aaPanel: a Linux hosting control panel you install as root
Simple but Powerful web-based Control Panel
At a glance
- What is it?
- aaPanel is a web-based control panel for Linux servers that installs LNMP or LAMP stacks from a browser. It suits admins who want a GUI over nginx, MySQL and PHP, and it expects a clean OS with no existing web stack.
- Who is it for?
- Adopt aaPanel when you have a clean Ubuntu 22.04, Debian 11/12, CentOS 9 or Rocky/AlmaLinux 8/9 host and want a browser GUI over nginx, MySQL and PHP without hand-editing configs. Skip it on a server that already runs Apache, Nginx, PHP or MySQL from another source, since the README states an existing environment cannot be installed over, and skip it on Windows, which the supported system list does not include.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 35 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What aaPanel replaces, and who it is for
Setting up a LAMP or LNMP host by hand means installing nginx or Apache, PHP with the right extensions, MySQL, and then wiring vhosts, TLS and cron jobs. aaPanel puts that work behind a browser GUI. The README describes it as "a simple but powerful hosting control panel" that manages the web server through a web-based interface, with "one-click function" installs for LNMP/LAMP environments and software. The stated goal is to save deployment time so operators can focus on their own project.
The audience is a sysadmin or developer running one or more Linux servers who wants a panel rather than a configuration management repo. It is not a managed platform: you supply the machine, the root access and the clean operating system. The README is explicit that this must be a clean OS with no Apache, Nginx, PHP or MySQL installed from other environments, and that an existing environment cannot be installed over. That single constraint rules out dropping aaPanel onto a server that is already serving traffic.
Support is Linux only. The README says the panel is developed on Ubuntu 22+ and strongly recommends Ubuntu 22 or newer, with tested systems listed as Ubuntu 22.04 and 24.04, Debian 11 and 12, CentOS 9, and Rocky/AlmaLinux 8 and 9. Windows does not appear in that list. Resource floors are low: 512M of memory, 768M recommended, and over 100M of disk, with the README noting the pure panel uses about 60M of memory and 20M of disk.
How the panel is put together: Flask, a task process and the BT directories
The repository layout shows a Python panel rather than a single static binary. Top-level entries include runserver.py, runconfig.py, task.py, tools.py, init.sh and install.sh, alongside directories named class, class_v2, config, data, install, mod, rewrite, script, ssl, vhost and webserver. There are also BT-Panel and BT-Task entries plus BTPanel and BTTask directories, which suggests the panel and its background task runner are separate components. The README does not document the internal architecture, so what follows is read from the file tree and requirements.txt, not from a design document.
requirements.txt pins a Flask stack: Flask 2.2.5, Flask-Session 0.4.0, Flask-SQLAlchemy 3.0.3 and flask-sock 0.7.0. Gevent 24.2.1 and gevent-websocket 0.10.1 are present, which points at the web terminal and websocket handling the README mentions when it says the server can be managed through a Web terminal. The file also pins paramiko 3.4.0, psutil 5.9.5, pyinotify 0.9.6 and supervisor 4.2.5, and includes client libraries for several object stores and cloud providers: oss2, cos-python-sdk-v5, qiniu, upyun, google-cloud-storage, plus Aliyun SDK packages. That mix is consistent with a panel that manages local services while also handling remote storage and notification integrations.
The data flow implied by the README's Docker section is that the panel owns fixed paths on disk. Website data lives at /www/wwwroot, MySQL data at /www/server/data, and vhost files at /www/server/panel/vhost. Those three paths are the ones the Docker deployment mounts as volumes, which tells you where the panel expects to read and write state. Ports are fixed too: the control panel listens on 8888 and phpMyAdmin on 888.
Installing aaPanel on Ubuntu or Debian with the shell script
The README's installation command downloads a script and runs it with root authority. It picks curl if /usr/bin/curl exists and falls back to wget otherwise. The trailing token in the command is part of the README's published line, so copy it as written.
URL=https://www.aapanel.com/script/install_6.0_en.sh && if [ -f /usr/bin/curl ];then curl -ksSO "$URL" ;else wget --no-check-certificate -O install_6.0_en.sh "$URL";fi;bash install_6.0_en.sh 66959f96Run this on a clean Ubuntu 22.04 or 24.04, Debian 11 or 12, CentOS 9, or Rocky/AlmaLinux 8 or 9 host, as root. The README warns that Apache, Nginx, PHP or MySQL from another environment must not already be present. After the script finishes, the panel is reachable in a browser on the control panel port, 8888, and phpMyAdmin on 888. The README does not print the first-login credentials for the script path, so treat the panel's own login screen as the place to find them.
The README also lists memory and disk floors worth checking before you start: 512M of memory with 768M recommended, and more than 100M of free disk space. If the machine is smaller than that, the install is the wrong first step.
Running aaPanel from the official Docker image
For a container-based setup, the README gives a docker run command using the image aapanel/aapanel:lib, which it states is officially released by aaPanel. The command maps the panel port and the service ports, and mounts the same three directories the panel uses on a bare-metal install.
docker run -d -p 8886:8888 -p 22:21 -p 443:443 -p 80:80 -p 889:888 -v ~/website_data:/www/wwwroot -v ~/mysql_data:/www/server/data -v ~/vhost:/www/server/panel/vhost aapanel/aapanel:libNote the port mapping: the host port 8886 forwards to the container's 8888, so the README says to reach the panel at http://youripaddress:8886/. The other mappings follow the same pattern, with host 889 forwarding to the container's 888 for phpMyAdmin, and 80 and 443 exposed for web traffic. The default credentials in the README are username aapanel and password aapanel123. The README's own note is blunt: after deployment, immediately modify the username and password in the panel settings and add the installation entry. Leaving those defaults in place on a reachable host is the most obvious way to lose the box.
The volume mounts matter more than they look. Website data goes to ~/website_data, MySQL data to ~/mysql_data, and vhost files to ~/vhost. If you omit them, container state lives and dies with the container.
Where aaPanel is the wrong tool
The clean-OS requirement is the sharpest limitation. The README states the existing environment cannot be installed, meaning a server already running nginx or MySQL from a package manager or from source is not a candidate. Migration means rebuilding the host, not layering the panel on top. For anyone with a long-lived server, that is a real cost the README does not soften.
Second, the supported system list is narrow and Linux-only. Ubuntu 22.04 and 24.04, Debian 11 and 12, CentOS 9, and Rocky/AlmaLinux 8 and 9 are named. If you run a distribution outside that set, or you need Windows, the README offers nothing. The panel is also developed on Ubuntu 22+, which is a hint about where testing effort sits.
Third, the repository does not present itself as a hardened, audited component. The license field is NOASSERTION, and the only license artifact visible in the top-level listing is license.txt. There is a SECURITY.md, but the README does not describe a disclosure process, a supported-versions policy, or a patch cadence. The README documents installation and deployment; it does not document rollback, backup of panel state, or an upgrade path. Anyone planning to run this in production is making a judgement about a project whose public documentation covers setup far better than it covers recovery.
aaPanel against cPanel and against doing it by hand
The comparison people reach for is cPanel, and the difference in approach is structural. cPanel is a commercial product tied to a licensing model and to specific distributions, and it is typically sold with hosting accounts. aaPanel is distributed from a public repository and installed by a shell script or a Docker image, with no license key step described in the README. The practical difference is who pays and who is accountable: with cPanel you are buying a supported product, while with aaPanel you are running software whose README points to a documentation site and a demo, not to a support contract. The README does link a demo at demo.aapanel.com with the credentials aapanel and aapanel, which is the fastest way to see the interface before committing a server.
The other alternative is no panel at all: configure nginx, PHP-FPM, MySQL and certbot directly, and keep the configuration in version control. That approach has no clean-OS constraint, no fixed /www paths, and no panel process holding port 8888. It also has no one-click installer and no web terminal. The honest split is that aaPanel trades control over the exact stack layout for speed of setup. If your server's configuration is itself a deliverable that other people review, the panel's generated vhosts under /www/server/panel/vhost are a layer you will have to read through rather than author.
Maintenance, licensing and what to check before adopting
The repository is not archived, and the last push was on 2026-08-27. The most recent release listed is 7.65.0 from 2026-01-22, preceded by 7.63.0 on 2026-01-09 and 7.59.0 on 2025-12-04. So commits have continued after the latest tagged release, which is worth knowing if you pin versions: the release tags and the branch head are not the same thing.
Upgrade cost is mostly operational. The panel installs a Python stack pinned by requirements.txt, with exact versions for Flask, gevent, SQLAlchemy, paramiko and dozens of other packages. Those pins include Flask 2.2.5, Jinja2 3.1.3, cryptography 40.0.2 and PyYAML 6.0.1. A pin list that long is a compatibility surface: the panel's own upgrades have to move those versions together, and anything you install into the same Python environment risks colliding with them. The README does not describe how the panel upgrades itself, so verify that on a staging host before you rely on it.
On licensing, the repository's license field is NOASSERTION, and the top-level listing includes license.txt. That means the terms are not machine-classified by the hosting platform; read license.txt yourself and decide whether your use fits. This is not legal advice, and the README does not summarise the terms. The README does state that the Docker image is officially released by aaPanel, which tells you the image is a first-party artifact rather than a community build.
Editorial conclusion
Adopt aaPanel when you have a clean Ubuntu 22.04, Debian 11/12, CentOS 9 or Rocky/AlmaLinux 8/9 host and want a browser GUI over nginx, MySQL and PHP without hand-editing configs. Skip it on a server that already runs Apache, Nginx, PHP or MySQL from another source, since the README states an existing environment cannot be installed over, and skip it on Windows, which the supported system list does not include. Before trusting it with production, verify three things: the licence terms, because the repository license is marked NOASSERTION and license.txt is the only pointer; the panel's own update path, since the README documents installation but not rollback; and whether the Docker image's default credentials have been changed, because the README ships aapanel/aapanel123 and tells you to change them immediately.
Frequently asked questions
How do I install aaPanel on Ubuntu 22.04?
Run the README's installation command as root on a clean Ubuntu 22.04 host that has no Apache, Nginx, PHP or MySQL installed from another environment. The command downloads install_6.0_en.sh with curl or wget and executes it. Ubuntu 22.04 is one of the systems the README lists as supported.
How do I install aaPanel on Debian 12?
Use the same root installation command the README publishes, on a clean Debian 12 system. Debian 11 and 12 both appear in the README's supported system list. The machine needs at least 512M of memory and more than 100M of free disk space.
How do I install aaPanel on AlmaLinux?
The README lists Rocky/AlmaLinux 8 and 9 as supported systems, and the install is the same root shell command used on Ubuntu and Debian. The README requires a clean OS with no existing Apache, Nginx, PHP or MySQL environment.
How do I install aaPanel on Windows?
The README does not offer a Windows installation. Its supported system list covers Ubuntu 22.04 and 24.04, Debian 11 and 12, CentOS 9, and Rocky/AlmaLinux 8 and 9, and it describes aaPanel as server management software that supports the Linux system.
How do I access aaPanel after installing it?
Access it in a browser on the control panel port, which the README lists as 8888, with phpMyAdmin on 888. With the Docker deployment the README maps host port 8886 to the container's 8888 and says to open http://youripaddress:8886/, using the default username aapanel and password aapanel123, which it says to change immediately.
How do I use Docker in aaPanel?
The README's Docker path is the official aapanel/aapanel:lib image, started with docker run and three volume mounts for website data, MySQL data and vhost files. The docker package is also pinned in requirements.txt, but the README does not document managing containers from inside the panel.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/aapanel-aapanel)