// Engineering Log
Hosting Control Panels: Part 3 — Hestia Control Panel (HestiaCP)
Published on 2026-09-22
// Fast route
This article belongs to the topic Servers and infrastructure.
Hestia Control Panel (HestiaCP) — a free open-source hosting control panel licensed under GPLv3. The project grew out of VestaCP, which stopped being developed, and is now maintained by the community. HestiaCP is installed on a VPS or dedicated server running Debian or Ubuntu and manages websites, mail, DNS and databases via a web interface or command line. No license fee is required regardless of the number of sites.
The current branch is 1.10; the latest stable release as of September 2026 is 1.10.5. Version 1.10.0 was released on August 13, 2026. It added PHP 8.5 and support for Debian 13 and Ubuntu 26.04, dropped support for Debian 10 and Ubuntu 20.04, and included a major security overhaul after a series of critical vulnerabilities in the 1.9 branch.
What HestiaCP can do
- Web server. Nginx as a frontend with Apache, or Nginx with PHP-FPM. Multiple PHP versions can be installed on the same server, from 5.6 to 8.5, and a PHP version can be chosen per site.
- Mail. Exim, Dovecot, antivirus ClamAV, antispam SpamAssassin, webmail.
- DNS. Built-in BIND DNS server, including in a cluster of multiple servers.
- Databases. MariaDB or MySQL, with optional PostgreSQL selected during installation.
- Certificates. Let’s Encrypt, including wildcard certificates for all subdomains.
- Security. iptables firewall managed from the panel, Fail2Ban, IP blocklists (IPSet).
- Backups. Local and remote storage: SFTP, FTP, Backblaze B2.
- Quick app installation. WordPress and other CMSs can be installed from the panel. Six apps were added in 1.10, including Shopware and ClassicPress.
- CLI and API. Any action is performed with
v-…commands, which is convenient for scripts and automation. - Import from cPanel. A cPanel account backup can be restored with
v-import-cpanel(since version 1.7).
What HestiaCP does not have
- Docker management. A request for built-in container support was closed without implementation. Docker can be installed alongside, but the panel does not manage it.
- Reseller accounts. There is no built-in hosting resale. In June 2026 a third-party reseller module began testing, but it is not part of the project.
- RHEL-family systems and Windows. Only Debian and Ubuntu are supported.
- 32-bit processors. A 64-bit x86-64 or ARM64 processor is required. i386 and ARMv7 are not supported.
Server requirements
| Parameter | Minimum | Recommended |
|---|---|---|
| CPU | 1 core, 64-bit | 4 cores |
| RAM | 1 GB (without ClamAV and SpamAssassin) | 4 GB |
| Disk | 10 GB | 40 GB SSD |
Supported systems according to the installation guide are Debian 12 and 13, Ubuntu 22.04, 24.04 and 26.04 LTS. The project’s GitHub description additionally lists Debian 11. The system must be a clean install: HestiaCP installs and configures Nginx, Apache, mail services and BIND itself and may conflict with anything configured before it.
Installation
The installer is downloaded from the project repository and run as root:
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
bash hst-install.shWithout parameters the installer asks questions and installs the default set. The list of parameters is shown by bash hst-install.sh -h. Example installation for a server where mail is hosted by an external provider and the sites need PostgreSQL:
bash hst-install.sh \
--hostname panel.example.ru \
--email admin@example.ru \
--username admin \
--password 'long-random-password' \
--apache no \
--multiphp yes \
--postgresql yes \
--exim no --dovecot no --clamav no --spamassassin noMain parameters:
| Parameter | Default | What it does |
|---|---|---|
--apache | yes | Apache behind Nginx; no — Nginx only with PHP-FPM |
--multiphp | no | multiple PHP versions on the server |
--mysql / --mysql8 | yes / no | MariaDB or MySQL 8 |
--postgresql | no | PostgreSQL |
--exim, --dovecot | yes | mail services |
--clamav, --spamassassin | yes | antivirus and antispam for mail |
--named | yes | BIND DNS server |
--fail2ban | yes | brute-force protection |
--quota | no | disk quotas |
--port | 8083 | panel port |
--interactive | yes | ask questions during installation |
After installation the panel is available at https://panel.example.ru:8083 or by the server’s IP address using the same port.
First steps after installation
- Enable two-factor authentication for admin. This user manages the whole server, and the documentation strongly recommends 2FA. It can be enabled in the user settings or with the command
v-add-user-2fa admin. - Create a regular user for sites. HestiaCP relies on Linux system users, so domains and mail should not be hosted under admin.
- Issue a certificate for the panel itself:
v-add-letsencrypt-host. - Restrict access to the panel. You can change the port with
v-change-sys-port 5678, but it’s more secure to allow connections to it only from your addresses in the panel’s firewall. - Configure remote backup storage:
v-add-backup-host sftp backup.example.ru backupuser 'password' /backups 22. A single user’s backup can be made manually:v-backup-user user1 yes. - Enable automatic panel updates:
v-add-cron-hestia-autoupdate apt.
Updates
HestiaCP packages come from the project repository and are updated with the system via apt update && apt upgrade or automatically on a schedule. Timely updates are especially important here. In August 2026 a critical vulnerability was fixed in release 1.9.9: a user with minimal privileges could execute commands as root via backup exclusion settings.
When upgrading the OS itself additional steps are needed:
- after switching to a new Debian or Ubuntu version, check that the repository lines in
/etc/apt/sources.list.dare not commented out, and runapt update && apt upgradeagain; - when upgrading from Debian 12 to Debian 13 run the script
migrate_conf_to_debian_13.sh, as noted in the 1.10 release notes.
Security
- Fail2Ban and the firewall are installed by default. Rules are configured in the panel, blocklists are attached via IPSet (the list must contain at least ten addresses or subnets).
- The panel overwrites iptables rules. After any firewall change HestiaCP clears current iptables rules and leaves only its own and those listed in
/usr/local/hestia/data/firewall/custom.sh. Therefore rules added by other programs, for example Docker, may disappear. Keep your custom rules in that file. - Don’t install unnecessary services. If mail or DNS are not needed on the server, disable them during installation: each service is an open port and a separate set of updates.
Common mistakes
- Installing on a server where something is already running. The panel is intended for a clean system.
- Hosting sites under the admin user. The documentation recommends creating a regular user before adding domains and mail.
- ClamAV and SpamAssassin on a server with 1 GB of RAM. According to the developers’ requirements, 1 GB is sufficient only without these services; with them plan for more memory.
- Manual edits to Nginx and Apache configuration. The panel assembles configuration from templates and may overwrite changes. For custom settings create your own web server template.
- Delaying updates. Several critical vulnerabilities were fixed in the 1.9 branch in 2026.
- Importing from cPanel without verification.
v-import-cpaneldoes not transfer DKIM signatures, and certificates may not be restored on import. After the transfer issue certificates again and publish new DKIM records.
When to choose HestiaCP
HestiaCP is suitable if you need a free panel for several sites with mail and DNS on Debian or Ubuntu and you are ready to seek help on the community forum. For hosting resale, container management, or servers on AlmaLinux it is better to choose ISPmanager or another commercial panel.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Servers and infrastructure
VPS, Linux, web stack, migrations, hosting, databases, and core operations.
Typical tasks behind this topic
- Move a site or service to a new server
- Set up Linux, Nginx, databases, and backups
- Figure out why the system behaves unstably
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler, more affordable solution. In the end I saved time and money. Mikhail — a true expert who works for the client's result, not for the fee. I recommend him!
I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler and more cost-effective solution. In the end I saved budget and time. Mikhail — a true expert who …
VPS setup, server setup
2026-05-12 · ★ 5/5
Excellent work! Set up the server very quickly, installed the control panel, and configured the IP. Definitely recommend!
Excellent work! Very quickly set up the server, installed the panel, configured the IP I can definitely recommend it!
Everything was excellent; helped promptly and professionally. Thank you — I recommend them to the community.
Everything's great, helped promptly and professionally, thank you, I recommend it to the community
VPS setup, server setup
2026-04-16 · ★ 5/5
There were several issues concerning both the technical side and overall understanding. Mikhail responded quickly, resolved the technical problems, and helped me understand them — many thanks. I'm satisfied with the result.
There were several issues concerning both the technical side and overall understanding. Mikhail responded quickly to the request, helped sort things out and resolved the technical problems and helped clarify …
VPS setup, server setup
2026-02-18 · ★ 5/5
Everything was done quickly and efficiently. I recommend.
Everything was done quickly and efficiently. I recommend.
VPS setup, server setup
2026-01-17 · ★ 5/5
Everything went well; the contractor responded quickly to questions and helped resolve the issue. Thanks!
Everything went well, the contractor responded quickly to questions and helped resolve the issue. Thank you!
VPS setup, server setup
2025-12-16 · ★ 5/5
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related