HestiaCP is a free, open-source hosting control panel and a common self-hosted alternative to cPanel. It manages web (NGINX with optional Apache), PHP-FPM, DNS, email, databases, FTP, backups and the firewall for multiple users from one web interface, and exposes every action as a v-* command-line script. In this tutorial you will install HestiaCP on a fresh Ubuntu 24.04 server, pick the components you need, secure the panel and host your first website with a Let's Encrypt certificate and a database.

Prerequisites

To follow this guide you need:

  • A freshly installed server running Ubuntu 24.04 LTS, for example a CubePath VPS. The minimum is 1 GB of RAM and 10 GB of disk; plan for 4 GB of RAM if you install the full mail stack with ClamAV and SpamAssassin.
  • Root access or a user with sudo privileges.
  • A domain name (your_domain) and a subdomain for the panel itself, for example panel.your_domain, both with A records pointing to your server's public IP (your_server_ip).
  • If you plan to send email: outbound port 25 open on your provider and a reverse DNS (PTR) record for your_server_ip that matches the panel hostname.

HestiaCP also supports Debian 11 and 12, and Ubuntu 22.04. It does not support RHEL-based distributions.

Step 1 - Preparing the server

Update the system so the installer starts from current packages:

sudo apt update
sudo apt -y upgrade

Check that the panel hostname resolves to this server. Run it from the server or your workstation:

dig +short panel.your_domain
your_server_ip

The installer sets the hostname for you from the --hostname option, but it must be a fully qualified domain name that resolves, or the panel's Let's Encrypt certificate will fail later.

Step 2 - Downloading the installer

Download the official installer from the HestiaCP GitHub repository:

wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh

Review the file with less hst-install.sh. Then list every option it accepts:

sudo bash hst-install.sh --help

The options that matter most are:

OptionPurpose
--hostnameFQDN of the panel, for example panel.your_domain
--emailAdministrator email address
--usernameName of the administrator account
--passwordAdministrator password
--portPanel port, 8083 by default
--apacheyes for NGINX in front of Apache (.htaccess support), no for NGINX with PHP-FPM only
--multiphpyes to install several PHP versions and choose one per site
--clamav, --spamassassinAntivirus and spam filtering for mail; disable on servers with little RAM
--namedyes to run your own DNS server with BIND
--interactiveno to skip the confirmation prompt

The HestiaCP website also has an install command generator if you prefer to pick options from a form.

Step 3 - Running the installation

This example installs a web and mail server with NGINX, PHP-FPM, several PHP versions and MariaDB, without Apache, ClamAV or SpamAssassin to keep memory usage low. Replace the placeholders, and use a strong password that you store in a password manager:

sudo bash hst-install.sh \
  --hostname panel.your_domain \
  --email admin@your_domain \
  --username your_admin_user \
  --password 'your_strong_password' \
  --apache no \
  --multiphp yes \
  --clamav no \
  --spamassassin no \
  --interactive no

The installation takes 10 to 20 minutes. At the end the script prints the panel URL, the administrator user name and password, sends the same details to the email you configured, and asks whether to reboot. Answer y.

After the reboot, check that the panel services are running:

sudo systemctl status hestia
● hestia.service - ...
     Loaded: loaded (...)
     Active: active (running) since ...

HestiaCP's commands live in /usr/local/hestia/bin. List the services it manages and their state:

sudo /usr/local/hestia/bin/v-list-sys-services

Every service you installed (NGINX, PHP-FPM, Exim, Dovecot, MariaDB and so on) should appear with the state running.

Step 4 - Logging in and securing the panel

Open https://panel.your_domain:8083 and log in with the administrator account. Issue a trusted certificate for the panel hostname so the browser stops warning you:

sudo /usr/local/hestia/bin/v-add-letsencrypt-host

Reload the page: the certificate should now be valid. HestiaCP renews it automatically, together with all site certificates.

Then harden the admin account from the web interface:

  1. Click your user name (top right) and enable Two-factor authentication, scanning the QR code with an authenticator app. Store the recovery code HestiaCP shows you.
  2. Go to Server settings (the gear icon) > Firewall and edit the rule for port 8083 so it only allows your admin IP instead of 0.0.0.0/0.

The firewall page also shows the default rules for SSH, web, mail, DNS and FTP. Remove the rules for services you did not install. Fail2ban is enabled by default and bans IPs after repeated failed logins to SSH, the panel and mail.

Step 5 - Creating a hosting user

The administrator account should be used to manage the server, not to host websites. Create a regular user that will own the sites, either from Users > Add User in the panel or from the command line:

sudo /usr/local/hestia/bin/v-add-user site_user 'your_strong_password' site_user@your_domain

Verify the new account:

sudo /usr/local/hestia/bin/v-list-users

Both the administrator and site_user should be listed, the new user with the default package.

Log out and log back in as site_user for the next steps, or use the administrator's Login as action on the user list.

Step 6 - Adding a website with SSL

As site_user, go to Web > Add Web Domain, enter your_domain, and open Advanced options to add www.your_domain as an alias and select the PHP version. Tick Enable SSL for this domain and Use Let's Encrypt to obtain SSL certificate, then save.

The equivalent commands are:

sudo /usr/local/hestia/bin/v-add-web-domain site_user your_domain
sudo /usr/local/hestia/bin/v-add-letsencrypt-domain site_user your_domain www.your_domain

The site's files are in /home/site_user/web/your_domain/public_html, which initially contains a HestiaCP placeholder page. Upload your application there with SFTP using the site_user credentials, or use the built-in file manager.

Verify that HTTPS works:

curl -I https://your_domain
HTTP/2 200
server: nginx
...

Step 7 - Creating a database

Go to DB > Add Database and fill in a name, a user and a password. HestiaCP prefixes both names with the owner's user name, so a database called app owned by site_user becomes site_user_app. From the command line:

sudo /usr/local/hestia/bin/v-add-database site_user app app 'your_strong_password'

Confirm it exists:

sudo /usr/local/hestia/bin/v-list-databases site_user

The output should show site_user_app with the database user site_user_app on localhost.

Use localhost as the database host in your application. phpMyAdmin is available from the phpMyAdmin button on the DB page.

Troubleshooting

The installer aborts saying a package is already installed. HestiaCP requires a clean system. Reinstall the OS and run the installer before installing anything else.

Let's Encrypt fails for the panel or a site. Check that the name resolves to your_server_ip with dig +short, and that port 80 is allowed in Server settings > Firewall. Error details are in /var/log/hestia/ and the panel's Logs page.

You locked yourself out with the firewall rule. Log in over SSH (or through your provider's console) and list the rules with sudo /usr/local/hestia/bin/v-list-firewall. Delete the wrong rule with sudo /usr/local/hestia/bin/v-delete-firewall-rule RULE_ID and add a corrected one from the panel.

Outgoing email lands in spam or is never delivered. Check the PTR record and that outbound port 25 is open. In Mail, check that DKIM is enabled for the domain and publish the SPF, DKIM and DMARC records that HestiaCP shows.

Conclusion

You installed HestiaCP on Ubuntu 24.04 with the components you needed, secured the panel with a trusted certificate, two-factor authentication and a firewall rule, and hosted a website with SSL and a database under a dedicated user. As next steps, configure off-server backups under Server settings > Backups, create hosting packages to set limits for each user, and keep the panel updated with sudo apt update && sudo apt upgrade, since HestiaCP is distributed as APT packages.