HestiaCP is a free, open-source hosting control panel and a common self-hosted alternative to cPanel. It manages web (NGINX with optional Apache), PHP-FPM, DNS, email, databases, FTP, backups and the firewall for multiple users from one web interface, and exposes every action as a v-* command-line script. In this tutorial you will install HestiaCP on a fresh Ubuntu 24.04 server, pick the components you need, secure the panel and host your first website with a Let's Encrypt certificate and a database.
Prerequisites
To follow this guide you need:
- A freshly installed server running Ubuntu 24.04 LTS, for example a CubePath VPS. The minimum is 1 GB of RAM and 10 GB of disk; plan for 4 GB of RAM if you install the full mail stack with ClamAV and SpamAssassin.
- Root access or a user with
sudoprivileges. - A domain name (
your_domain) and a subdomain for the panel itself, for examplepanel.your_domain, both with A records pointing to your server's public IP (your_server_ip). - If you plan to send email: outbound port 25 open on your provider and a reverse DNS (PTR) record for
your_server_ipthat matches the panel hostname.
ImportantHestiaCP must be installed on a clean operating system. The installer sets up NGINX, PHP, Exim, Dovecot, BIND, MariaDB and the firewall itself and refuses to run if some of these are already installed. Do not enable UFW either: HestiaCP manages iptables and Fail2ban on its own.
HestiaCP also supports Debian 11 and 12, and Ubuntu 22.04. It does not support RHEL-based distributions.
Step 1 - Preparing the server
Update the system so the installer starts from current packages:
sudo apt update
sudo apt -y upgrade
Check that the panel hostname resolves to this server. Run it from the server or your workstation:
dig +short panel.your_domain
your_server_ip
The installer sets the hostname for you from the --hostname option, but it must be a fully qualified domain name that resolves, or the panel's Let's Encrypt certificate will fail later.
Step 2 - Downloading the installer
Download the official installer from the HestiaCP GitHub repository:
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
Review the file with less hst-install.sh. Then list every option it accepts:
sudo bash hst-install.sh --help
The options that matter most are:
| Option | Purpose |
|---|---|
--hostname | FQDN of the panel, for example panel.your_domain |
--email | Administrator email address |
--username | Name of the administrator account |
--password | Administrator password |
--port | Panel port, 8083 by default |
--apache | yes for NGINX in front of Apache (.htaccess support), no for NGINX with PHP-FPM only |
--multiphp | yes to install several PHP versions and choose one per site |
--clamav, --spamassassin | Antivirus and spam filtering for mail; disable on servers with little RAM |
--named | yes to run your own DNS server with BIND |
--interactive | no to skip the confirmation prompt |
The HestiaCP website also has an install command generator if you prefer to pick options from a form.
Step 3 - Running the installation
This example installs a web and mail server with NGINX, PHP-FPM, several PHP versions and MariaDB, without Apache, ClamAV or SpamAssassin to keep memory usage low. Replace the placeholders, and use a strong password that you store in a password manager:
sudo bash hst-install.sh \
--hostname panel.your_domain \
--email admin@your_domain \
--username your_admin_user \
--password 'your_strong_password' \
--apache no \
--multiphp yes \
--clamav no \
--spamassassin no \
--interactive no
TipIf you leave out
--password, the installer generates a random one and shows it at the end. Passing the password on the command line stores it in your shell history, so runhistory -cafterwards or omit the option.
The installation takes 10 to 20 minutes. At the end the script prints the panel URL, the administrator user name and password, sends the same details to the email you configured, and asks whether to reboot. Answer y.
After the reboot, check that the panel services are running:
sudo systemctl status hestia
● hestia.service - ...
Loaded: loaded (...)
Active: active (running) since ...
HestiaCP's commands live in /usr/local/hestia/bin. List the services it manages and their state:
sudo /usr/local/hestia/bin/v-list-sys-services
Every service you installed (NGINX, PHP-FPM, Exim, Dovecot, MariaDB and so on) should appear with the state running.
Step 4 - Logging in and securing the panel
Open https://panel.your_domain:8083 and log in with the administrator account. Issue a trusted certificate for the panel hostname so the browser stops warning you:
sudo /usr/local/hestia/bin/v-add-letsencrypt-host
Reload the page: the certificate should now be valid. HestiaCP renews it automatically, together with all site certificates.
Then harden the admin account from the web interface:
- Click your user name (top right) and enable Two-factor authentication, scanning the QR code with an authenticator app. Store the recovery code HestiaCP shows you.
- Go to Server settings (the gear icon) > Firewall and edit the rule for port
8083so it only allows your admin IP instead of0.0.0.0/0.
The firewall page also shows the default rules for SSH, web, mail, DNS and FTP. Remove the rules for services you did not install. Fail2ban is enabled by default and bans IPs after repeated failed logins to SSH, the panel and mail.
Step 5 - Creating a hosting user
The administrator account should be used to manage the server, not to host websites. Create a regular user that will own the sites, either from Users > Add User in the panel or from the command line:
sudo /usr/local/hestia/bin/v-add-user site_user 'your_strong_password' site_user@your_domain
Verify the new account:
sudo /usr/local/hestia/bin/v-list-users
Both the administrator and site_user should be listed, the new user with the default package.
Log out and log back in as site_user for the next steps, or use the administrator's Login as action on the user list.
Step 6 - Adding a website with SSL
As site_user, go to Web > Add Web Domain, enter your_domain, and open Advanced options to add www.your_domain as an alias and select the PHP version. Tick Enable SSL for this domain and Use Let's Encrypt to obtain SSL certificate, then save.
The equivalent commands are:
sudo /usr/local/hestia/bin/v-add-web-domain site_user your_domain
sudo /usr/local/hestia/bin/v-add-letsencrypt-domain site_user your_domain www.your_domain
The site's files are in /home/site_user/web/your_domain/public_html, which initially contains a HestiaCP placeholder page. Upload your application there with SFTP using the site_user credentials, or use the built-in file manager.
Verify that HTTPS works:
curl -I https://your_domain
HTTP/2 200
server: nginx
...
Step 7 - Creating a database
Go to DB > Add Database and fill in a name, a user and a password. HestiaCP prefixes both names with the owner's user name, so a database called app owned by site_user becomes site_user_app. From the command line:
sudo /usr/local/hestia/bin/v-add-database site_user app app 'your_strong_password'
Confirm it exists:
sudo /usr/local/hestia/bin/v-list-databases site_user
The output should show site_user_app with the database user site_user_app on localhost.
Use localhost as the database host in your application. phpMyAdmin is available from the phpMyAdmin button on the DB page.
Troubleshooting
The installer aborts saying a package is already installed. HestiaCP requires a clean system. Reinstall the OS and run the installer before installing anything else.
Let's Encrypt fails for the panel or a site. Check that the name resolves to your_server_ip with dig +short, and that port 80 is allowed in Server settings > Firewall. Error details are in /var/log/hestia/ and the panel's Logs page.
You locked yourself out with the firewall rule. Log in over SSH (or through your provider's console) and list the rules with sudo /usr/local/hestia/bin/v-list-firewall. Delete the wrong rule with sudo /usr/local/hestia/bin/v-delete-firewall-rule RULE_ID and add a corrected one from the panel.
Outgoing email lands in spam or is never delivered. Check the PTR record and that outbound port 25 is open. In Mail, check that DKIM is enabled for the domain and publish the SPF, DKIM and DMARC records that HestiaCP shows.
Conclusion
You installed HestiaCP on Ubuntu 24.04 with the components you needed, secured the panel with a trusted certificate, two-factor authentication and a firewall rule, and hosted a website with SSL and a database under a dedicated user. As next steps, configure off-server backups under Server settings > Backups, create hosting packages to set limits for each user, and keep the panel updated with sudo apt update && sudo apt upgrade, since HestiaCP is distributed as APT packages.
