Installation
Before you start
- A clean AlmaLinux 8/9/10 or Rocky Linux 9/10 server, with root access (see Requirements).
- The server's hostname resolving to its public IP, if you want a real panel certificate.
- Keep another SSH session open while the installer configures the firewall.
Run the installer
The installer is a single Bash script. It is idempotent: running it again on a working node updates it without wiping configuration.
curl -fsSLO https://license.teraservercloud.com/artefactos/instalar.sh
sudo bash instalar.sh -artefacto <panel-package>.tar.gz
<panel-package>.tar.gz is the signed release package that matches the script. The script carries the provider's public key and the package checksum, and refuses to continue if the package does not match. After this first install, every update is verified by the panel binary itself with an Ed25519 signature.
Environment variables
Defaults are the ones the market expects; override only if you must.
| Variable | Default | Meaning |
|---|---|---|
PUERTO_ADMIN | 2087 | Admin interface port |
PUERTO_CLIENTE | 2083 | Client interface port |
FTP_PASIVO_DESDE / FTP_PASIVO_HASTA | 30000 / 30100 | FTP passive port range |
MODO_CLUSTER | (empty = standalone) | master to found a cluster, slave to join one (see Clustering) |
NODO_ID, ANUNCIADA_CLUSTER | hostname / <host>:7000 | Node name and address other nodes use to reach it |
PAQUETE_CLUSTER | Join package from the founder, for unattended slave installs |
When run from a terminal, the installer asks one question: standalone (default), found a new cluster, or join an existing one. Without a terminal it installs a standalone node and asks nothing.
What gets installed
- The
panelbinary in/usr/local/bin, its signed modules in/usr/share/controlpanel/modules, and its state in/var/lib/controlpanel. - Web: Apache (default edge), plus nginx and OpenLiteSpeed support; PHP-FPM; ModSecurity with the OWASP ruleset where packaged.
- Mail: Postfix, Dovecot, Rspamd, ClamAV, Roundcube webmail, a local
unboundresolver (needed by the spam filter). - DNS: BIND (authoritative only, no recursion).
- FTP: Pure-FTPd with TLS required.
- Databases: MariaDB and PostgreSQL, phpMyAdmin and phpPgAdmin.
- Firewall: nftables managed by the panel.
firewalldis disabled, not removed. - Disk quotas enabled on the filesystem that holds
/home. resticandrclone(checksum-pinned) for backups.- SELinux is set to disabled on hosting nodes (a reboot completes the change); the isolation between customers does not depend on it. See Security model.
The installer ends by checking that the panel service is actually serving and that SSH is still open in the new firewall ruleset. If either fails the installation fails loudly instead of leaving a half-working node.
First login
At the end of the installation the installer prints, once:
- the user
admin, - a generated password,
- the second-factor secret (TOTP) and one-time recovery codes.
Copy them immediately; they are not shown again. Open https://<your-hostname>:2087, enter the password and the 6-digit code from your authenticator app.
The second factor is mandatory for admins and resellers and optional for clients. The panel's certificate is self-signed until you issue a real one for the panel's hostname, so the browser warns on the first visit.
Client accounts use https://<your-hostname>:2083.
First steps
From the admin interface (Accounts → New account) or from the CLI on the server:
panel cliente-crear acme
panel sitio-crear acme example.com www.example.com
panel estado
Next, read Admin guide to set up services, the firewall and updates, and Licensing if you want paid features.
Updating
The panel updates itself on request, never silently. See Updates in the Admin guide.
Uninstalling
There is no automated uninstaller. The panel is a set of ordinary packages and files on the server; plan a rebuild rather than an in-place removal.