CloudPanel is a free control panel for hosting PHP, Node.js, Python and static websites. It installs and manages an NGINX, PHP-FPM, MySQL or MariaDB and Redis stack, and gives each site its own Linux user, virtual host and log files. In this tutorial you will install CloudPanel Community Edition on a fresh Ubuntu 24.04 server, create the administrator account, publish a PHP site with a database and a free TLS certificate, and restrict access to the admin panel.
Prerequisites
To follow this guide you need:
- A freshly installed server running Ubuntu 24.04 LTS (x86_64 or arm64), for example a CubePath VPS, with at least 1 CPU core, 2 GB of RAM and 10 GB of free disk space.
- Root access or a user with
sudoprivileges. - A domain name (
your_domain) with an A record pointing to the server's public IP (your_server_ip), for the site you will host in Step 4.
ImportantCloudPanel must be installed on a clean operating system. The installer configures NGINX, PHP, the database server and the firewall itself, and it will conflict with any web or database server you installed before. Do not install Apache, NGINX or MySQL beforehand.
CloudPanel also supports Ubuntu 22.04, Debian 12 and Debian 11. It does not support RHEL-based distributions.
Step 1 - Preparing the server
Update the package index and installed packages, and make sure curl, wget and sudo are present (the installer uses them):
sudo apt update
sudo apt -y upgrade
sudo apt -y install curl wget sudo
If the upgrade installed a new kernel, reboot before continuing:
sudo reboot
Step 2 - Running the CloudPanel installer
CloudPanel is installed with an official script. Download it first instead of piping it straight into a shell:
curl -sS https://installer.cloudpanel.io/ce/v2/install.sh -o install.sh
The CloudPanel documentation for Ubuntu 24.04 publishes the SHA-256 checksum of the current installer. Copy it from the install page and verify the file, replacing installer_checksum with that value:
echo "installer_checksum install.sh" | sha256sum -c
install.sh: OK
If the check fails, download the script again and do not run it until the checksum matches.
By default the installer sets up MySQL. You can choose a different database engine with the DB_ENGINE variable. For example, to install MariaDB 11.4:
sudo DB_ENGINE=MARIADB_11.4 bash install.sh
Or run it without the variable to keep the default MySQL:
sudo bash install.sh
The installation takes several minutes. When it finishes, the script prints a completion message with the panel URL, https://your_server_ip:8443.
Verify that NGINX is listening on the web ports and the admin port:
sudo ss -tlnp | grep -E ':(80|443|8443) '
LISTEN 0 511 0.0.0.0:80 0.0.0.0:* users:(("nginx",...))
LISTEN 0 511 0.0.0.0:443 0.0.0.0:* users:(("nginx",...))
LISTEN 0 511 0.0.0.0:8443 0.0.0.0:* users:(("nginx",...))
Step 3 - Creating the administrator account
Open https://your_server_ip:8443 in your browser as soon as the installation finishes. The panel uses a self-signed certificate at this point, so accept the browser warning.
WarningThe first visitor to the panel creates the administrator account. Do this immediately after installation so nobody else can claim it.
Fill in the form with your name, email, a user name and a strong password, choose your timezone and click Create User. You are then logged in to the Sites view.
Then open your account settings from the user menu in the top right corner and enable two-factor authentication with an authenticator app.
If you ever lose the admin password, reset it from the server as root with clpctl, CloudPanel's command-line tool. Replace the placeholders with your user name and a new strong password:
sudo clpctl user:reset:password --userName=your_admin_user --password='your_new_strong_password'
Step 4 - Adding a PHP site
In CloudPanel each site runs as its own Linux user, with files in /home/site_user/htdocs/your_domain and logs in /home/site_user/logs. To create one from the panel:
- Click + Add Site and choose Create a PHP Site.
- Select an Application template. Generic works for any PHP application; there are also templates for WordPress, Laravel, Symfony and other frameworks with the right NGINX rules.
- Enter
your_domainas the domain name, pick a PHP version, and set a Site User and a strong Site User Password. - Click Create.
You can do the same from the command line, which is useful for scripting. For example:
sudo clpctl site:add:php --domainName=your_domain --phpVersion=8.3 --vhostTemplate='Generic' --siteUser='site_user' --siteUserPassword='your_strong_password'
Check that the site's document root exists:
sudo ls /home/site_user/htdocs/
your_domain
Upload your application with SFTP or SSH using the site user's credentials. Each site user can log in with SSH and SFTP; its home is /home/site_user.
Step 5 - Creating a database
Open the site in the panel, go to the Databases tab and click Add Database. Enter a database name, a database user and a strong password. The same can be done with clpctl:
sudo clpctl db:add --domainName=your_domain --databaseName=your_database --databaseUserName=your_db_user --databaseUserPassword='your_strong_password'
The database server listens only on localhost, so use 127.0.0.1 as the host in your application's configuration. CloudPanel also includes phpMyAdmin: the Manage button on the Databases tab opens it and logs you in automatically.
Step 6 - Issuing a Let's Encrypt certificate
With the A record for your_domain pointing to the server, open the site, go to SSL/TLS, click Actions > New Let's Encrypt Certificate and then Create and Install. CloudPanel requests the certificate, installs it in the NGINX virtual host and renews it automatically.
From the command line:
sudo clpctl lets-encrypt:install:certificate --domainName=your_domain
Verify the certificate from any machine:
curl -I https://your_domain
HTTP/2 200
server: nginx
...
A 200, or a redirect to your application, without certificate errors means the site is served over HTTPS.
Step 7 - Restricting access to the admin panel
CloudPanel manages its own firewall rules. By default ports 22, 80, 443 and 8443 are open to everyone. Go to Admin Area > Security > Firewall, edit the rule for port 8443 and replace the source 0.0.0.0/0 with your admin IP (your_admin_ip/32). Do the same for port 22 if you always connect from fixed addresses.
WarningMake sure the IP you enter is your current public IP before saving, or you will lock yourself out of the panel. You can check it from your workstation with
curl -4 ifconfig.me.
In the same Security section you can also enable Basic Auth in front of the panel for an extra login prompt, and block specific IPs or bots.
Troubleshooting
The installer stops with an error about an existing web server or database. CloudPanel requires a clean system. Reinstall the operating system and run the installer before installing anything else.
The Let's Encrypt request fails. Check that your_domain resolves to the server with dig +short your_domain and that port 80 is open in Security > Firewall. If the domain is behind a proxy such as Cloudflare, the HTTP-01 challenge must still reach the server.
A site returns 502 Bad Gateway. PHP-FPM for that PHP version is not running or the application crashed. Check the site's logs under /home/site_user/logs/ and the PHP-FPM service with systemctl status php8.3-fpm (replace the version with the one the site uses).
Conclusion
You installed CloudPanel on Ubuntu 24.04, created the administrator account with two-factor authentication, published a PHP site with a database and a trusted certificate, and limited access to the admin port. Next, configure Admin Area > Remote Backups to store backups off the server, and explore the Vhost tab of each site if you need custom NGINX rules.
