# Install ZoPanel

> Install ZoPanel with one command, choose components and options with flags, run it unattended from cloud-init, and sign in at https://IP:8888.

Source: https://zopanel.net/docs/install  
Updated: 2026-10-07

ZoPanel installs with a single command on a fresh Ubuntu or Debian server. The installer brings the system up to date, sets up the web stack and starts the panel. Check the [system requirements](/docs/requirements) first.

## Quick install

Connect to the server over SSH as root (or a sudo user) and run:

```bash
curl -fsSL https://get.zopanel.net | sudo bash
```

To pass options, put them after `sudo bash -s --`:

```bash
curl -fsSL https://get.zopanel.net | sudo bash -s -- --php 8.3,8.2 --admin-email you@example.com
```

The bootstrap script checks the OS and architecture, downloads the release manifest, verifies its Ed25519 signature and the binary's SHA-256 checksum, installs `/usr/local/zopanel/bin/zopanel` and then runs `zopanel setup` with your options.

## What the installer does

The installer prints each step as it runs:

1. **Checking system**: supported OS and architecture, RAM, and no other web server or control panel.
2. **Updating the system**: `apt update` and a full upgrade of all packages, retried up to 3 times. It then turns on **automatic security updates** (unattended-upgrades) and handles the kernel (see below).
3. **Installing packages**: nginx, MariaDB, UFW, Fail2ban, quota tools, OpenSSH and the PHP repository (ondrej PPA on Ubuntu, packages.sury.org on Debian).
4. **Installing PHP**: the versions from `--php`, plus wp-cli.
5. **Installing language runtimes**: Node.js 22, Composer and Python by default.
6. **Creating users and directories**: the `zopanel` system user and the hosting groups.
7. **Configuring nginx**, **MariaDB** (buffer pool at 20% of RAM, swap on small servers) and **SFTP** (chrooted).
8. **Configuring firewall and fail2ban**: UFW with your SSH port, 80, 443 and 8888 open; Fail2ban for SSH and the panel login.
9. **Enabling disk quotas** and **hiding processes between accounts**.
10. **Installing ZoPanel**: configuration, a self-signed certificate, the first administrator, a `Default` package and the `zopanel` and `zopanel-agent` services.

Optional components and a license key are then queued for the panel, which installs or activates them in the background after it starts.

The installer is safe to run again: it repairs the configuration without touching your data, and keeps existing administrator accounts.

### Kernel handling

ZoPanel can compress customers' idle memory in RAM on Linux 6.8 or newer. If the running kernel is older:

| System | What happens |
| --- | --- |
| Ubuntu 22.04 | Ubuntu's HWE kernel (`linux-generic-hwe-22.04`) is installed by default |
| Debian 12 | The installer asks whether to install the 6.12 backports kernel (default: no). It is outside Debian's security support. |
| Ubuntu 24.04, Debian 13 | Already on a 6.8+ kernel: nothing to do |
| Containers | The host's kernel is used: nothing to do |

You can change your mind later: the **Tuning** page shows the command to install a newer kernel.

### The restart question

When a new kernel or system libraries need a restart, the installer asks **once, near the start**:

```text
A restart is needed to finish (new kernel or system libraries). Restart automatically
when the installation is done? [Y/n]
```

If you answer yes, the server restarts 15 seconds after the installer finishes and ZoPanel starts by itself. Queued components are installed after the restart. If you answer no, restart later with `reboot` to finish the update.

## Installer options

| Flag | Default | What it does |
| --- | --- | --- |
| `--profile web\|full` | `web` | `web`: the web stack only. `full`: also mail, webmail, calendars & contacts, DNS, WAF, Apache (.htaccess), FTP, PostgreSQL, Adminer and Docker. |
| `--with LIST` | none | Extra components, comma separated: `mail`, `webmail`, `dav`, `dns`, `waf`, `apache`, `ftp`, `postgres`, `mongo`, `adminer`, `docker`, `storage`. |
| `--php VERSIONS` | `8.3` | PHP versions to install, comma separated (7.4 to 8.4). The first becomes the default. |
| `--admin-user NAME` | `admin` | Login name of the first administrator. |
| `--admin-email EMAIL` | none | Administrator email, used for Let's Encrypt and notifications. |
| `--hostname HOST` | system hostname | Server hostname. |
| `--mail-hostname HOST` | none | Mail server hostname, needed for `mail` and `webmail`. If omitted and `--hostname` has at least three labels (like `srv1.example.com`), that hostname is used. |
| `--nameservers LIST` | none | Nameservers for the DNS server, needed for `dns`. |
| `--license KEY` | none | License key to activate once the panel runs. |
| `--runtimes LIST` | `node22,composer,python` | Language runtimes to install (`node<major>`, `go`, `python`, `composer`). |
| `--yes` | off | Ask nothing; defaults apply. No restart unless `--reboot` is also given. |
| `--reboot` | off | Restart automatically at the end when a restart is needed. |
| `--no-reboot` | off | Never restart; just say when a restart is needed. |
| `--keep-kernel` | off | Never install a newer kernel. |
| `--kernel-backports` | off | Debian 12: install the 6.12 backports kernel without asking. |
| `--no-os-upgrade` | off | Leave the system packages as they are (also skips automatic security updates and the kernel). |
| `--force` | off | Continue on an unsupported system or one with another web server. |

Notes:

- `--reboot` and `--no-reboot` cannot be used together.
- If `mail`/`webmail` is chosen without a mail hostname, or `dns` without nameservers, that component is skipped with a message; install it later from **Components**.
- To keep secrets out of the process list, pass the license as `ZOPANEL_LICENSE_KEY` and a chosen admin password as `ZOPANEL_ADMIN_PASSWORD` instead of flags. Without a password, a random one is generated.
- Without a terminal, questions take their default answer.

### Examples

A full server with mail and DNS:

```bash
curl -fsSL https://get.zopanel.net | sudo bash -s -- \
  --profile full \
  --hostname srv1.example.com \
  --admin-email admin@example.com \
  --mail-hostname mail.example.com \
  --nameservers ns1.example.com,ns2.example.com
```

Two PHP versions and a license:

```bash
curl -fsSL https://get.zopanel.net | sudo bash -s -- --php 8.3,8.2 --license ZP-XXXX-XXXX-XXXX
```

## Unattended install (cloud-init)

Use `--yes` so nothing is asked, and decide the restart with `--reboot` or `--no-reboot`:

```yaml
#cloud-config
runcmd:
  - curl -fsSL https://get.zopanel.net | ZOPANEL_LICENSE_KEY=ZP-XXXX-XXXX-XXXX bash -s -- --yes --reboot --admin-email admin@example.com
```

cloud-init already runs as root, so `sudo` is not needed. The generated admin password is printed in the installer output, which cloud-init writes to its log (usually `/var/log/cloud-init-output.log`). Reset it at any time with `zopanel ctl reset-password admin`.

## When it finishes

The installer prints the address and the first login:

```text
 ZoPanel is ready!

  URL:      https://203.0.113.10:8888
  Username: admin
  Password: ••••••••••••••••

  Save this password now — it is not stored anywhere in plain text.
  The certificate is self-signed until you set a panel domain in Settings.
```

Open the URL in your browser, accept the self-signed certificate warning once, and sign in. Then follow the [Quick start](/docs/quick-start).

### If something goes wrong

- Run `zopanel ctl doctor` to check the server and see how to fix what is wrong.
- Lost the password: `zopanel ctl reset-password admin`.
- Locked out by the panel IP restriction: `zopanel ctl allow-ip --clear`.
- A failed step can be retried by running the installer again.
