projects/

LESta

runs in CI, waiting for its first real install

serveraddict@home:~/projects/lesta$ cat README.md

LESta is a Laravel and React rewrite of VestaCP, the free hosting panel a lot of cheap servers ran until its installer shipped a backdoor in 2018 and the maintainers stopped answering. It started with a comment on LowEndSpirit on 2026-08-25, where I said I'd vibe-code something better in a day or two. A member replied that it would take weeks or months. I wrote back "Challenge accepted." They were right.

The one rule: I don't write the code. I write prompts, Claude Code writes everything else, and hand edits are kept to a minimum. What came back wasn't a weekend project, it was a system. A Laravel control plane holds all desired state. A Go agent on each server is the only thing allowed to touch the host, and only through named, versioned, idempotent operations. No raw shell commands. Anyone who has read Vesta's eval loops knows why.

What works today: web hosting on nginx and Apache with ACME certificates, DNS on BIND9 with atomic activation and rollback, mail on Exim and Dovecot with DKIM rotation, per-tenant MariaDB, cron, encrypted backups with a real restore path, quotas, resellers and a hash-chained audit log. Every installer runs its full apply, re-apply, tamper and rollback cycle in CI. Roughly 94,000 lines across PHP, Go, shell and TypeScript, with 201 test files.

What doesn't exist yet: a real install on a server anyone can reach. Everything so far has run on disposable CI machines and a laptop, and the security review was the same tool grading its own homework. That's next, along with finding out what breaks.

The whole story, from the forum bet to the first security pass, is written up as a book, built from the decision logs, the transcripts and the code. The TL;DR is two pages if you only want the feature list and the honest gap list.

$ ls -la