CyberPanel can simplify administration of an OpenLiteSpeed-based VPS, but installing a control panel does not turn an unmanaged server into managed hosting. You still own operating-system maintenance, access control, backups, monitoring and recovery unless another provider explicitly manages those layers.
This page owns the installation and initial configuration workflow. Once the panel and first website are working, continue with the separate CyberPanel Post-Installation Checklist for deeper security review, LSPHP capacity, caching, Redis, database health, backup drills and performance validation.
This refresh uses CyberPanel's current release changelog, installation documentation, firewall/SSL guidance, backup/restore documentation and current custom OpenLiteSpeed notes.
Evidence boundary: this is a documentation-based deployment guide. No Digital Bhatti load test or fixed CyberPanel performance result is claimed.
Last verified: September 26, 2026. Release versions, OS support, installer behavior, ports, backup workflows and OpenLiteSpeed integration can change.
Use the 2026 Release Changelog, Not Only the Older OS Table
The latest CyberPanel changelog entry checked for this guide is v3.0.6 (September 7, 2026), which restores standalone webmail authentication separation. The immediately preceding v3.0.5 (August 26, 2026) is an API two-factor security update, so review older servers against the current stable release before production use.
CyberPanel's older installation page still displays a 2024-era compatibility list. Newer release notes add Ubuntu 26.04 and AlmaLinux 10 and retain existing Ubuntu/EL8/EL9/openEuler paths. Verify the live release notes and installer before provisioning.
1. Decide Whether CyberPanel Fits the Server You Want to Operate
CyberPanel is a server control panel. A self-managed deployment still requires Linux administration.
Use this installation workflow when you want:
- a VPS or cloud server you control;
- CyberPanel as the web-based administration layer;
- OpenLiteSpeed as the standard free web-server path;
- responsibility for patching, monitoring, access control and recovery.
If you want a provider to own most server operations, compare managed alternatives before installing a control panel yourself.
If you are still deciding whether CyberPanel itself fits your workflow rather than following installation steps, read the CyberPanel Review before provisioning.
2. Choose a Current Supported Operating-System Path
CyberPanel's public installation article and its 2026 release changelog are not fully synchronized. The older installation Knowledge Base still shows a narrower historical OS list, so use the newer release changelog plus the current installer as the support check immediately before provisioning.
| Current evidence | What it means |
|---|---|
| v3.0.0 release validation | CyberPanel says clean installs/browser workflows were validated on Ubuntu 22.04, 24.04 and 26.04. |
| v3.0.4 | Adds AlmaLinux 10 for fresh installs/upgrades and says existing Ubuntu, EL8, EL9 and openEuler paths remain unchanged. |
| Older install KB | Still shows an older list; do not use that page alone to decide 2026 support. |
For a new deployment, use a fresh server without another hosting panel and confirm the exact distribution/release in the current CyberPanel changelog immediately before installation.
3. Size the VPS for the Workload, Not the Installer Minimum
CyberPanel's older installer documentation lists 1 GB RAM and 10 GB disk as minimums. Treat those as installation minimums only; they are not production WordPress, WooCommerce, mail or multi-site sizing recommendations.
Production sizing should account for:
- number and type of websites;
- uncached PHP concurrency;
- database workload;
- mail/DNS services if enabled;
- backup working space;
- Redis or other optional services;
- traffic spikes and maintenance operations.
If you are still choosing infrastructure, use the Best Hosting for CyberPanel page for provider comparison rather than turning this installation tutorial into a hosting roundup.
4. Prepare the Server and a Recovery Path
Before running the installer:
- confirm provider console/recovery access;
- record the server's public IP;
- create a provider snapshot where available;
- decide the hostname;
- update the operating system using the commands appropriate for that distribution;
- verify you have root/privileged access;
- avoid installing CyberPanel over an existing web/mail/database control-panel stack.
For Ubuntu-family systems, the package update may look like:
apt update
apt upgrade -y
Do not copy Debian/Ubuntu package commands into AlmaLinux/RHEL-family systems.
5. Configure the Hostname and DNS Deliberately
A clear hostname helps panel access, TLS and mail-related configuration.
hostnamectl set-hostname panel.example.com
hostnamectl
Create the required DNS record before expecting hostname certificate issuance to succeed.
6. Run the Current Official CyberPanel Installer
CyberPanel's current HTTPS installation documentation uses this installer command:
sh <(curl https://cyberpanel.net/install.sh || wget -O - https://cyberpanel.net/install.sh)
Use the HTTPS command above. Some older CyberPanel documentation copies still expose an HTTP form of the installer URL; do not copy that older form into a new production deployment.
CyberPanel's installation guide expects root access. If your provider starts you with a sudo-capable user, obtain a root shell according to the provider's documented administration model before running the installer.
7. Review Installer Choices Instead of Accepting Everything Blindly
The installer can prompt for the OpenLiteSpeed/LiteSpeed path and optional services. Enable only what the server actually needs.
- OpenLiteSpeed: standard free CyberPanel path.
- LiteSpeed Enterprise: separate licensed path where applicable.
- DNS: enable only if this server will operate authoritative DNS.
- Mail: enable only if you intend to operate mail services here.
- Redis/Memcached: do not interpret an installer option as proof every WordPress site needs that cache layer.
- Remote database: requires a deliberately designed external database architecture.
Use a strong generated/custom administrator password rather than an installer default.
8. Reboot and Verify the Core Services
After installation and reboot, verify the environment before creating production sites.
systemctl status lscpd --no-pager
systemctl status lsws --no-pager
ss -lntup
CyberPanel documentation currently uses https://SERVER_IP:8090 for panel access. If a service fails, inspect current service logs and CyberPanel installation logs before repeatedly rerunning the installer.
9. Open Only the Ports for Services You Intentionally Operate
CyberPanel's installer documentation lists several possible ports, but that is not a recommendation to expose every service.
| Purpose | Typical CyberPanel-documented ports | Rule |
|---|---|---|
| Web | 80/TCP, 443/TCP; 443/UDP where HTTP/3 is used | Normally public for hosted websites. |
| CyberPanel | 8090/TCP | Restrict administrative access where practical. |
| SSH | Your configured SSH port | Keep a tested recovery path before tightening. |
| DNS | 53/TCP + 53/UDP | Only if the VPS is authoritative DNS. |
| 25/465/587/110/143/993 as applicable | Only if hosting mail services. | |
| FTP | 21 plus passive range documented by CyberPanel | Only when FTP is actually required. |
Do not publicly expose Redis or MariaDB/MySQL merely because they run on the same server.
10. Secure CyberPanel and SSH Before Adding Production Sites
- replace/default-check administrator credentials;
- keep CyberPanel on HTTPS;
- limit panel access by trusted IP/VPN/firewall policy where practical;
- use SSH keys where appropriate;
- remove unused administrator/users;
- do not disable your only working recovery route;
- keep the current stable CyberPanel release under review because security updates are shipped through the release line.
As of this verification, the latest release entry is v3.0.6, and v3.0.5 immediately before it was specifically described as an API two-factor security update.
11. Understand CyberPanel's Custom OpenLiteSpeed Stack
CyberPanel currently maintains a custom OpenLiteSpeed binary/integration that is installed automatically through the CyberPanel path. Its product documentation warns against mixing stock and custom OLS/ModSecurity/module binaries because ABI/module compatibility matters.
For CyberPanel users, the custom OLS stack is currently installed/updated through the CyberPanel upgrade path. Do not replace OLS, ModSecurity or CyberPanel OLS modules with unrelated binaries simply because a generic OpenLiteSpeed tutorial recommends it.
12. Create the First Website and Validate Routing
After creating a website, verify:
- the intended domain points to this VPS;
- the document root is correct;
- the correct OpenLiteSpeed virtual host serves the request;
- the intended LSPHP version is active;
- rewrites work;
- HTTP/HTTPS behavior is intentional.
Do this before tuning PHP process counts or cache layers.
13. Issue SSL Only After DNS and Reachability Are Correct
CyberPanel can issue Let's Encrypt certificates for websites and hostname access. Before requesting a certificate:
- verify the hostname/domain resolves to the correct server;
- verify required validation traffic reaches the server;
- confirm the correct website/virtual host exists;
- avoid repeated certificate requests while DNS is still wrong.
For hostname SSL, CyberPanel's documentation uses the SSL → Hostname SSL workflow after the relevant hostname site exists.
14. Install WordPress and Establish a Known-Good Baseline
After WordPress installation:
- verify frontend and
wp-admin; - confirm HTTPS and permalinks;
- remove unused default plugins/themes where appropriate;
- check PHP errors;
- verify scheduled tasks and application email if required;
- avoid enabling every LiteSpeed Cache optimization at once.
This installation page stops at the baseline. Detailed LSPHP, LiteSpeed Cache, Redis and database tuning belongs in the post-install checklist.
15. Create a Backup and Prove You Can Restore It
CyberPanel's current backup guide covers manual full backups, incremental jobs, scheduled backups and remote destinations. A production deployment should keep at least one usable copy outside the server because a same-disk backup does not protect against full server or disk failure.
For a manual full restore, CyberPanel's updated guide currently describes this workflow:
- Create and retain a completed CyberPanel website backup.
- Keep the original copy outside the production server.
- On the destination/restore server, place the completed archive under
/home/backupwhen using the current Restore Backup workflow. - Open Backups → Restore Backup.
- Select the detected archive and start restoration.
- After restoration, verify files, database, DNS, SSL and application login.
16. Plan CyberPanel Upgrades Like Infrastructure Changes
CyberPanel's current upgrade documentation uses:
sh <(curl https://raw.githubusercontent.com/usmannasir/cyberpanel/stable/preUpgrade.sh || wget -O - https://raw.githubusercontent.com/usmannasir/cyberpanel/stable/preUpgrade.sh)
Before a production upgrade:
- read the current changelog;
- take a provider snapshot or verified full backup;
- confirm off-server recovery data exists;
- schedule a maintenance window;
- record the current CyberPanel/OLS/PHP versions;
- validate panel login, websites, SSL, databases, backups and mail afterward.
CyberPanel's 3.0.0 release notes explicitly recommend a provider snapshot or verified full backup plus a maintenance window before upgrading production.
17. Installation Handoff: Move Tuning to the Post-Install Page
Once the following are true, installation is complete:
- CyberPanel admin works over HTTPS;
- SSH/provider-console recovery access works;
- firewall exposure is intentional;
- the first website resolves and serves the correct vhost;
- WordPress/app baseline works;
- SSL is valid;
- a backup exists off-server;
- a representative restore has been tested.
Then continue with the CyberPanel Post-Installation Checklist for LSPHP capacity, caching, Redis, database review, monitoring and measured tuning.
18. Common CyberPanel Installation Mistakes
- Using the stale OS list as the only support check.
- Installing over an existing hosting stack.
- Running the installer without a recovery snapshot/path.
- Opening every CyberPanel-documented port even when services are disabled.
- Running old HTTP/mirror installer commands copied from third-party posts.
- Mixing stock and CyberPanel custom OLS modules.
- Trying to optimize LSPHP/Redis before the baseline works.
- Keeping the only backup on the production VPS.
- Never testing restore.
- Assuming CyberPanel means the server is managed.
CyberPanel Installation Checklist
- Confirm current supported OS in the newest release information.
- Use a clean server.
- Create provider recovery access/snapshot.
- Configure hostname/DNS.
- Run only the official HTTPS installer.
- Choose only required services.
- Use a strong admin password.
- Verify LSCPD/OpenLiteSpeed after reboot.
- Expose only required ports.
- Secure panel and SSH access.
- Create and verify the first website.
- Issue SSL only after DNS is correct.
- Validate WordPress/application baseline.
- Create an off-server backup.
- Test a restore.
- Move tuning tasks to the post-install page.
CyberPanel Is Installed—Now Validate the Server
Continue with the post-install checklist for LSPHP concurrency, cache validation, Redis, database health, backup drills, monitoring and measured performance tuning.
Open Post-Installation Checklist →Frequently Asked Questions
What is the current CyberPanel version?
The latest entry in CyberPanel's changelog checked September 26, 2026 is v3.0.6, dated September 7, 2026. It is titled the Standalone Webmail Authentication Fix; v3.0.5 immediately before it is an API two-factor security update. Always check the current changelog before installing or upgrading because security and platform releases can change quickly.
Which operating systems does CyberPanel support in 2026?
The current 3.x release notes explicitly add Ubuntu 26.04 and AlmaLinux 10 and state that existing Ubuntu, EL8, EL9 and openEuler paths continue. CyberPanel also says its 3.0.0 browser/install validation covered Ubuntu 22.04, 24.04 and 26.04. The older installation article is not the complete current support list, so verify the current release documentation before provisioning.
What is the official CyberPanel installation command?
CyberPanel currently documents the HTTPS installer at https://cyberpanel.net/install.sh. Run privileged remote installers only from the current official source and keep a rollback path.
Does CyberPanel use OpenLiteSpeed?
The standard free CyberPanel path uses OpenLiteSpeed. Current CyberPanel versions maintain a CyberPanel-specific custom OLS stack, so generic stock-OLS replacement instructions should not be applied blindly.
Should I enable Redis during installation?
Only if the workload and WordPress/application design will use it. Redis is not mandatory for every site.
Where should CyberPanel backups be restored from?
CyberPanel's updated full backup/restore guide says the Restore Backup workflow detects archives under /home/backup. Keep an independent copy before restoration and verify the recovered website afterward.
Abdul Shakoor
Founder of Digital Bhatti, an independent technical publication focused on web hosting and infrastructure, WordPress, technical SEO, web performance and automation.