Installation

Before you start

  • A clean AlmaLinux 8/9/10 or Rocky Linux 9/10 server, with root access (see Requirements).
  • The server's hostname resolving to its public IP, if you want a real panel certificate.
  • Keep another SSH session open while the installer configures the firewall.

Run the installer

The installer is a single Bash script. It is idempotent: running it again on a working node updates it without wiping configuration.

curl -fsSLO https://license.teraservercloud.com/artefactos/instalar.sh
sudo bash instalar.sh -artefacto <panel-package>.tar.gz

<panel-package>.tar.gz is the signed release package that matches the script. The script carries the provider's public key and the package checksum, and refuses to continue if the package does not match. After this first install, every update is verified by the panel binary itself with an Ed25519 signature.

Environment variables

Defaults are the ones the market expects; override only if you must.

VariableDefaultMeaning
PUERTO_ADMIN2087Admin interface port
PUERTO_CLIENTE2083Client interface port
FTP_PASIVO_DESDE / FTP_PASIVO_HASTA30000 / 30100FTP passive port range
MODO_CLUSTER(empty = standalone)master to found a cluster, slave to join one (see Clustering)
NODO_ID, ANUNCIADA_CLUSTERhostname / <host>:7000Node name and address other nodes use to reach it
PAQUETE_CLUSTERJoin package from the founder, for unattended slave installs

When run from a terminal, the installer asks one question: standalone (default), found a new cluster, or join an existing one. Without a terminal it installs a standalone node and asks nothing.

What gets installed

  • The panel binary in /usr/local/bin, its signed modules in /usr/share/controlpanel/modules, and its state in /var/lib/controlpanel.
  • Web: Apache (default edge), plus nginx and OpenLiteSpeed support; PHP-FPM; ModSecurity with the OWASP ruleset where packaged.
  • Mail: Postfix, Dovecot, Rspamd, ClamAV, Roundcube webmail, a local unbound resolver (needed by the spam filter).
  • DNS: BIND (authoritative only, no recursion).
  • FTP: Pure-FTPd with TLS required.
  • Databases: MariaDB and PostgreSQL, phpMyAdmin and phpPgAdmin.
  • Firewall: nftables managed by the panel. firewalld is disabled, not removed.
  • Disk quotas enabled on the filesystem that holds /home.
  • restic and rclone (checksum-pinned) for backups.
  • SELinux is set to disabled on hosting nodes (a reboot completes the change); the isolation between customers does not depend on it. See Security model.

The installer ends by checking that the panel service is actually serving and that SSH is still open in the new firewall ruleset. If either fails the installation fails loudly instead of leaving a half-working node.

First login

At the end of the installation the installer prints, once:

  • the user admin,
  • a generated password,
  • the second-factor secret (TOTP) and one-time recovery codes.

Copy them immediately; they are not shown again. Open https://<your-hostname>:2087, enter the password and the 6-digit code from your authenticator app.

The second factor is mandatory for admins and resellers and optional for clients. The panel's certificate is self-signed until you issue a real one for the panel's hostname, so the browser warns on the first visit.

Client accounts use https://<your-hostname>:2083.

First steps

From the admin interface (Accounts → New account) or from the CLI on the server:

panel cliente-crear acme
panel sitio-crear acme example.com www.example.com
panel estado

Next, read Admin guide to set up services, the firewall and updates, and Licensing if you want paid features.

Updating

The panel updates itself on request, never silently. See Updates in the Admin guide.

Uninstalling

There is no automated uninstaller. The panel is a set of ordinary packages and files on the server; plan a rebuild rather than an in-place removal.