Skip to content
BETA · SELF-HOST IT TODAY

Run Minecraft on
hardware you own.
Free and open source.

The whole panel is free and open source: servers, modpacks, files, users, scheduling, profiling. Run it on a VPS, a NAS or the PC under your desk, and nothing phones home. Want a clean domain instead of an IP? Our managed edge adds no open ports, just a CNAME, always :25565. Take a free subdomain from us, or point your own domain at the edge and keep your branding - that part is a paid service, and it is optional.

Self-host

Run the open-core stack on your own box: Core, Node and Panel. No phone-home, your data, free to run today.

Bring your own node

Got a server or a gaming PC? Bring the hardware to our managed, DDoS-protected edge. No router config, a server for you and your friends.

How BYON works →
No SSH requiredNo terminal work. It is just a Docker install.REST API + per-user keysLinux-native, runs on WindowsWindows/Docker Desktop is perfect for a BYON home server on your gaming PC (you and your friends). For production, Linux is recommended: hard disk quotas and CPU pinning are Linux-only.Open source, self-hostableThe panel, Core, the node agent and the Beam desktop app are published under Apache-2.0 today. Self-host all of it. The DDoS-protected edge is the one closed part.
Where the line is

Two halves. Only one of them is ours.

Free and yours

The panel, all of it

Published under Apache-2.0. Install it on a VPS, a NAS or the PC under your desk and keep it. No account, no key, no phone-home, no feature held back.

  • Servers, sub-servers, console and RCON
  • Modpack builder, publisher and Modrinth browser
  • Files, backups, the shared library
  • Users, granular permissions, scoped API keys
  • Scheduled tasks, live metrics, the Spark profiler
  • The Beam desktop app, Windows and Linux

Players connect to your-ip:port, and you forward a port like anywhere else.

We run this

The protected address

A clean domain on :25565 in front of your machine. This is the part that costs bandwidth and absorbs attacks, so it is the part we charge for. It is optional.

  • No open ports, no public IP needed
  • Your real address is never visible to a player
  • Attack traffic absorbed before it reaches you
  • A CNAME is the whole setup on your side
  • Works from behind NAT, so a home PC qualifies

Closed source and in testing. Whether it becomes a paid service, a licence for running your own edges, or both, is not decided. Ask us.

Integrated modpack builder ModrinthTechnic / Solder
Modpack Workflow

Browse. Build. Publish. Play.

Search Modrinth from inside the panel, drop mods into a versioned modpack, and publish it to Modrinth or ship it to Technic/Solder launchers, all from one project. Then create your server straight from that modpack, and players launch it right from the Modrinth or Technic launcher to play.

One panel, end-to-end modpack pipeline

Cached Modrinth proxy, in-panel mod browser, versioned modpack builder, draft/beta/release channels, collaborator sync, AES-encrypted PAT storage, and an .mrpack server installer with host allowlist and override handling. Publish to Modrinth, ship to Technic/Solder, and deploy to your own fleet from the same project, no jumping between tools.

In-Panel Mod Browser

Search the full Modrinth catalogue from inside Dylaris. Cached proxy keeps results fast, supports loader and version filtering, installs with a click via the Node queue.

Search Modrinth without leaving the panel

Versioned Modpack Builder

Build modpacks like a real release pipeline: draft, beta, release. Frozen versions are immutable. Collaborators sync to Modrinth's member API automatically.

Beta channels, frozen releases, collaborator sync

Modpack-as-a-Server

Take any pack, a Modrinth .mrpack or a Technic/Solder pack, yours or someone else's, and deploy it as a fully managed server. Host allowlist, override handling, automatic loader chaining.

Your modpack and your server, same project
Capabilities

Everything you need, in one panel.

Modpacks, server lifecycle, scaling, operations, all first-class and native to Dylaris.

Free and yours

Modrinth Mod Browser

Search the full Modrinth catalogue by loader and MC version and install with one click. A cached proxy keeps results fast.

Modpack Builder

Build modpacks as a real release pipeline (draft, beta, release) with frozen, immutable versions. Modrinth and Technic/Solder packs live in one builder.

Spark Profiler

Start and stop Spark profiling from the panel; report URLs are captured from the console over SSE and a history tab keeps every run.

Multi Sub-Server Slots

One server entry holds many sub-servers (vanilla, survival, creative, modded) and switches between them in place.

Live Console & RCON

An in-panel RCON terminal with full command access, streamed live over SSE, plus an external API surface for bots and automation.

Player Management

Kick, ban, op and pardon from the panel. Online sessions are tracked live over SSE, so the list never lies.

File Browser

A native per-server file browser bound to the server UUID. Edit, upload, move and download over SFTP or Beam.

Scheduled Tasks

Cron-style restarts, commands and broadcast messages per server. Set them once with a live cron preview and forget.

Docker-Isolated Servers

Every server runs in its own container with hard RAM, CPU and disk limits, and per-server Java (8, 17, 21). One noisy server can never starve another.

Beam Desktop App

A free, open-source desktop client for server files (Windows and Linux). On your own network it connects straight to the node at full speed; elsewhere it relays without ever exposing the node IP. No port 22.

Backups & Restore

Scheduled or on-demand backups with include/exclude patterns, retention limits and one-click restore. Back up a whole server or just one sub-server.

Granular Permissions

80 fine-grained capabilities across server, owner and panel scopes. A build-time test proves every protected endpoint is gated, and sessions and API keys run through the exact same check.

We run this

The gateway exists so that nobody ever learns where your server actually is. Players reach it on :25565 at our edge, and Beam moves your files through the same gateway instead of an open SFTP port - from the internet both are relayed, so the machine behind them keeps every port shut and never appears in a DNS record. Edges run several to a region, which is what spreads the load and what lets players keep playing while we update one.

It is closed source and still in testing, and we have not settled whether it becomes a paid service, a licence for people who want their own edges, or both. Ask us if that matters to your plans. Without it, everything above still works - players just connect to your-ip:port.

Edge Routing & Custom Domains

Multi-region edge routing with TLS termination and custom domains. Players connect to a clean address, always ending in :25565, with no exposed backend IP.

Multi-Region Fleet

Region-tagged servers and nodes with region-aware scheduling and per-user region access, from one VPS to a global fleet.

Kernel-Level Anti-DDoS

An XDP/eBPF firewall drops junk traffic in the kernel before it costs a CPU cycle, with a Minecraft-protocol-aware parser at the edge.

Warp NAT Bridge

Pull NAT’d home machines and off-site VPSes into the fleet over a hub-and-spoke WireGuard overlay: self-enrolling, no port forwarding.

Relayed File Transfer

File traffic takes the same road as players: Beam moves it through the gateway instead of an open SFTP port, so the node keeps 22 and 25520 shut and never appears in a DNS record.

Seamless Edge Updates

Run more than one edge in a region and live sessions move to a sibling before one restarts. Players keep playing through an update instead of being kicked to the server list.

Bring your own node

Run a server from your closet,
your VPS,
your friend's basement.

Got a server or a gaming PC but don't want to wrestle with ports, firewalls and networking? Bring the hardware, Dylaris does the hard part. Your machine joins the fleet and the panel treats it like any other node, even behind NAT with no public IP.

Under the hood it is Warp, a hub-and-spoke WireGuard overlay. Nodes self-enroll with a scoped key and come online automatically. No manual key exchange, no tunnels to babysit.

You bring
Any machine
Networking
No router config
Setup
One Docker stack
Fleet Topology
Home PC
behind NAT
VPS
off-site
DC Node
datacenter
WireGuard tunnel
one fleet · one view

From your machine to play.yourserver.com

Connect your node

Install the Dylaris stack (three lightweight Docker containers) on your PC, VPS or a friend's box. It dials out over an outbound-only tunnel: nothing to forward, nothing to expose. Works behind NAT and CGNAT.

No open ports · outbound only

Create servers in the panel

Spin up vanilla, Paper, Fabric, NeoForge, proxies or a full modpack from one web panel. Start, stop, edit files, run RCON, schedule restarts, full control, no SSH.

Full control, zero terminal

Players just connect

Point one CNAME, ours (a free subdomain) or your own domain. No SRV records, no IP addresses, no port numbers. The address always ends in the default :25565.

Just a CNAME, always :25565
No open ports
Outbound-only
Behind NAT / CGNAT
CNAME only, no SRV
No IPs, no ports
Always :25565
Your domain or ours
DDoS-protected edge
Full control in-panel
Easy setup
Your hardware
No lock-in

It stays your machine

Dylaris adds just three lightweight containers: the Node daemon, the Link outbound tunnel, and the Warp VPN. The Node then spawns your Minecraft server containers on top. Everything else on the box keeps running untouched, you keep full control, and nothing listens on a public port. Plain Docker is enough for a node or two; Docker Swarm is optional and only pays off when you self-host a larger fleet and want the full multi-node setup.

Node
daemon · spawns MC
Link
outbound edge tunnel
Warp
WireGuard VPN
How we compare

vs. conventional hosting

Most setups expose a public IP for every server. With the optional Dylaris edge, backends stay portless behind an outbound-only tunnel.

ApproachNo exposed IPKernel DDoSMC protocolRolling updatesFull panelDocker-native
DYLARIS
Traditional Panel Hosting
Each server needs its own IP. One DDoS and the server is offline.
~~
BungeeCord / Velocity
MC proxy only. Still exposes the proxy IP. No DDoS layer.
Cloudflare Tunnel
TCP tunneling only. No Minecraft parsing, no eBPF, no panel.
~
Pterodactyl / Pelican
Panel + Docker orchestration, but servers stay fully exposed.
Ngrok / frp
General TCP tunneling. No DDoS, no protocol awareness, no panel.

The portless edge is optional. Run Dylaris on plain ports today, add the edge when you want it.

Under the Hood

Service-oriented. Single panel.

Core API, Node agents, Gateway routing, Beam file relay, Hub coordination, Warp NAT bridge. Each piece is its own service, each one cleanly composed, and from your view, it's still just one panel.

Control PlaneAPI · scheduling · panel

Core

API, Auth, Scheduling, Modpack Service

43,356 Go
~22 MB img · 60-120 MB RAM

Node

Docker Agent, Server Lifecycle, RCON

10,695 Go
~20 MB img · 40-80 MB RAM

Panel

Next.js Web Console, SSE-driven

26,005 TS
~200 MB img · 80-150 MB RAM
Data Planerouting · file transport · tunnels

Gateway

Edge Routing, TLS, Custom Domains

5,604 Go
~20 MB img · 40-70 MB RAM

Hub

Routing State, Leader Election

1,528 Go
~20 MB img · 20-40 MB RAM

Beam

P2P File Transfer + Desktop Client

2,919 Go
~20 MB img · 15-35 MB RAM

Warp

WireGuard NAT Bridge for Off-Site Nodes

895 Go
~24 MB img · 15-30 MB RAM

Run the Core, Node and Panel on a single VPS and you have a working host. Add Gateway and Warp when you grow into a multi-region fleet, attach Beam when ops teams want bandwidth-capped file transfer, the panel is the same panel.

Line counts from source; image sizes and memory are rough estimates.

Backend
Go
Native-compiled, no runtime overhead: fast, tiny static binaries. One workspace across Core, Node and the edge.
Panel
Next.js + Tailwind
A modern, typed stack for a clean, fast UI. App Router, SSE-driven, no page reloads.
Data
Postgres + Valkey
Postgres for durable state, TimescaleDB for time-series metrics, Valkey (Redis-compatible) for queues and live streams.
Orchestration
Docker + Swarm
Every server in its own container: isolated, resource-capped, no host pollution. One host or a full Swarm, same agent.

Every service, line-count, image size and protocol, laid out with diagrams and code.

Read the full technical deep dive
WHERE WE ARE

Open source today.
Beta, honestly.

The panel, Core, the node agent and the Beam desktop app are published under Apache-2.0, right now, not after a beta. Clone it, run it, fork it. No waitlist, no key, no phone-home. It is still beta, so expect the odd rough edge while we harden it with real users. Everything below is already shipped, not a roadmap promise.

Core API + Server Lifecycle
Done
Docker + Multi-Node Swarm
Done
Modrinth Browser + Modpack Builder
Done
Modpack-as-Server + Spark
Done
RCON + Player Management
Done
Gateway + Beam + Warp
Done
Live SSE + Custom Tabs
Done
First-Run Wizard + Recovery
Done

Planned: Bedrock Edition (first over a normal port, later through the portless edge via GeyserMC).

Panel · free

Yours under Apache-2.0

The panel, Core, the node agent and the Beam desktop app are published today. Every feature, no crippled edition: what we run is the code you can run. Your hardware, your data, no strings.

Gateway · Closed

Gateway as a service

The DDoS-protected edge and NAT bridge are a service we operate, and the part that is genuinely hard to self-run. Closed source and in testing. Whether it becomes a paid service, a licence for people who want their own edges, or both, is honestly not decided yet. Ask us if that matters to your plans - we would rather talk than have you guess.

App · planned

Mobile app

Planned, not built. Pick our hosting or your own self-hosted domain right at login, the way Bitwarden lets you choose your server. It will be a paid, one-time purchase in the app stores - saying so now so nobody budgets for a free one. Price undecided.