Ajenti is a lightweight, open source web panel for managing a Linux server from the browser. Ajenti 2 is written in Python and ships with a dashboard, a file manager, a web terminal, a service manager and a package manager, and more plugins can be added from the panel itself. In this tutorial you will install Ajenti 2 on Ubuntu 24.04, log in with a regular sudo user, restrict access to the panel with UFW and replace the self-signed certificate with a Let's Encrypt one.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS (for example, a CubePath VPS) with at least 1 GB of RAM.
  • A non-root user with sudo privileges and a password set (Ajenti authenticates against the system's accounts).
  • UFW enabled with SSH allowed.
  • Optional, for a trusted certificate: a domain or subdomain such as panel.your_domain with a DNS A record pointing to your_server_ip.

Ajenti also supports Debian 12 and Rocky Linux 9 with the same installer, but the firewall and certificate commands below are written for Ubuntu.

Step 1 - Setting the hostname

The Ajenti installer runs ajenti-ssl-gen, which generates a self-signed certificate for the server's hostname, and shows that name in the panel. Set a meaningful fully qualified hostname before installing. Replace panel.your_domain with your own name:

sudo hostnamectl set-hostname panel.your_domain

Check the result:

hostname -f
panel.your_domain

If hostname -f returns only the short name, add a line to /etc/hosts that maps your server's IP to the full name:

sudo nano /etc/hosts
your_server_ip panel.your_domain panel

Step 2 - Installing Ajenti 2

Ajenti 2 is distributed as Python packages. The project's supported installation method is a script that installs the build dependencies with apt, creates a Python virtual environment in /opt/ajenti, installs the core plugins with pip, writes /etc/ajenti/config.yml, generates a self-signed certificate in /etc/ajenti/ajenti.pem and registers a systemd service.

Download the script first so you can read it before running it as root:

curl -fsSL -o install-ajenti.sh https://raw.githubusercontent.com/ajenti/ajenti/master/scripts/install-venv.sh
less install-ajenti.sh

When you are happy with what it does, run it:

sudo bash install-ajenti.sh

The installation takes a few minutes because some Python modules are compiled. When it finishes, the ajenti service is enabled and started. Confirm that it is running:

sudo systemctl status ajenti --no-pager
● ajenti.service - Ajenti panel
     Loaded: loaded (/usr/lib/systemd/system/ajenti.service; enabled; preset: enabled)
     Active: active (running) since Thu 2026-09-25 10:12:41 UTC; 20s ago

Ajenti listens on TCP port 8000. Verify it:

sudo ss -tlnp | grep 8000
LISTEN 0      128          0.0.0.0:8000      0.0.0.0:*    users:(("python3",pid=4127,fd=6))

If the service is not active, read its log with sudo journalctl -u ajenti -n 50 --no-pager.

Step 3 - Opening the panel port in UFW

Port 8000 is closed while UFW is active. The safest option is to allow it only from the IP address you administer the server from. Replace your_admin_ip with that address:

sudo ufw allow from your_admin_ip to any port 8000 proto tcp

If your IP changes often, you can open the port to everyone with sudo ufw allow 8000/tcp, but then the login form is exposed to the whole Internet, so use a strong password.

Check the rule:

sudo ufw status
Status: active

To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
8000/tcp                   ALLOW       your_admin_ip

Step 4 - Logging in to Ajenti

Open https://your_server_ip:8000 in your browser. The certificate is self-signed, so the browser shows a warning the first time. Accept it to continue; you will replace it in Step 6.

Ajenti 2 has no separate admin account. It uses the os authentication provider, so you log in with a Linux user and its password. Log in with your sudo user. Because allow_sudo is enabled in the default configuration, the panel lets that user elevate to root for administrative tasks: when you open a section that needs root, Ajenti asks for your sudo password again.

After logging in you land on the dashboard with CPU, memory, load and disk widgets. From the left menu you can:

  • Services: start, stop and restart systemd units.
  • Packages: search, install and remove apt packages.
  • File Manager and Notepad: browse the filesystem and edit configuration files.
  • Terminal: open a shell in the browser.
  • Plugins: install additional official plugins, which Ajenti downloads from PyPI.

Step 5 - Reviewing the configuration file

All panel settings are stored in /etc/ajenti/config.yml. Open it to see the defaults written by the installer:

sudo nano /etc/ajenti/config.yml

The relevant parts look like this:

auth:
  allow_sudo: true
  emails: {}
  provider: os
  users_file: /etc/ajenti/users.yml
bind:
  host: 0.0.0.0
  mode: tcp
  port: 8000
max_sessions: 9
name: panel.your_domain
session_max_time: 3600
ssl:
  certificate: /etc/ajenti/ajenti.pem
  enable: true

Useful changes:

  • bind.port: move the panel to another port. Remember to update the UFW rule.
  • bind.host: set it to a private IP if you only reach the panel over a private network or VPN.
  • session_max_time: session lifetime in seconds.

After any change, restart the service:

sudo systemctl restart ajenti

Step 6 - Using a Let's Encrypt certificate

A trusted certificate removes the browser warning and protects your login. This step requires that panel.your_domain resolves to your server. Install Certbot:

sudo apt update
sudo apt install certbot

Certbot's standalone mode starts a temporary web server on port 80 to validate the domain, so allow HTTP in UFW:

sudo ufw allow 80/tcp

Request the certificate:

sudo certbot certonly --standalone -d panel.your_domain
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/panel.your_domain/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/panel.your_domain/privkey.pem

Ajenti expects a single PEM file that contains both the certificate chain and the private key. Create a deploy hook that builds that file and restarts Ajenti every time Certbot renews the certificate:

sudo nano /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh
#!/usr/bin/env bash
set -euo pipefail

domain="panel.your_domain"
live="/etc/letsencrypt/live/${domain}"
target="/etc/ajenti/${domain}-le.pem"

cat "${live}/fullchain.pem" "${live}/privkey.pem" > "${target}"
chmod 600 "${target}"
systemctl restart ajenti

Make it executable and run it once to create the file:

sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh
sudo /etc/letsencrypt/renewal-hooks/deploy/ajenti.sh

Now point Ajenti to the new file. Edit /etc/ajenti/config.yml and change the certificate line in the ssl block:

ssl:
  certificate: /etc/ajenti/panel.your_domain-le.pem
  enable: true

Restart Ajenti and check that it came back up:

sudo systemctl restart ajenti
sudo systemctl is-active ajenti
active

Open https://panel.your_domain:8000. The browser should now show a valid certificate. Confirm that automatic renewal works with a dry run:

sudo certbot renew --dry-run

Troubleshooting

  • The page does not load: check sudo systemctl status ajenti and sudo ufw status. If you connect from a different IP than the one you allowed, the connection times out.
  • "Invalid credentials" with a correct password: the user must have a password set (sudo passwd your_user). Users that only log in with SSH keys and no password cannot log in to Ajenti.
  • The service fails after editing config.yml: YAML is indentation sensitive. Run sudo journalctl -u ajenti -n 50 --no-pager to see the parsing error, fix it and restart.

Conclusion

You installed Ajenti 2 on Ubuntu 24.04, logged in with a sudo user, limited access to the panel with UFW and served it with a trusted Let's Encrypt certificate. From here, explore the Plugins section to add only the modules you need, keep the server updated with sudo apt update && sudo apt upgrade, and consider reaching the panel only through a VPN or private network so port 8000 never faces the public Internet.