Root-Server Tutorial

ROOT-SERVER TUTORIAL

Set Up a Web Server Using Hestia Control Panel on netcup

Learn how to set up a Root Server for hosting using Hestia Control Panel on netcup.

Introduction

In this tutorial, we will guide you through the process of setting up a netcup Root Server for hosting using Hestia Control Panel. Hestia Control Panel is a popular open source web server control panel that simplifies the management of your website, email accounts, databases, and other hosting-related tasks. This tutorial is compatible with both VPS and Root Server offerings by netcup.

The reading time of this tutorial is about 15 minutes; implementation will take approximately 45 minutes.

Prerequisites

  • A Root Server from netcup with latest Ubuntu 20.04/22.04 (LTS); Debian 10/11/12 or later installed (see the below URL) - use minimal mode of installation, also called clean installation. Requirement Details
  • Please note latest Hestia Control Panel only supports the latest versions of the above OS. To know more visit:

Supported OS

  • A registered domain name (optional)
  • Root access to your server

Step 1: Update your system

Before we begin, it's essential to ensure that your system is up-to-date. Log in to your server via SSH as the root user and run the following command:

For Ubuntu/Debian:

apt update && apt upgrade -y

Step 2: Install Hestia Control Panel

To install Hestia Control Panel, you'll first need to install the installation script. Run the following commands to download and to execute the installation script:

cd ~ && wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh && bash hst-install.sh

If the download fails due to an SSL validation error, please be sure you've installed the ca-certificate package on your system - you can do this with the following command: apt-get update && apt-get install ca-certificates

To install with custom commands, use the script generator: Script Generator

Possible options to use in the command are:

-a, --apache Install Apache [yes | no] default: yes
-w, --phpfpm Install PHP-FPM [yes | no] default: yes
-o, --multiphp Install MultiPHP [yes | no] default: no
-v, --vsftpd Install VSFTPD [yes | no] default: yes
-j, --proftpd Install ProFTPD [yes | no] default: no
-k, --named Install BIND [yes | no] default: yes
-m, --mysql Install MariaDB [yes | no] default: yes
-M, --mysql8 Install Mysql8 [yes | no] default: no
-g, --postgresql Install PostgreSQL [yes | no] default: no
-x, --exim Install Exim [yes | no] default: yes
-z, --dovecot Install Dovecot [yes | no] default: yes
-Z, --sieve Install Sieve [yes | no] default: no
-c, --clamav Install ClamAV [yes | no] default: yes
-t, --spamassassin Install SpamAssassin [yes | no] default: yes
-i, --iptables Install Iptables [yes | no] default: yes
-b, --fail2ban Install Fail2ban [yes | no] default: yes
-q, --quota Filesystem Quota [yes | no] default: no
-d, --api Activate API [yes | no] default: yes
-r, --port Change Backend Port default: 8083
-l, --lang Default language default: en
-y, --interactive Interactive install [yes | no] default: yes
-s, --hostname Set hostname
-e, --email Set admin email
-p, --password Set admin password
-D, --with-debs Path to Hestia debs
-f, --force Force installation
-h, --help Print this help

An example of an updated command to run the script:

cd ~ && wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh && bash hst-install.sh --apache yes --phpfpm yes --multiphp yes --vsftpd yes --port '8083' --hostname 'DOMAIN-HERE' --email 'EMAIL-HERE' --password 'PASSWORD-HERE' --lang 'en' --force

Follow the on-screen instructions to complete the installation. The installation process may take some time. Once it's complete, the Hestia Control Panel will be installed on your system.

Step 3: Configure Hestia Control Panel

After the installation is complete, you can access Hestia via your browser. Open your browser and navigate to:

https://your_server_ip:8083
Hestia Control Panel Login

Replace "your_server_ip" with the IP address of your server. You'll encounter a security warning since the SSL certificate is self-signed. Proceed to the website and log in with the username and password that were displayed at the end of the script run.

Upon logging in, you'll be presented with the dashboard where you can view and configure the panel as per your needs.

Panel Dashboard

Step 4: Create a new user (regular)

On the dashboard, click the "Add User" button; fill out the fields; click the "Save" button in the top right.

To switch to the new user, hover over the user you want to login as; click the login as icon (-]) on the right of the user’s name and email; you are now logged in as the user. As such, any action you perform will be done as this user.

Info Never run a web or mail domain with the admin user - by default, the admin user has elevated privileges. This can pose a security threat to your server!

Step 5: Set up your domain

Navigate to the "Web" tab and click the "+ Add Web Domain" button, then enter your domain information. Example: exampledomain.com

After creating a new account, you'll need to update your domain's nameservers to point to your server. This process varies depending on your domain registrar, so consult their documentation for instructions.

Step 6: Create DNS zone, email accounts & databases

Click on the box labeled "DNS" & fill in the required details. A minimum of 2 name servers are necessary for redundancy.

DNS Setup

With your domain set up, you can now create email accounts and databases for your website. To create an email account, click on the box labeled "MAIL".

MAIL Setup

To create a database, click on the box labeled "DB".

Database Setup

Step 6: Upload your website files

To upload your website files, you can use the File Manager in the Panel or an FTP client such as FileZilla. If using the File Manager, click on the File Manager icon on the right top side and upload your files to the "public_html" directory under WEB -> domain_name_folder -> public_html.

Upload Files

If using an FTP client, you'll need to create an FTP account in the Panel first. Click on the "WEB" icon -> "domain name (edit domain)" -> "Advanced Options" -> "Additional FTP account(s)" -> fill in the username, password and the default path & click "Save" to create a new account, then use the provided credentials to connect and upload your files.

Step 7: Enable two-factor authentication (2FA) for the admin user

Documentation

Since the admin user has full control on the server, as well as elevated privileges, it is highly recommended that you enable 2FA on this account. To access your account settings, click the user button in the top right. Note that you might need to switch back to the admin user first, using the "Arrow up" button in the top right.

  • In your account settings, check the box labeled "Enable two-factor authentication".
  • Click the "Save" button in the top right.
  • Scan the QR code using an authentication app, for example "Google Authenticator".
  • Save your Account Recovery Code somewhere safe, in case you lose access to your authenticator.

To secure your account further check out the following tutorial (applies to all server setups): Secure Linux Server

Conclusion

Awesome! You've successfully set up a netcup Root Server for hosting using Hestia Control Panel. You can now manage your websites, emails, and databases through the userfriendly interface. Remember to keep your server and Panel updated to ensure consistent security and performance.

Licence

MIT

Copyright (c) 2024 netcup

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicence, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Contributor's Certificate of Origin

By making a contribution to this project, I certify that:

  1. The contribution was created in whole or in part by me and I have the right to submit it under the licence indicated in the file; or

  2. The contribution is based upon previous work that, to the best of my knowledge, is covered under an appropriate licence and I have the right under that licence to submit that work with modifications, whether created in whole or in part by me, under the same licence (unless I am permitted to submit under a different licence), as indicated in the file; or

  3. The contribution was provided directly to me by some other person who certified (a), (b) or (c) and I have not modified it.

  4. I understand and agree that this project and the contribution are public and that a record of the contribution (including all personal information I submit with it, including my sign-off) is maintained indefinitely and may be redistributed consistent with this project or the licence(s) involved.

Published 18/11/2024 by vdbhb59

Submit your tutorial

Get 60€ netcup vouchers for every published tutorial.