What Is aaPanel? How to Install the Free Hosting Control Panel

What is aaPanel and what does it do?
aaPanel is a free web hosting control panel that lets you manage a Linux server from your browser. It brings the web server, PHP, MySQL, FTP, SSL certificates, a file manager and scheduled backups into one interface. So you can launch sites, create databases and issue certificates without typing every command by hand.
In this guide we walk through an aaPanel install in a safe order. We also cover where the panel helps and where it adds risk. We are a digital marketing and web team, not a hosting company. Therefore we base the technical details on aaPanel's official documentation, and we leave out any value we could not confirm there.
In short, our goal is simple. If you run your own VPS as a site owner or developer, you should finish this article able to decide whether aaPanel fits. And if you go ahead, you should not skip the security steps that matter on day one.
How is aaPanel related to BT Panel?
aaPanel is widely known as the international edition of BT Panel (Baota), a control panel that is popular in China. That said, the official aaPanel website does not highlight this link on its home page. However, file names in the official aaPanel GitHub repository and the panel's command line tool, called bt, point to that shared history.
Why should this matter to you? Because the development team, release schedule and support channels work differently from Western panels. For example, most community help happens on the official forum. The docs are in English, yet some menu names change between versions.
So when you evaluate aaPanel, ask two questions together. The first is technical fit: does the panel cover what you need? The second is governance: can you follow updates, security notices and data processing terms? In a corporate project, the second question weighs at least as much as the first. For a personal project, a test box or a small site, technical fit usually decides.
What features does aaPanel offer?
The official home page lists WP Toolkit, websites, a mail server, FTP, MySQL, file management and an online code editor in the free edition. In addition, it mentions one click Docker apps and scheduled backups. Here are the core functions in plain terms:
- Website management: add domains, set the document root, pick a PHP version and write redirect rules.
- Databases: create MySQL databases and users, with phpMyAdmin access.
- SSL: request and renew Let's Encrypt certificates from the panel.
- FTP: create FTP accounts per site.
- File manager: upload, download, edit files and change permissions in the browser.
- App Store: install web servers, PHP versions, Redis and plugins.
- Cron: a scheduler for backups and custom commands.
- Security: a built in firewall, panel login restrictions and two factor authentication.
In other words, aaPanel gives a single VPS most of what you see in a classic shared hosting panel. Still, do not assume every feature ships production ready. The mail server in particular calls for real expertise, and we cover it separately below.
Which web servers does aaPanel support?
On first login, aaPanel offers two ready stacks: LNMP (Nginx based) and LAMP (Apache based). The official quick start guide also tells you to install one of these from the dashboard first. OpenLiteSpeed is a third option you can add from the App Store.
According to the official multi web server FAQ, aaPanel can run Nginx, Apache and OpenLiteSpeed on the same server and tries to resolve port conflicts on its own. Even so, we recommend you start with one web server. After all, running three at once makes debugging harder and uses memory you probably need elsewhere.
Which one should you pick? Here is a quick way to think about it:
- Nginx: fast with static files, common as a reverse proxy, and well documented.
- Apache: .htaccess support makes life easier for older PHP projects and some plugins.
- OpenLiteSpeed: popular with WordPress thanks to the LiteSpeed cache plugin, but its configuration logic differs.
For a deeper comparison, read our guide on OpenLiteSpeed vs Nginx.
What are the server requirements for aaPanel?
The official download page lists a minimum of 1 CPU core and 512 MB of RAM. For comfort, it recommends 1 core and 1 GB of RAM. The quick start guide also mentions at least 1 GB of storage. Keep in mind that these numbers cover the panel itself. Your sites, database and PHP workers need resources on top of that.
Supported operating systems also change from release to release. The current quick start guide lists specific versions of Ubuntu, Debian, AlmaLinux, Rocky Linux and CentOS. Therefore, check the version list on the official page on install day instead of relying on any article. The download page recommends the current Ubuntu LTS.
A practical pre install checklist looks like this:
- A fresh, clean server with no other panel and no hand installed web server.
- A root or sudo user and SSH key login.
- Access to your provider's security group or cloud firewall settings.
- A domain you plan to point at the server, plus access to its DNS.
If you have not picked a server type yet, our guide on VPS vs cloud server vs VDS will help you decide.
How should you prepare the server before installing?
An aaPanel install takes a few minutes. Skip the prep, though, and you may lose hours later. First, update your system packages. On Ubuntu or Debian, these two commands do the job:
sudo apt update
sudo apt upgrade -y
Next, switch SSH login from passwords to keys. Turning off password based root login is one of the most effective first steps against brute force attempts. Our Fail2ban setup guide covers this topic in more depth.
Then set the server time zone and hostname. Otherwise, a wrong clock causes confusion in SSL renewals and log files. Moreover, the hostname matters for reputation checks if you ever send email from this machine.
Finally, take a snapshot right before the install if your provider offers one. That way, if the install goes wrong, you can roll the server back to a clean state in minutes. This small step is a real safety net, especially for your first panel install.
How do you install aaPanel safely in two steps?
The official download page gives a one line command. In practice, that command downloads the script and runs it right away. We suggest you split the same official script into separate steps: download it, read it, then run it.
- Download the script. The address matches the one on the official download page:
URL=https://www.aapanel.com/script/install_panel_en.sh curl -fsSL -o install_panel_en.sh "$URL" - Review the script. Open it in a pager and look at what it installs and which hosts it contacts:
less install_panel_en.sh - Run the script. After the review, start it with root privileges:
sudo bash install_panel_en.sh
You will sometimes see an extra argument at the end of the official command. That argument can change over time. So check the current command on the official download page on install day. The script asks for confirmation during setup; read each prompt before you answer. The official page says the install takes about two minutes on a fresh server.
Why not run the official one liner as is?
Running a script from the internet as root without reading it hands that script full control of your server. Even if the script itself is harmless, a broken download can leave you running half a file. The two step method therefore lowers that risk.
There is also a detail worth noting in the official one liner. It passes -k to curl and --no-check-certificate to wget. Specifically, both flags turn off TLS certificate verification. In other words, the download happens without confirming that the connection really reaches aapanel.com.
Our version drops that flag. As a result, curl checks the certificate as usual and stops if verification fails. That is also why an accurate system clock and an up to date CA bundle on the server matter.
What should you look for while reviewing the script? Check which package manager it calls, which directories it writes to and which domains it pulls extra files from. You do not need to understand every line. However, if you spot an unexpected host or an action you did not agree to, stop and ask on the official forum. This habit applies to every install script, not only aaPanel.
How do you log in to aaPanel for the first time?
When the install finishes, the script prints a panel address, a username and a password. The official docs show the format: your server IP, a port number and a random path at the end. That path is what aaPanel calls the security entrance.
Save these details in a password manager right away. If you already closed the terminal, do not worry. According to the official docs, this command shows the login details again:
sudo bt default
If you forget the password, you can reset it with bt 5. To see which port the panel uses, read the file that the official download page points to:
sudo cat /www/server/panel/data/port.pl
Your browser may show a certificate warning on the first visit. The official settings docs say the panel uses a self signed certificate by default. That makes the warning expected. For a lasting fix, though, we recommend you set a valid certificate for your own panel domain. After that, the panel asks you to install the LNMP or LAMP stack; choose based on the section above.
How do you protect the aaPanel port and security entrance?
Put simply, a control panel is the key to your server. That is why you should guard the panel more tightly than your websites. Older docs and the GitHub page list 8888 as the default panel port. The current installer, by contrast, prints its own port and security entrance path at the end. Whichever release you install, do not keep a default or guessable port.
The official settings docs describe several layers of protection. We suggest you turn them on in this order:
- Security entrance: keep the random path and never swap it for a guessable word.
- Authorized IP: allow panel access only from your own static IP.
- Two factor authentication: require a dynamic code from a Google Authenticator compatible app.
- BasicAuth: add an extra username and password layer in front of the panel.
- Panel SSL: set a valid certificate for your own domain.
- Session timeout: log out automatically after a period of inactivity.
To change the port, use the panel settings or the bt 8 command. Open the new port in your provider's security group first; otherwise you lock yourself out. If you do get locked out, the official docs list bt 23 for BasicAuth and bt 24 for two factor authentication as SSH recovery commands.
Which aaPanel ports should you open and which should stay closed?
The official quick start guide says that if you cannot reach the panel, you should open the panel port plus ports 888, 80, 443, 20 and 21 in your security group. However, that list solves an access problem. It does not mean every port should face the internet forever. We use the table below as a starting point:
| Port | Purpose | Our advice |
|---|---|---|
| 22 | SSH | Open, but ideally only to your IP; key login only |
| 80 and 443 | HTTP and HTTPS | Open to everyone; your sites need them |
| Panel port | aaPanel dashboard | Open only to your IP |
| 888 | phpMyAdmin | Closed; open briefly and IP restricted when needed |
| 20 and 21 | FTP | Closed; use SFTP for file transfers |
| 3306 | MySQL | Closed; use an SSH tunnel for remote access |
According to the official security docs, the aaPanel firewall denies traffic by default. So only the ports you allow stay open. Your cloud provider's security group, however, is a separate layer, and you need to plan both together. For more advanced rules, see our CSF firewall guide.
How do you add your first website and SSL certificate?
Once the stack is in place, open the Website menu and add a new site. Next, the panel asks for the domain, the document root and the PHP version. You can also create a database and an FTP account on the same screen.
Before you add the site, point your domain's A record to the server IP. To confirm the record, use our DNS lookup tool. Do not request a certificate until the record looks right, because Let's Encrypt checks that the domain really resolves to this server.
When DNS is ready, request a Let's Encrypt certificate from the site's SSL tab. Then turn on the option that forces HTTPS. Finally, run the domain through our SSL checker to confirm the chain and expiry date look correct.
If you want the fundamentals, our SSL certificate guide explains how certificates work. One more note: the official download page says the panel now supports trusted certificates for IP addresses too. Even so, always prefer a domain based certificate for your site.
How should you use databases, FTP and the file manager?
The Databases menu lets you create MySQL databases and users. Also, give each site its own database user. That way, a flaw in one site cannot reach another site's data directly. Keep the random passwords the panel suggests and store them in your password manager.
phpMyAdmin is handy, but it does not need to stay open all the time. Close its port when you finish, or allow it only from your IP. For large dumps, the command line is more reliable anyway. We cover that in our guide to backup and restore with mysqldump.
Plain FTP can send passwords and files without encryption. For that reason, use SSH based SFTP for file transfers. Open FTP only if an older tool forces you to, and only for a short time.
The file manager, on the other hand, is great for small fixes. For example, you can edit a config file or extract an archive in seconds. Still, avoid making large code changes there. Use version control and a simple deploy process instead. That way you always know what changed and when.
How do you plan backups in aaPanel?
The official home page says aaPanel can run scheduled backups to local disk, FTP or cloud storage. You then set this up in the Cron menu. There you create separate tasks for site files and databases, then choose the frequency and how many copies to keep.
That said, do not rely only on a local backup on the same server. A disk failure, an accidental delete or a compromised server can take both the site and the backup with it. So keep at least one copy off the server, with a different provider.
To build a solid plan, answer these three questions:
- Can you live with losing a day of data, or do you need hourly backups?
- Do the backups sit off the server, in a separate account with its own access key?
- When did you last test a restore, and how long did it take?
The third question is the one people skip most. After all, a backup you have never restored is a backup nobody has proven. Also, treat your provider's snapshots as an addition to panel backups, not a replacement. For the full picture, read our website backup strategy guide.
What is the difference between aaPanel Free and Pro?
According to the official download page, core functions such as site building and file management are free and need no registration. The home page describes the free edition as free for life. Meanwhile, the Pro edition adds extra features, and the download page offers it with a trial period.
The main Pro additions on the official home page are:
- Multi user accounts for shared hosting setups.
- A web application firewall (WAF).
- Traffic and log analysis.
- File protection features.
- Bulk email sending.
We leave pricing out of this article because license terms and prices can change. Check the current table on the official site before you decide.
So do you need Pro? For a single site or a few of your own projects, the free edition usually covers it. If you want to give clients their own panel logins, however, multi user support becomes the deciding factor. And before you buy Pro just for the WAF, check whether your provider or a CDN service already offers similar protection.
Which panel fits whom: aaPanel, cPanel, Plesk or CyberPanel?
Choosing a panel depends more on your business model than on technical taste. The table below compares the options from the view of a site owner who manages a VPS. Still, details vary by version and license.
| Criteria | aaPanel | cPanel | Plesk | CyberPanel |
|---|---|---|---|---|
| License model | Free edition plus paid Pro | Paid license | Paid license | Free edition available |
| Web server | Nginx, Apache, OpenLiteSpeed | Apache based | Apache and Nginx | OpenLiteSpeed |
| Typical user | Self managed VPS owner | Hosting companies and enterprises | Agencies and enterprises | WordPress focused VPS owner |
| Support | Forum and docs | Commercial support via license provider | Commercial support | Mostly community |
We cover these sibling panels in separate articles. If you want the Docker basics first, our Docker guide is a good start. In short, aaPanel suits users who want a modern interface without license fees and who are ready to own the server.
What are the pros and cons of aaPanel?
Above all, every panel is a trade off. Seeing the strengths and weaknesses of aaPanel side by side keeps surprises to a minimum.
Pros:
- Many core functions with no license fee.
- A fast install and a clean, readable interface.
- Freedom to choose Nginx, Apache or OpenLiteSpeed.
- Easy access to PHP versions and Docker apps through the App Store.
- Several layers of protection for the panel login.
Cons:
- No commercial support contract, so you lean on the forum and docs.
- The panel manages system files in its own layout, so manual edits can clash.
- Leaving the panel or moving to another one takes real effort.
- The easy interface can make you forget that security is still your job.
We think the last point matters most. The panel makes the work easier, but server security stays with you. Therefore, put updates, log reviews and open port checks on your calendar.
Should you run a mail server on aaPanel?
aaPanel lists a mail server among its free features. Technically, you can set one up. Running your own mail server, however, takes far more work than hosting a website.
For email to land in the inbox, your SPF, DKIM, DMARC and reverse DNS (PTR) records all need to be correct. On top of that, your server IP's reputation may carry the history of whoever used that IP before you. Some cloud providers also restrict outbound mail ports by default to prevent abuse. Check your provider's docs for its current policy.
That is why we suggest a split for most small businesses. Host the website on aaPanel, and keep business email with a dedicated email provider. Use an SMTP service for your site's form notifications as well. Then a server problem never takes your email down with it.
If you still want your own mail server, set up every DNS record first. Next, send test messages and review the headers. After that, check blocklists on a regular schedule.
What should you check before you use aaPanel in production?
For instance, everything may work on a test server. Once real customer traffic and real data arrive, though, the bar moves. Before you go live, tick off this list one item at a time:
- Can you reach the panel only from your own IP?
- Is two factor authentication on, with recovery codes stored safely?
- Is SSH password login off, with key login only?
- Are the phpMyAdmin, FTP and MySQL ports closed to the outside?
- Do all sites redirect to HTTPS, and do certificates renew on their own?
- Do you have off server backups, and have you tested a restore?
- Is it clear who applies OS and panel updates, and how often?
- Do you have an alert channel for full disks and service outages?
In other words, every "no" on this list is a reason to delay launch. Also, if your site processes personal data, record which country the server and backups live in. To look at the hosting decision as a whole, our guide to choosing web hosting will help.
When should you not install aaPanel yourself?
Let's be honest: installing a control panel is easy, while keeping a server secure for years is hard. In the cases below, managed hosting or a managed VPS is the better call.
First, nobody on your side will follow updates and security notices on a regular basis. Second, your site handles payments or sensitive personal data, and a breach would cost a lot. Third, nobody can step in at midnight when something goes down.
In these cases, leave server management to your hosting provider and focus on what matters, which is the site itself. A shared or managed plan takes care of panel updates, OS patches and hardware failures for you. In return you also give up some flexibility. For most businesses, that trade makes sense.
On the other hand, aaPanel is a great starting point for learning, building a test environment or hosting a few personal projects. Setting things up and breaking them yourself is the fastest way to understand how servers work. The key is to experiment where you understand the risk.
Who is aaPanel the right choice for?
aaPanel is a strong option if you want to manage a VPS through a modern interface without license fees and you are ready to own server security. Developers, small agencies and founders who host their own projects fit that description well.
Install it in two steps, lock down the panel login on day one, close the ports you do not need and never skip off server backups. These four habits prevent most of the problems people run into with aaPanel.
If you would rather leave the server side to a hosting provider and simply want a fast, reliable website, our team can help. As part of our web design services, we plan the infrastructure choice, setup and launch around your needs. That way you can focus on your business instead of server menus.



