Packages and limits
Create hosting packages in ZoPanel with CPU, memory, disk, inode, I/O, process, mail and PHP limits, and learn how limits are enforced and capped for resellers.
A package is a resource plan you assign to hosting accounts. Every account on a package gets the same limits, enforced by the Linux kernel, so one busy or hacked website cannot take the whole server down. Administrators and resellers manage packages under Packages.
Create or edit a package
- Go to Packages.
- Click New package, or the edit button on an existing one.
- Enter a Package name and set the limits (see the tables below).
- Click Save.
When you edit a package, the new limits are applied at once to every account that uses it, including the PHP settings.
The installer creates a package named Default: 10 websites, 10 databases, 20 cron jobs, 10 GB disk, 100% CPU (one core), 1 GB RAM, 200 processes, PHP memory_limit 256 MB, 10 PHP workers and SFTP on.
Counts
| Field | Limits | 0 means |
|---|---|---|
| Websites | Websites the account can create | Unlimited |
| Databases | Databases | Unlimited |
| Cron Jobs | Scheduled tasks | Unlimited |
| FTP | Extra FTP accounts | Unlimited |
| Mailboxes | Unlimited | |
| Docker apps | Apps the customer may install from the App Store (n8n, Uptime Kuma…). Their memory counts toward the package memory. | None allowed |
| Sub-accounts (resellers) | Customer accounts a reseller on this package may create. Only administrators see this field. | Unlimited |
Resources
| Field | Unit | How it is enforced |
|---|---|---|
| Disk (MB) | MB | Filesystem quota: the account cannot write past it |
| Files (inodes) | Files and folders | Filesystem quota. Needs disk quotas (Settings → System → Disk quotas) |
| CPU (%) | % of one core (100 = one full core, 200 = two cores) | systemd cgroups |
| RAM (MB) | MB, for all the account's websites, apps and PHP together | systemd cgroups |
| Processes | Number of processes | systemd cgroups |
| Disk speed (MB/s) | MB/s of disk throughput | systemd cgroups |
| Database connections | Per database user | MariaDB |
| Emails per hour | Outgoing recipients per hour | Mail server sending limit |
0 means unlimited for these fields, with three exceptions that have an automatic value when left empty:
| Field | Empty (automatic) | -1 |
|---|---|---|
| Disk speed (MB/s) | About 40 MB/s per GB of package RAM (2 GB ≈ 80 MB/s), between 30 and 300 MB/s. Not capped when RAM is unlimited. | Unlimited |
| Database connections | 3 × PHP workers, at least 30 | Unlimited |
| Emails per hour | The server default set in Email → Sending limits | Unlimited |
Without disk quotas, disk and inode usage is only measured, and one account could fill the whole disk. Check that quotas are enforced in Settings → System → Disk quotas.
PHP settings
| Field | What it does |
|---|---|
| PHP memory_limit (MB) | PHP's memory_limit for the account's websites |
| PHP workers | Maximum PHP processes serving requests at the same time for the account |
| PHP always running | The account's PHP never sleeps when idle (see below) |
Each account runs its own isolated PHP-FPM pool per PHP version, inside the account's limits. A website's diagnostics suggest raising PHP workers when too many PHP requests arrive at once; the Tuning page warns when all packages together allow more PHP processes than the RAM can hold.
Website owners can adjust other PHP options for one website in the website's Tools tab, under PHP settings for this website: upload_max_filesize, post_max_size, max_input_vars, max_input_time, session.gc_maxlifetime, date.timezone, short_open_tag and output_buffering. The memory limit always comes from the package.
PHP always running
By default, the PHP of a quiet website stops after an idle time and starts again on the next visit (see PHP performance). Turn on PHP always running for premium plans: the sites' PHP never sleeps, so every visit is as fast as possible. It costs the pool's memory (about 20-60 MB per site) even when nobody visits.
The package list shows each package's PHP mode as Always running or Sleeps when idle.
Access
| Switch | What it allows |
|---|---|
| SFTP | Chrooted SFTP access to the account's home directory |
| Terminal | A sandboxed shell in the browser, limited to the home directory |
Assign a package
Choose the package when you create an account (Accounts → New account → Package), or edit the account later to change it. No package (unlimited) leaves the account without limits; use it only for your own trusted accounts.
Customers see their limits and current usage on the Resources page. Administrators can open the same view for any account from Accounts.
How limits apply
- CPU, RAM, processes and disk speed are cgroup limits on everything the account runs: PHP, apps, cron jobs and shells. A process that goes over the RAM limit is stopped by the kernel inside the account, without touching other accounts.
- Disk and inodes are kernel quotas. When an account is full, writes fail for that account only.
- Database connections are set per database user in MariaDB.
- Emails per hour counts recipients sent through PHP
mail()and SMTP logins. Messages over the limit are refused, which stops a hacked website from getting the server's IP blocklisted. - Counts (websites, databases, mailboxes…) are checked when something is created.
The server's license also limits the total number of accounts, websites and databases across all packages: see Licensing.
Packages for resellers
Resellers (Pro license) create their own packages for their customers. These packages are always held within the reseller's own plan:
- A reseller cannot save a package that gives more than the reseller's own package allows: any count or resource above the reseller's own (websites, disk, CPU, RAM, PHP memory, PHP workers, apps, disk speed, database connections, emails per hour and so on), or SFTP, terminal access or always-on PHP when the reseller's own package does not include them. The panel refuses the package and lists what is not allowed.
- All of a reseller's accounts together stay within the reseller's own websites and disk space, unless the administrator turns on Let resellers oversell in Settings → General. Then each customer is only held to its own package.
- Resellers do not see the Sub-accounts (resellers) field.
When the administrator edits a reseller's package, the customers' packages of that reseller are held to the new limits too.
Resellers cannot use or assign packages that belong to another reseller.