// Engineering Log

Hosting Control Panels: Part 3 — Hestia Control Panel (HestiaCP)

Published on 2026-09-22

// Fast route

This article belongs to the topic Servers and infrastructure.

Hestia Control Panel (HestiaCP) — a free open-source hosting control panel licensed under GPLv3. The project grew out of VestaCP, which stopped being developed, and is now maintained by the community. HestiaCP is installed on a VPS or dedicated server running Debian or Ubuntu and manages websites, mail, DNS and databases via a web interface or command line. No license fee is required regardless of the number of sites.

The current branch is 1.10; the latest stable release as of September 2026 is 1.10.5. Version 1.10.0 was released on August 13, 2026. It added PHP 8.5 and support for Debian 13 and Ubuntu 26.04, dropped support for Debian 10 and Ubuntu 20.04, and included a major security overhaul after a series of critical vulnerabilities in the 1.9 branch.

What HestiaCP can do

  • Web server. Nginx as a frontend with Apache, or Nginx with PHP-FPM. Multiple PHP versions can be installed on the same server, from 5.6 to 8.5, and a PHP version can be chosen per site.
  • Mail. Exim, Dovecot, antivirus ClamAV, antispam SpamAssassin, webmail.
  • DNS. Built-in BIND DNS server, including in a cluster of multiple servers.
  • Databases. MariaDB or MySQL, with optional PostgreSQL selected during installation.
  • Certificates. Let’s Encrypt, including wildcard certificates for all subdomains.
  • Security. iptables firewall managed from the panel, Fail2Ban, IP blocklists (IPSet).
  • Backups. Local and remote storage: SFTP, FTP, Backblaze B2.
  • Quick app installation. WordPress and other CMSs can be installed from the panel. Six apps were added in 1.10, including Shopware and ClassicPress.
  • CLI and API. Any action is performed with v-… commands, which is convenient for scripts and automation.
  • Import from cPanel. A cPanel account backup can be restored with v-import-cpanel (since version 1.7).

What HestiaCP does not have

  • Docker management. A request for built-in container support was closed without implementation. Docker can be installed alongside, but the panel does not manage it.
  • Reseller accounts. There is no built-in hosting resale. In June 2026 a third-party reseller module began testing, but it is not part of the project.
  • RHEL-family systems and Windows. Only Debian and Ubuntu are supported.
  • 32-bit processors. A 64-bit x86-64 or ARM64 processor is required. i386 and ARMv7 are not supported.

Server requirements

ParameterMinimumRecommended
CPU1 core, 64-bit4 cores
RAM1 GB (without ClamAV and SpamAssassin)4 GB
Disk10 GB40 GB SSD

Supported systems according to the installation guide are Debian 12 and 13, Ubuntu 22.04, 24.04 and 26.04 LTS. The project’s GitHub description additionally lists Debian 11. The system must be a clean install: HestiaCP installs and configures Nginx, Apache, mail services and BIND itself and may conflict with anything configured before it.

Installation

The installer is downloaded from the project repository and run as root:

bash
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
bash hst-install.sh

Without parameters the installer asks questions and installs the default set. The list of parameters is shown by bash hst-install.sh -h. Example installation for a server where mail is hosted by an external provider and the sites need PostgreSQL:

bash
bash hst-install.sh \
  --hostname panel.example.ru \
  --email admin@example.ru \
  --username admin \
  --password 'long-random-password' \
  --apache no \
  --multiphp yes \
  --postgresql yes \
  --exim no --dovecot no --clamav no --spamassassin no

Main parameters:

ParameterDefaultWhat it does
--apacheyesApache behind Nginx; no — Nginx only with PHP-FPM
--multiphpnomultiple PHP versions on the server
--mysql / --mysql8yes / noMariaDB or MySQL 8
--postgresqlnoPostgreSQL
--exim, --dovecotyesmail services
--clamav, --spamassassinyesantivirus and antispam for mail
--namedyesBIND DNS server
--fail2banyesbrute-force protection
--quotanodisk quotas
--port8083panel port
--interactiveyesask questions during installation

After installation the panel is available at https://panel.example.ru:8083 or by the server’s IP address using the same port.

First steps after installation

  1. Enable two-factor authentication for admin. This user manages the whole server, and the documentation strongly recommends 2FA. It can be enabled in the user settings or with the command v-add-user-2fa admin.
  2. Create a regular user for sites. HestiaCP relies on Linux system users, so domains and mail should not be hosted under admin.
  3. Issue a certificate for the panel itself: v-add-letsencrypt-host.
  4. Restrict access to the panel. You can change the port with v-change-sys-port 5678, but it’s more secure to allow connections to it only from your addresses in the panel’s firewall.
  5. Configure remote backup storage: v-add-backup-host sftp backup.example.ru backupuser 'password' /backups 22. A single user’s backup can be made manually: v-backup-user user1 yes.
  6. Enable automatic panel updates: v-add-cron-hestia-autoupdate apt.

Updates

HestiaCP packages come from the project repository and are updated with the system via apt update && apt upgrade or automatically on a schedule. Timely updates are especially important here. In August 2026 a critical vulnerability was fixed in release 1.9.9: a user with minimal privileges could execute commands as root via backup exclusion settings.

When upgrading the OS itself additional steps are needed:

  • after switching to a new Debian or Ubuntu version, check that the repository lines in /etc/apt/sources.list.d are not commented out, and run apt update && apt upgrade again;
  • when upgrading from Debian 12 to Debian 13 run the script migrate_conf_to_debian_13.sh, as noted in the 1.10 release notes.

Security

  • Fail2Ban and the firewall are installed by default. Rules are configured in the panel, blocklists are attached via IPSet (the list must contain at least ten addresses or subnets).
  • The panel overwrites iptables rules. After any firewall change HestiaCP clears current iptables rules and leaves only its own and those listed in /usr/local/hestia/data/firewall/custom.sh. Therefore rules added by other programs, for example Docker, may disappear. Keep your custom rules in that file.
  • Don’t install unnecessary services. If mail or DNS are not needed on the server, disable them during installation: each service is an open port and a separate set of updates.

Common mistakes

  • Installing on a server where something is already running. The panel is intended for a clean system.
  • Hosting sites under the admin user. The documentation recommends creating a regular user before adding domains and mail.
  • ClamAV and SpamAssassin on a server with 1 GB of RAM. According to the developers’ requirements, 1 GB is sufficient only without these services; with them plan for more memory.
  • Manual edits to Nginx and Apache configuration. The panel assembles configuration from templates and may overwrite changes. For custom settings create your own web server template.
  • Delaying updates. Several critical vulnerabilities were fixed in the 1.9 branch in 2026.
  • Importing from cPanel without verification. v-import-cpanel does not transfer DKIM signatures, and certificates may not be restored on import. After the transfer issue certificates again and publish new DKIM records.

When to choose HestiaCP

HestiaCP is suitable if you need a free panel for several sites with mail and DNS on Debian or Ubuntu and you are ready to seek help on the community forum. For hosting resale, container management, or servers on AlmaLinux it is better to choose ISPmanager or another commercial panel.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Servers and infrastructure

VPS, Linux, web stack, migrations, hosting, databases, and core operations.

Typical tasks behind this topic

  • Move a site or service to a new server
  • Set up Linux, Nginx, databases, and backups
  • Figure out why the system behaves unstably

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Reviews

Related reviews

I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler, more affordable solution. In the end I saved time and money. Mikhail — a true expert who works for the client's result, not for the fee. I recommend him!

I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler and more cost-effective solution. In the end I saved budget and time. Mikhail — a true expert who …

kfhzasorin

VPS setup, server setup

2026-05-12 · ★ 5/5

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply