Panel settings
A tour of Settings in ZoPanel: panel domain and SSL, allowed IPs, required 2FA, alerts by Telegram, email or webhook, activity log shipping and account retention.
The Settings page holds the server-wide configuration of ZoPanel. Only administrators can open it. It is split into tabs: General, Alerts, Remote backups, License, AI assistant, Hooks, Updates and System. This page covers the settings you are most likely to change; licensing and updates have their own pages.
General
Basic settings
| Setting | What it does |
|---|---|
| Administrator email | Used for Let's Encrypt registration and notifications. Required before you can issue the panel certificate. |
| Default PHP version | The PHP version preselected for new websites. |
| Panel name (white-label) | Shown instead of "ZoPanel". Requires a Business license. |
| Automatic backups | Off, Daily or Weekly (Sunday). Runs at 02:00 server time. |
| Backups to keep per account | 1 to 90. |
| Require two-factor authentication | See below. |
| Send the activity log to | See below. |
| Keep deleted accounts (days) | See below. |
| Let resellers oversell | Off: a reseller's customers together stay within the reseller's own plan (disk and websites). On: each customer is only held to its own package. |
Click Save after changing them.
Require two-factor authentication
Choose who must use 2FA:
| Option | Who |
|---|---|
| Not required | Nobody is forced (default) |
| Administrators and resellers | Every administrator and reseller |
| Everyone | All users, including customers |
Users without 2FA are asked to set it up at their next sign-in, and cannot continue until they do. Each user sets it up under My account → Two-factor authentication with an authenticator app, and gets recovery codes.
If an administrator loses both the phone and the recovery codes, root on the server can turn 2FA off for that user:
zopanel ctl disable-2fa USERNAME
Send the activity log to (remote syslog)
Every entry of the Activity Log can also be sent to a syslog server outside this one. Someone who later takes over this server cannot change that copy.
Enter the target as udp://host:port or tcp://host:port:
udp://logs.example.com:514
Leave the field empty to turn it off. If the syslog server is slow or unreachable, the panel is not held up; the local activity log and the system journal keep every entry.
Keep deleted accounts (days)
When you delete a hosting account, its websites, databases and mailboxes stay recoverable for this many days (0 to 90, default 7). Set 0 to delete everything at once.
Panel domain & SSL
By default the panel uses a self-signed certificate at https://SERVER-IP:8888. To use a trusted certificate:
- Point a domain such as
panel.example.comto the server (A record). - Make sure Administrator email is filled in and saved.
- Enter the domain in Panel domain.
- Click Issue certificate.
A task requests a Let's Encrypt certificate. The panel is then available at https://panel.example.com:8888, and the certificate renews automatically. The same certificate is also used by the mail server and webmail when they are installed.
Restrict panel access
Limit the panel to your own addresses, such as your office or VPN.
-
In Restrict panel access, enter IP addresses or networks in CIDR notation, one per line:
203.0.113.10 198.51.100.0/24 -
Click Save.
Leave the list empty to allow everyone. Include the address you are connecting from, or you will lock yourself out. If that happens, run on the server:
zopanel ctl allow-ip --clear
You can also replace the list with a single address: zopanel ctl allow-ip 203.0.113.10. Both commands restart the panel.
If another ZoPanel server manages this one (central management), add that server's IP to the list.
Alerts
The Alerts tab sends notifications to administrators. Turn on one or more channels:
| Channel | Fields |
|---|---|
| Telegram | Bot token (create a bot with @BotFather) and Chat ID (from @userinfobot) |
| Email (SMTP) | SMTP host, Port, Username, Password, From, To (comma separated) |
| Webhook (Discord / Slack) | Type (Discord, Slack or JSON) and URL |
Then choose the Events that trigger an alert, such as:
- Website down, Service down or restarted, Fleet server unreachable
- SSL expiring soon, SSL renewal failed, Domain expiring soon
- High CPU usage, High memory usage, Disk almost full
- Failed panel logins, Login from a new IP
- Backup failed, Malware detected, Deployment failed
- Mail sending limit reached, Mail queue growing, Server IP on a blocklist
- Update available, Panel update failed or rolled back
Set the thresholds for the resource alerts in CPU %, RAM % and Disk %. Click Save, then Send test to check the channels.
Customers have their own notification settings for their websites, under My account.
Other tabs
| Tab | What it holds |
|---|---|
| Remote backups | Copy every backup to S3-compatible storage (AWS S3, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean, MinIO). Requires a Pro license. |
| License | Plan, limits, activation and offline tokens. See Licensing. |
| AI assistant | An optional assistant that answers questions about websites and the server using live panel data. It needs your own Anthropic API key, and changes only run after the user confirms. |
| Hooks | Event webhooks to your own HTTPS URLs (signed with HMAC-SHA256), and root-owned hook scripts that run after each event. |
| Updates | Version, channel and automatic updates. See Updating ZoPanel. |
| System | Hostname, OS, kernel and component versions; PHP performance; Disk quotas; IP addresses for dedicated IPs per account; and Central management. |
The PHP performance card is described in PHP performance. In Disk quotas, click Enable quotas if the installer could not turn them on; without quotas, disk and file limits are only measured, not enforced.
Settings from the command line
A few settings can be fixed from the server when the panel is not reachable:
| Command | Effect |
|---|---|
zopanel ctl reset-password USER |
Sets a new random password (or --password PASS) and signs the user out everywhere |
zopanel ctl disable-2fa USER |
Turns off 2FA for the user |
zopanel ctl allow-ip IP / --clear |
Replaces or clears the panel IP restriction |
zopanel ctl info |
Version, Server ID, plan, websites and accounts |
zopanel ctl doctor |
Checks the server and says how to fix what is wrong |