How to Set Up a Web Hosting Control Panel on Ubuntu
Install a web hosting control panel on Ubuntu 22.04/24.04 in one command: prerequisites, what the installer does, first login, first account and fixes.
In this guide 10 sections
On a fresh Ubuntu 22.04 or 24.04 server, setting up a web hosting control panel takes one command and about ten minutes. With Vanta Panel it is curl -fsSL https://get.vantapanel.com | sudo bash; when it finishes you have Apache, MariaDB, PHP, a Postfix/Dovecot mail server, authoritative DNS, a firewall and an admin login at /vwhm/. This guide covers choosing a panel, prerequisites, what the installer does, first login, the first hosting account, common errors and updates.
Which control panel should you install on Ubuntu?
All of the panels below run on Ubuntu 22.04 and 24.04 and install with a script over SSH. What differs is what each ships with and who it is for.
| Panel | Web server | Mail server | DNS server | Login per customer | Licence |
|---|---|---|---|---|---|
| Vanta Panel | Apache + PHP-FPM | Postfix + Dovecot, Roundcube webmail | PowerDNS, private nameservers | Yes (vPanel per account) | Commercial; free for one account, flat fee per server above that |
| HestiaCP | Nginx with Apache or PHP-FPM | Exim + Dovecot | BIND | Yes | Free, GPLv3 open source |
| CyberPanel | OpenLiteSpeed (or LiteSpeed Enterprise) | Postfix + Dovecot | PowerDNS | Yes | Free, open source; paid LiteSpeed licence optional |
| CloudPanel | Nginx + PHP-FPM | None | None | No customer panel (admin and site-user roles) | Free |
| Webmin / Virtualmin | Apache or Nginx | Postfix + Dovecot | BIND | Yes (per virtual server owner) | Free GPL edition; paid Pro edition |
If you host only your own applications and buy email elsewhere, CloudPanel is lean and pleasant. If you host for other people, you need mail, DNS and a per-customer login, which narrows the field to Vanta Panel, HestiaCP, CyberPanel and Virtualmin. HestiaCP is the strongest free choice, as we say plainly in the best cPanel alternatives in 2026. This guide uses Vanta Panel because of its one-command installer, signed automatic updates, first-party WHMCS module and cPanel importer. New to the category? What is a web hosting control panel? explains what these tools do.
Prerequisites
- A fresh server running Ubuntu 22.04 LTS or 24.04 LTS (Debian 12 or newer also works). Ubuntu 20.04 and older ship PHP 7.x, which the panel does not support. Fresh means nothing else installed; mixing the installer with an existing LAMP or mail stack is unsupported.
- 64-bit CPU, x86_64 or arm64.
- At least 2 GB of RAM and 3 GB of free disk for the panel and its services; the sites need more, as discussed in how to host multiple websites on one VPS.
- Root access over SSH.
- Ports 80 and 443 free. The pre-flight check stops the install if nginx, Apache or Caddy is already listening.
- Provider firewall open for 22, 80 and 443; the mail ports (25, 587, 465, 143, 993, 110, 995) if you will host email; and 53 TCP/UDP if you will run private nameservers.
- A hostname and an A record. Pick a subdomain you control, such as
panel.example.com, and point its A record at the server's IP before you start. Optional, but it is what gets you a trusted certificate instead of a browser warning.
Step 1: Prepare the server
Log in and update the base system:
ssh root@your-server-ip
apt update && apt upgrade -yConfirm nothing holds the web ports; this should print nothing:
ss -ltnp | grep -E ':80 |:443 'If it lists nginx or apache2, remove them or, better, start from a clean image.
Step 2: Run the installer
If you set up a hostname, pass it as DOMAIN so the panel and mail server are branded to it:
curl -fsSL https://get.vantapanel.com | sudo DOMAIN=panel.example.com bashWithout a domain, the panel is reached by IP:
curl -fsSL https://get.vantapanel.com | sudo bashWhat happens, in order:
- The bootstrap checks the server can reach the internet, downloads the release and verifies its SHA-256 against the published manifest.
- It verifies a detached Ed25519 signature over the release against a public key pinned inside the installer; if the signature does not verify, the install aborts.
- Pre-flight checks run: OS version, PHP version, CPU architecture, free disk and ports 80/443.
- Apache, MariaDB, PHP and the panel services are installed, then Postfix, Dovecot and SpamAssassin for mail and Roundcube webmail (skippable with
VANTAPANEL_SKIP_MAIL=1andVANTAPANEL_SKIP_WEBMAIL=1), the PowerDNS authoritative DNS engine, firewall rules for the ports the panel needs, and fail2ban. - A self-signed certificate is created so the panel is served over HTTPS from the first minute; once a domain points at the server, a trusted Let's Encrypt certificate replaces it (Step 4).
- The installer prints a banner with your admin URLs, username (default
root) and generated password, and writes the same to/root/vantapanel-install.txt, readable only by root.
The installer is idempotent: if it fails part way, or you want to add a component later, run it again; it never resets your admin account or database password. The full reference, including every environment variable, is in the installation doc.
Step 3: First login at /vwhm/
Open https://panel.example.com/vwhm/ (or https://your-server-ip/vwhm/). The per-account interface, vPanel, is at /vpanel/ on the same address. The panel services bind to localhost and are proxied through Apache, so there is no extra port to open. Sign in with the credentials from the banner. On an IP-only install the browser warns about the self-signed certificate; click through.
Three things to do immediately:
- Change the admin password if you did not set
ADMIN_PASS, and enable two-factor authentication. - In vWHM → Server Setup, set the server hostname (for example
server.example.com) and your private nameservers if you plan to run DNS yourself; the server setup doc explains the glue records to register. - In vWHM → Firewall, confirm ufw is active and fail2ban is reporting. The page cannot lock you out: 22, 80 and 443 are always allowed before the firewall is enabled.
Step 4: Give the panel a trusted certificate
DOMAIN brands the panel and mail hostname; it does not issue a certificate by itself. Point the hostname's A record at the server, then run certbot, which the installer already put in place:
sudo certbot --apache -d panel.example.comCertbot renews it with every other certificate. Behind Cloudflare, proxy the record and set SSL mode to Full (strict), never Flexible, which causes redirect loops. More in SSL / TLS certificates.
Step 5: Create your first hosting account
In vWHM, open Create Account. Enter a username (3–16 lowercase letters and digits, starting with a letter), the primary domain, a password or let one be generated, and optionally a package. One click creates a Linux user, a home directory at /home/<username>, a public_html document root, an Apache vhost and a vPanel login, with HTTPS on a self-signed certificate immediately.
The confirmation screen shows the DNS records to add at the registrar, or the nameservers to set if authoritative DNS is on. Once the domain resolves here, log into vPanel as that account, open Domains, and click Install SSL with force HTTPS ticked. The account can then install WordPress with one click, create databases and mailboxes, and upload files. See your first hosting account.
Without a licence the panel runs one hosting account, one mailbox and one database, enough to host your own site for free. Basic ($5 per server per month) allows five of each; Unlimited ($10 per server per month) removes the caps. See the pricing page; the licence is per server with no per-account fees.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| Installer stops at the port check | Something is already on 80 or 443. Run ss -ltnp to see what, remove it, or reinstall from a clean Ubuntu image. |
| "PHP is too old" | You are on Ubuntu 20.04 or earlier. Reinstall on 22.04 or 24.04, or add the ondrej/php PPA for PHP 8.1+ and re-run the installer. |
| Install fails or services die with little RAM | You are under the 2 GB minimum. Resize the VPS. Skipping mail and webmail with VANTAPANEL_SKIP_MAIL=1 VANTAPANEL_SKIP_WEBMAIL=1 lowers the footprint but does not change the supported minimum. |
| Panel does not load at /vwhm/ | Check the provider's edge firewall for 80/443, then sudo apache2ctl configtest and systemctl status vantapanel-whm vantapanel-user. |
| Lost the admin password | sudo -u paneluser php /opt/vantapanel/bin/vantapanel-admin.php root 'NewPassword' on the server. |
| Sites work but SSL will not issue | The domain's A record does not point here yet, or port 80 is blocked. Behind Cloudflare, grey-cloud the record until the certificate is issued. |
The troubleshooting doc covers more, including 2FA lockouts and mail deliverability.
Keeping the panel and Ubuntu updated
The panel updates itself. Automatic updates are on by default: the server checks the release manifest at most once a day, verifies the vendor's Ed25519 signature and the package's SHA-256, refuses anything older than what is running, backs up the current install to /opt/vantapanel.bak.<timestamp>, applies the new files and emails you the result. To review first, switch it off in vWHM → Updates and use Install when ready. Re-running the install command is also safe, and is the right move when a release needs new system packages. The updating Vanta Panel doc covers rollback.
Ubuntu still needs its own security patches. Enable unattended upgrades so kernel and OpenSSL fixes land without you:
apt install unattended-upgrades
dpkg-reconfigure -plow unattended-upgradesReboot after kernel updates in a quiet hour; hosted sites come back with the services.
Moving from cPanel? How to migrate from cPanel covers the built-in importer. Still deciding whether to run your own panel? Why self-host your control panel makes the case.
FAQ
Is there a free web hosting control panel for Ubuntu?
Yes. HestiaCP, CyberPanel, CloudPanel and Virtualmin GPL are free and open source. Vanta Panel is free for one hosting account, one mailbox and one database per server, with paid plans at $5 and $10 per server per month.
Does the installer work on Ubuntu 24.04?
Yes. Ubuntu 22.04 LTS and newer are supported, including 24.04 LTS, plus Debian 12 and newer. Older releases are refused because their PHP is too old.
Can I install a control panel on a server that already runs nginx or Apache?
Not safely. The pre-flight check refuses to continue if ports 80 or 443 are in use. Use a fresh server and migrate the sites over.
Do I need a domain name before installing?
No. The panel works by IP with a self-signed certificate. A domain pointing at the server gets you a trusted certificate and a proper mail hostname.
All guides · Something here out of date or wrong? Tell us and we will fix it.