Skip to content

Installation

These steps turn a fresh Debian 13 server into a complete, working hosting platform — a cluster of one that more servers can join later. Run them as root.

Copy the OPanel package to the server and install it:

Terminal window
apt install ./opanel_*_amd64.deb

On arm64 servers, use the arm64 package.

Before running the installer, give /srv/opanel a filesystem that enforces disk quotas — see Disk quotas below. Without one, the installer warns and continues, but plan disk limits are not enforced.

Terminal window
opanel install --panel-hostname panel.example.com --acme-email ops@example.com

This installs and configures nginx, MariaDB, Valkey and every other package a node needs, creates the platform database and master key, issues the cluster’s internal certificates, and starts every component. It waits up to two minutes for the node to finish applying its first configuration and reports the node is in sync, or lists what isn’t ready yet. Every step, including each database migration, is logged to /var/log/opanel/install.log. Running the command again repairs an existing installation without losing data.

OPanel also takes over the server’s firewall: if ufw or firewalld is active (common on cloud images), the installer disables it once its own nftables rules are in place.

Flag Purpose
--panel-hostname Hostname of the control panel. Point its DNS at this server before or shortly after installing.
--ssh-hostname Hostname customers use for SFTP and SSH (defaults to the panel hostname).
--ssh-port Port of the customer SFTP/SSH gateway (default 2222). Applies to the whole cluster; cannot be changed by re-running the installer.
--brand Name customers see (default opanel).
--acme-email Contact address for the certificate authority.
--support-email Support address shown to customers.
--node-name Name of this server (default: its hostname).
--node-address IP other servers use to reach this one (default: auto-detected). Use the private address if servers share a private network.
--public-ipv4, --public-ipv6 Public addresses of this server, for domain DNS checks.
--admin-cidr Network allowed to reach the server’s own SSH port; repeatable.
--apt-url URL of the OPanel APT repository, if not the default.
--channel Release channel: stable, beta or nightly.
--skip-packages Don’t install Debian packages; they must already be present.
--skip-services Write configuration without starting services.

The installer prints a one-time setup link. It works at the panel hostname once its DNS points at this server (the edge fetches a certificate on first visit), and, until then, at port 7443 of the server’s own address — browsers will warn about its self-signed certificate there, which is expected. Open the link and create your administrator account. See First steps for what to do next.

If the link expires before you use it, generate a new one:

Terminal window
runuser -u opanel -- opanel admin setup-token
Terminal window
opanel doctor

opanel doctor checks every component’s configuration, service, certificate and listeners, plus disk quotas, clock sync, updates and free disk space. Every failing check comes with a suggested fix; run it with --json for monitoring.

Give each web server its own XFS (or quota-enabled ext4) volume for /srv/opanel:

Terminal window
mkfs.xfs /dev/vdb
mkdir -p /srv/opanel
echo "UUID=$(blkid -s UUID -o value /dev/vdb) /srv/opanel xfs defaults,prjquota 0 2" >> /etc/fstab
mount /srv/opanel
findmnt -no FSTYPE,OPTIONS /srv/opanel # confirm prjquota is listed

Without an enforcing filesystem, opanel doctor fails its disk quotas check with filesystem- specific fix instructions, and affected servers show a quota_unenforced problem in the console.

Port Purpose Reachable from
80, 443/tcp, 443/udp Public sites and the panel (HTTP, HTTPS, HTTP/3) Everyone
2222 Customer SFTP/SSH Everyone, on ssh-role servers
22 The server’s own SSH Admin networks (--admin-cidr)
7443 Controller, direct (setup and recovery) Admin networks
7444, 7445, 8080, 3306 Cluster traffic Cluster servers only

To grow beyond one server, create a join token on this one and run the printed command on a fresh Debian 13 server with the opanel package installed — see Cluster.