Resellers

A reseller is a panel user between the admin and the clients. The admin gives a reseller a pool of resources; the reseller builds hosting plans inside that pool and creates clients with them. Each reseller sees only their own clients, and can present the panel under their own brand.

Plans: two classes

Plans (Accounts → Plans) come in two classes, and each can combine any set of limits.

ClassCreated byAssigned toMeasured against
Hosting planAdmin or resellerA clientThat client's own consumption
Reseller planAdmin onlyA resellerThe total of their whole portfolio

Limits a plan can set (zero means unlimited): disk, monthly transfer, sites, subdomains, parked domains, mail domains, mailboxes, databases, FTP accounts, DNS zones, containers, cron jobs, emails per hour, and CPU %, RAM, IO and process limits.

  • A client's cap is hard. It is enforced when the resource is created, not afterwards.
  • A reseller cannot give themselves more. They configure the plans inside their pool; the reseller plan that contains them is set by the admin. A reseller plan with every limit at zero is not a way around this: what a reseller commits across their clients is counted against their pool.
  • Editing a plan replaces all its limits with what the form shows, so the form loads the current values first. On the CLI, panel plan-guardar only changes the keys you pass.
  • Resource limits (CPU, RAM, IO, processes) are applied to each client's cgroup and need a License.
panel plan-guardar basic disco_mb=5000 sitios=3 bases=5 transfer_mb=50000 tipo=hosting
panel plan-asignar acme basic
panel uso acme

Overage policy

Each plan chooses what happens when the client passes its monthly transfer: suspend, warn and keep serving, or "not defined" (falls to the reseller's policy, then the node's, then warn). The plan also sets the percentage at which to warn. For a reseller plan the policy applies to the portfolio total: if the whole portfolio crosses the cap and the policy is suspend, all its clients and the reseller are suspended (the reseller can still sign in).

  • Warnings always appear in the panel (bell icon), and optionally by email.
  • Accounts the panel suspended for transfer are reactivated automatically when the month changes. Accounts a person suspended are not.
  • A reseller can set their own overage policy for their clients only if the admin enabled "own policy" for that reseller (off by default).

Overselling

The admin controls it per reseller and it is off by default. When on, the reseller's committed total may exceed their pool up to the percentage you set. The client's own cap is always enforced either way. panel pool <reseller> sobreventa=120 permite_politica_propia=on.

Creating and managing resellers

Admins create a reseller from Accounts → Users (role reseller), assign a reseller plan under Accounts → Resellers, and can see the pool and its current commitment there. Resellers need the second factor like admins.

A reseller can, on their own clients only: create/suspend/reactivate them, assign plans, reset a client's password, regenerate their second factor, and impersonate them. They cannot touch admins or other resellers, and they cannot see clients of other resellers (the same message is returned whether a client does not exist or belongs to someone else).

A reseller can be suspended or deactivated: that cascades to the portfolio. Suspending a reseller removes their ability to create or change things, not their ability to sign in and read.

White-label branding

Panel → Brand sets: product name, logo URL, primary and accent colors (hex only), a support URL and a support email. The rule is that a client sees the brand of whoever sold them the service: a client sees their reseller's brand, a reseller their own, and anyone who has configured nothing inherits from the level above, up to the node's brand. Each user configures only their own brand.

Brand values are validated when saved and again when shown, so a broken value falls back to the node's default instead of breaking the page. The default product name is TNS Panel. The second-factor issuer shown in authenticator apps is always the fixed product name, not the reseller's brand, because it is stored in the user's app when they enroll.

DNS zone templates let a reseller also make new zones for their clients come with the reseller's own name servers and records (DNS → Zone templates).

Transferring a client to another reseller

Accounts → Clients → Transfer (admin only). The panel checks the destination reseller's pool before moving anything, closes any impersonation sessions the old reseller had, keeps the client's plan, and records both resellers in the audit log. Only an admin can do this because it is an operation between two third parties.

Impersonation

Admins, and resellers on their own clients, can open a client's panel to troubleshoot (Accounts → Impersonate). It requires your own password, ends automatically, and the audit trail names both you and the client. The impersonated session has the client role: it cannot reach the admin interface. Live impersonations can be listed and closed from Accounts → Impersonations.