Deployment Overview of FASTPANEL on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Debian, Ubuntu, CentOS, Rocky Linux, or AlmaLinux.
-
Privileges: Root or sudo access is required for installation and configuration.
-
Network/Ports:
-
8888: Internal panel management port. -
443: External HTTPS traffic (managed via Nginx proxy). -
80: External HTTP traffic (used for ACME challenges).
FQDN of the final panel on hostkey.in domain¶
The application uses a dynamic domain template based on the server ID and the configured zone. If no custom domain is provided, the following template is used:
| Parameter | Value |
|---|---|
| Prefix | fastpanel |
| Domain | hostkey.in |
| Full template | fastpanel{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment creates several directories to manage Nginx configurations, SSL certificates, and webroot challenges:
-
/root/nginx: Contains the Docker Compose file for the Nginx proxy. -
/data/nginx: Main directory for Nginx configuration files. -
/data/nginx/user_conf.d: Stores custom virtual host configurations. -
/data/nginx/letsencrypt/.well-known/acme-challenge: Used for Let's Encrypt SSL certificate validation.
Application installation process¶
The installation method depends on the operating system of the server:
-
Package Installation: The system updates the package cache and ensures
wgetis installed. -
Installation Script: A specialized installation script is downloaded and executed to install the core Fastpanel components:
-
For Debian/Ubuntu:
wget http://repo.fastpanel.direct/install_fastpanel.sh -O - | bash - -
For RHEL/CentOS/Rocky/AlmaLinux: The script is saved to
/root/install_fastpanel.sh, executed, and then removed. -
User Configuration: A system user named
fastuseris created/configured with a secure password.
Access Rights and Security¶
-
Firewall: Ensure ports
80and443are open for external web traffic, and port8888is accessible for panel management (though it is typically proxied via HTTPS on port 443). -
User Management: A dedicated user
fastuseris managed by the system. -
SSL/TLS: The deployment automatically configures SSL certificates using Let's Encrypt to secure the connection to the panel.
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to act as a reverse proxy, handling SSL termination and routing traffic to the Fastpanel service.
Nginx Proxy Container
-
Image:
jonasal/nginx-certbot:latest -
Ports: Uses
hostnetwork mode (mapping directly to host ports 80 and 443). -
Volumes:
-
nginx_secrets:/etc/letsencrypt: Persistent storage for SSL certificates. -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d: Custom Nginx configuration files. -
/data/nginx/letsencrypt:/var/www/letsencrypt: Webroot for ACME challenges. -
Environment Variables:
-
Configured via
/data/nginx/nginx-certbot.env(includesRENEWAL_INTERVAL=8d). -
Restart Policy:
unless-stopped.
Custom Scripts and Additional Setup¶
The deployment performs several automated configuration steps after the core software is installed:
-
Nginx Proxy Configuration: A reverse proxy configuration is generated to route traffic from port 443 (HTTPS) to the internal Fastpanel service running on port 8888.
-
SSL Certificate Provisioning:
-
The system uses Certbot via the Nginx container to obtain a Let's Encrypt certificate for the panel's FQDN.
-
Once obtained, the Nginx configuration is updated to include an SSL block.
-
Panel Domain Registration: The command
/usr/local/bin/mogwai panel addis used to register the domain within the Fastpanel management system. -
Internal Certificate Management: The command
/usr/local/bin/mogwai panel change-certificateis executed to ensure the panel itself uses a Let's Encrypt certificate for its internal service.
Application Update Instructions¶
To update the main application, follow the procedure relevant to your deployment method:
-
Docker Proxy: To update the Nginx proxy container, navigate to
/root/nginxand run: -
Core Application: Updates for the Fastpanel core are typically managed through the internal panel interface or by re-running the official installation script.
Location of configuration files and data¶
-
Nginx Proxy Configs:
/data/nginx/user_conf.d/ -
SSL Certificates (Docker): Managed via the
nginx_secretsvolume. -
Environment Settings:
/data/nginx/nginx-certbot.env
Available ports for connection¶
| Port | Protocol | Purpose |
|---|---|---|
80 | HTTP | Web traffic and SSL challenges |
443 | HTTPS | Secure web traffic (Proxied) |
8888 | HTTPS/HTTP | Internal Fastpanel management service |
Starting and Stopping the application¶
-
Nginx Proxy:
-
Start:
docker compose up -d(inside/root/nginx) -
Stop:
docker compose down(inside/root/nginx) -
Fastpanel Service: Managed via the internal
mogwaicommand-line tools or system service management.
Proxy Servers¶
The deployment uses an Nginx container acting as a reverse proxy. It handles:
-
SSL termination for the domain.
-
HTTP to HTTPS redirection.
-
WebSocket support (via
UpgradeandConnectionheaders). -
Proper header forwarding (
X-Forwarded-For,X-Real-IP, etc.) to ensure the application receives correct client IP information.