Skip to content

CLI reference

The opanel binary is a single executable; each daemon is a subcommand run by its own systemd unit, and a handful of subcommands are for operators. Every command accepts --log-level and --log-format from the root command.

Installs and starts every component on this server, turning it into a complete platform (a cluster of one). Run as root on a fresh Debian 13 server; running it again repairs an existing installation without losing data.

Terminal window
opanel install --panel-hostname panel.example.com --acme-email ops@example.com
Flag Purpose
--brand Name customers see (default opanel)
--panel-hostname Hostname of the control panel
--ssh-hostname Hostname for customer SFTP/SSH (default: the panel hostname)
--acme-email Contact address for the certificate authority
--support-email Support address shown to customers
--node-name Name of this server (default: its hostname)
--node-address IP other servers use to reach this one (default: detected)
--public-ipv4, --public-ipv6 Public addresses of this server
--ssh-port Port of the customer SFTP/SSH gateway (default 2222); cluster-wide, fixed after first install
--admin-cidr Network allowed to reach the server’s own SSH port (repeatable)
--apt-url URL of the OPanel APT repository
--channel Release channel: stable, beta or nightly
--skip-packages Don’t install Debian packages; they must already be present
--skip-services Write configuration without starting services

Adds this server to an existing cluster with the roles of a join token created by opanel cluster token create. Run as root; running it again on a server that already joined repairs it without needing a token.

Terminal window
opanel join --controller 10.0.0.1:7444 --token opj_... --ca-sha256 <fingerprint>
Flag Purpose
--controller host:port of a controller’s cluster API
--token One-time join token from opanel cluster token create
--ca-sha256 SHA-256 fingerprint of the cluster CA the controller must present
--node-name Name of this server in the cluster
--node-address Address other servers reach this one at
--public-ipv4, --public-ipv6 Public addresses, if this server has them
--apt-url URL of the OPanel APT repository
--channel Release channel: stable, beta or nightly
--skip-packages Don’t install Debian packages
--skip-services Write configuration without starting services

Commands for adding servers, run on a controller server.

Creates a one-time join token and prints the opanel join command to run on the new server.

Terminal window
opanel cluster token create --roles web,edge --pool default --ttl 1h
Flag Purpose
--roles Roles of the new server: web, edge, ssh, db, cache (comma-separated)
--pool Node pool the server joins, by slug or ID (default default)
--ttl How long the token stays valid, up to 168h (default 1h)

Lets every edge in the cluster serve the same TLS certificates as this server’s edge.

Terminal window
opanel cluster share-certificates

Checks this server’s installation: every component’s configuration, service, certificate and listeners, plus disk quotas, clock sync, updates and free disk space.

Terminal window
opanel doctor
opanel doctor --json
Flag Purpose
--json Print results as JSON, for monitoring

Exits non-zero when a check fails.

Operator commands for first-time setup and regaining access. Run on a controller server, as the opanel service account (runuser -u opanel -- opanel admin ...).

Creates a one-time token/link for creating the first administrator account.

Terminal window
runuser -u opanel -- opanel admin setup-token --ttl 24h

Prints a one-time password reset link for an account.

Terminal window
runuser -u opanel -- opanel admin reset-password --email person@example.com
runuser -u opanel -- opanel admin reset-password --email person@example.com --clear-mfa
Flag Purpose
--email Email address of the account
--clear-mfa Also remove the account’s authenticator app, passkeys and recovery codes, and sign it out everywhere

opanel controller / opanel agent / opanel edge / opanel sshgw

Section titled “opanel controller / opanel agent / opanel edge / opanel sshgw”

Run the controller, node agent, edge proxy and SSH gateway daemons respectively; each is managed by its own systemd unit (opanel-controller, opanel-agent, opanel-edge, opanel-sshgw) and takes --config pointing at its TOML configuration file. Operators don’t normally invoke these directly.

Terminal window
opanel controller --config /etc/opanel/controller.toml

The controller subcommand also has opanel controller migrate (apply pending database migrations and exit) and opanel controller openapi (print the public API’s OpenAPI document).

Prints version information.

Terminal window
opanel version