Skip to content

Requirements

OPanel runs on Debian 13 “trixie” only, on amd64 or arm64. Install on a fresh server: no existing web server, control panel or conflicting package. opanel install checks for this and refuses to run over one.

Each server needs:

  • systemd and cgroup v2 (the default on Debian 13).
  • Root access, at least for the initial install.
  • A stable IP address other servers and customers can reach it at.

There is no hard minimum, but keep in mind what runs on a web server: nginx, MariaDB (or just its client in a cluster), Valkey, and one PHP-FPM master per site. OPanel is deliberately light on idle sites — PHP sleep stops the PHP-FPM master of a site with no recent traffic, so a small server can hold many quiet sites without paying for their memory. Size a server the way you would any hosting box: by how many active sites and how much traffic you expect it to carry, not by a fixed per-site allowance.

Disk and inode limits on plans are enforced as project quotas on the filesystem that holds /srv/opanel, where site files live. This works on:

  • XFS, mounted with prjquota, or
  • ext4 with the project and quota features, mounted with prjquota.

On any other filesystem — including the ext4 root filesystem of a stock Debian install — quotas do nothing, and a single site can fill the disk. Give each web server a dedicated volume for /srv/opanel before installing:

Terminal window
mkfs.xfs /dev/vdb
mkdir -p /srv/opanel
echo "UUID=$(blkid -s UUID -o value /dev/vdb) /srv/opanel xfs defaults,prjquota 0 2" >> /etc/fstab
mount /srv/opanel

Full details, including how to enable project quotas on a root filesystem, are in Installation.

  • A public IPv4 address for every server with the edge role (IPv6 is supported alongside it). Point your panel hostname and customer domains at these addresses.
  • DNS control over the hostname you’ll use for the control panel (for example panel.example.com) and, ideally, a separate hostname for SFTP/SSH.
  • A private network between servers, if you plan to cluster. Traffic between edges and web servers is not encrypted, so keep it off the public internet — a VPC or private network from your provider is enough.
Port Used for Reachable from
80, 443 (tcp), 443 (udp) Public sites and the panel, over HTTP, HTTPS and HTTP/3 Everyone
2222 Customer SFTP and SSH Everyone (servers with the ssh role)
22 The server’s own SSH, for operators Admin networks only
7443 The controller directly, for setup and recovery Admin networks only
7444, 7445, 8080, 3306 Cluster traffic between servers Cluster servers only

OPanel manages an nftables firewall that opens exactly these ports for each server’s roles; see Security. If a cloud image ships with ufw or firewalld enabled, the installer turns it off once its own firewall is in place.

Section titled “Email and payments (optional, but recommended before going live)”

Not requirements for installing, but you’ll want them within the first hour: an SMTP relay for transactional email, and a Stripe account if you’re using OPanel’s built-in billing. Both are covered in First steps.