Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Building a modern alternative to cPanel – looking for feedback from the LET community

14567810»

Comments

  • HPanelHPanel Member, Patron Provider

    Are you serious? Who are you to question whether we use AI or any other tool to write our replies? We'll use whatever tools we want.

    People who can't build anything themselves always show up to troll those who actually do. Instead of running our replies through AI detectors, try building something useful yourself.

  • AndruAndru Member
    edited May 26

    @HPanel said:

    Are you serious? Who are you to question whether we use AI or any other tool to write our replies? We'll use whatever tools we want.

    People who can't build anything themselves always show up to troll those who actually do. Instead of running our replies through AI detectors, try building something useful yourself.

    You are just stupid. Look on your garden TM is back?

    "© 2026 HPanel. All rights reserved."
    What rights?

    Thanked by 3Saragoldfarb forest tux
  • SaragoldfarbSaragoldfarb Veteran, Megathread Squad

    @HPanel said:

    Are you serious? Who are you to question whether we use AI or any other tool to write our replies? We'll use whatever tools we want.

    People who can't build anything themselves always show up to troll those who actually do. Instead of running our replies through AI detectors, try building something useful yourself.

    That's why I built boloxmedia.co.uk.

  • Neat321Neat321 Member

    @cxg said:

    @Neat321 said:
    Since that panel appears to be just a vibe coded slop, I asked AI too to create a security report for you :lol:

    https://files.catbox.moe/39h3g3.md

    Would you mind sharing the prompt(s) used to create this? And the LLM used?

    Z.AI agent mode
    GLM 5.1

    Thanked by 2cxg tux
  • HPanelHPanel Member, Patron Provider

    After a long time, we’re finally back on the forum! We’ve been quite busy behind the scenes working on HPanel and bringing a lot of new updates and improvements.

    Over the past few months, we’ve made significant progress, including:

    cPanel/WHM migration is now built directly into HPanel.
    Several bugs and stability issues have been fixed and improved.
    Major improvements have been made to the overall performance and reliability.
    HPanel is now fully production-ready.
    A Free Forever plan is available for users who want to run HPanel without ongoing license costs.
    Paid plans are also available for users who need additional features and resources.

    We’ve put a lot of work into making HPanel a reliable, modern alternative for hosting providers and server administrators.

    It’s great to be back on LowEndTalk, and we’re looking forward to sharing more updates with the community.

    HPanel: https://hpanel.net/

  • @HPanel said:

    We’ve put a lot of TOKENS into making HPanel a reliable, modern alternative for hosting providers and server administrators.

    I have corrected for you.

  • systemfreakssystemfreaks Member, Patron Provider

    I did evaluate this panel a couple of years ago during our R&D phase, and I have a few questions that you may be able to answer.

    Our old setup, DirectAdmin + CloudLinux + litespeed enteprise, costs approximately $65 per server with unlimited accounts.

    Some of our R&D clusters are currently using Enhance Control Panel. Since Enhance is priced per account, to make the economics comparable to DA, a server would need to host around 400 accounts to cost the same

    Enhance is not yet ready for all of our hosting requirements, but it does solve some very common problems, so we are willing to compromise and at least give it a try.

    My main question is: What problems of a modern hosting company does HPanel actually solve that would make it worth a company like SystemFreaks considering it as part of its stack?

    I am asking because, from what I have seen so far, I haven't found anything that would make it compelling enough to compete with DirectAdmin for us. DirectAdmin has been running essentially problem-free for us since 2015, so there would need to be a clear operational or financial advantage for us to consider changing.

    I would be interested in hearing what you believe HPanel offers that could make it worthwhile for a hosting company with our requirements.

  • @systemfreaks said: I did evaluate this panel a couple of years ago during our R&D phase

    How did you evaluate it a couple of years ago when OP says he has been working on it "over the past year"?

  • systemfreakssystemfreaks Member, Patron Provider

    @Obelous said:

    @systemfreaks said: I did evaluate this panel a couple of years ago during our R&D phase

    How did you evaluate it a couple of years ago when OP says he has been working on it "over the past year"?

    It can be last year, i cant really recall when i saw it, i passed it fast and i figure it doesn't solve any of the problems of a modern host

  • iKeyZiKeyZ Veteran

    @HPanel said: Interesting conversation. One asks "has it been hacked?" and the other confirms "yes multiple times" within 8 minutes, with zero evidence from either side.

    It got compromised earlier in this thread... just look at pages like: https://lowendtalk.com/discussion/215436/building-a-modern-alternative-to-cpanel-looking-for-feedback-from-the-let-community/p6

  • HPanelHPanel Member, Patron Provider

    @systemfreaks said:
    I did evaluate this panel a couple of years ago during our R&D phase, and I have a few questions that you may be able to answer.

    Our old setup, DirectAdmin + CloudLinux + litespeed enteprise, costs approximately $65 per server with unlimited accounts.

    Some of our R&D clusters are currently using Enhance Control Panel. Since Enhance is priced per account, to make the economics comparable to DA, a server would need to host around 400 accounts to cost the same

    Enhance is not yet ready for all of our hosting requirements, but it does solve some very common problems, so we are willing to compromise and at least give it a try.

    My main question is: What problems of a modern hosting company does HPanel actually solve that would make it worth a company like SystemFreaks considering it as part of its stack?

    I am asking because, from what I have seen so far, I haven't found anything that would make it compelling enough to compete with DirectAdmin for us. DirectAdmin has been running essentially problem-free for us since 2015, so there would need to be a clear operational or financial advantage for us to consider changing.

    I would be interested in hearing what you believe HPanel offers that could make it worthwhile for a hosting company with our requirements.

    Fair question, and I'd rather answer it straight than pitch you.

    If DirectAdmin + CloudLinux + LiteSpeed has run clean since 2015, I'm not going to tell you to replace it. That combination is hard to argue with on either of the points you raised.

    Where HPanel differs is what's included rather than bolted on. Per-account filesystem isolation (a chroot jail per user) and per-account CPU / RAM / IO / IOPS / process limits via cgroups are built in, along with a PHP selector across 7.4–8.4. ModSecurity WAF, malware scanning with quarantine and restore, DNS clustering, and backups to S3, S3-compatible, Google Cloud or SFTP are part of the panel rather than separate licences. Licensing is flat per server with unlimited accounts, so account density never changes the bill.

    To be upfront about the gap: we're nginx + PHP-FPM with FastCGI page caching, not LiteSpeed. If your stack is built around LSWS and LSCache, that's a genuine difference and worth weighing.

    Happy to hand you a test instance if you'd rather judge it yourself than take my word for it.

  • itzsenuitzsenu Member
    edited September 1

    @HPanel said: DirectAdmin + CloudLinux + LiteSpeed has run clean since 2015, I'm not going to tell you to replace it. That combination is hard to argue with on either of the points you raised.

    Where HPanel differs is what's included rather than bolted on. Per-account filesystem isolation (a chroot jail per user) and per-account CPU / RAM / IO / IOPS / process limits via cgroups are built in, along with a PHP selector across 7.4–8.4. ModSecurity WAF, malware scanning with quarantine and restore, DNS clustering, and backups to S3, S3-compatible, Google Cloud or SFTP are part of the panel rather than separate licences. Licensing is flat per server with unlimited accounts, so account density never changes the bill.

    To be upfront about the gap: we're nginx + PHP-FPM with FastCGI page caching, not LiteSpeed. If your stack is built around LSWS and LSCache, that's a genuine difference and worth weighing.

    Happy to hand you a test instance if you'd rather judge it yourself than take my word for it.

    before trusting ur pannel, please answer my little google form first. ( cuz i can see the smeel of AI )

    1. one account gets hacked what stops the hacker from going sightseeing through every other account and the host ?

    2. how do cpu, ram, i/o, iops, and process limits actually get enforced at the kernel and cgroup level? asking for the receipts.

    3. what is hpanel’s actual source of truth? how do you stop hpanel, nginx, phpfpm, dns, and the filesystem from slowly doing their own thing?

    4. what is the highest account count youve actually tested on one production server? and what breaks first when you keep adding more?

    5. live website and database backup. how do you keep the backup consistent, and how do you know the backup isnt quietly corrupted?

    6. server gets completely wiped. can you rebuild the whole thing from off server backups alone, including accounts, databases, dns, ssl, permissions, and resource limits?

    7. cpanel migration time. what happens to custom apache or .htaccess rules, plugins, cron jobs, mail, dns, permissions, ssl, and weird custom configs ?

    8. migration + backup + restore + account changes happening at the same time. how does hpanel stop everything from stepping on each other and creating broken state?

    9. hpanel itself gets compromised. what stops it from turning into unrestricted root access across the entire server?

    10. where are the actual benchmark numbers? performance, resource overhead, account density, backup and restore speed, migration speed, and failure recovery compared with directadmin + cloudlinux + litespeed.

  • hyperhostsolutionshyperhostsolutions Member, Patron Provider

    FYI Hostingers Panel is called HPanel
    hPanel is a custom-made web hosting control panel created by Hostinger to help users manage their websites, domains, emails, and server resources from one central dashboard

    Thanked by 1Saragoldfarb
  • ObelousObelous Member
    edited September 1

    @itzsenu said: one account gets hacked what stops the hacker from going sightseeing through every other account and the host ?

    hpanel itself gets compromised. what stops it from turning into unrestricted root access across the entire server?

    hopes and prayers, maybe the attacker is a nice person

    what is the highest account count youve actually tested on one production server? and what breaks first when you keep adding more?

    1, the panel

    live website and database backup. how do you keep the backup consistent, and how do you know the backup isnt quietly corrupted?

    a new innovative technology: decentralized backups. claude makes sure to introduce security holes so anyone can help us make a backup!!!

    someone helped us demo it back in march: https://lowendtalk.com/discussion/comment/4752630/#Comment_4752630

    server gets completely wiped. can you rebuild the whole thing from off server backups alone, including accounts, databases, dns, ssl, permissions, and resource limits?

    yes. ask claude, it will handle it.

  • I loved that. It's amazing how fast HPanel was hacked.

  • MikeAMikeA Patron Provider, Veteran

    @HPanel said:

    @systemfreaks said:
    I did evaluate this panel a couple of years ago during our R&D phase, and I have a few questions that you may be able to answer.

    Our old setup, DirectAdmin + CloudLinux + litespeed enteprise, costs approximately $65 per server with unlimited accounts.

    Some of our R&D clusters are currently using Enhance Control Panel. Since Enhance is priced per account, to make the economics comparable to DA, a server would need to host around 400 accounts to cost the same

    Enhance is not yet ready for all of our hosting requirements, but it does solve some very common problems, so we are willing to compromise and at least give it a try.

    My main question is: What problems of a modern hosting company does HPanel actually solve that would make it worth a company like SystemFreaks considering it as part of its stack?

    I am asking because, from what I have seen so far, I haven't found anything that would make it compelling enough to compete with DirectAdmin for us. DirectAdmin has been running essentially problem-free for us since 2015, so there would need to be a clear operational or financial advantage for us to consider changing.

    I would be interested in hearing what you believe HPanel offers that could make it worthwhile for a hosting company with our requirements.

    Fair question, and I'd rather answer it straight than pitch you.

    If DirectAdmin + CloudLinux + LiteSpeed has run clean since 2015, I'm not going to tell you to replace it. That combination is hard to argue with on either of the points you raised.

    Where HPanel differs is what's included rather than bolted on. Per-account filesystem isolation (a chroot jail per user) and per-account CPU / RAM / IO / IOPS / process limits via cgroups are built in, along with a PHP selector across 7.4–8.4. ModSecurity WAF, malware scanning with quarantine and restore, DNS clustering, and backups to S3, S3-compatible, Google Cloud or SFTP are part of the panel rather than separate licences. Licensing is flat per server with unlimited accounts, so account density never changes the bill.

    To be upfront about the gap: we're nginx + PHP-FPM with FastCGI page caching, not LiteSpeed. If your stack is built around LSWS and LSCache, that's a genuine difference and worth weighing.

    Happy to hand you a test instance if you'd rather judge it yourself than take my word for it.

    Sounds good, Mr. Claude!

    Thanked by 1forest
  • systemfreakssystemfreaks Member, Patron Provider

    @HPanel said:

    @systemfreaks said:
    I did evaluate this panel a couple of years ago during our R&D phase, and I have a few questions that you may be able to answer.

    Our old setup, DirectAdmin + CloudLinux + litespeed enteprise, costs approximately $65 per server with unlimited accounts.

    Some of our R&D clusters are currently using Enhance Control Panel. Since Enhance is priced per account, to make the economics comparable to DA, a server would need to host around 400 accounts to cost the same

    Enhance is not yet ready for all of our hosting requirements, but it does solve some very common problems, so we are willing to compromise and at least give it a try.

    My main question is: What problems of a modern hosting company does HPanel actually solve that would make it worth a company like SystemFreaks considering it as part of its stack?

    I am asking because, from what I have seen so far, I haven't found anything that would make it compelling enough to compete with DirectAdmin for us. DirectAdmin has been running essentially problem-free for us since 2015, so there would need to be a clear operational or financial advantage for us to consider changing.

    I would be interested in hearing what you believe HPanel offers that could make it worthwhile for a hosting company with our requirements.

    Fair question, and I'd rather answer it straight than pitch you.

    If DirectAdmin + CloudLinux + LiteSpeed has run clean since 2015, I'm not going to tell you to replace it. That combination is hard to argue with on either of the points you raised.

    Where HPanel differs is what's included rather than bolted on. Per-account filesystem isolation (a chroot jail per user) and per-account CPU / RAM / IO / IOPS / process limits via cgroups are built in, along with a PHP selector across 7.4–8.4. ModSecurity WAF, malware scanning with quarantine and restore, DNS clustering, and backups to S3, S3-compatible, Google Cloud or SFTP are part of the panel rather than separate licences. Licensing is flat per server with unlimited accounts, so account density never changes the bill.

    To be upfront about the gap: we're nginx + PHP-FPM with FastCGI page caching, not LiteSpeed. If your stack is built around LSWS and LSCache, that's a genuine difference and worth weighing.

    Happy to hand you a test instance if you'd rather judge it yourself than take my word for it.

    This is an AI-generated answer, and I don’t mind the use of AI. However, my question still hasn’t been answered.

  • SaragoldfarbSaragoldfarb Veteran, Megathread Squad

    @hyperhostsolutions said:
    FYI Hostingers Panel is called HPanel
    hPanel is a custom-made web hosting control panel created by Hostinger to help users manage their websites, domains, emails, and server resources from one central dashboard

    Unlucky... Also the logo design doesn't help much. Such a shit show.

  • Can't you at least tweak the AI‑shiting color scheme? It doesn't inspire confidence in its stability and reliability.

    After the summer host launch, the summer panel is finally here—what’s take?

  • SplitIceSplitIce Member, Host Rep

    @Saragoldfarb said: Unlucky... Also the logo design doesn't help much. Such a shit show.

    AI copied what it found. Likely also came up with the product name.

    Thanked by 1Saragoldfarb
  • HPanelHPanel Member, Patron Provider
    edited September 2

    @itzsenu said:

    @HPanel said: DirectAdmin + CloudLinux + LiteSpeed has run clean since 2015, I'm not going to tell you to replace it. That combination is hard to argue with on either of the points you raised.

    Where HPanel differs is what's included rather than bolted on. Per-account filesystem isolation (a chroot jail per user) and per-account CPU / RAM / IO / IOPS / process limits via cgroups are built in, along with a PHP selector across 7.4–8.4. ModSecurity WAF, malware scanning with quarantine and restore, DNS clustering, and backups to S3, S3-compatible, Google Cloud or SFTP are part of the panel rather than separate licences. Licensing is flat per server with unlimited accounts, so account density never changes the bill.

    To be upfront about the gap: we're nginx + PHP-FPM with FastCGI page caching, not LiteSpeed. If your stack is built around LSWS and LSCache, that's a genuine difference and worth weighing.

    Happy to hand you a test instance if you'd rather judge it yourself than take my word for it.

    before trusting ur pannel, please answer my little google form first. ( cuz i can see the smeel of AI )

    1. one account gets hacked what stops the hacker from going sightseeing through every other account and the host ?

    2. how do cpu, ram, i/o, iops, and process limits actually get enforced at the kernel and cgroup level? asking for the receipts.

    3. what is hpanel’s actual source of truth? how do you stop hpanel, nginx, phpfpm, dns, and the filesystem from slowly doing their own thing?

    4. what is the highest account count youve actually tested on one production server? and what breaks first when you keep adding more?

    5. live website and database backup. how do you keep the backup consistent, and how do you know the backup isnt quietly corrupted?

    6. server gets completely wiped. can you rebuild the whole thing from off server backups alone, including accounts, databases, dns, ssl, permissions, and resource limits?

    7. cpanel migration time. what happens to custom apache or .htaccess rules, plugins, cron jobs, mail, dns, permissions, ssl, and weird custom configs ?

    8. migration + backup + restore + account changes happening at the same time. how does hpanel stop everything from stepping on each other and creating broken state?

    9. hpanel itself gets compromised. what stops it from turning into unrestricted root access across the entire server?

    10. where are the actual benchmark numbers? performance, resource overhead, account density, backup and restore speed, migration speed, and failure recovery compared with directadmin + cloudlinux + litespeed.

    1- Each account runs as its own Linux user inside its own chroot jail one account's process physically cannot see or touch another account's files.

    2- Each account gets its own systemd cgroup slice with CPUQuota, MemoryMax, IOWeight, IOReadIOPSMax, IOWriteIOPSMax, and TasksMax enforced at the kernel level no userspace tricks.

    3- PostgreSQL is the single source of truth. Every change writes to the database first, then nginx, PHP-FPM, and DNS configs are generated from it and validated before reload. Manual edits to config files get overwritten the next time that account changes.

    4- Current production peak is 60 accounts on a single server, running stable.

    5- Files are backed up with rsync, databases with mysqldump using --single-transaction for InnoDB so the dump is consistent without locking tables. Backups are verified after transfer if the restore test fails, the backup is flagged.

    6- Yes. A full backup includes everything needed to rebuild the account on a fresh server files, databases, DNS, mail, SSL, permissions, and resource limits. Restore it and the account comes back complete, no manual re-provisioning needed.

    7- Cron jobs, mail, DNS, permissions, SSL migrated automatically. Plugins and files copied as-is. .htaccess files are copied but nginx handles rewrites natively so WordPress and standard redirects just work. Custom Apache-specific rules need moving to Site Rules. Anything that can't migrate is listed in the migration report nothing is silently dropped.

    8- Migrations are serialized one at a time via a global I/O lock with a queue. Each job is claimed atomically from the database so two workers can never grab the same job. Account changes validate and test configs before applying them and roll back on failure.

    Nothing stops it completely the panel runs as root, same as cPanel and DirectAdmin. If the panel itself is compromised, the attacker has root. That's the honest answer. The prevention is keeping the admin port firewalled, not exposed to the public internet.

    9- We're not positioning ourselves against DirectAdmin or LiteSpeed we have our own user base and it's growing. If the panel fits your requirements, great. If not, no hard feelings.

  • forestforest Member
    edited September 2

    @HPanel said: the panel runs as root

    Bad idea, especially given your sordid security track record. The panel should run unprivileged and communicate instead with a privileged daemon that can perform privileged actions on its behalf. There's no reason you should let a vulnerability in PHP give you root in some module that does not need to be privileged to do its job. Just because cPanel and DirectAdmin do the same does not mean you should.

    @HPanel said: If the panel fits your requirements, great. If not, no hard feelings.

    That is not an answer to whether or not you have benchmarks and what the real numbers are regarding e.g. overhead.

  • ObelousObelous Member
    edited September 2

    @HPanel said: We're not positioning ourselves against DirectAdmin or LiteSpeed

    https://hpanel.net/compare/hpanel-vs-directadmin.php

    Hmm...

    Thanked by 2forest borkedascii
  • WindsOfChangeWindsOfChange Member
    edited September 2

    https://www.corepanel.net/docs/cpanel-transform/ - that's very neat, do you have something like that too?

  • We wanted to make an alternative to cPanel so we took their logo and made hPanel.
    Made with vibes, layered with hopes n prayers™

    Thanked by 1forest
  • itzsenuitzsenu Member
    edited September 2

    @HPanel said: 1- Each account runs as its own Linux user inside its own chroot jail one account's process physically cannot see or touch another account's files.

    2- Each account gets its own systemd cgroup slice with CPUQuota, MemoryMax, IOWeight, IOReadIOPSMax, IOWriteIOPSMax, and TasksMax enforced at the kernel level no userspace tricks.

    3- PostgreSQL is the single source of truth. Every change writes to the database first, then nginx, PHP-FPM, and DNS configs are generated from it and validated before reload. Manual edits to config files get overwritten the next time that account changes.

    4- Current production peak is 60 accounts on a single server, running stable.

    5- Files are backed up with rsync, databases with mysqldump using --single-transaction for InnoDB so the dump is consistent without locking tables. Backups are verified after transfer if the restore test fails, the backup is flagged.

    6- Yes. A full backup includes everything needed to rebuild the account on a fresh server files, databases, DNS, mail, SSL, permissions, and resource limits. Restore it and the account comes back complete, no manual re-provisioning needed.

    7- Cron jobs, mail, DNS, permissions, SSL migrated automatically. Plugins and files copied as-is. .htaccess files are copied but nginx handles rewrites natively so WordPress and standard redirects just work. Custom Apache-specific rules need moving to Site Rules. Anything that can't migrate is listed in the migration report nothing is silently dropped.

    8- Migrations are serialized one at a time via a global I/O lock with a queue. Each job is claimed atomically from the database so two workers can never grab the same job. Account changes validate and test configs before applying them and roll back on failure.

    Nothing stops it completely the panel runs as root, same as cPanel and DirectAdmin. If the panel itself is compromised, the attacker has root. That's the honest answer. The prevention is keeping the admin port firewalled, not exposed to the public internet.

    9- We're not positioning ourselves against DirectAdmin or LiteSpeed we have our own user base and it's growing. If the panel fits your requirements, great. If not, no hard feelings.

    im still missing the actual technical details. i want to know what actually happens under the hood.

    1. account isolation

    you said every account gets a separate linux user and chroot.

    • what else is used besides chroot?
    • namespaces?
    • separate uid?
    • separate php-fpm process?
    • what stops account a from reading account b?
    • symlinks?
    • hardlinks?
    • /proc?
    • /tmp?
    • sockets?
    • dropped capabilities?
    • show a sanitized example config.

    if a wordpress plugin gets fully compromised, what can the attacker access?

    1. cgroups / resource limits

    you mentioned:

    CPUQuota
    MemoryMax
    IOWeight
    IOReadIOPSMax
    IOWriteIOPSMax
    TasksMax

    how are these actually applied?

    • cgroup v1 or v2?
    • what does the hierarchy look like?
    • show systemctl show output or /sys/fs/cgroup.
    • how does HPanel -> database -> systemd ->kernel work?
    • what happens when a limit is reached?
    • do php/cron/ssh child processes get limited?
    • do limits survive reboot?
    • can limits change while processes are running?
    1. source of truth

    you said postgresql is the source of truth.

    • what tables store accounts?
    • domains?
    • dns?
    • php settings?
    • limits?
    • ssl?
    • mail?
    • what happens if someone manually edits nginx or php-fpm?
    • does HPanel detect drift?
    • are generated configs deterministic?
    • are configs validated first?
    • what happens if reload fails?
    • does it roll back?
    • what happens if the server dies halfway through?
    1. production scale

    you said 60 accounts is the current production peak.

    what was the server?

    • cpu?
    • ram?
    • storage?
    • traffic?
    • php requests/sec?
    • database load?
    • disk iops?
    • cpu usage?
    • ram usage?

    what was the first bottleneck? and have you actually tested more than 60 accounts?

    1. backups

    you mentioned rsync and mysqldump --single-transaction.

    • where are backups stored?
    • separate server?
    • separate failure domain?
    • encrypted?
    • versioned?
    • retention?
    • checksums?
    • corruption detection?
    • restore tests?
    • alerts when backups fail?

    when was the last successful restore test? having a backup and successfully restoring one are two different things.

    1. disaster recovery

    you said a full account can be restored to a fresh server. okay. production server gets completely destroyed. only the off server backup survives. can you restore all of this?

    • HPanel config
    • accounts
    • files
    • databases
    • database users
    • dns
    • mailboxes
    • mail config
    • ssl
    • cron
    • permissions
    • ownership
    • php versions/settings
    • resource limits
    • firewall config
    • domains/subdomains

    without manually rebuilding everything? have you actually tested this on a clean server?

    • restore time?
    • automation percentage ?
    • what failed?
    1. cpanel / directadmin migration

    for cpanel:

    • .htaccess?
    • apache modules?
    • php extensions?
    • custom php settings?
    • cron jobs?
    • mailboxes?
    • passwords?
    • dns?
    • ssl?
    • database users?
    • permissions?
    • custom nginx/apache config?
    • cpanel plugins?

    what happens when HPanel finds something unsupported?does it stop or continue and report it? also how do you detect .htaccess rules which cannot be converted to nginx?

    1. concurrent operations

    you mentioned a global i/o lock and atomic database queue.

    • global lock or per account?
    • can two accounts migrate at once?
    • can backup and migration run together?
    • what happens if an account changes during backup?
    • what happens if migration dies halfway?
    • what happens after power loss?
    • can a job run twice?
    • how are failed jobs recovered?
    • idempotency?
    • config versioning?
    1. panel compromise

    you said a fully compromised root-level panel basically means root access. what else is protecting the system?

    • what runs as root?
    • what runs unprivileged?
    • public site separated from management?
    • public api?
    • can customer websites access the api?
    • authentication?
    • authorization?
    • rate limiting?
    • mfa?
    • scoped api tokens?
    • audit logs?
    • session protection?
    • plugin sandboxing?
    • independent security audit?

    if HPanel gets compromised, can the attacker also grab the backup credentials?

    1. HPanel attack surface

    what is HPanel built with?

    • language?
    • framework?
    • dependency scanning?
    • static analysis?
    • security testing?
    • secret storage?
    • database credentials encrypted?
    • password hashing?
    • encrypted credentials?
    • ssh/api credential protection?
    • security disclosure process?
    • cve history?
    • patch time for critical bugs?
    1. multi tenancy

    what stops one customer from destroying the node for everyone else?

    • all ram?
    • all cpu?
    • all processes?
    • all disk i/o?
    • all inodes?
    • millions of files?
    • network connections?
    • dns?
    • /tmp?

    what noisy neighbor protections exist?

    1. php fpm
    • separate pool per account?
    • separate uid?
    • separate socket?
    • separate limits?
    • can pool a access account b?
    • how are php extensions controlled?
    • dangerous functions?
    • multiple php versions?
    • how are php upgrades handled?
    1. database isolation
    • separate databases per account?
    • separate database users?
    • can account a connect to account b?
    • how are credentials stored?
    • cpu limits?
    • ram limits?
    • i/o limits?
    • what happens when one database goes crazy?
    • how are consistent backups made?
    • how are restores tested?
    1. dns
    • what dns server?
    • what backend?
    • generated from postgresql?
    • how are changes pushed?
    • what happens when generation fails?
    • dnssec?
    • rollback?
    • version history?
    • what prevents unauthorized changes?
    1. mail

    if HPanel handles mail:

    • which mta?
    • which imap/pop3 server?
    • mailbox isolation?
    • spam limits?
    • abuse limits?
    • sending limits?
    • dkim?
    • spf?
    • dmarc?
    • mail backups?
    • what happens if one mailbox gets compromised?
    1. ssl
    • letsencrypt automated?
    • automatic renewal?
    • what happens when renewal fails?
    • encrypted certificate storage?
    • can customer processes access private keys?
    • automatic nginx rollback?
    1. updates / rollback
    • how does HPanel update?
    • atomic updates?
    • rollback?
    • what happens if an update dies halfway?
    • can one bad update take down every site?
    • database migrations backward compatible?
    • zero-downtime updates?
    1. monitoring

    what happens when:

    • nginx dies?
    • phpfpm dies?
    • postgresql dies?
    • dns dies?
    • disk fills?
    • inodes hit 100%?
    • backup fails?
    • ssl renewal fails?
    • config generation fails?
    • migration fails?
    • network dies?

    does HPanel detect it automatically?

    does someone get an alert?

    or do customers have to start screaming first?

    1. benchmarks

    this was question #10 from my original post. i don’t need a "HPanel is faster than everything" benchmark. i want the actual HPanel numbers.

    • cpu overhead
    • ram usage
    • account creation time
    • domain creation time
    • php performance
    • database performance
    • max tested accounts
    • backup speed
    • restore speed
    • migration speed
    • server rebuild time
    • config generation time
    • concurrent operations
    1. reproducibility

    the easiest way to prove most of this would be one public test.

    something like:

    fresh debian
    -> install HPanel
    -> create 10/50/100 accounts
    -> apply cpu/ram/iops limits
    -> run workloads
    -> kill services
    -> break configs
    -> run backup
    -> destroy server
    -> reinstall
    -> restore
    -> check websites
    -> check databases
    -> check dns
    -> check limits

    post the results.

    i said i want to see the difference between "this is how HPanel is designed" and "we tested it, here are the results."

    show the receipts.

    i swear i never used AI to structure the message. i did it manually like hpanel, but without vibing the message.

  • itzsenuitzsenu Member
    edited September 2

    @CheepCluck said: We wanted to make an alternative to cPanel so we took their logo and made hPanel.
    Made with vibes, layered with hopes n prayers™

    but he forgot ai is gonna fuck up if its made with layers and side panels. the side panel is a nice copycat, and the others are just blinking blinking. and damn browser based audio. my speakers are asking for a bigger disk than playing it.

  • He literally said he isn't positioning it, not comparing it.

    @Obelous said: yes. ask claude, it will handle it.

    usage limit :#

    @forest said: Bad idea, especially given your sordid security track record. The panel should run unprivileged and communicate instead with a privileged daemon that can perform privileged actions on its behalf. There's no reason you should let a vulnerability in PHP give you root in some module that does not need to be privileged to do its job. Just because cPanel and DirectAdmin do the same does not mean you should.

    Sure. maybe He wants to make a copy of cPanel, or he just cant architect it himself and is asking Claude about current architecture of other pannels and having it recreate the architecture.

Sign In or Register to comment.