Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Short answer: Install CyberPanel only on a fresh 64-bit AlmaLinux 8 or Rocky Linux 8 server with root SSH access, then choose CyberPanel with OpenLiteSpeed in the installer. AlmaLinux 8 is the safer choice for this version-specific walkthrough because CyberPanel’s detailed installation documentation explicitly names it. Rocky Linux is listed on CyberPanel’s current support pages, but Rocky Linux 8 compatibility should be confirmed by the current installer before you proceed.

This guide covers preparation, installation, firewall rules, first login, DNS, SSL, website deployment, verification, and recovery from common failures. It focuses on the free OpenLiteSpeed edition, not CyberPanel Enterprise.

What you are installing

The free CyberPanel edition is a hosting control panel built around OpenLiteSpeed. Depending on the options selected, it can also install and manage:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • PHP/LSPHP
  • MariaDB
  • PowerDNS
  • Postfix mail services
  • Pure-FTPd
  • CyberPanel’s administration service

CyberPanel Enterprise uses LiteSpeed Enterprise instead. The installer presents both choices, but this guide uses CyberPanel with OpenLiteSpeed. CyberPanel describes the OpenLiteSpeed edition as free and supporting unlimited domains; that does not mean unlimited server CPU, RAM, bandwidth, storage, backups, or support.

AlmaLinux 8 or Rocky Linux 8?

Both distributions belong to the RHEL-compatible family, and OpenLiteSpeed documents support for RHEL derivatives including AlmaLinux and Rocky Linux. However, CyberPanel’s older detailed installation page, updated June 5, 2024, explicitly lists AlmaLinux 8 and AlmaLinux 9, while its current homepage uses broader wording that includes Rocky Linux without providing a Rocky Linux 8-specific matrix.

For the most conservative installation, use a fresh AlmaLinux 8 x86_64 image. Rocky Linux 8 can be used as an alternative if the current CyberPanel installer recognizes the image. Do not mix repositories or instructions from another control panel, and do not force the installer past an operating-system check.

Requirements and preparation

Resource guidance

CyberPanel publishes 1 GB RAM and 10 GB disk space as minimums. Its current getting-started page recommends 2 GB RAM. Treat the minimum as a test-server baseline, not a production recommendation:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • 1 GB RAM: testing or one very small site.
  • 2 GB RAM: a reasonable starting point for a light single-site server.
  • 4 GB or more: preferable for WordPress with mail, backups, Redis, malware scanning, or several websites.

Allow additional storage for databases, mailboxes, logs, backups, and uploaded media.

Pre-installation checklist

  • A fresh 64-bit AlmaLinux 8 or Rocky Linux 8 VPS or dedicated server.
  • Root SSH access and a public IPv4 address.
  • No Apache, Nginx, existing database stack, other hosting panel, or production websites.
  • Access to the VPS provider’s firewall or security-group controls.
  • Control of the domain’s DNS records.
  • A provider snapshot or image backup before installation.

The installer changes a substantial part of the server. A clean rebuild is normally safer than trying to remove an existing web stack.

Check the server before changing anything:

cat /etc/os-release
uname -m
hostnamectl
ip addr
free -h
df -h

Confirm that the architecture is x86_64, that the distribution is the image you intended to deploy, and that sufficient disk space is available.

Set a fully qualified hostname

Use a hostname such as server.example.com. It is the server’s identity and is not the same as the first website you will host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
hostnamectl set-hostname server.example.com
hostnamectl

Create a DNS record such as:

server.example.com  A  SERVER_IP

Reverse DNS/PTR should also be configured with your VPS provider where possible, especially if you intend to send mail. A hostname alone does not guarantee mail delivery; PTR, SPF, DKIM, DMARC, provider policy, and sender reputation also matter.

Update the operating system

dnf update -y

On AlmaLinux and Rocky Linux, dnf is the clearest command to use. Older CyberPanel instructions show yum, which generally maps to DNF on these systems.

If the update installs a new kernel or other core components, reboot and reconnect:

reboot

After reconnecting, verify that the server is back:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
uptime
dnf history info last

Avoid adding unrelated third-party repositories before CyberPanel is installed.

Open the required firewall ports

You must configure both the cloud provider’s firewall/security group and the server’s local firewall. Opening a port in firewalld does not help if the provider blocks it upstream.

CyberPanel’s documented ports include:

Function Ports
CyberPanel TCP 8090
Web TCP 80 and 443
HTTP/3 UDP 443
DNS TCP and UDP 53
FTP TCP 21 and 40110–40210
SMTP TCP 25, 465, and 587
POP3 TCP 110 and 995, if used
IMAP TCP 143 and 993, if used

For a web-only server, start with HTTP, HTTPS, and the panel port:

firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --permanent --add-port=8090/tcp
firewall-cmd --reload

If CyberPanel will provide authoritative DNS, add DNS ports:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
firewall-cmd --permanent --add-port=53/tcp
firewall-cmd --permanent --add-port=53/udp
firewall-cmd --reload

Only open mail and FTP ports when those services are enabled and required:

firewall-cmd --permanent --add-service=smtp
firewall-cmd --permanent --add-service=imap
firewall-cmd --permanent --add-service=imaps
firewall-cmd --permanent --add-port=21/tcp
firewall-cmd --permanent --add-port=40110-40210/tcp
firewall-cmd --reload

For file transfers, prefer SFTP over SSH where possible instead of exposing traditional FTP.

Run the current CyberPanel installer

CyberPanel’s current homepage publishes this installer command:

sudo su - -c 'sh <(curl https://cyberpanel.net/install || wget -O - https://cyberpanel.net/install)'

An equivalent root-shell form is:

sudo -i
sh <(curl https://cyberpanel.net/install || wget -O - https://cyberpanel.net/install)

The older knowledge-base page uses install.sh instead:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sh <(curl https://cyberpanel.net/install.sh || wget -O - https://cyberpanel.net/install.sh)

Use the command from the current CyberPanel homepage as the primary path. The older command is included only because older documentation may still reference it.

This downloads and executes a remote script with root privileges. That is convenient, but it requires trust in CyberPanel and the network path. Organizations with strict supply-chain controls should use an officially documented download and verification process, if CyberPanel provides one, and inspect the installer before execution. Do not copy an installer from an unrelated blog or forum.

Choose the installer options

Labels can change between installer versions, but the important decisions are consistent.

1. Select OpenLiteSpeed

When prompted, choose:

1. Install CyberPanel with OpenLiteSpeed

Do not select LiteSpeed Enterprise unless you specifically need its commercial features and understand its licensing. CyberPanel’s documentation distinguishes the free OpenLiteSpeed edition from Enterprise, which has different domain and plan limits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Choose the service profile

The full-service option can install PowerDNS, Postfix, and Pure-FTPd.

  • Choose Full Service if CyberPanel will manage your DNS, mail, and FTP.
  • Do not install mail services when using Google Workspace, Microsoft 365, Amazon SES, Mailgun, or another external mail provider.
  • Do not run authoritative DNS on the VPS unless you understand nameserver delegation, redundancy, and the consequences of a single-server DNS outage.

3. Remote MySQL

For most new installations, select:

Remote MySQL: No

Choose remote MySQL only when the database server already exists and you have planned authentication, network access, TLS, backups, latency, and firewall rules.

4. Version and administrator password

Select the current version unless a documented compatibility requirement requires a pinned release. Do not hard-code a version number in a guide because the installer and interface change over time.

Use a strong administrator password if the installer asks you to create one. Store it in a password manager and change any default or generated credential immediately after the first login.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reboot and log in

The installer may request a reboot. After the server restarts, open:

https://SERVER-IP:8090

The first connection may show a certificate warning because you are using an IP address or a certificate that is not yet trusted for your hostname. Do not treat that warning as a permanent production configuration.

After logging in:

  1. Change the administrator password if it was generated or shared during installation.
  2. Create a separate administrative user if the installed CyberPanel version supports it.
  3. Restrict port 8090 to trusted source IPs where practical.
  4. Configure the server hostname and panel SSL.
  5. Decide whether CyberPanel or an external provider will manage DNS and mail.
  6. Configure backups before deploying production data.
  7. Check the system time and timezone.
  8. Disable services you do not need.
  9. Enable available multi-factor authentication controls.

Verify the installation from SSH

Check failed services and the CyberPanel service:

systemctl --failed
systemctl status lscpd
ss -ltnp
ss -lunp

Test the panel locally:

curl -kI https://127.0.0.1:8090

Test the public web listeners:

curl -I http://SERVER_IP
curl -kI https://SERVER_IP

The installation log is:

less /var/log/installLogs.txt

A working local response combined with an unreachable public panel usually points to a provider firewall, local firewall, routing, or binding problem rather than a failed installation.

Create and secure the first website

  1. In CyberPanel, create a new website and enter the domain name.
  2. Select the required PHP version and a package or resource limits.
  3. Create or select the website owner.
  4. Point the domain’s A and, if appropriate, AAAA records to the server.
  5. Wait for DNS caches to update. Propagation is not a fixed-duration process; TTLs, resolvers, registrars, and existing records affect it.
  6. Issue a Let’s Encrypt certificate after the domain resolves to the server and ports 80/443 are reachable.
  7. Upload the application files or use the available application installer.
  8. Create the database and database user, then add the credentials to the application.
  9. Test HTTP-to-HTTPS redirection, PHP execution, uploads, cron jobs, and database connectivity.

For WordPress, also verify permalink rewrites, the upload directory, scheduled tasks, PHP memory limits, and any cache configuration. OpenLiteSpeed is not identical to Apache or Nginx, so application rewrite rules and server-specific modules may need adjustment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

The installer refuses the operating system

Check the image, architecture, repositories, and network:

cat /etc/os-release
uname -m
dnf repolist
curl -I https://cyberpanel.net/install

Possible causes include an unsupported minor release, the wrong architecture, a Rocky Linux image the installer does not recognize, existing control-panel packages, broken repositories, or DNS/network failure. Do not bypass the OS check by editing the installer. Reinstalling with AlmaLinux 8 is safer than forcing an unsupported combination.

Existing services occupy ports

ss -ltnp
systemctl --type=service --state=running

Apache, Nginx, another panel, or a preinstalled database may conflict with CyberPanel. Do not stop production services blindly; use a fresh server.

The panel returns 503

systemctl status lscpd
journalctl -u lscpd -n 100 --no-pager
tail -n 100 /var/log/installLogs.txt

CyberPanel’s troubleshooting documentation specifically points to the lscpd service and the installation log for this failure. Restarting the service may help after a transient startup problem, but inspect the journal before repeatedly restarting it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The panel is unreachable

Check the listener and local firewall first:

ss -ltnp | grep 8090
firewall-cmd --list-all
curl -kI https://127.0.0.1:8090

Then check the cloud firewall/security group, provider restrictions, public IP, reboot status, and whether the service is bound only to localhost.

The website shows a 404 or the wrong site

Verify the A and AAAA records, domain spelling, document root, virtual-host configuration, HTTP versus HTTPS, and browser/resolver cache. Confirm that the domain was added to CyberPanel before testing it.

SSL issuance fails

Common causes are incorrect DNS, blocked port 80 or 443, another service answering the challenge, rate limits, or an unreachable IPv6 destination. Test both A and AAAA records. If an AAAA record points to an address that does not serve the site, correct it or remove the incorrect record before retrying.

Email does not send

Check whether Postfix was installed, whether TCP port 25 is blocked by the VPS provider, and whether the firewall allows the selected submission ports. Configure PTR, SPF, DKIM, and DMARC, but remember that these do not guarantee delivery. Recipient filtering and sender reputation also matter. CyberPanel’s installation documentation warns that provider-level port-25 restrictions can prevent outgoing mail.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FTP connections fail

Check TCP 21, the passive range 40110–40210, both firewall layers, passive mode in the client, TLS settings, and any NAT or private-network configuration. Use SFTP instead where possible.

Backups, updates, and rollback

Before CyberPanel or operating-system updates, take a provider snapshot and confirm that your backup includes websites, databases, mail, DNS data, and panel configuration. A configuration archive alone is not a tested disaster-recovery plan.

A basic configuration archive can be created with:

tar -czf /root/cyberpanel-config-backup-$(date +%F).tar.gz 
  /etc 2>/dev/null

Also keep independent backups, test restoration on a separate server, and record the installed CyberPanel version and any custom changes. If an upgrade breaks the server, restore the snapshot or rebuild the clean VPS rather than trying to repair an unknown mix of partially upgraded services.

Security checklist

  • Use SSH keys and disable password SSH authentication after confirming key access.
  • Restrict SSH and CyberPanel port 8090 to trusted IPs where practical.
  • Use unique, strong panel, database, and mailbox credentials.
  • Keep the operating system, CyberPanel, OpenLiteSpeed, PHP, and applications updated.
  • Expose mail, FTP, and DNS ports only when required.
  • Configure HTTPS for the panel and every hosted domain.
  • Monitor disk space, RAM, failed services, logs, and certificate expiry.
  • Maintain off-server backups and test restores.
  • Do not assume that installing a control panel automatically hardens the VPS.

When CyberPanel is the wrong tool

Choose a different approach if you need a minimal hardened host, immutable infrastructure, container-first deployment, a non-PHP workload, formal enterprise support, high availability across multiple nodes, or infrastructure managed primarily through code. A panel also creates operational coupling: web, database, mail, DNS, FTP, backups, and administration may all depend on one VPS.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Possible alternatives include:

  • Manual OpenLiteSpeed: more control and less panel overhead; see the official OpenLiteSpeed installation documentation.
  • CloudPanel: a lighter application-management panel.
  • Virtualmin/Webmin: broader Unix administration with a different hosting model.
  • cPanel/WHM or Plesk: mature commercial ecosystems with recurring licensing costs.
  • Docker with a reverse proxy: better isolation and reproducibility for application-focused deployments, but not a direct replacement for a traditional hosting panel.

Hosting cost and support choices

The OpenLiteSpeed edition may be free, but the server, backups, storage, domain, DNS or email services, and administration time are not necessarily free.

CyberPanel’s own managed Cloud VPS/Next-Gen Cloud page shows a starting price signal of $14.99 per month and states that those offerings include 24/7 ticket support. Self-installed deployments generally rely on community support and documentation. Prices and included resources can change, so verify the current offer before purchasing.

A self-managed general-purpose VPS can cost less. DigitalOcean’s reviewed pricing page lists Droplets from $4 per month, with 1 GiB and 2 GiB plans shown at $6 and $12 per month respectively. Backups and snapshots are extra products; the page lists weekly backups at 20% of Droplet cost, daily backups at 30%, usage-based backups starting at $0.01/GiB-month, and snapshots at $0.06/GB-month. Confirm current pricing, image availability, provider firewall behavior, and port-25 policy during deployment.

In practical terms, the managed path is simpler, while the self-managed path offers more provider and server-image control. Neither removes the need for backups and maintenance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line

For this exact installation, deploy a fresh AlmaLinux 8 x86_64 server, update it, set a real hostname, configure both firewall layers, and run CyberPanel’s current official installer. Select OpenLiteSpeed, choose only the services you genuinely need, reboot, secure port 8090, configure DNS and SSL, and verify the panel and first website before putting production data on the server. Use Rocky Linux 8 only after confirming that the current installer recognizes your specific image.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.