# 1Panel reaches its own interface through a port and a secret path

> A Go server management panel that installs with one curl into bash, positions itself against cPanel, Plesk, aaPanel and Webmin with a table of checkmarks, and gates multi-node management, tamper protection and uptime monitoring behind a paid tier. The free tier is free forever, which is different from free of limits.

**1Panel-dev/1Panel** — Project brief: 1Panel is a modern, open-source VPS control panel, and the only one with native AI agent support. Run Ollama models, deploy OpenClaw agents, and manage your entire server stack from one clean web interface.

- Repository: https://github.com/1Panel-dev/1Panel
- Website: https://1panel.pro
- Stars: 37,077 · Forks: 3,363
- Language: Go
- License: GPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/1panel-dev-1panel

## The interface is hidden behind a port and a path, not behind a login alone

The quick start ends with an instruction worth reading closely, because it describes how access control actually works here. After installation you open http://<your-server-ip>:<port>/<security-path> in a browser, so the panel is not at a well-known route on a well-known port. It sits behind a port you chose and a path segment that is meant to be unguessable, which is URL obfuscation standing in front of the application rather than authentication doing the work. The second detail compounds it: if you need your credentials, you retrieve them by running 1pctl user-info over SSH. So the admin surface is reachable over plain HTTP, the obscurity is the first barrier, and the password is only recoverable by shell access to the host. That is a deliberate trade, and it is a different security posture from a panel that terminates TLS itself before showing anything.

## One command against a versioned URL does the whole install

The installation is a single line, and the URL carries a version segment:

```bash
bash -c "$(curl -sSL https://resource.1panel.pro/v2/quick_start.sh)"
```

What that buys you is a Linux server panel with host monitoring, file management, database management and container management behind a web interface, plus an app store offering one-click install and upgrade, one-click backup and restore integrated with cloud storage, and website deployment that integrates with builders including WordPress and Halo with one-click domain binding and SSL configuration. The version in the path is worth noting as a practice rather than a detail, since it means the script fetched today is the v2 installer and not whatever happens to be current later. What the one line does not tell you is what it changed on the host, and the panel's own access model above is the reason to read it before running.

## Multi-node management, tamper protection and uptime monitoring are paid

The edition table is the most useful thing on the page and it is worth reading row by row rather than the summary. One-click app installs are in all three editions, and the WAF and advanced security row gives OSS a basic version against full in Pro and Ent. But website tamper protection, website uptime monitoring, multi-node management, and custom logo and theme are all marked absent in OSS. KVM Web UI, the AI Gateway and priority support are absent in both OSS and Pro, appearing only in Ent. The consequence is direct. If you have one server, the free tier is genuinely capable. If you have several and were planning to manage them from one console, that capability is a paid feature, and the honest summary of the free edition is a single-host panel rather than a small-fleet one.

## The free tier allows five AI agents, which sits oddly with the AI-first pitch

The repository description leads with what it calls native AI agent support, the only panel with it, and the management layer is described as running from bare metal to agents, with an AI gateway, a Skills Hub, and centralised management of agents and models. The edition table then puts the AI agents row, referring to OpenClaw, at 5 agents on OSS and unlimited on Pro. So the marquee capability is the one with a numeric cap in the free edition, and the AI Gateway, the piece that would unify model access across those agents, is Ent only. A reader assessing this project should weigh those two facts together. The model management and Ollama support in the description are real, but the ceiling on the free tier is low enough that it is a preview of the feature rather than a way to run a project, and the part that sounds most like a platform is the part you pay most for.

## Two Go binaries and an npm frontend, and the frontend target is named pro

The Makefile is short and shows the shape of the build. There are two Go entry points, one under core/cmd/server and one under agent/cmd/server, producing binaries named 1panel-core and 1panel-agent, both compiled with CGO_ENABLED=0, -trimpath and stripped symbols, with an optional upx target to compress them further. The frontend is a separate step that changes directory into frontend/ and runs npm install followed by npm run build:pro, with the built assets landing under a path inside the core tree. Two details deserve a second look. The only frontend build target invokes a script named for the pro edition, which is a confusing thing to find in a GPL-3.0 repository, and the two darwin targets are named for macOS while cross-compiling for linux on amd64, so build_on_local produces Linux binaries from a Mac. The default branch is dev-v2, not main.

## The comparison table is a marketing document and should be read as one

There is a table setting 1Panel against cPanel and Plesk, aaPanel and Webmin, with rows for being free and open source, AI management, a one-click app marketplace, a modern post-2020 interface, Docker and container management, and active development. The project marks itself with a check on every row, marks cPanel and Plesk as failing nearly all of them, marks Webmin as slow on active development, and claims 165 or more apps in its own store. None of those cells carries a version number, a date or a method, and the cPanel and Plesk verdict in particular flattens a commercial product with a paid tier into a single row. The header also claims a global community of 2.5 million or more self-hosters, which is a figure no reader can check from here and which says nothing about whether the panel is good. Use the table to understand what the project thinks it is, not as evidence.

## Three releases in ten days on a branch named for the version

Maintenance looks brisk and the versioning is conventional. The releases listed are v2.3.0 on 2026-09-14, v2.3.1 on 2026-09-18 and v2.3.2 on 2026-09-24, so three tagged versions in about ten days, and the repository is not archived with the last push on 2026-09-29. That cadence is normal for a panel that ships user-facing fixes often. The default branch is the thing to note, because it is dev-v2 rather than main or master, so a clone of the default branch is tracking a version line for the second major release and will include unreleased work. A reader who wants a stable panel should install from a release rather than build the default branch, and the one-line installer appears to do the former since its URL is versioned. The repository also carries a SECURITY.md with a request to read it before disclosing a vulnerability, an OWNERS file, and a Sonar project properties file for static analysis.

## Conclusion

Adopt 1Panel if you run one server, want a modern interface over file, database and container management, and accept that the agent features are capped. Do not adopt it for a multi-server estate on the free tier, because multi-node management, tamper protection and uptime monitoring are all marked absent from OSS, and paying for a panel to manage a fleet is a different purchase from paying for hosting. Verify first what your port and security path will be and how you will recover the credentials, since the panel exposes its own admin surface over HTTP and the setup command prints neither.

## FAQ

### What is 1Panel?

A GPL-3.0 licensed open-source Linux server management panel written in Go, with a web interface covering host monitoring, file, database and container management, an app store, website deployment, and management of AI agents and models. The default branch is dev-v2.

### How do I install 1Panel?

With bash -c "$(curl -sSL https://resource.1panel.pro/v2/quick_start.sh)" on a prepared Linux server. Afterwards you open the panel at your server IP with your chosen port and a security path, and recover credentials with 1pctl user-info over SSH.

### How to use 1Panel?

Through the web interface, where you manage files, databases and containers, install or upgrade apps from the store, bind domains and configure SSL, and set up backup and restore including integration with cloud storage. Deeper work goes through the app store and the AI agent layer.

### is 1 panel safe

The project makes no security claim. What it describes is that applications deploy on containers to limit exposure, that WAF and log auditing are available with WAF basic in the free tier, and that its interface sits behind a chosen port and a secret path over HTTP, with credentials only recoverable over SSH.

### 1panel vs webmin

The project compares the two in a table and marks itself ahead on open source status, a one-click app store, a post-2020 interface and container management, and marks Webmin as slow on active development. That table carries no versions, dates or method, so it indicates the project's position rather than a measured difference.

## Sources

- [Official documentation](https://1panel.pro)
- [Official README](https://github.com/1Panel-dev/1Panel#readme)
- [Project repository](https://github.com/1Panel-dev/1Panel)
- [Release notes](https://github.com/1Panel-dev/1Panel/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/1panel-dev-1panel
