CyberPanel installation on a fresh VPS: what the guides leave out
The CyberPanel installation takes about five minutes. Every guide on the first page of Google says so, and they’re all correct. What none of them mention is that the five minutes are the easy part. The next forty-five decide whether the box is still yours in six months.
We run CyberPanel on production for eight active client sites. Here’s the sequence we follow on a fresh VPS, including the steps the official installer leaves for you.
Before you run the installer
The docs say 1 GB of RAM is the minimum. Ignore that number. OpenLiteSpeed, MariaDB, Postfix, Dovecot, PowerDNS and pure-ftpd all start at boot, and on a 1 GB box they spend their lives fighting over swap. The install itself can get OOM-killed halfway through and leave you with a half-configured MariaDB, which is a worse place to be than not having started. We don’t build anything under 2 GB. For a single WooCommerce store we start at 4 GB.
Disk: the stated floor is 10 GB. CyberPanel plus a base OS eats about 4-5 GB before you host anything, and the backup directory lands on the same volume by default. We wouldn’t put a real site on less than 40 GB of NVMe.
Set the hostname before the installer runs, not after:
hostnamectl set-hostname panel.yourdomain.com
echo "127.0.1.1 panel.yourdomain.com panel" >> /etc/hosts
Point an A record at the server’s IP first, and set the reverse DNS while you’re in the provider’s panel. Hetzner and DigitalOcean both bury PTR under the server’s networking tab. CyberPanel writes the hostname into its self-signed certificate, and Let’s Encrypt issuance for the panel later depends on that name resolving. Changing it afterwards means re-issuing certs and hand-editing PowerDNS. Two minutes now, or an hour in a fortnight.
For the OS, use Ubuntu 22.04 or 24.04, AlmaLinux 8 or 9, or Rocky. Start from a clean image. The installer assumes nothing else is bound to ports 80, 443, 8090 or 7080, so a VPS that already has nginx or a stray Apache on it will fail in ways that are tedious to unpick.
The install command, and the three choices it asks you
sh <(curl https://cyberpanel.net/install.sh || wget -O - https://cyberpanel.net/install.sh)
Run it as root inside screen or tmux. A dropped SSH session mid-install is how people end up reinstalling the OS.
Three of the prompts matter. The first is OpenLiteSpeed versus LiteSpeed Enterprise. OpenLiteSpeed is free and it’s what we put on every client box. Enterprise gives you .htaccess handling without a restart, plus ESI, plus a licence fee. Unless you’re migrating a site that leans hard on per-directory rewrites, take OpenLiteSpeed. Switching later is possible but it means reinstalling the web server layer, so treat it as a decision rather than a default.
The second is Memcached and Redis. Say yes to Redis. LSCache covers page caching, but WordPress object caching wants Redis, and adding it later means restarting PHP anyway.
The third is the admin password. Older builds shipped with a default of 1234567. Newer ones generate one and print it at the end. Either way, set your own at the prompt and don’t leave it for later. The next section explains why that sentence is doing so much work.
The installer finishes with a banner giving you https://your-ip:8090 and credentials. Most tutorials stop here. Don’t.
Close port 8090 before you do anything else
In October 2024 an unauthenticated remote code execution bug in CyberPanel (CVE-2024-51378) went public. Within days the PSAUX ransomware crew swept roughly 22,000 internet-facing CyberPanel instances and encrypted them. The patch shipped quickly. What made the campaign so effective was that 22,000 admin panels were sitting on a public port, waiting for somebody to knock.
A hosting control panel doesn’t need to be reachable from the entire internet. Restrict 8090 to the addresses that actually use it:
# Ubuntu / ufw
ufw allow from YOUR.OFFICE.IP.ADDR to any port 8090 proto tcp
ufw allow 80,443/tcp
ufw allow 22/tcp
ufw --force enable
# AlmaLinux / firewalld
firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=YOUR.OFFICE.IP.ADDR port port=8090 protocol=tcp accept'
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload
On a dynamic IP, put the panel behind a WireGuard tunnel or a Cloudflare Access policy instead of opening it up. In four years we’ve never had a client who needed to reach the panel from an arbitrary coffee shop badly enough to justify the exposure.
Then update, before the first site goes on:
sh <(curl https://raw.githubusercontent.com/usmannasir/cyberpanel/stable/preUpgrade.sh)
Seven things the installer doesn’t do
This is the list we work through on every build. None of it is in the official knowledge base, and the tutorials currently ranking for this query cover one or two items between them.
- Add swap. Most VPS images ship without any. Two gigabytes on a 4 GB box costs nothing and stops MariaDB getting OOM-killed during a backup run.
fallocate -l 2G /swapfile, chmod 600, mkswap, swapon, then add it to fstab. - Turn on unattended security upgrades:
apt install unattended-upgradeson Debian-family,dnf-automaticon RHEL-family. CyberPanel updates itself on its own schedule. The OS underneath does not. - Send backups off the box. CyberPanel’s backup feature writes to
/home/backup, which is the same disk that ransomware would encrypt. Configure a remote destination (S3, Backblaze, or an rsync target) on day one. A backup that dies with the server isn’t a backup. - Jail the panel login. CyberPanel ships fail2ban, but on some builds the panel login itself has no jail. Run
fail2ban-client statusand add one if 8090 is reachable at all. - Sort out mail DNS. Postfix comes up and will happily send, but nothing has SPF, DKIM or DMARC until you create the records per-domain in the panel. Mail from a fresh VPS with no PTR and no DKIM lands in spam more or less always. Do this before the client sends their first newsletter.
- Pin the PHP version. The default is whatever the build shipped with. Set it per website in the panel, 8.2 or 8.3 for current WordPress, instead of assuming.
- Set up monitoring. Nothing alerts you out of the box. We push disk, RAM and uptime checks to an external monitor, because a server that fails silently is a server you find out about from the client.
What we actually build
Our three standard shapes, at 2026 European provider prices:
| Workload | Spec | Rough monthly | Notes |
|---|---|---|---|
| 1-3 brochure sites | 2 vCPU / 4 GB / 80 GB NVMe | $8-12 | Hetzner CPX21 or equivalent. Comfortable. |
| WooCommerce, moderate traffic | 4 vCPU / 8 GB / 160 GB | $18-30 | Redis object cache on, LSCache tuned per store. |
| Multi-tenant, 10+ sites | 8 vCPU / 16 GB / 320 GB | $45-60 | Needs a separate DB pass. See our CyberPanel MariaDB tuning notes. |
Set that against a managed WordPress plan at $30 a month for one site and the arithmetic looks obvious. What the managed plan buys you is somebody else’s pager, and that’s worth being honest about, because it’s the whole trade. We compared CyberPanel with the incumbent in more detail in CyberPanel vs cPanel.
When CyberPanel is the wrong answer
We don’t put every client on it. Skip CyberPanel if you need reseller billing with WHMCS integration that works out of the box, since cPanel’s ecosystem is still deeper there. Skip it if your team lives in .htaccess and won’t move to OpenLiteSpeed rewrite syntax. Skip it if nobody on the account can SSH into a server, because a control panel narrows the need for a sysadmin without removing it.
And if the site is one low-traffic brochure page, shared hosting at $5 a month is genuinely fine. You’ve saved yourself a server to patch.
Everywhere else, we like it. It’s free, it’s LiteSpeed-backed, and at our traffic levels the resource footprint sits well below nginx plus php-fpm plus a separate caching layer.
If you’d rather not do the forty-five minutes
We build and hand over CyberPanel servers as a fixed-price job: install, harden, firewall, off-box backups, mail DNS, monitoring, and a written runbook. Pricing is on our CyberPanel setup bundle, and the ongoing side lives under CyberPanel support. If the box is already up and you only want the security pass, that’s CyberPanel hardening. Or work through our Linux server hardening checklist yourself.
Once the box is built and hardened, the next question is usually what to put on it. If the answer is an existing cPanel server, read what the cPanel importer leaves behind before you start moving accounts.
Next in the journal
- 30 Aug 2026 Email bounce back: read the code, then fix the cause An email bounce back reads like a mystery and works like a diagnosis. The cause is written into it, in a format nobody ever…
- 26 Aug 2026 Headless WordPress in 2026: when to pick it, and what it costs Everyone selling headless WordPress lists complexity as a drawback and declines to price it. Here is the plugin rebuild list, the second hosting bill,…