Install ZoPanel
Install ZoPanel with one command, choose components and options with flags, run it unattended from cloud-init, and sign in at https://IP:8888.
ZoPanel installs with a single command on a fresh Ubuntu or Debian server. The installer brings the system up to date, sets up the web stack and starts the panel. Check the system requirements first.
Quick install
Connect to the server over SSH as root (or a sudo user) and run:
curl -fsSL https://get.zopanel.net | sudo bash
To pass options, put them after sudo bash -s --:
curl -fsSL https://get.zopanel.net | sudo bash -s -- --php 8.3,8.2 --admin-email you@example.com
The bootstrap script checks the OS and architecture, downloads the release manifest, verifies its Ed25519 signature and the binary's SHA-256 checksum, installs /usr/local/zopanel/bin/zopanel and then runs zopanel setup with your options.
What the installer does
The installer prints each step as it runs:
- Checking system: supported OS and architecture, RAM, and no other web server or control panel.
- Updating the system:
apt updateand a full upgrade of all packages, retried up to 3 times. It then turns on automatic security updates (unattended-upgrades) and handles the kernel (see below). - Installing packages: nginx, MariaDB, UFW, Fail2ban, quota tools, OpenSSH and the PHP repository (ondrej PPA on Ubuntu, packages.sury.org on Debian).
- Installing PHP: the versions from
--php, plus wp-cli. - Installing language runtimes: Node.js 22, Composer and Python by default.
- Creating users and directories: the
zopanelsystem user and the hosting groups. - Configuring nginx, MariaDB (buffer pool at 20% of RAM, swap on small servers) and SFTP (chrooted).
- Configuring firewall and fail2ban: UFW with your SSH port, 80, 443 and 8888 open; Fail2ban for SSH and the panel login.
- Enabling disk quotas and hiding processes between accounts.
- Installing ZoPanel: configuration, a self-signed certificate, the first administrator, a
Defaultpackage and thezopanelandzopanel-agentservices.
Optional components and a license key are then queued for the panel, which installs or activates them in the background after it starts.
The installer is safe to run again: it repairs the configuration without touching your data, and keeps existing administrator accounts.
Kernel handling
ZoPanel can compress customers' idle memory in RAM on Linux 6.8 or newer. If the running kernel is older:
| System | What happens |
|---|---|
| Ubuntu 22.04 | Ubuntu's HWE kernel (linux-generic-hwe-22.04) is installed by default |
| Debian 12 | The installer asks whether to install the 6.12 backports kernel (default: no). It is outside Debian's security support. |
| Ubuntu 24.04, Debian 13 | Already on a 6.8+ kernel: nothing to do |
| Containers | The host's kernel is used: nothing to do |
You can change your mind later: the Tuning page shows the command to install a newer kernel.
The restart question
When a new kernel or system libraries need a restart, the installer asks once, near the start:
A restart is needed to finish (new kernel or system libraries). Restart automatically
when the installation is done? [Y/n]
If you answer yes, the server restarts 15 seconds after the installer finishes and ZoPanel starts by itself. Queued components are installed after the restart. If you answer no, restart later with reboot to finish the update.
Installer options
| Flag | Default | What it does |
|---|---|---|
--profile web|full |
web |
web: the web stack only. full: also mail, webmail, calendars & contacts, DNS, WAF, Apache (.htaccess), FTP, PostgreSQL, Adminer and Docker. |
--with LIST |
none | Extra components, comma separated: mail, webmail, dav, dns, waf, apache, ftp, postgres, mongo, adminer, docker, storage. |
--php VERSIONS |
8.3 |
PHP versions to install, comma separated (7.4 to 8.4). The first becomes the default. |
--admin-user NAME |
admin |
Login name of the first administrator. |
--admin-email EMAIL |
none | Administrator email, used for Let's Encrypt and notifications. |
--hostname HOST |
system hostname | Server hostname. |
--mail-hostname HOST |
none | Mail server hostname, needed for mail and webmail. If omitted and --hostname has at least three labels (like srv1.example.com), that hostname is used. |
--nameservers LIST |
none | Nameservers for the DNS server, needed for dns. |
--license KEY |
none | License key to activate once the panel runs. |
--runtimes LIST |
node22,composer,python |
Language runtimes to install (node<major>, go, python, composer). |
--yes |
off | Ask nothing; defaults apply. No restart unless --reboot is also given. |
--reboot |
off | Restart automatically at the end when a restart is needed. |
--no-reboot |
off | Never restart; just say when a restart is needed. |
--keep-kernel |
off | Never install a newer kernel. |
--kernel-backports |
off | Debian 12: install the 6.12 backports kernel without asking. |
--no-os-upgrade |
off | Leave the system packages as they are (also skips automatic security updates and the kernel). |
--force |
off | Continue on an unsupported system or one with another web server. |
Notes:
--rebootand--no-rebootcannot be used together.- If
mail/webmailis chosen without a mail hostname, ordnswithout nameservers, that component is skipped with a message; install it later from Components. - To keep secrets out of the process list, pass the license as
ZOPANEL_LICENSE_KEYand a chosen admin password asZOPANEL_ADMIN_PASSWORDinstead of flags. Without a password, a random one is generated. - Without a terminal, questions take their default answer.
Examples
A full server with mail and DNS:
curl -fsSL https://get.zopanel.net | sudo bash -s -- \
--profile full \
--hostname srv1.example.com \
--admin-email admin@example.com \
--mail-hostname mail.example.com \
--nameservers ns1.example.com,ns2.example.com
Two PHP versions and a license:
curl -fsSL https://get.zopanel.net | sudo bash -s -- --php 8.3,8.2 --license ZP-XXXX-XXXX-XXXX
Unattended install (cloud-init)
Use --yes so nothing is asked, and decide the restart with --reboot or --no-reboot:
#cloud-config
runcmd:
- curl -fsSL https://get.zopanel.net | ZOPANEL_LICENSE_KEY=ZP-XXXX-XXXX-XXXX bash -s -- --yes --reboot --admin-email admin@example.com
cloud-init already runs as root, so sudo is not needed. The generated admin password is printed in the installer output, which cloud-init writes to its log (usually /var/log/cloud-init-output.log). Reset it at any time with zopanel ctl reset-password admin.
When it finishes
The installer prints the address and the first login:
ZoPanel is ready!
URL: https://203.0.113.10:8888
Username: admin
Password: ••••••••••••••••
Save this password now — it is not stored anywhere in plain text.
The certificate is self-signed until you set a panel domain in Settings.
Open the URL in your browser, accept the self-signed certificate warning once, and sign in. Then follow the Quick start.
If something goes wrong
- Run
zopanel ctl doctorto check the server and see how to fix what is wrong. - Lost the password:
zopanel ctl reset-password admin. - Locked out by the panel IP restriction:
zopanel ctl allow-ip --clear. - A failed step can be retried by running the installer again.