Sites
WordPress, PHP apps, or static sites on your own server, with automatic HTTPS, file access over SFTP, and daily backups. Sites from cPanel can be moved over together with their databases, and a site can be moved to another server with only a short pause.
Who it is for
Sites (Situs in the app) is built for app owners who used cPanel only to run their own site or app, not for hosting companies that sell accounts to many customers. It focuses on the functions people actually use: installing a site, domains and HTTPS, uploading files, databases, and backups.
Sites connect with the rest of Saka: the database can live on the same server or in a multi-location database cluster, and a site can sit behind a load balancer.
Site types
| Type | What you get | Database |
|---|---|---|
| WordPress | Installed automatically and ready to use (Indonesian or English). The admin password is randomly generated and shown in the panel. | Yes |
| PHP | Apache with PHP 8.2, 8.3, or 8.4, and .htaccess works. For Laravel, CodeIgniter, or other PHP apps; upload files over SFTP. | Yes |
| Statis (HTML) (Static) | HTML/CSS/JS pages served directly by the web server. The lightest option. | No |
| Pindahkan dari cPanel (Move from cPanel) | Sign in to the old cPanel (like the WHM Transfer Tool), or use a cPanel backup file or a site archive. Files and database are moved, and WordPress is adjusted automatically. See Moving from cPanel. | Yes |
Creating a site
Server requirements: connected to Saka, ports 80 and 443 free (not used by another nginx or apache), and at least 1 GB of RAM.
- Open the Situs (Sites) menu in the panel, then press + Buat situs (Create site).
- Jenis (Type). Choose WordPress, PHP, Statis (HTML), or Pindahkan dari cPanel.
- Server. Pick the target server from the list of connected servers.
- Domain. Enter the domain, for example
tokokue.idorblog.tokokue.id. For a root domain, tick Sertakan juga www (Also include www) if you want it. A domain can only be used by one site in your account. - PHP & database (not for static sites). Choose the PHP version (8.3 recommended), the WordPress language, and where the database lives: Database di server ini (Database on this server) or Klaster database (Database cluster).
- Nama situs (Site name), for example "Toko Kue Ibu". For WordPress, this is also used as the site title (you can change it in WordPress).
- Press Buat situs (Create site), or Pindahkan situs (Move site) when moving from cPanel.
A site is usually ready in 2-5 minutes. The first site on a server takes a little longer because PHP is prepared first; a cPanel move depends on the size of the backup. You are also notified on Telegram. If it fails, the detail page shows why; delete that site and try again.
Domains, DNS, and HTTPS
After the site is created, point the domain to the server in your domain's DNS manager (where you bought the domain, or Cloudflare). The Domain & HTTPS card on the detail page shows the records you need:
tokokue.id. A 203.0.113.10
www.tokokue.id. A 203.0.113.10
; optional, if the server has IPv6:
tokokue.id. AAAA 2001:db8::10- An A record to the server's IPv4 address is required. An AAAA record to the server's IPv6 address is optional, for IPv6 visitors.
- The DNS column for each domain shows mengarah (pointing), ke IP lain (to another IP), or belum ada (not set yet). The HTTPS column shows aktif (active) or menunggu DNS (waiting for DNS).
- HTTPS turns on by itself within a few minutes after DNS points to the server. Let's Encrypt certificates are issued per domain and renewed automatically.
- Domains can be changed or added with Ubah / tambah domain (Change / add domain), one per line; the first one becomes the main address. For WordPress, when the main address changes, the addresses inside WordPress are replaced automatically.
Turn off the orange cloud first (choose "DNS only", grey cloud) until HTTPS is active in Saka.
Files over SFTP
Every site has its own SFTP account. Open the Akses (Access) card on the detail page and press Tampilkan sandi (Show password) to see the host, port, username, and password.
- Use FileZilla, WinSCP, or Cyberduck with the SFTP protocol.
- The site folder is
/www. Files uploaded there are served right away. - The account is jailed: it can only see that site's folder, cannot open a shell, and cannot see other files on the server.
- PHP apps run as the site's own user, so files created by WordPress or your app can still be edited over SFTP.
Database
| Option | What it is | When to use it |
|---|---|---|
| Database di server ini (Database on this server, recommended) | MariaDB 11.8 on the same server, one database and user per site, reachable only from that server. | Regular sites on one server. |
| Klaster database (Database cluster) | Saka creates a database and user for this site in your MariaDB cluster, and installs the Saka proxy on the site's server. Connections use TLS; if one database server goes down, the proxy moves to a healthy node. | Sites that must keep running even if one database server goes down. |
You can pick a MariaDB cluster that is ready and runs on other servers (the site's server must not be a member of that cluster). For WordPress, the TLS connection to the cluster is set up automatically. The database connection details (host, name, user, password) are in the Akses (Access) card. To view and edit the database contents, use phpMyAdmin.
phpMyAdmin
WordPress and PHP sites have their own phpMyAdmin. On the Access card, press Open phpMyAdmin; it opens in a new tab and signs you in.
- No open port. phpMyAdmin opens through the Saka dashboard tunnel (the same way as the OpenClaw dashboard): the agent connects outward, and no port is opened on your server.
- Signed in automatically as that site's database user, and it only sees that site's database. You do not need to type the database password.
- Stops by itself after 3 hours. Press the button again if you still need it.
- The first time on a server can take about 30 seconds because the phpMyAdmin image is downloaded first.
- Works for a database on this server and for a database cluster (TLS connection). Static sites have no database, so they have no phpMyAdmin.
Via the API: POST /api/v1/situs/{id}/phpmyadmin returns {"url"}, a single-use sign-in link valid for 60 seconds. phpMyAdmin is not available through MCP.
Backups and restore
- Daily, automatic. Files and database are backed up every day into one
.tar.gzfile on your server. The last 7 daily backups are kept. The first daily backup is made within 24 hours. - Manual. Press Cadangkan sekarang (Back up now) on the Cadangan (Backups) card at any time (the last 5 are kept).
- Restore. Press Pulihkan (Restore) on the backup you want. The site's files and database are replaced with the contents of that backup. Before that, the current state is always backed up first (type "sebelum pemulihan", before restore), so a restore can still be undone by restoring that backup.
Backups are stored on the same server as the site. To protect against a server that is lost completely, also keep a copy somewhere else (see Coming soon).
Moving from cPanel
Choose the Pindahkan dari cPanel (Move from cPanel) type when creating a site. There are two ways to move.
Option 1: Sign in to the old cPanel (recommended)
Like the WHM Transfer Tool, but with just the cPanel account login. Saka creates a full backup on the old cPanel, waits for it to finish, downloads it to the new server, deletes that backup file from the old cPanel, and then sets it up.
- Old cPanel address: the domain or IP of the old server, for example
oldshop.com. Port 2083 is used automatically (you can add your own:port). - cPanel username and cPanel password (the cPanel account password, not the WHM or root password).
- If the account uses two-factor authentication (2FA), tick the API token option and enter a token from cPanel (Security, then Manage API Tokens). You can delete the token after the move.
- Tick Skip cPanel's HTTPS certificate check only if the old cPanel's certificate is self-signed.
- The password is not stored. The password or token is only passed to your server for this one transfer and is not written to disk.
- The new server must be able to reach port 2083 on the old server. If it cannot, make sure the old server's firewall allows it.
- How long it takes depends on the account size: cPanel needs time to build the backup, and then the file is downloaded.
Option 2: Use a backup file
- In the old cPanel, open Backup (or Backup Wizard), choose Download a Full Account Backup, then wait until the
backup-….tar.gzfile is ready. - Fill in one of:
- A download link for the backup file (it must be reachable from the internet), or
- A file path on the target server, after you upload it to
/root,/home, or/tmp, for example/root/backup-….tar.gz.
A plain site archive also works: a .zip or .tar.gz containing the site folder, with or without .sql files.
What Saka does
- The archive is unpacked safely: symlinks and paths that escape the folder are ignored, and the contents are limited to 20 GB. Free disk space is checked first.
- The contents of
public_htmlbecome the site files (including.htaccess). - For WordPress, the database to import is chosen from
DB_NAMEinwp-config.php. The database settings inwp-config.phpare updated for the new database, and the old address in the database is replaced with the new domain (https://plus the main domain). - Other databases in the backup are not imported, but their names are reported.
- If the site is not WordPress, the main database is still imported, and you are told the new host, database name, and user so you can update your app's settings yourself.
All of this is shown in the Catatan pemindahan (Move notes) box on the site's detail page. For a moved WordPress site, sign in with your old WordPress admin account.
Move to another server
For changing VPS (for example to a bigger server or another location) without the hassle. The site is copied straight to the new server, and the old site keeps serving visitors until you are ready. The target server must be connected to the same Saka account, with ports 80/443 free.
- Copy. On the site's detail page, open the Move to another server card. Choose the Target server and PHP on the new server (you can change the PHP version, for example up to 8.4). For WordPress, tick Update WordPress, plugins, and themes during the move if you want. Press Copy to new server. The old site keeps running; you are notified on Telegram when the copy is ready. You can press Copy again at any time to refresh the copy.
- Move now. The old site shows a maintenance page (HTTP 503) briefly, the latest changes are copied, and the site goes live on the new server. If you chose the WordPress update, WordPress core, plugins, themes, and translations are updated after a backup; if the site breaks afterwards, it is rolled back automatically to the state before the update. If this step fails, the old site goes live again.
- Change DNS. Change the domain's A record to the new server's IP at your domain's DNS provider. The DNS column on the Domain & HTTPS card turns to pointing here afterwards.
- Finish. Once DNS points to the new server, press Finish (delete from old server). The site on the old server is deleted; its last backup is kept in
/rooton the old server.
Cancel is available until you finish. Before Move now, the copy on the new server is deleted and the old site is unchanged. After it, Cancel, go back to the old server makes the site live on the old server again and deletes the copy on the new server; changes made on the new server since the move are lost, and an A record you already changed needs to point back to the old server's IP.
How it works
- Directly from server to server over HTTPS, not through Saka. The old server opens a temporary sender with a one-time certificate; Saka passes that certificate's fingerprint to the new server, so the new server only accepts the right sender.
- The sender port is random, opened only for the target server's IP, uses a random token, and stops by itself after 1 hour at most.
- The database name, user, password, and the SFTP account stay the same, so your app's settings do not need to change.
- Sites with a database cluster: the database is not copied, because the new server is connected to the same cluster (the Saka proxy is installed on the new server).
Behind a load balancer
If a load balancer in proxy mode is ready and forwards the site's domain to this server, the site is automatically served through the balancer: visitors come in through the balancer, and the balancer holds HTTPS. The HTTPS column then shows di load balancer (at the load balancer). This is reapplied automatically when a load balancer is created or deleted, or when a balancer's IP changes.
PHP versions
Choose PHP 8.2, 8.3, or 8.4. On the PHP card, pick a version and press Ganti versi (Change version). The site restarts with the new version within a few seconds; a version that has not been used on that server yet is prepared first (about 1-2 minutes).
PHP settings
The same card has PHP settings, like cPanel's MultiPHP INI Editor but without editing files:
- Upload limit (
upload_max_filesize, 2 to 2048 MB;post_max_sizeis adjusted to match). Default 64 MB. - Memory limit (
memory_limit, 64 to 2048 MB, at most three quarters of the server's RAM). The site container's memory limit is raised to match. Default 256 MB. - Max execution time (
max_execution_timeandmax_input_time, 10 to 3600 seconds). Default 120 seconds. - max_input_vars (1000 to 100000), often needed for long WordPress menus. Default 3000.
- Time zone (
date.timezone, e.g. Asia/Jakarta). Default UTC. - Show PHP errors (
display_errors): only for debugging, turn it off again afterwards.
Press Save settings; the site restarts for a few seconds. Via the API: PATCH /api/v1/situs/{id} with php_ini; via MCP: the situs_atur_php tool.
Deleting a site
In the Zona berbahaya (Danger zone) section, press Hapus situs (Delete site) and type the site name to confirm. The site's files, database, SFTP account, and all its backups on the server are deleted. Your domain and server are not touched.
Tick Simpan cadangan terakhir dulu di /root server (Keep the last backup in /root on the server first, recommended) to copy one final backup to /root before the site is deleted. If that copy fails, the site is not deleted.
When you release a server, every site on it is cleaned up too; with the keep-backups option, each site's backup is copied to /root.
What we deliberately do not do
- Email hosting. Use the email provider of your choice. Help with email DNS settings is coming.
- Reseller or WHM accounts. Sites is for app owners, not for selling hosting.
- One-by-one technical menus such as a zone editor or MIME types.
Security
- Passwords stay on your server. Database, SFTP, and WordPress admin passwords are stored on the server (in a file only root can read) and read by the panel when you press Tampilkan sandi (Show password). They are never given to an AI agent through MCP. The old cPanel's password or API token is only passed to your server once and is not stored.
- Root SSH settings stay unchanged. Saka adds SFTP settings just for site accounts, then compares the SSH settings for root before and after. If anything changed, the change is rolled back. Root stays without password login if it was that way before.
- Separated per site. Every PHP or WordPress site runs in its own container that only listens on
127.0.0.1; visitors come in through a single web server with HTTPS on ports 80/443. - Logged. Creating, changing, backing up, restoring, and deleting sites is recorded in the server's task history.
Through your AI agent (MCP) and the API
MCP tools
| Tool | What it does |
|---|---|
situs_daftar | Lists sites across all servers, with their domains and state. |
situs_buat | Creates a WordPress, PHP, or static site, with a local or cluster database, or moves one from cPanel (sumber with a backup file, or cpanel to sign in to the old cPanel). The agent must confirm the plan with you first. |
situs_status | Site state: HTTPS and DNS for each domain, size, list of backups, SFTP account. No passwords. |
situs_cadangkan | Makes a backup now. |
situs_atur_php | Changes the PHP settings: upload limit, memory, execution time, max_input_vars, time zone, show errors. |
situs_pindah_salin | First step of moving to another server: copies the site to the target server (optionally with another PHP version and a WordPress update). The old site keeps running. |
situs_ubah_siapkan | Step 1 of 2 for pulihkan (restore), hapus (delete), pindah_sekarang (move now), pindah_selesai (finish the move), or pindah_batal (cancel the move): a preview and a confirmation token (10 minutes). |
situs_ubah | Step 2 of 2: runs that action with the token, only after you have approved the preview. |
There is no MCP tool for reading site passwords. See Connect your AI (MCP).
API endpoints
| Method | Path | Details |
|---|---|---|
GET | /situs | List sites (can be filtered with ?server_id=). |
POST | /situs | Create a site. Body {"nama", "server_id", "jenis", "domain", "php", "bahasa", "db", "klaster_id", "sumber", "cpanel"}. |
GET | /situs/{id} | Details and status (DNS, HTTPS, backups, SFTP without password, pindah while a move is in progress). |
PATCH | /situs/{id} | Change the name, domains, PHP version, or PHP settings. Body {"nama", "domain", "php", "php_ini"}. |
DELETE | /situs/{id} | Delete. Body {"konfirmasi": "<site name>", "simpan_cadangan": true}. |
POST | /situs/{id}/rahasia | Read the database, SFTP, and WordPress admin passwords directly from the server. |
POST | /situs/{id}/cadangan | Back up now. |
POST | /situs/{id}/pulihkan | Restore. Body {"berkas": "<backup name>", "konfirmasi": "<site name>"}. |
POST | /situs/{id}/phpmyadmin | Start the site's phpMyAdmin. Returns {"url"}, a single-use sign-in link (60 seconds). |
POST | /situs/{id}/pindah | Copy to another server. Body {"server_id", "php", "perbarui_wp"}. |
POST | /situs/{id}/pindah/sekarang | Move now. Body {"konfirmasi": "<site name>"}. |
POST | /situs/{id}/pindah/selesai | Finish: delete the site on the old server (last backup kept in /root). |
POST | /situs/{id}/pindah/batal | Cancel the move; the site stays on, or goes back to, the old server. |
curl -s -X POST https://app.saka.work/api/v1/situs \
-H "Authorization: Bearer $SAKA_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"nama": "Toko Kue Ibu",
"server_id": "srv_aaaaaaaaaaaaaaaa",
"jenis": "wordpress",
"domain": ["tokokue.id", "www.tokokue.id"],
"php": "8.3",
"bahasa": "en",
"db": "lokal"
}'jenis (type): wordpress, php, or statis (static); a cPanel move uses php with sumber, or with cpanel: {"host", "pengguna", "sandi"}, or "token" instead of the password, plus "abaikan_tls": true for a self-signed certificate. php: 8.2, 8.3 (default), or 8.4. db: lokal (local, default) or klaster (cluster) with klaster_id. The 202 response contains the site with keadaan: "dibuat" (being created); poll GET /situs/{id} until it is siap (ready) or gagal (failed). General details are in the REST API page.
Coming soon
Sites in two locations that keep running even if one location goes down (file copies between servers, a load balancer, and a database cluster), backups to your own S3 storage and downloading backups from the panel, WordPress and plugin updates at any time with automatic rollback if something breaks (already available when moving to another server), and help with email DNS (MX, SPF, DKIM, DMARC) for the email provider you choose.
Need something else? Suggest it from the Request a feature menu in the panel (see Feature requests & migration help).