expiry timer to be genuinely past, and a four-hour advance warning to have actually been dispatched. Turning auto-termination off skips every server unconditionally, with no partial application. These read as paranoia until the day one of them saves a customer from a bad afternoon.

Interface

Dark interface built on a glass utility layer, with announcement embeds rendered inside Discord so support messages look native rather than bolted on.