# Hestia Control Panel: a shell-driven web server panel for Debian and Ubuntu

> HestiaCP bundles NGINX, Apache2, PHP-FPM, Bind, mail and databases behind one dashboard and a CLI. It is for administrators who already know their way around a Linux server, and the install script takes over a fresh one.

**hestiacp/hestiacp** — Hestia Control Panel | A lightweight and powerful control panel for the modern web.

- Repository: https://github.com/hestiacp/hestiacp
- Website: https://hestiacp.com
- Stars: 4,510 · Forks: 945
- Language: Shell
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/hestiacp-hestiacp

## What HestiaCP replaces, and who it is built for

Running a web server by hand means holding several configuration files in your head at once: an NGINX or Apache vhost, a PHP-FPM pool, a Bind zone, Dovecot and Exim for mail, a MariaDB or PostgreSQL instance, and a firewall with fail2ban on top. Hestia Control Panel exists to put those under one administrative surface. The README describes the goal plainly: administrators get a web and command line interface that lets them "quickly deploy and manage web domains, mail accounts, DNS zones, and databases from one central dashboard without the hassle of manually deploying and configuring individual components or services."

The audience is narrower than that sentence suggests. The README states that it assumes "some prior knowledge and understanding in the basics how to set up a Linux server." This is not a panel you hand to someone who has never opened an SSH session. It is for the sysadmin who already knows what a vhost is and would rather not write each one by hand. The feature list confirms the scope: Apache2 and NGINX with PHP-FPM, multiple PHP versions from 5.6 to 8.5 with 8.5 as default, Bind with clustering, POP/IMAP/SMTP with ClamAV, SpamAssassin, Sieve and Roundcube, MariaDB/MySQL and PostgreSQL, Let's Encrypt including wildcard certificates, and a firewall built on iptables, fail2ban and ipset.

That is a full hosting stack rather than a site builder. If you only need to deploy a containerised application behind a reverse proxy, most of what HestiaCP installs is weight you did not ask for.

## How the panel, the CLI and the managed services fit together

The repository layout says a lot about the architecture. The top level holds bin/, func/, install/, src/ and web/ alongside a package.json whose only job is front-end tooling. The package name is "hestia" and it is marked private, with dependencies such as alpinejs, chart.js, floating-vue, @xterm/xterm and @xterm/addon-webgl. Those are the components of the browser interface: a terminal emulator, charts, a Vue-based component layer. The panel itself is not a Node application. The primary language of the repository is Shell, and the build script at the top level exists to assemble assets for web/.

So the data flow is conventional for this class of tool. The browser interface calls into the PHP layer under web/, which in turn drives the shell functions and binaries under func/ and bin/. Those scripts are what actually write the service configuration and reload the daemons. The README's two interfaces, web and command line, are therefore not two separate products but two front ends over the same set of system operations.

That design has a practical consequence. Anything the panel can do, a script can do, and vice versa. It also means the panel is only as safe as the shell layer beneath it, and that an administrator who edits a vhost by hand can create state the panel does not know about. The README does not document how the panel reconciles manual edits to managed configuration files, and that silence is worth noting before you plan a workflow that mixes both.

## Installing HestiaCP on a fresh Debian or Ubuntu server

The README is explicit that HestiaCP "must" be installed on top of a fresh operating system installation. Supported targets are Debian 13, 12 and 11, and Ubuntu 26.04 LTS, 24.04 LTS and 22.04 LTS. The first step is to log in as root, either at the console or over SSH:

```bash
ssh root@your.server
```

Next, download the installer for the latest release. The README notes that if the download fails with an SSL validation error, you should install the ca-certificates package first:

```bash
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
apt-get update && apt-get install ca-certificates
```

Then run the script and follow the prompts. The README states that you receive a welcome email at the address you supply during installation, plus on-screen instructions for logging in:

```bash
bash hst-install.sh
```

For anything other than a default build, the installer takes flags. The README points at the help output as the authoritative list, and at a web form at hestiacp.com/install.html that generates a command for you:

```bash
bash hst-install.sh -h
```

The README does not print the flag list itself, so read that help output rather than guessing at option names. After installation, upgrades are handled by apt, and automatic updates are on by default for new installs, configurable under Server Settings > Updates:

```bash
apt-get update
apt-get upgrade
```

## Where HestiaCP is the wrong choice

The virtualisation constraint is the one most likely to bite. The README warns that HestiaCP combined with OpenVZ 7 or lower "might have issues with DNS and/or firewall," and advises a VPS based on KVM or LXC instead. Since the firewall and DNS server are two of the listed features, a provider running older OpenVZ can leave you with a panel that installs cleanly and then misbehaves in exactly the areas you chose it for. Check the virtualisation type before you buy, not after.

32-bit operating systems are unsupported outright. That rules out older or unusually cheap hardware.

The fresh-install requirement is the second hard boundary. There is no documented in-place migration from an existing configured server into HestiaCP. If you have a machine already serving mail and sites, the README gives you no path; you would be provisioning a new host and moving workloads yourself. The README is silent on rollback and on uninstalling the panel, so treat installation as a commitment to the host rather than a reversible experiment.

Finally, the support policy is deliberate. The README states that support requests without troubleshooting steps already performed will not be handled, and that third-party applications such as WordPress are out of scope. If you want a vendor to debug your CMS, this is not that product.

## HestiaCP against CyberPanel, CloudPanel and aaPanel

The comparison that matters is not feature count but what the panel assumes about your stack. HestiaCP installs a classic LAMP-style arrangement with a choice of Apache2 or NGINX in front of PHP-FPM, and it treats mail and DNS as first-class: Bind with clustering, and a full POP/IMAP/SMTP set with ClamAV, SpamAssassin, Sieve and Roundcube. That is a hosting-provider shape, where one machine serves sites, mailboxes and zones for many domains.

A panel oriented around modern application deployment typically assumes a container or a single runtime per site, and often leaves mail and DNS to external services. If your DNS lives at a registrar and your mail at a hosted provider, HestiaCP's Bind and Exim components are installed but idle, and you are carrying the configuration surface of services you do not use. Conversely, if you want to run your own mail and authoritative DNS on the same box as your sites, the alternatives that skip those components leave you assembling them yourself.

The lineage is also part of the comparison. The README states that HestiaCP is based on the VestaCP project and is licensed under GPL v3. Anyone migrating from VestaCP is moving within the same design tradition rather than to a different architecture. The README does not document a migration procedure from VestaCP, so the shared heritage does not by itself imply a supported upgrade path.

## Maintenance, releases and what the licence permits

The last push to the repository was on 2026-09-21, and the most recent release is 1.10.5, a service release dated 2026-09-14, following 1.10.4 and 1.10.3 in the weeks before. Service releases at that cadence suggest a project that ships fixes rather than sitting still, and the package.json version matches the release at 1.10.5. The repository is not archived.

Upgrade cost is low by design. Automatic updates are enabled by default on new installations and managed from Server Settings > Updates, and manual upgrades are two apt commands. The operational cost sits elsewhere: because the panel manages system services, an upgrade can touch NGINX, PHP-FPM, Dovecot, Exim, Bind and the database server at once. The README does not describe a staging or rollback procedure for panel upgrades, so the prudent assumption is that you need your own backups before running them.

On licensing, HestiaCP is GPL v3, and the package metadata records GPL-3.0-or-later. The README adds a separate trademark restriction that is not part of the GPL: you may use the names "Hestia Control Panel", "HestiaCP" and the logo in contexts directly related to the project, but you may not sell or redistribute the application under those names or use the logo in branding tied to revenue-generating activity. Note that HestiaCP is a fork lineage: it is based on VestaCP. This is a summary of what the README states, not legal advice; if you plan to redistribute or rebrand, read the LICENSE file and the copyright section yourself.

## Conclusion

Adopt HestiaCP if you run Debian 11 to 13 or Ubuntu 22.04 to 26.04 LTS on KVM or LXC and want web, mail, DNS and database management from one panel with a command line behind it. Do not adopt it on a server that already carries data, on 32-bit systems, or on OpenVZ 7 or lower, where the README warns DNS and firewall may misbehave. Before you commit, read install/hst-install.sh -h for the flags that match your stack, and confirm your provider's virtualisation type.

## FAQ

### What is HestiaCP?

It is an open source Linux web server control panel, licensed GPL v3 and based on the VestaCP project. It provides a web and command line interface for managing web domains, mail accounts, DNS zones and databases on a single server.

### How do I install HestiaCP?

Log in as root on a fresh supported operating system, download install/hst-install.sh from the release branch with wget, and run it with bash. The installer prompts for the details it needs and can take flags, which you list with bash hst-install.sh -h.

### How do I install HestiaCP on Ubuntu 22.04?

Ubuntu 22.04 LTS is one of the supported platforms, alongside 24.04 LTS and 26.04 LTS. The installation steps are the same as on any supported system: a fresh OS, root access, then the downloaded hst-install.sh run with bash.

### How do I access HestiaCP?

The README states that after installation completes you receive a welcome email at the address given during setup, along with on-screen instructions for logging in and accessing the server. The README does not list the panel's port or URL in the installation section.

### Is HestiaCP free?

It is licensed under GPL v3, and the package metadata records GPL-3.0-or-later, so there is no licence fee. The README does add separate trademark restrictions on the names Hestia Control Panel and HestiaCP and on the logo.

## Sources

- [hestiacp/hestiacp on GitHub](https://github.com/hestiacp/hestiacp)
- [License: GPL-3.0](https://github.com/hestiacp/hestiacp/blob/main/LICENSE)
- [Project website](https://hestiacp.com)
- [README](https://github.com/hestiacp/hestiacp/blob/main/README.md)
- [Releases](https://github.com/hestiacp/hestiacp/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/hestiacp-hestiacp
