How to Host Multiple Websites on One VPS
How to host multiple websites on one VPS: vhosts vs Docker vs a control panel, sizing the server, isolating sites, DNS, SSL and a step-by-step setup.
In this guide 9 sections
You can host multiple websites on one VPS in three ways: hand-written Apache or nginx virtual hosts, one Docker container per site, or a hosting control panel that gives every site an isolated account. For a developer with two or three personal projects, manual virtual hosts are fine. For an agency putting client sites on one server, a control panel wins on isolation, SSL, backups and maintenance time. This guide compares the three, sizes the server, and walks through the panel route with Vanta Panel step by step.
Three ways to run several sites on one server
| Approach | Best for | Pros | Cons |
|---|---|---|---|
| Manual Apache/nginx virtual hosts | 1–5 sites you run yourself | No extra software, full control, lightest footprint | All sites share one Linux user unless you build PHP-FPM pools yourself; SSL, DNS, mail, backups and users are separate manual jobs |
| Docker (one container per site) | Developers, apps with unusual stacks | Strong process isolation, reproducible builds, versions pinned per site | Still needs a reverse proxy, certificate automation, volume backups and a database plan; no mail or DNS; nothing for a client to log into |
| Hosting control panel | Agencies, freelancers, anyone hosting for other people | One account per site with its own Linux user, domains, databases, email, SSL and backups; clients get their own login | Another service to keep updated; some panels are licensed per account |
Manual virtual hosts are the classic approach: create a directory and a vhost file per site, enable them and point DNS at the server. For a couple of sites you own it is the simplest option. The pain starts with the third client, when all sites run PHP as the same www-data user, certbot needs a hook per site, and nothing is backed up.
Docker solves isolation well: each site runs in its own container with its own PHP version, and a compromised container cannot read another's files. What Docker does not give you is the hosting layer around it: a reverse proxy, certificate automation, database backups, mail, DNS, and a way for a client to upload a file without learning docker cp.
A control panel packages all of that: each website lives in a hosting account with its own Linux user, virtual host, database prefix, mailboxes, FTP and SSH access, and a login for whoever owns the site. If the category is new to you, what is a web hosting control panel? covers the basics, and why self-host your control panel explains why running one on your own VPS beats shared hosting.
How big a VPS do you need?
It depends on traffic, on how heavy each application is, and on whether you also run mail. A static brochure site uses almost nothing; a WooCommerce store with 40 plugins can fill a server on its own. Treat these as starting points, then measure.
- RAM. Vanta Panel needs about 2 GB to install, including Apache, MariaDB, PHP and the mail stack. Budget roughly 256–512 MB more per small PHP or WordPress site. A 4 GB VPS is a comfortable start for five to ten quiet sites; one or two busy sites can justify 8 GB alone.
- Disk. Add up site files and databases, then multiply by three or four, because backups live on the same disk unless you ship them off-site. The install minimum is about 3 GB; 40 GB is a sane floor for a small multi-site server.
- CPU. Two vCPUs is enough for a handful of PHP sites; CPU rarely becomes the limit before RAM does.
Once sites are live, the resource overview in vWHM shows which accounts use the disk and traffic, so you upgrade on numbers rather than guesses.
Keep the sites isolated from each other
Isolation is the whole point: "one site got hacked" must never become "every site got hacked". A hosting account gives you several layers:
- A separate Linux user per account. Creating an account provisions its own system user, a home directory at
/home/<username>, a document root atpublic_htmland its own Apache vhost. See creating your first hosting account. - A PHP-FPM pool and PHP version per account. Pick PHP 8.1, 8.2, 8.3 or 8.4 per account on the MultiPHP page. Choosing a version moves the account into its own PHP-FPM pool, running as its own user with
open_basedirlocked to its home directory and shell functions such asexecdisabled, so an isolated site cannot read a neighbour'swp-config.php. Read PHP versions and account isolation for exactly which virtual hosts the pool covers before relying on it as a security boundary. - Prefixed databases. Every database and database user is prefixed with the account name, so
acme_shopandbravo_shopnever collide and each account sees only its own databases in phpMyAdmin. See MySQL databases. - Per-account SSH and FTP. Each account authorises its own SSH keys and creates its own FTP users, and the administrator can switch shell access off for any account. See SSH access.
- Packages for limits. Define a package once and assign it, so one client cannot quietly fill the server.
DNS: many domains, one IP address
All sites share one public IP; Apache picks the site from the hostname in the request. What you need is DNS that sends each domain to the server, and there are three options that can be mixed:
- A records at the client's existing DNS host. After creating an account, vWHM shows the two A records (bare domain and
www) to add. - Your own private nameservers. Vanta Panel includes PowerDNS as an authoritative DNS server, so
ns1.yourdomain.comandns2.yourdomain.comanswer from the same VPS. Register glue records once at your registrar, switch on automatic zones, and every new account gets a complete zone; clients just point their domain at your nameservers. See the private nameservers guide. - Cloudflare automation. If a domain already lives on Cloudflare, the panel can create its records through the API.
SSL for a lot of domains
Free Let's Encrypt certificates are issued per hostname from the account's Domains page, so a primary domain, its subdomains and each addon domain get their own certificate. Tick force HTTPS when installing to redirect plain HTTP. Renewal is automatic and a deploy hook reloads Apache afterwards, so fifty certificates need no more attention than one.
HTTP validation needs the domain's DNS already pointing at the server and port 80 reachable, so add DNS records first and issue certificates second. For domains behind Cloudflare's proxy, or for wildcards, switch to DNS validation with a Cloudflare API token, as described in SSL / TLS certificates.
Backups when everything lives on one box
Ten sites on one VPS also means ten sites on one disk, so back up per account and keep copies elsewhere. Each account can schedule daily or weekly backups that bundle its home directory (files, uploads, mail) and a consistent mysqldump of every database into one archive, keeping at least three copies and refusing to run when free space is below 1.2 times the account's size. Because those archives sit on the same disk as the sites, configure the vWHM off-site backup destinations too. The backups doc lists what an archive does not contain: mailbox definitions, cron jobs and DNS zones are panel records rather than files, so record those separately.
Step by step: several sites on one VPS with Vanta Panel
- Install the panel. On a fresh Ubuntu 22.04+ or Debian 12+ VPS with at least 2 GB of RAM and nothing on ports 80/443, run
curl -fsSL https://get.vantapanel.com | sudo bash. It installs Apache, MariaDB, PHP, mail, DNS and the firewall, then prints your admin login. See installing Vanta Panel or the Ubuntu walk-through in how to set up a control panel on Ubuntu. - Set the server identity. In vWHM → Server Setup, give the server a hostname such as
server.yourdomain.com, enter yourns1/ns2nameservers if you want to run DNS yourself, and turn on automatic zone creation. - Create one hosting account per site or client. vWHM → Create Account asks for a username, primary domain, password and optional package, and creates the Linux user, home directory, vhost and vPanel login.
- Add extra domains where they belong. In an account's vPanel → Domains, add subdomains or addon domains when one client owns several sites. Each gets its own document root and certificate.
- Point DNS. Add the A records from the confirmation screen, or set the domain's nameservers to your ns1/ns2.
dig example.com Ashould return your server's IP once propagated. - Install SSL. On the Domains page, click Install SSL with force HTTPS ticked for each hostname.
- Turn on backups. Enable a schedule per account and an off-site destination in vWHM.
Each client then logs into vPanel on their own domain and manages files, email and databases without touching anyone else's site.
What it costs
The licence is per server, never per account. The Free tier covers 1 hosting account, 1 mailbox and 1 database, enough to run your own site plus addon domains. Basic is $5 per server per month for 5 accounts, 5 mailboxes and 5 databases. Unlimited is $10 per server per month with no caps, so a VPS running twenty client sites pays the same licence as one running two. cPanel, by contrast, climbs from $29.99 to $69.99 a month with account count, as broken down in cPanel pricing explained. Current plans are on the pricing page, and if you intend to sell hosting rather than just host it, how to start a web hosting business covers packages, billing and the WHMCS module.
FAQ
How many websites can one VPS host?
There is no fixed number. A 4 GB, 2 vCPU VPS comfortably runs a handful of low-traffic WordPress or PHP sites; heavier sites need more.
Can I host multiple websites in one hosting account?
Yes. One account can hold its primary domain plus subdomains and addon domains, each with its own folder and certificate. Use one account per client when sites belong to different people, so their files, databases and logins stay separate.
Do I need a separate IP address for each website?
No. Apache serves the right site based on the hostname in the request, and certificates are issued per hostname, so any number of domains can share one IPv4 address.
What happens if one site on the server is hacked?
With one Linux user per account and isolated PHP-FPM pools, a compromised site is confined to its own home directory. Restore that account from its backup, and check the firewall and brute-force protection page for repeated attempts against the server.
All guides · Something here out of date or wrong? Tell us and we will fix it.