CLI reference
The opanel binary is a single executable; each daemon is a subcommand run by its own systemd
unit, and a handful of subcommands are for operators. Every command accepts --log-level and
--log-format from the root command.
opanel install
Section titled “opanel install”Installs and starts every component on this server, turning it into a complete platform (a cluster of one). Run as root on a fresh Debian 13 server; running it again repairs an existing installation without losing data.
opanel install --panel-hostname panel.example.com --acme-email ops@example.com| Flag | Purpose |
|---|---|
--brand |
Name customers see (default opanel) |
--panel-hostname |
Hostname of the control panel |
--ssh-hostname |
Hostname for customer SFTP/SSH (default: the panel hostname) |
--acme-email |
Contact address for the certificate authority |
--support-email |
Support address shown to customers |
--node-name |
Name of this server (default: its hostname) |
--node-address |
IP other servers use to reach this one (default: detected) |
--public-ipv4, --public-ipv6 |
Public addresses of this server |
--ssh-port |
Port of the customer SFTP/SSH gateway (default 2222); cluster-wide, fixed after first install |
--admin-cidr |
Network allowed to reach the server’s own SSH port (repeatable) |
--apt-url |
URL of the OPanel APT repository |
--channel |
Release channel: stable, beta or nightly |
--skip-packages |
Don’t install Debian packages; they must already be present |
--skip-services |
Write configuration without starting services |
opanel join
Section titled “opanel join”Adds this server to an existing cluster with the roles of a join token created by
opanel cluster token create. Run as root; running it again on a server that already joined
repairs it without needing a token.
opanel join --controller 10.0.0.1:7444 --token opj_... --ca-sha256 <fingerprint>| Flag | Purpose |
|---|---|
--controller |
host:port of a controller’s cluster API |
--token |
One-time join token from opanel cluster token create |
--ca-sha256 |
SHA-256 fingerprint of the cluster CA the controller must present |
--node-name |
Name of this server in the cluster |
--node-address |
Address other servers reach this one at |
--public-ipv4, --public-ipv6 |
Public addresses, if this server has them |
--apt-url |
URL of the OPanel APT repository |
--channel |
Release channel: stable, beta or nightly |
--skip-packages |
Don’t install Debian packages |
--skip-services |
Write configuration without starting services |
opanel cluster
Section titled “opanel cluster”Commands for adding servers, run on a controller server.
opanel cluster token create
Section titled “opanel cluster token create”Creates a one-time join token and prints the opanel join command to run on the new server.
opanel cluster token create --roles web,edge --pool default --ttl 1h| Flag | Purpose |
|---|---|
--roles |
Roles of the new server: web, edge, ssh, db, cache (comma-separated) |
--pool |
Node pool the server joins, by slug or ID (default default) |
--ttl |
How long the token stays valid, up to 168h (default 1h) |
opanel cluster share-certificates
Section titled “opanel cluster share-certificates”Lets every edge in the cluster serve the same TLS certificates as this server’s edge.
opanel cluster share-certificatesopanel doctor
Section titled “opanel doctor”Checks this server’s installation: every component’s configuration, service, certificate and listeners, plus disk quotas, clock sync, updates and free disk space.
opanel doctoropanel doctor --json| Flag | Purpose |
|---|---|
--json |
Print results as JSON, for monitoring |
Exits non-zero when a check fails.
opanel admin
Section titled “opanel admin”Operator commands for first-time setup and regaining access. Run on a controller server, as the
opanel service account (runuser -u opanel -- opanel admin ...).
opanel admin setup-token
Section titled “opanel admin setup-token”Creates a one-time token/link for creating the first administrator account.
runuser -u opanel -- opanel admin setup-token --ttl 24hopanel admin reset-password
Section titled “opanel admin reset-password”Prints a one-time password reset link for an account.
runuser -u opanel -- opanel admin reset-password --email person@example.comrunuser -u opanel -- opanel admin reset-password --email person@example.com --clear-mfa| Flag | Purpose |
|---|---|
--email |
Email address of the account |
--clear-mfa |
Also remove the account’s authenticator app, passkeys and recovery codes, and sign it out everywhere |
opanel controller / opanel agent / opanel edge / opanel sshgw
Section titled “opanel controller / opanel agent / opanel edge / opanel sshgw”Run the controller, node agent, edge proxy and SSH gateway daemons respectively; each is managed by
its own systemd unit (opanel-controller, opanel-agent, opanel-edge, opanel-sshgw) and takes
--config pointing at its TOML configuration file. Operators don’t normally invoke these directly.
opanel controller --config /etc/opanel/controller.tomlThe controller subcommand also has opanel controller migrate (apply pending database
migrations and exit) and opanel controller openapi (print the public API’s OpenAPI document).
opanel version
Section titled “opanel version”Prints version information.
opanel version