RE:NODE

Guides11 min read

Garry's Mod ULX vs SAM admin permissions

Set up ULX and ULib or SAM on a Garry's Mod server: the first superadmin, groups and inheritance, target restrictions, bans, CAMI, databases and which to choose.

0 readers

ULX with ULib is the free, long-standing admin mod for Garry's Mod; SAM is a paid alternative that is lighter on clients and stores ranks and bans in a database from the start. Either one gives you groups, per-group permissions, bans and a menu. The setup is the same shape for both: install the addon, restart, create the first superadmin from the server console because nobody has rights in game yet, build a small group ladder that inherits upward, and give each group only the commands it needs - with limits on whom it can target. The difference shows up later: ULX keeps its data in text files and SQLite on one server unless you add a MySQL addon, while SAM is built for several servers sharing one database. This guide covers both, the permissions model they share through CAMI, and the mistakes that let a moderator ban the owner.

What an admin mod does, and which ones exist#

Garry's Mod has a basic notion of admin and superadmin built in, and nothing else: no groups, no bans with reasons, no menu. An admin mod adds:

  • Groups (ranks) with inheritance, so a moderator inherits everything a trusted player can do.
  • Permissions per command, per group, often with argument limits.
  • Targeting rules - who a group may act on.
  • Bans with reasons, lengths and history.
  • A menu, chat commands and console commands.
  • A permission API other addons use to ask "may this player do this?"
Admin modPriceStorageNotes
ULX + ULibFree, open sourceText files and the server's SQLiteThe default for a decade; huge addon support
SAMPaidSQLite, or MySQL for networksLighter client menu, built for multi-server
FAdminBundled with DarkRPDarkRP's databaseFine for small DarkRP servers; disable it if you install another

Run exactly one. Two admin mods fight over the same chat commands and the same built-in admin flags, and the result is commands that work for some people and not others. On DarkRP, disable FAdmin before installing ULX or SAM - the DarkRP server guide shows the one line that does it.

Installing ULX and creating the first superadmin#

ULX needs ULib, its library. Both are on the Workshop and on the authors' GitHub; use one source for both so their versions match. Add them to your Workshop collection or place them in garrysmod/addons/, then restart. Garry's Mod Workshop and FastDL covers collections if you have not set one up.

Nobody has permissions on a fresh install, so the first superadmin is made from the server console - the panel console or RCON - not from chat:

code
ulx adduser "YourName" superadminulx adduserid STEAM_0:1:12345678 superadmin

ulx adduser needs the player to be online and matches their name; ulx adduserid works with a SteamID whether they are online or not, which is the safer habit. Once you are superadmin, ulx menu - or !menu in chat - opens XGUI, the graphical menu where everything below can also be done.

ULX stores its data under garrysmod/data/:

code
garrysmod/data/  ulib/groups.txt     groups, inheritance, permissions  ulib/users.txt      who is in which group  ulx/config.txt      ULX settings, executed at start  ulx/motd.txt        message of the day

These are plain text and easy to fix by hand when you lock yourself out - stop the server, edit, start. Recent ULib versions keep bans in the server's SQLite database (garrysmod/sv.db) rather than a text file; older versions used a file. Back up both the data/ulib folder and sv.db.

Groups and inheritance in ULX#

ULX ships with four groups, each inheriting from the one below:

code
superadmin -> admin -> operator -> user

You will usually want your own names and a slightly longer ladder. Create groups with the group they inherit from:

code
ulx addgroup vip userulx addgroup moderator vipulx addgroup senioradmin adminulx groupallow moderator "ulx kick"ulx groupallow moderator "ulx gag"ulx groupallow moderator "ulx mute"ulx groupallow moderator "ulx slay"ulx groupallow moderator "ulx goto"ulx groupallow moderator "ulx bring"ulx groupdeny moderator "ulx noclip"

groupallow grants a command to a group and everything that inherits from it; groupdeny removes it. Grant at the lowest group that should have a command, and let inheritance do the rest. ulx userallow and ulx userdeny exist for one-off exceptions, but per-user permissions are hard to audit later - prefer a group.

A sensible ladder for a public server:

GroupInheritsTypical commands
user-ulx motd, ulx votemap
vipuserCosmetic perks, reserved slot
moderatorvipKick, gag, mute, slay, goto, bring, short bans
adminmoderatorLonger bans, map change, noclip, jail
superadminadminEverything, including ulx rcon and ulx luarun

Targeting rules: stopping a moderator banning you#

Inheritance decides what a group can do. Targeting decides whom it can do it to. Without a targeting rule, a moderator with ulx kick can kick an admin, and a moderator with ulx ban can ban the owner. ULib's target strings fix that:

TargetMeans
^Yourself
*Everyone
@The player you are looking at
#groupMembers of exactly that group
%groupMembers of that group and every group inheriting from it
$idA player by SteamID or unique ID
!Negates the next target

ulx setgroupcantarget sets a group's targeting limit:

code
ulx setgroupcantarget moderator !%moderatorulx setgroupcantarget admin !%admin

The first line means moderators can target anyone except moderators and the groups that inherit from them - admins and superadmins included. That single command removes the most common staff-abuse incident on a Garry's Mod server. Set it for every staff group as soon as the group exists.

XGUI also lets you restrict command arguments per group, such as the longest ban a moderator may give or the maximum slap damage. Use it: a moderator who can ban for an hour but not permanently makes fewer mistakes that you have to undo.

Bans, logging and the everyday commands#

CommandEffect
ulx kick <player> [reason]Remove a player
ulx ban <player> [minutes] [reason]Ban an online player; 0 is permanent
ulx banid <steamid> [minutes] [reason]Ban by SteamID, online or not
ulx unban <steamid>Lift a ban
ulx gag <player> / ulx mute <player>Block voice / block text chat
ulx slay, ulx slap, ulx freeze, ulx jailPunishments in place
ulx goto, ulx bring, ulx returnTeleport to, teleport here, send back
ulx map <map> [gamemode]Change map, optionally gamemode
ulx asay <message>Message only admins see (also @ in chat)
ulx whoList players with their groups

ULX logs admin actions to garrysmod/data/ulx_logs/ when logging is on, one file per day. That log is how you answer "who banned my friend" a week later; keep ulx logFile 1 (with ulx logEvents 1 and ulx logChat 1 if you want the context) in data/ulx/config.txt and skim it weekly. Server rules, moderation and staff covers how to run a staff team that uses all this consistently.

Reserved slots and VIP perks

A vip group is where most servers put the perks for supporters and regulars, and the most common perk is a reserved slot. ULX handles this itself: the reserved-slot settings live in data/ulx/config.txt as ulx rslotsMode, ulx rslots and ulx rslotsVisible, and the group that gets the slot is the one granted the reserved-slot access. The modes differ in whether slots are held empty for admins or someone is kicked to make room; the comments in config.txt describe each, and they are worth reading before you pick one, because the kick-to-make-room mode surprises regular players who get dropped mid-round.

Keep VIP perks cosmetic or convenient. A paid group that can noclip, spawn weapons or avoid punishment turns a community server into a pay-to-win one, and depending on the game it can also break the publisher's rules for community servers. Monetising a game server within the rules covers where that line sits.

Designing a staff ladder that lasts#

Permissions are the easy part. What makes an admin setup hold up for years is the process around it.

  1. Start new staff on a trial group. A trialmod group that inherits from vip with kick, gag, mute and nothing else. Promote after a few weeks of good judgement, visible in the logs.
  2. Grant the smallest set that does the job. Every command a moderator does not have is a mistake they cannot make. Bans longer than a day can wait for an admin.
  3. Write down what each group is for. One line per group in your staff channel. When someone asks for a new permission, the question becomes "does this match the group's purpose" rather than "do I like this person".
  4. Review the logs. Ten minutes a week reading ulx_logs catches abuse long before players complain about it.
  5. Remove access the same day someone leaves. ulx removeuserid <steamid> in game, their panel subuser removed, and any shared password - RCON, database - rotated if they ever had it. A former staff member with an old superadmin entry is how many servers get wiped.

The same ladder translates directly to SAM's ranks, so none of this is wasted if you switch later.

SAM: setup and how it differs#

SAM is sold through a Garry's Mod addon marketplace, installed as a normal addon folder, and licensed per purchase. Like ULX, it starts with no admins, so the first rank is set from the server console - SAM's console command for this is sam setrank with a name or SteamID and the rank, though check the documentation for your version in case the syntax has changed. After that, the in-game menu does the rest.

The differences that matter when choosing:

  • Storage. SAM uses SQLite by default and supports MySQL through the MySQLOO module, so several servers can share ranks and bans from one database. ULX can do the same only with a third-party MySQL addon.
  • Client weight. SAM's menu is lighter than XGUI, which helps on servers with many addons where client Lua load time is already long.
  • Model. Ranks with permissions and inheritance, targeting by rank immunity rather than ULib target strings. The concepts map across; the commands do not.
  • Ecosystem. ULX has a decade of addons written directly against it - TTT command packs, logging addons, MOTD plugins. SAM supports CAMI, and has its own modules for common gamemodes.

For MySQL, MySQLOO is a binary module: a .dll file in garrysmod/lua/bin/ built for the server's platform and branch. On the 64-bit server branch it needs the 64-bit build. Each game plan on RE:NODE includes a database slot with a generated host, user and password; check the engine it provides against what SAM or your ULX MySQL addon expects before migrating ranks into it.

may this player?yes or noPlayerruns a commandAny addone.g. a door systemULX or SAMgroups and ranksStoragefiles, SQLite or MySQLCAMIshared privilege API
How addons ask for permission through CAMI

CAMI: why your addons do not care which you pick#

CAMI, the Common Admin Mod Interface, is a small shared library that lets any addon register a privilege and ask whether a player has it, without knowing which admin mod is installed. Both ULX and SAM support it. A gamemode that registers "may edit doors" through CAMI shows up as a permission in XGUI or in SAM's menu automatically, and you grant it to a group like any other command.

Two practical consequences. When you switch admin mods, CAMI-aware addons keep working; you only re-grant their privileges in the new mod. And when an addon's feature is missing for a staff member, look in the admin mod for a privilege the addon registered - it is usually there, granted only to superadmin by default.

Panel access is a separate question#

In-game admin and server administration are different jobs. A moderator who needs to restart the server after a crash does not need the files, the database credentials or billing. On RE:NODE the panel's subusers and roles grant console access only, files only, or other narrow sets of permissions, with a per-server activity log, and access can be time-boxed. Pair that with the in-game ladder: a trusted admin might have console in the panel and admin in ULX, while nobody but the owner has file access and superadmin. Subusers and least privilege has the details, and game server admin account security covers protecting the accounts themselves.

Troubleshooting#

`ulx adduser` says the player was not found. They are offline or their name is ambiguous. Use ulx adduserid with the SteamID.

Commands work for superadmins but not for a new group. The group was created without inheriting from user, or the command was granted to a group it does not inherit from. Check the group's parent in XGUI.

A moderator banned an admin. No targeting rule. Set ulx setgroupcantarget for every staff group.

Two menus open, or chat commands do nothing. Two admin mods are installed - often FAdmin on DarkRP. Disable one.

Ranks reset after a restart. The data files were not writable, or a Workshop update replaced a legacy addon folder. Check data/ulib/ timestamps and keep a backup.

You locked yourself out after editing `groups.txt` by hand. A missing brace or quote makes ULib discard the file and fall back to defaults, leaving nobody with rights. Stop the server, restore the file from a backup or fix the syntax, start again, and use ulx adduserid from the console if you still have no rights.

An addon's admin feature is missing for staff. It registered a CAMI privilege that only superadmin has by default. Find it in XGUI's permissions list or SAM's rank editor and grant it to the right group.

MySQLOO fails to load. Wrong platform or architecture build in lua/bin/. Match the module to the server branch.

FAQ#

Should I use ULX or SAM?

ULX if you run one server, want something free and rely on addons written for ULX. SAM if you run several servers that should share ranks and bans, or want a lighter client menu and are happy to pay for it.

How do I make myself superadmin in ULX?

From the server console, not chat: ulx adduserid <your SteamID> superadmin. In-game commands need permissions you do not have yet.

Can I move from ULX to SAM without losing bans?

Yes, but it is a migration rather than a switch. SAM provides import tools for common admin mods; check its documentation, back up data/ulib and sv.db first, and test on a copy.

Where does ULX store groups and users?

In garrysmod/data/ulib/groups.txt and garrysmod/data/ulib/users.txt. ULX settings are in garrysmod/data/ulx/config.txt, and recent ULib versions store bans in garrysmod/sv.db.

Why can my moderators kick admins?

Because nothing stops them by default. Use ulx setgroupcantarget moderator !%moderator so moderators cannot target their own group or anyone above it.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000