Requirements
Operating system
Section titled “Operating system”OPanel runs on Debian 13 “trixie” only, on amd64 or arm64. Install on a fresh server:
no existing web server, control panel or conflicting package. opanel install checks for this and
refuses to run over one.
Each server needs:
- systemd and cgroup v2 (the default on Debian 13).
- Root access, at least for the initial install.
- A stable IP address other servers and customers can reach it at.
Hardware
Section titled “Hardware”There is no hard minimum, but keep in mind what runs on a web server: nginx, MariaDB (or just its client in a cluster), Valkey, and one PHP-FPM master per site. OPanel is deliberately light on idle sites — PHP sleep stops the PHP-FPM master of a site with no recent traffic, so a small server can hold many quiet sites without paying for their memory. Size a server the way you would any hosting box: by how many active sites and how much traffic you expect it to carry, not by a fixed per-site allowance.
Storage: a quota-enforcing volume
Section titled “Storage: a quota-enforcing volume”Disk and inode limits on plans are enforced as project quotas on the filesystem that holds
/srv/opanel, where site files live. This works on:
- XFS, mounted with
prjquota, or - ext4 with the
projectandquotafeatures, mounted withprjquota.
On any other filesystem — including the ext4 root filesystem of a stock Debian install — quotas do
nothing, and a single site can fill the disk. Give each web server a dedicated volume for
/srv/opanel before installing:
mkfs.xfs /dev/vdbmkdir -p /srv/opanelecho "UUID=$(blkid -s UUID -o value /dev/vdb) /srv/opanel xfs defaults,prjquota 0 2" >> /etc/fstabmount /srv/opanelFull details, including how to enable project quotas on a root filesystem, are in Installation.
Networking
Section titled “Networking”- A public IPv4 address for every server with the
edgerole (IPv6 is supported alongside it). Point your panel hostname and customer domains at these addresses. - DNS control over the hostname you’ll use for the control panel (for example
panel.example.com) and, ideally, a separate hostname for SFTP/SSH. - A private network between servers, if you plan to cluster. Traffic between edges and web servers is not encrypted, so keep it off the public internet — a VPC or private network from your provider is enough.
| Port | Used for | Reachable from |
|---|---|---|
| 80, 443 (tcp), 443 (udp) | Public sites and the panel, over HTTP, HTTPS and HTTP/3 | Everyone |
| 2222 | Customer SFTP and SSH | Everyone (servers with the ssh role) |
| 22 | The server’s own SSH, for operators | Admin networks only |
| 7443 | The controller directly, for setup and recovery | Admin networks only |
| 7444, 7445, 8080, 3306 | Cluster traffic between servers | Cluster servers only |
OPanel manages an nftables firewall that opens exactly these ports for each server’s roles; see
Security. If a cloud image ships with ufw or firewalld
enabled, the installer turns it off once its own firewall is in place.
Email and payments (optional, but recommended before going live)
Section titled “Email and payments (optional, but recommended before going live)”Not requirements for installing, but you’ll want them within the first hour: an SMTP relay for transactional email, and a Stripe account if you’re using OPanel’s built-in billing. Both are covered in First steps.