Requirements
Operating system
| Distribution | Versions |
|---|---|
| AlmaLinux | 8, 9, 10 |
| Rocky Linux | 9, 10 |
The installer refuses to run on anything else. Install on a clean server: the panel manages web, mail, DNS, FTP, databases and the firewall itself and does not coexist with another control panel.
Debian/Ubuntu is a separate branch and is Coming soon. Windows Server is not supported.
Hardware
These are practical guidelines, not enforced limits:
- 2 vCPU and 4 GB RAM as a comfortable minimum for a small node. ClamAV (mail antivirus, on by default) keeps roughly 1.5 GB of RAM resident; it can be turned off per node.
- Disk: whatever your customers need, plus room for backups and restore staging. Home directories live on a filesystem with user quotas (ext4 or XFS; the installer enables them).
- x86_64. The panel ships as one statically linked binary that is identical on all supported distributions.
Network and ports
The installer opens only what the services need. The panel's own firewall is built on nftables; the installer disables firewalld so the two do not fight.
| Port | Protocol | Purpose |
|---|---|---|
| 22 | TCP | SSH / SFTP (always kept open by the firewall) |
| 80, 443 | TCP | Websites |
| 25, 465, 587 | TCP | Mail: incoming, implicit TLS, authenticated submission |
| 143, 993 | TCP | IMAP / IMAPS |
| 110, 995 | TCP | POP3 / POP3S |
| 53 | TCP+UDP | DNS |
| 21 and 30000-30100 | TCP | FTPS and the passive range |
| 2087 | TCP | Admin interface (HTTPS) |
| 2083 | TCP | Client interface (HTTPS) |
| 7000, 7001 | TCP | Cluster only; opened automatically when the node joins a cluster |
Not opened by default: MariaDB/PostgreSQL (3306/5432). Remote database access is an explicit admin decision (see Client guide).
Ports from 33000 upward are reserved for things clients deploy (containers). They listen on loopback only and are never opened in the firewall. Everything below 33000 belongs to the node.
DNS and certificates
- Point your server's hostname at the node before installing if you want a real certificate for the panel. Until then the panel uses a self-signed certificate and the browser will warn once.
- Websites get Let's Encrypt certificates over HTTP-01 (webroot). If the zone is served by this node, a wildcard
*.example.complus the bare domain is issued by DNS-01 against the node's own BIND.
Outbound access the node needs
- Package repositories (
dnf, EPEL). license.teraservercloud.comover HTTPS for licenses, updates and the optional PHP packages (see Licensing).- Let's Encrypt.