Requirements
Controller
| Minimum | |
|---|---|
| Operating system | Debian 12 or 13, Ubuntu 22.04 or 24.04 |
| CPU and memory | 2 vCPUs and 2 GB of memory, enough for hundreds of servers |
| Disk | 20 GB |
| Software | Node.js 24, sqlite3 for backups of the database |
| Network | A domain name for the panel (e.g. panel.example.com) and ports 80 and 443 open |
The controller can run in a small VM.
Nodes (hypervisors)
| Requirement | |
|---|---|
| Operating system | Debian 12, Ubuntu 22.04 or 24.04, Rocky Linux 9 or Alma Linux 9 |
| CPU | Intel VT-x or AMD-V switched on in the BIOS |
| Kernel | 5.3 or newer, for connection tracking in nftables’ bridge family |
| Network | Outbound HTTPS to the controller. The install command puts the public network on a bridge for servers. |
| Between nodes | A management network with TCP 22 (moving servers) and UDP 4789 (private networks) open, and an SSH server on each node. See Files and ports. |
| Software | Installed by the install script: KVM, libvirt, nftables, LVM tools and Node.js 24. ZFS, if you use it, you install yourself. |
Bare metal is best. To try it inside VMs, switch on nested virtualization on the host and give the VM the host-passthrough CPU mode.
GPU container hosts
A node that runs customers’ GPU containers instead of servers needs less: no hardware virtualization, IOMMU or bridge. See Adding a GPU container host.
| Requirement | |
|---|---|
| Operating system | Debian 12, Ubuntu 22.04 or 24.04, Rocky Linux 9 or Alma Linux 9 |
| Cards | One or more NVIDIA cards. Turing and newer use the open driver; older cards need --nvidia-proprietary. |
| Secure Boot | Off, or a console at the next boot to enroll the driver’s signing key |
| Network | Outbound HTTPS to the controller, developer.download.nvidia.com, nvidia.github.io and download.docker.com |
| Software | Installed by the install script: the NVIDIA driver, Docker Engine, the NVIDIA Container Toolkit, nftables, LVM tools and Node.js 24 |
Optional
- PowerDNS Authoritative with its HTTP API, if customers should host DNS zones and you want reverse DNS pushed automatically. See DNS with PowerDNS.
- An SMTP server for invitations, password resets and alerts.
- S3-compatible storage or an SFTP server for backups.
Lab or production
| Lab | Production | |
|---|---|---|
| Address | http://<server IP> (install.sh --no-domain) |
https://panel.example.com |
| Encryption to browsers and nodes | None, so only on a private, trusted network | TLS through Caddy or nginx |
| Extra settings | PANEL_AGENT_INSECURE=1 when enrolling nodes |
None |