Installation
These steps turn a fresh Debian 13 server into a complete, working hosting platform — a cluster of one that more servers can join later. Run them as root.
1. Install the package
Section titled “1. Install the package”Copy the OPanel package to the server and install it:
apt install ./opanel_*_amd64.debOn arm64 servers, use the arm64 package.
2. Prepare storage
Section titled “2. Prepare storage”Before running the installer, give /srv/opanel a filesystem that enforces disk quotas — see
Disk quotas below. Without one, the installer warns and continues, but plan disk
limits are not enforced.
3. Run the installer
Section titled “3. Run the installer”opanel install --panel-hostname panel.example.com --acme-email ops@example.comThis installs and configures nginx, MariaDB, Valkey and every other package a node needs, creates
the platform database and master key, issues the cluster’s internal certificates, and starts every
component. It waits up to two minutes for the node to finish applying its first configuration and
reports the node is in sync, or lists what isn’t ready yet. Every step, including each database
migration, is logged to /var/log/opanel/install.log. Running the command again repairs an
existing installation without losing data.
OPanel also takes over the server’s firewall: if ufw or firewalld is active (common on cloud
images), the installer disables it once its own nftables rules are in place.
| Flag | Purpose |
|---|---|
--panel-hostname |
Hostname of the control panel. Point its DNS at this server before or shortly after installing. |
--ssh-hostname |
Hostname customers use for SFTP and SSH (defaults to the panel hostname). |
--ssh-port |
Port of the customer SFTP/SSH gateway (default 2222). Applies to the whole cluster; cannot be changed by re-running the installer. |
--brand |
Name customers see (default opanel). |
--acme-email |
Contact address for the certificate authority. |
--support-email |
Support address shown to customers. |
--node-name |
Name of this server (default: its hostname). |
--node-address |
IP other servers use to reach this one (default: auto-detected). Use the private address if servers share a private network. |
--public-ipv4, --public-ipv6 |
Public addresses of this server, for domain DNS checks. |
--admin-cidr |
Network allowed to reach the server’s own SSH port; repeatable. |
--apt-url |
URL of the OPanel APT repository, if not the default. |
--channel |
Release channel: stable, beta or nightly. |
--skip-packages |
Don’t install Debian packages; they must already be present. |
--skip-services |
Write configuration without starting services. |
4. Create the first administrator
Section titled “4. Create the first administrator”The installer prints a one-time setup link. It works at the panel hostname once its DNS points at
this server (the edge fetches a certificate on first visit), and, until then, at port 7443 of the
server’s own address — browsers will warn about its self-signed certificate there, which is
expected. Open the link and create your administrator account. See
First steps for what to do next.
If the link expires before you use it, generate a new one:
runuser -u opanel -- opanel admin setup-token5. Check the result
Section titled “5. Check the result”opanel doctoropanel doctor checks every component’s configuration, service, certificate and listeners, plus
disk quotas, clock sync, updates and free disk space. Every failing check comes with a suggested
fix; run it with --json for monitoring.
Disk quotas
Section titled “Disk quotas”Give each web server its own XFS (or quota-enabled ext4) volume for /srv/opanel:
mkfs.xfs /dev/vdbmkdir -p /srv/opanelecho "UUID=$(blkid -s UUID -o value /dev/vdb) /srv/opanel xfs defaults,prjquota 0 2" >> /etc/fstabmount /srv/opanelfindmnt -no FSTYPE,OPTIONS /srv/opanel # confirm prjquota is listedWithout an enforcing filesystem, opanel doctor fails its disk quotas check with filesystem-
specific fix instructions, and affected servers show a quota_unenforced problem in the console.
| Port | Purpose | Reachable from |
|---|---|---|
| 80, 443/tcp, 443/udp | Public sites and the panel (HTTP, HTTPS, HTTP/3) | Everyone |
| 2222 | Customer SFTP/SSH | Everyone, on ssh-role servers |
| 22 | The server’s own SSH | Admin networks (--admin-cidr) |
| 7443 | Controller, direct (setup and recovery) | Admin networks |
| 7444, 7445, 8080, 3306 | Cluster traffic | Cluster servers only |
Adding more servers
Section titled “Adding more servers”To grow beyond one server, create a join token on this one and run the printed command on a fresh
Debian 13 server with the opanel package installed — see
Cluster.