How to Install aaPanel on a VPS: aaPanel (BaoTa International) Installation and Security Guide
aaPanel, the international edition of the BaoTa panel, gives you a web interface for websites, databases, PHP versions, SSL certificates and backups. This guide explains how to install aaPanel on a VPS from JUSTG in Johannesburg, Moscow, Tokyo or Seoul running Ubuntu, Debian, CentOS, Rocky Linux or AlmaLinux, using the official install script, and then how to secure the panel so it is not an easy target. aaPanel is third-party software; JUSTG provides the server and network, and the panel itself is maintained by the aaPanel project.
Step 1: Check the aaPanel system requirements
aaPanel should be installed on a clean system: a freshly installed OS without Apache, Nginx, MySQL or PHP already present, because the panel installs and manages its own copies. Recommended minimums:
- Memory: 1 GB or more (512 MB works for a very light site but leaves little headroom).
- Disk: a few GB free for the panel and the web stack, plus space for your sites and backups.
- OS: a current 64-bit release of Ubuntu, Debian, CentOS, Rocky Linux or AlmaLinux.
- Root access over SSH.
Confirm what you have:
cat /etc/os-release | head -n 3
free -h
df -h /Step 2: Install screen so the installer survives a dropped SSH session
The installation downloads and configures several components and can take a few minutes. Running it inside screen keeps it going even if your SSH connection breaks.
# Debian / Ubuntu
apt update && apt install -y screen curl wget
# CentOS / Rocky Linux / AlmaLinux (screen comes from EPEL on 8/9)
dnf install -y epel-release
dnf install -y screen curl wgetscreen -S aapanel
# detach: press Ctrl+A, then D
# reattach later:
screen -r aapanelStep 3: Run the official aaPanel install command
Inside the screen session, paste the official command exactly as below. It downloads the English installer with curl (or wget if curl is missing) and starts it.
URL=https://www.aapanel.com/script/install_panel_en.sh && if [ -f /usr/bin/curl ];then curl -ksSO $URL ;else wget --no-check-certificate -O install_panel_en.sh $URL;fi;bash install_panel_en.sh aapanelAnswer y when the script asks whether to install to the /www directory, and accept any other prompts that apply to you. When it finishes, the installer prints the panel address (including port and security entrance path), the username and the password. Copy them somewhere safe. If you lose them, the bt command shows them again:
# show the panel address, username and password again
bt default
# open the aaPanel command-line menu (change port, password, entry, etc.)
btStep 4: Open the aaPanel port in the firewall
The panel listens on the port shown at the end of the installation. If you use UFW or firewalld on the server, allow that port along with HTTP and HTTPS for your websites:
# replace 12345 with the panel port printed by the installer
# Debian / Ubuntu with UFW
ufw allow 12345/tcp
ufw allow 80/tcp
ufw allow 443/tcp
# CentOS / Rocky / AlmaLinux with firewalld
firewall-cmd --permanent --add-port=12345/tcp
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reloadIf you restrict traffic elsewhere, for example with your own hardware or network firewall, open the same port there.
Step 5: First login to aaPanel
Open the full address from the installer, such as https://203.0.113.10:12345/abcd1234, in your browser. The panel uses a self-signed certificate at first, so the browser shows a warning; continue to the page and log in with the generated username and password. On first login aaPanel suggests a web stack. Choose LNMP (Nginx) or LAMP (Apache) with the PHP and MySQL versions your application needs; the installation runs in the background and appears in the task list.
Step 6: Secure the panel: entry path, port, IP binding and 2FA
A control panel with root-level power deserves strong protection. In the panel's Settings page, review these options:
- Security entrance: change the entry path to a long random string so the login page cannot be found by guessing.
- Panel port: move the panel to another high port, then update the firewall rule from Step 4 and close the old port.
- Authorized IP: bind the panel to your own fixed IP addresses so other visitors cannot reach the login page at all.
- Two-step verification (2FA): enable Google Authenticator or any TOTP app, so a stolen password alone is not enough.
- Username and password: replace the generated credentials with a unique, long password.
- Panel SSL: enable HTTPS for the panel with a certificate.
bt menu to reset the settings. Keep the panel and its plugins updated.FAQ
I forgot the aaPanel login address or password. How do I recover it?
Log in over SSH as root and run bt default to display the address and username, or use the bt menu to set a new password.
The panel page does not open after installation.
Check that the port is allowed in UFW or firewalld, that you used the full address including the entrance path, and that the service is running (bt menu offers a restart).
Can I install aaPanel on a server that already runs Nginx or MySQL?
It is not recommended. Conflicts with existing packages are common, so start from a clean system.
If you still cannot resolve the issue, please submit a ticket to contact JUSTG technical support about the server or network side.