Ajenti is a lightweight, open source web panel for managing a Linux server from the browser. Ajenti 2 is written in Python and ships with a dashboard, a file manager, a web terminal, a service manager and a package manager, and more plugins can be added from the panel itself. In this tutorial you will install Ajenti 2 on Ubuntu 24.04, log in with a regular sudo user, restrict access to the panel with UFW and replace the self-signed certificate with a Let's Encrypt one.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS (for example, a CubePath VPS) with at least 1 GB of RAM.
- A non-root user with
sudoprivileges and a password set (Ajenti authenticates against the system's accounts). - UFW enabled with SSH allowed.
- Optional, for a trusted certificate: a domain or subdomain such as
panel.your_domainwith a DNS A record pointing toyour_server_ip.
Ajenti also supports Debian 12 and Rocky Linux 9 with the same installer, but the firewall and certificate commands below are written for Ubuntu.
Step 1 - Setting the hostname
The Ajenti installer runs ajenti-ssl-gen, which generates a self-signed certificate for the server's hostname, and shows that name in the panel. Set a meaningful fully qualified hostname before installing. Replace panel.your_domain with your own name:
sudo hostnamectl set-hostname panel.your_domain
Check the result:
hostname -f
panel.your_domain
If hostname -f returns only the short name, add a line to /etc/hosts that maps your server's IP to the full name:
sudo nano /etc/hosts
your_server_ip panel.your_domain panel
Step 2 - Installing Ajenti 2
Ajenti 2 is distributed as Python packages. The project's supported installation method is a script that installs the build dependencies with apt, creates a Python virtual environment in /opt/ajenti, installs the core plugins with pip, writes /etc/ajenti/config.yml, generates a self-signed certificate in /etc/ajenti/ajenti.pem and registers a systemd service.
Download the script first so you can read it before running it as root:
curl -fsSL -o install-ajenti.sh https://raw.githubusercontent.com/ajenti/ajenti/master/scripts/install-venv.sh
less install-ajenti.sh
When you are happy with what it does, run it:
sudo bash install-ajenti.sh
The installation takes a few minutes because some Python modules are compiled. When it finishes, the ajenti service is enabled and started. Confirm that it is running:
sudo systemctl status ajenti --no-pager
● ajenti.service - Ajenti panel
Loaded: loaded (/usr/lib/systemd/system/ajenti.service; enabled; preset: enabled)
Active: active (running) since Thu 2026-09-25 10:12:41 UTC; 20s ago
Ajenti listens on TCP port 8000. Verify it:
sudo ss -tlnp | grep 8000
LISTEN 0 128 0.0.0.0:8000 0.0.0.0:* users:(("python3",pid=4127,fd=6))
If the service is not active, read its log with sudo journalctl -u ajenti -n 50 --no-pager.
Step 3 - Opening the panel port in UFW
Port 8000 is closed while UFW is active. The safest option is to allow it only from the IP address you administer the server from. Replace your_admin_ip with that address:
sudo ufw allow from your_admin_ip to any port 8000 proto tcp
If your IP changes often, you can open the port to everyone with sudo ufw allow 8000/tcp, but then the login form is exposed to the whole Internet, so use a strong password.
Check the rule:
sudo ufw status
Status: active
To Action From
-- ------ ----
OpenSSH ALLOW Anywhere
8000/tcp ALLOW your_admin_ip
Step 4 - Logging in to Ajenti
Open https://your_server_ip:8000 in your browser. The certificate is self-signed, so the browser shows a warning the first time. Accept it to continue; you will replace it in Step 6.
Ajenti 2 has no separate admin account. It uses the os authentication provider, so you log in with a Linux user and its password. Log in with your sudo user. Because allow_sudo is enabled in the default configuration, the panel lets that user elevate to root for administrative tasks: when you open a section that needs root, Ajenti asks for your sudo password again.
After logging in you land on the dashboard with CPU, memory, load and disk widgets. From the left menu you can:
- Services: start, stop and restart systemd units.
- Packages: search, install and remove apt packages.
- File Manager and Notepad: browse the filesystem and edit configuration files.
- Terminal: open a shell in the browser.
- Plugins: install additional official plugins, which Ajenti downloads from PyPI.
Step 5 - Reviewing the configuration file
All panel settings are stored in /etc/ajenti/config.yml. Open it to see the defaults written by the installer:
sudo nano /etc/ajenti/config.yml
The relevant parts look like this:
auth:
allow_sudo: true
emails: {}
provider: os
users_file: /etc/ajenti/users.yml
bind:
host: 0.0.0.0
mode: tcp
port: 8000
max_sessions: 9
name: panel.your_domain
session_max_time: 3600
ssl:
certificate: /etc/ajenti/ajenti.pem
enable: true
Useful changes:
bind.port: move the panel to another port. Remember to update the UFW rule.bind.host: set it to a private IP if you only reach the panel over a private network or VPN.session_max_time: session lifetime in seconds.
After any change, restart the service:
sudo systemctl restart ajenti
Step 6 - Using a Let's Encrypt certificate
A trusted certificate removes the browser warning and protects your login. This step requires that panel.your_domain resolves to your server. Install Certbot:
sudo apt update
sudo apt install certbot
Certbot's standalone mode starts a temporary web server on port 80 to validate the domain, so allow HTTP in UFW:
sudo ufw allow 80/tcp
Request the certificate:
sudo certbot certonly --standalone -d panel.your_domain
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/panel.your_domain/fullchain.pem
Key is saved at: /etc/letsencrypt/live/panel.your_domain/privkey.pem
Ajenti expects a single PEM file that contains both the certificate chain and the private key. Create a deploy hook that builds that file and restarts Ajenti every time Certbot renews the certificate:
sudo nano /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh
#!/usr/bin/env bash
set -euo pipefail
domain="panel.your_domain"
live="/etc/letsencrypt/live/${domain}"
target="/etc/ajenti/${domain}-le.pem"
cat "${live}/fullchain.pem" "${live}/privkey.pem" > "${target}"
chmod 600 "${target}"
systemctl restart ajenti
Make it executable and run it once to create the file:
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh
sudo /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh
Now point Ajenti to the new file. Edit /etc/ajenti/config.yml and change the certificate line in the ssl block:
ssl:
certificate: /etc/ajenti/panel.your_domain-le.pem
enable: true
Restart Ajenti and check that it came back up:
sudo systemctl restart ajenti
sudo systemctl is-active ajenti
active
Open https://panel.your_domain:8000. The browser should now show a valid certificate. Confirm that automatic renewal works with a dry run:
sudo certbot renew --dry-run
NoteCertbot needs port 80 at every renewal because it uses standalone mode. Keep the
80/tcprule, or switch to the webroot method if a web server already runs on this machine.
Troubleshooting
- The page does not load: check
sudo systemctl status ajentiandsudo ufw status. If you connect from a different IP than the one you allowed, the connection times out. - "Invalid credentials" with a correct password: the user must have a password set (
sudo passwd your_user). Users that only log in with SSH keys and no password cannot log in to Ajenti. - The service fails after editing
config.yml: YAML is indentation sensitive. Runsudo journalctl -u ajenti -n 50 --no-pagerto see the parsing error, fix it and restart.
Conclusion
You installed Ajenti 2 on Ubuntu 24.04, logged in with a sudo user, limited access to the panel with UFW and served it with a trusted Let's Encrypt certificate. From here, explore the Plugins section to add only the modules you need, keep the server updated with sudo apt update && sudo apt upgrade, and consider reaching the panel only through a VPN or private network so port 8000 never faces the public Internet.
