Web

What Is CageFS? Account Isolation on Shared Hosting

Talha Aslan 20 min read 2 views

What is CageFS and what does it do on shared hosting?

CageFS is a CloudLinux layer that locks each hosting account inside its own virtual file system. In practice, the account sees only its own files and the system tools it may use. As a result, it cannot reach the files, usernames or processes of neighboring accounts. It is one of the core building blocks of account isolation on shared hosting.

CloudLinux documentation describes CageFS as a virtualized file system plus a set of tools that isolate each user in a "cage." The name comes from that idea. Inside the cage, the user sees what looks like a normal Linux environment. In reality, the account never touches the real file system of the server.

So what is CageFS in one sentence? It hides your neighbors from you and hides you from your neighbors. Sharing a server does not have to mean sharing risk.

We are a digital marketing and web team, not a hosting company. For that reason, the technical details here follow the official CloudLinux documentation. Your own panel may differ, because every provider configures things a little differently. If you are still choosing a provider, start with our guide on how to choose web hosting.

Why should shared hosting accounts be separated from each other?

On shared hosting, many accounts share one server, one operating system and one kernel. That model is cheap, so many providers use it. However, it brings a real risk: if accounts can see each other, one weak site can endanger all its neighbors.

For example, a site with loose file permissions can give an attacker a way to read a neighbor's configuration files. Also, database passwords often live in those files. So isolation is not something you should leave to goodwill.

Without isolation, these risks stand out:

  • Malware on one account can list the files of other accounts.
  • An attacker can discover other usernames on the server and pick targets.
  • You could see the running processes of a neighbor from your own account.
  • Server-wide configuration files can leak more information than they should.

This list is a summary based on general security knowledge. Therefore, the cage approach aims to reduce exactly these risks. We cover weaknesses at the application layer separately in our OWASP Top 10 guide.

How does CageFS lock each account into a virtual file system?

According to CloudLinux documentation, CageFS uses a skeleton directory that holds safe system files. By default, that skeleton lives under /usr/share/cagefs-skeleton. Each user also gets a private area under /var/cagefs/.

When a user connects over SSH or runs a script, the process starts inside that cage. It does not see the real root directory. Instead, it sees a restricted view. For example, picture one building where every account gets its own room.

What is CageFS at the technical level? Three ideas matter: the skeleton, the per-user area and the mount points. First, the skeleton carries shared, safe files. Second, the user area belongs to your account alone. Mount points reflect a few directories from outside the cage into it. Knowing these three also helps you when you troubleshoot.

The documentation also stresses that user scripts run without changes. In other words, you do not rewrite your code for CageFS. However, a script can fail if it depends on a file or tool outside the cage. We cover that case below.

For exact details, read the official page: CloudLinux OS components documentation.

What is CageFS in a simple example?

Let's build a hypothetical example. Two accounts, A and B, share one server. Account A runs a site with an outdated plugin, and an attacker gets in through it. However, this is not a real incident. It is a scenario we made up to show the concept.

Without a cage, the attacker can start hunting for the directory of account B. With a cage, the attacker sees only the view of account A. So the directory, username and processes of account B stay invisible.

So the damage stays inside a smaller boundary, even if account A falls. However, the data of site A is still at risk. In short, a cage keeps a fire in one room. It does not save the furniture in that room. That is why your own site still needs updates and regular backups.

What can an account see inside the cage, and what stays hidden?

According to the official documentation, a user inside CageFS cannot see other users or their usernames. Also, access to server configuration files is restricted. The /proc file system is limited, so processes of neighbors stay hidden. Only safe binaries can run.

In short, the cage narrows what you can see:

  • Home directories and usernames of other accounts stay hidden.
  • Server-wide configuration files are off limits to you.
  • Your process list shows only your own processes.
  • Only whitelisted programs run, not every program on the system.

So even if an attacker takes over one account, spreading to neighbors gets harder. Note that we say "harder," not "impossible." No isolation layer is perfect. You still need kernel and software updates.

What is the difference between CageFS and LVE?

They solve different problems. First, CageFS decides what an account can see. Second, LVE limits how many resources an account can use. CloudLinux ships them together because shared hosting needs both security and fair resource sharing.

CloudLinux documentation presents LVE as a kernel-level technology. It shares common roots with container-based virtualization and uses cgroups in its latest incarnation. In short, the goal is to stop one site from eating server resources and crashing the others.

FeatureCageFSLVE
Core questionWhat can the account see?How many resources can it use?
What it protectsFiles, users, processesCPU, memory, disk, process count
What happens at the edgeA file or tool stays invisibleThe site slows down or errors out
What the site owner noticesA restricted system viewA usage screen and limit errors

In short, CageFS gives you privacy and LVE gives you balance. If you mix them up, you knock on the wrong door while troubleshooting.

What is the noisy neighbor problem on shared hosting?

A noisy neighbor is an account that eats so many resources that it slows the others on the same server. The term is a general infrastructure concept. For example, without resource limits, one neighbor's heavy script can slow your pages too.

Often, you are not the one at fault. Your site can be healthy and still lag because the server runs out of resources. That is why resource limits matter on shared hosting. We explain those limits in the LVE section below.

On the other hand, the limits also apply to your own site. During a sudden traffic spike, you can hit the ceiling too. So before a campaign, ask your provider what your limits are.

Which resources does LVE limit, and what does error 508 mean?

CloudLinux documentation lists seven resource categories for LVE. The result of hitting a limit depends on the resource. For example, a site that hits a CPU or disk limit slows down. A site that hits a memory or process limit can return 500 or 503 errors. At the concurrent connection limit, you see 508.

The documented categories are:

  • SPEED: CPU performance.
  • PMEM: physical memory, meaning the RAM an account really uses.
  • VMEM: virtual memory, which the documentation marks as deprecated.
  • IO: disk throughput.
  • IOPS: read and write operations per second.
  • NPROC: the total number of processes and threads allowed.
  • EP: entry processes, meaning concurrent web connections.

When the entry process limit fills up, the documentation says the server returns a 508 (Resource Limit Reached) error. Your hosting panel usually offers a "Resource Usage" style screen that shows CPU, memory, disk, process and inode use. However, your provider sets the actual values, and we do not quote numbers.

For details, see the CloudLinux limits documentation.

What is CageFS from the site owner's point of view?

Most site owners never notice CageFS, because scripts keep running normally. However, the effect usually appears when you use SSH or try to install a custom tool. If you look for a file outside the cage, you may see a "not found" style message.

Typical effects you may observe:

  • In an SSH session, you see only your home directory and a limited system view.
  • Trying to list neighboring accounts returns nothing.
  • A command that exists on the server may not exist inside your cage.
  • The process list shows only your own processes.

The documentation also lists a few known limitations. For example, mod_php is unsupported and the lastlog command does not work. So how PHP runs on your account depends on your provider's setup. If you see odd behavior, asking your provider about these limits is a good start.

How can you tell you are inside the cage when you connect over SSH?

The most concrete method is to run a few read-only commands in an SSH session. The commands below change nothing. Instead, they only show information. However, not every plan includes SSH access, so skip this section if you have none.

# Shows which user you are connected as
whoami

# Looks at the list of home directories
ls /home

# Lists running processes
ps aux

Inside a cage, you expect the result the documentation describes. In other words, you cannot see other users or their processes. The output can still vary with your provider's setup. So treat the result as an observation, not as proof.

Why do some files and tools look missing inside the cage?

CageFS works like an allow list. It hides everything and reflects only what counts as safe into the cage. As a result, a tool installed on the server may not exist inside your cage. That is not a bug. Instead, it is a natural result of the design.

According to the documentation, new or updated software reaches the cage only after the administrator runs cagefsctl --update. Also, you need the same command after a php.ini change. So this job belongs to the server administrator, not to the site owner.

If you notice something missing, follow these steps:

  1. Write down the exact name of the missing tool or file.
  2. Note why your script needs it.
  3. Ask your provider to add the tool to the cage instead of turning CageFS off.
  4. Meanwhile, check whether another method can do the same job without that tool.

The third step matters. Turning CageFS off for your account may fix the problem, but it also removes the isolation.

How does PHP Selector work with CageFS?

PHP Selector is the CloudLinux component that lets end users pick their PHP version and extensions. According to CloudLinux sources, CageFS is required for it to work. In cPanel, it usually sits in the Software section as "Select PHP Version." So you can switch versions without writing to your provider.

In practice, you can do the following:

  • Choose the PHP version your site needs.
  • Tick the extensions you need.
  • Untick unneeded extensions to keep the environment lean.
  • Adjust PHP options such as memory and time limits.

For example, if an e-commerce plugin asks for a specific extension, enabling it in the panel may be enough. According to the documentation, PHP inside the cage reads its settings from /usr/selector/php.ini. That file is a link to the real php.ini.

However, do not rush when you choose a version. Moving to a new PHP version can break some old plugins. So take a backup first, then switch and test the site. Choosing the current stable version usually makes sense, but check the range your software supports.

Also, option names in the panel can vary by provider. Check the official requirements of your software before you decide. This also helps you understand how site speed affects SEO.

Why might a php.ini change not show up right away?

The CloudLinux documentation says you must run cagefsctl --update after you change php.ini or add new software to the cage. If the administrator skips this step, the view inside the cage stays old. So the change may not reach your site right away.

As a site owner, you cannot run this command, because it needs root access. If you changed a setting in the panel and see no effect, try this order:

  1. Reopen the setting in the panel and confirm it saved.
  2. Clear your site cache and your browser cache.
  3. Wait a few minutes and test again.
  4. If you still see the old value, tell your provider which setting you changed and when.

Our guide on how caching works with Redis and Memcached widens the context. In short, a "setting did not change" complaint does not always involve CageFS. Rule out caching first.

What is the isolation difference between shared hosting and a VPS?

On shared hosting, the provider builds and runs the isolation. However, on a VPS, you manage the virtual machine itself. So a VPS gives a stronger boundary from other customers. However, if you host several sites inside one VPS, you must build the isolation between those sites yourself.

TopicShared hostingVPS
Isolation boundaryPer-account cage and resource limitsVirtual machine
Root accessNoYes
Isolation between sitesProvider builds itYou build it
Freedom to install softwareLimitedWide
Security responsibilityMostly the providerMostly you
Management workloadLowHigh

Consider CageFS on a VPS, too. A cage does not come ready there, so you must build one. For example, if you host five client sites on one VPS, run each site under its own user with its own permissions. Otherwise, one site's flaw puts all five at risk.

CageFS is a component of CloudLinux OS. In other words, the server must run CloudLinux to have CageFS. Not every VPS comes with it. So before you move to a VPS, answer the question "how will I build isolation?"

Is CageFS enough for website security on its own?

No, CageFS only strengthens the boundary between accounts. However, it does not close holes inside your own site. An outdated plugin, a weak password or a flawed form can still be exploited inside the cage. So isolation is only one layer of security.

For a sturdier setup, think about these layers together:

  • Keep software, themes and plugins up to date.
  • Use strong passwords and two-step verification.
  • Take regular backups and test a restore.
  • Use a valid SSL certificate.
  • Ask your provider about firewall and WAF protection.

For example, a stolen admin password does damage inside the cage too. The attacker already has the permissions of your site. So password hygiene and update discipline must continue no matter what isolation you have.

Also, we have separate guides for each of these topics. Our website backup strategy guide explains the road back after an attack. The SSL certificate and HTTPS security guide covers traffic encryption. ModSecurity, CSF Firewall and Fail2ban get their own sibling articles in this series.

How do you find out whether your hosting provider uses CageFS?

Only your provider can give a definite answer. So the soundest way is to ask the support team directly. Still, a few hints exist. If your panel shows screens like "Select PHP Version" and "Resource Usage," the environment is probably CloudLinux based.

That is a hint, however, not proof. If you have SSH access, seeing only your own processes is a similar sign. So for a definite answer, ask for a written reply.

A support agent may not recognize these terms at first. In that case, ask them to forward your question to the technical team. Also ask in writing. That way, the answer stays on record and helps you in any later dispute.

Clear questions you can ask your provider:

  • Do you separate accounts with CageFS?
  • Do you enforce resource limits with LVE?
  • Which error and notice does a customer get when a limit is hit?
  • Can I change the PHP version and extensions from the panel?

To confirm where your site lives, you can use our WHOIS lookup and IP lookup tools. They do not show CageFS, but they also help you verify the provider.

How do you manage CageFS with cagefsctl on your own server?

You manage CageFS with the cagefsctl tool, and it needs root access. The commands below are the basic ones from the CloudLinux documentation. Before you try anything on a production server, take a backup and read the current version of the documentation. The sample username is for illustration only.

# Creates the cage skeleton
cagefsctl --init

# Updates the template (after new software or a php.ini change)
cagefsctl --update

# Enables CageFS for one user
cagefsctl --enable exampleuser

# Lists enabled and disabled users
cagefsctl --list-enabled
cagefsctl --list-disabled

# Shows the current mode
cagefsctl --display-user-mode

The documentation describes two modes. In the first mode, CageFS is on for everyone except users you explicitly disable. In the second mode, only users you explicitly enable go into the cage. You switch modes with cagefsctl --toggle-mode, but that decision affects every account.

Keep the official documentation open for the full list of options.

What do cagefs.mp and mount points do?

Some directories must be reflected into the cage. A database directory or a scheduled task directory is an example. According to CloudLinux documentation, the file /etc/cagefs/cagefs.mp defines these directories. In other words, each line in the file is one mount point.

The documented line formats are:

  • Regular mount: a plain path such as /var/lib/mysql.
  • Per-user copy: a path that starts with @, such as @/var/spool/cron,700.
  • Split by username: a path that starts with %.
  • Split by user ID: a path that starts with *.

Also, files under /etc/cagefs/exclude/ list the users you keep outside CageFS. According to the documentation, you restart the mount points with cagefsctl --remount-all after mount changes.

Warning: a wrong edit to this file can break accounts inside the cage or open more space than you intend. So verify every change in a test environment before production.

When should you not manage CageFS yourself?

On shared hosting, you cannot manage CageFS, and you do not need to. Therefore, that job belongs to the provider. If you have no root access, no solid backup, or no clear idea what a command does, leave this topic to your hosting provider.

Do not step in yourself in these cases:

  • Experimenting without a backup on a server that hosts a live online store.
  • Turning off CageFS for a user just to silence an error message.
  • Running commands by hand when your managed VPS contract puts server care on the provider.
  • Running a "quick fix" script of unknown origin with root rights.

Also, the search for a quick fix can push you toward a risky shortcut. For example, running a command from a forum thread without understanding it can break isolation. In short, if you are unsure, stop, measure and write to your provider.

A wrong step can affect not only your site but also the other accounts on the same server. Honestly, for many site owners the right move is therefore a support ticket. If your needs are more specialized, we can talk through infrastructure decisions in our custom software development service.

How do you diagnose problems that involve CageFS?

When you troubleshoot, first look at the type of error. If a file or command is not found, cage visibility is the suspect. If the site is slow or returns 500, 503 or 508, LVE limits are the suspect. So this split makes your support ticket much clearer.

A simple diagnosis order looks like this:

  1. Reproduce the error and record the full message and the time.
  2. If the message says "not found," note the missing file or tool.
  3. If the error is 500, 503 or 508, open the resource usage screen in the panel.
  4. Confirm that your PHP version and extensions match your software.
  5. Send your findings to the provider, and share measurements instead of guesses.

However, slowness does not always come from a resource limit. Image sizes, plugins and scripts also play a part. Our guide to testing site performance with Google Lighthouse helps you measure where the slowness starts.

What does isolation mean for e-commerce and business sites?

For e-commerce and business sites, isolation is one of the layers that protect customer and order data. However, it is not enough alone. Limit hits can also hit your sales directly. For example, seeing a 508 or 503 on a campaign day means lost orders.

Also, you should know in advance what happens during an outage. For example, ask whether your provider's support channel is open on weekends. That way, you do not lose time when a problem appears.

For a serious store, these questions matter:

  • Are your resource limits enough during traffic peaks?
  • Do you keep backups in a separate location and test restores?
  • How and how fast does your provider tell you about a security incident?

A small load rehearsal before a campaign also makes sense. That way, you see in advance whether you hit your limits. Coordinate the rehearsal with your provider, because some companies restrict load tests in their terms of use.

We covered the link between page speed and sales in does ecommerce page speed affect sales. If you want to plan infrastructure and software choices together, our ecommerce consulting service can guide you.

Which isolation questions should you ask when you choose hosting?

First, ask about isolation and resource management before you look at the price list. The clarity of the answers shows how mature the provider is. A company that gives vague answers may not explain its infrastructure openly. That alone is a warning sign.

A checklist you can use before you decide:

  • Which technology do you use for account isolation?
  • What are the resource limits, and what happens when I exceed them?
  • Can I choose the PHP version and extensions in the panel?
  • How often do you take backups, and where do you store them?
  • Do you run a firewall or WAF layer?
  • How do you protect neighboring accounts when one account gets attacked?

Then get the answers in writing and compare them. For example, if one provider shares its limits openly while another uses a vague word like "unlimited," question the second one. Resources cannot be infinite in reality. So a clear limit is often a sign of honesty.

Weigh these questions together with the other criteria in our hosting selection guide. If you build your site from scratch, infrastructure is one of the first decisions in the web design process.

What should you read after learning what is CageFS?

CageFS is only one piece of the server security and performance puzzle. The next step is to learn the protections at the network and application layers. ModSecurity, CSF Firewall and Fail2ban are sibling topics in this series. In short, each one covers a different attack surface.

If container logic interests you, read our what is Docker guide. In other words, Docker reaches the idea of isolating applications with a different tool. To understand weaknesses in software, our OWASP Top 10 article is a good start.

If you want to check your domain and DNS side, our free DNS lookup and SSL checker tools can help. In short, the answer to what is CageFS is simple: a file system layer that protects you from a neighboring account. A good hosting decision, however, weighs isolation, resource limits, backups and support together.

Frequently Asked Questions

Does CageFS make hosting faster?
No, CageFS exists for isolation, not for speed. Resource limits, PHP version, caching and page optimization shape your speed far more. CloudLinux documentation describes CageFS as an isolation layer. If your site feels slow, check the resource usage in your panel and the weight of your pages first, then use measurement tools to find the bottleneck.
What happens if CageFS is turned off?
An account without CageFS runs outside the restricted view the cage provides. In other words, it can see more of the real server file system. CloudLinux documentation describes enabling and disabling CageFS per user. However, turning it off weakens isolation. That decision belongs to your provider, and it should be a deliberate exception, not a casual fix.
Can I see in my control panel whether I use CageFS?
There is no definite indicator, but there are hints. If your panel shows screens such as Select PHP Version and Resource Usage, the environment is probably CloudLinux based. Seeing only your own processes over SSH is another sign. Still, the most reliable route is to ask your hosting provider a written question.
Can I install CageFS on my own VPS?
CageFS is a component of CloudLinux OS. So your server must run CloudLinux. Not every VPS comes with that operating system. Check the official CloudLinux documentation for installation and licensing terms. If you lack server administration experience, talk to a system administrator or your provider before you try an installation.
Does CageFS affect my WordPress site?
Most WordPress sites never notice CageFS. CloudLinux documentation says user scripts run without changes. However, you may see an error if a plugin needs a tool or file outside the cage. In that case, ask your provider to add the tool to the cage instead of turning CageFS off.
What is the difference between CageFS and LVE?
CageFS limits what an account can see, while LVE limits how many resources it can use. CageFS narrows the visibility of files, users and processes. LVE controls resources such as CPU, memory, disk and process count. On shared hosting, the two work together to support both security and fair resource sharing.
  • cagefs
  • cloudlinux
  • shared hosting
  • account isolation
  • lve
  • php selector
  • hosting security
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.