Requirements

Operating system

DistributionVersions
AlmaLinux8, 9, 10
Rocky Linux9, 10

The installer refuses to run on anything else. Install on a clean server: the panel manages web, mail, DNS, FTP, databases and the firewall itself and does not coexist with another control panel.

Debian/Ubuntu is a separate branch and is Coming soon. Windows Server is not supported.

Hardware

These are practical guidelines, not enforced limits:

  • 2 vCPU and 4 GB RAM as a comfortable minimum for a small node. ClamAV (mail antivirus, on by default) keeps roughly 1.5 GB of RAM resident; it can be turned off per node.
  • Disk: whatever your customers need, plus room for backups and restore staging. Home directories live on a filesystem with user quotas (ext4 or XFS; the installer enables them).
  • x86_64. The panel ships as one statically linked binary that is identical on all supported distributions.

Network and ports

The installer opens only what the services need. The panel's own firewall is built on nftables; the installer disables firewalld so the two do not fight.

PortProtocolPurpose
22TCPSSH / SFTP (always kept open by the firewall)
80, 443TCPWebsites
25, 465, 587TCPMail: incoming, implicit TLS, authenticated submission
143, 993TCPIMAP / IMAPS
110, 995TCPPOP3 / POP3S
53TCP+UDPDNS
21 and 30000-30100TCPFTPS and the passive range
2087TCPAdmin interface (HTTPS)
2083TCPClient interface (HTTPS)
7000, 7001TCPCluster only; opened automatically when the node joins a cluster

Not opened by default: MariaDB/PostgreSQL (3306/5432). Remote database access is an explicit admin decision (see Client guide).

Ports from 33000 upward are reserved for things clients deploy (containers). They listen on loopback only and are never opened in the firewall. Everything below 33000 belongs to the node.

DNS and certificates

  • Point your server's hostname at the node before installing if you want a real certificate for the panel. Until then the panel uses a self-signed certificate and the browser will warn once.
  • Websites get Let's Encrypt certificates over HTTP-01 (webroot). If the zone is served by this node, a wildcard *.example.com plus the bare domain is issued by DNS-01 against the node's own BIND.

Outbound access the node needs

  • Package repositories (dnf, EPEL).
  • license.teraservercloud.com over HTTPS for licenses, updates and the optional PHP packages (see Licensing).
  • Let's Encrypt.