ISPConfig 3

Introduction

This article is released for AWS solution,

ISPConfig: Open Source Hosting Control Panel

ISPConfig 3 is an open source hosting control panel for Linux. It manages websites, email, FTP accounts, databases, DNS and shell users from one interface, and can manage several servers from a single panel. This image is built for a hosting operator: everything is installed conventionally on the instance, so you administer it exactly as ISPConfig’s own documentation describes, and you update it with ISPConfig’s own updater, ispconfig_update.sh, which ships with the panel at /usr/local/ispconfig/server/scripts/.

Pre-bundled with this image are

  • ISPConfig 3.3.2: the control panel, installed and configured at first boot with credentials generated for your instance.
  • AlmaLinux 10: a stable and secure open source operating system.
  • Apache HTTP Server with PHP 8.3: serving your websites and the control panel.
  • MariaDB 11.4: a long-term support release of the open source database.
  • Postfix and Dovecot: a complete mail server, with IMAP, POP3 and submission over TLS.
  • Amavis, SpamAssassin and ClamAV: spam and virus filtering on incoming mail.
  • Postfix postscreen: rejects the bulk of spam at the connection, before it reaches filtering.
  • Roundcube Webmail: browser webmail for your mail accounts.
  • pure-FTPd: FTP over TLS, with a firewalled passive port range.
  • phpMyAdmin: database administration from the panel, per database.
  • Jailkit: jailed SSH and shell users, so a shell account cannot see the rest of the server.
  • Fail2ban: ships with an SSH jail enabled, so brute-force attempts are blocked from the first boot.
  • rkhunter: rootkit detection.
  • AWStats: website traffic statistics.
  • getmail6: fetching mail from external mailboxes.
  • A dynamic swap file: sized from the instance’s own memory at build time.

 
Your control panel is ready when the installer finishes. The installation is unattended and takes about three minutes. Every credential is generated on your own instance, so no password is shared between customers and none is baked into the image. The panel sign-in is shown once, in the summary at the end of installation. Write it down: it is not stored anywhere it can be read back, and there is no recovery tool by design.

Your own domain and a trusted certificate are two steps, not one. The control panel starts on a self-signed certificate because no certificate authority will issue for an Amazon hostname. Once you add a website for your own domain, a single command moves the panel, mail and FTP onto a free Let’s Encrypt certificate. See Associating Your Domain.

This server needs more than three inbound ports. Unlike a single web application, a hosting panel serves web, mail, FTP and the panel itself. The full list is on the Requirement page.

SELinux runs in permissive mode. ISPConfig writes configuration, virtual hosts, jails and mail paths across the system in response to what you do in the panel, and an enforcing policy would block those changes in ways that surface later as a broken site or mailbox. Denials are still logged, so the diagnostic value is kept. Your inbound port list and the panel’s own access controls are the controls that matter here.
 
Elyxia Global Limited presents a pre-configured AMI on AlmaLinux, a trusted and stable platform, with the hosting stack installed, configured and ready to run so you can create your first website within minutes of launching the instance.

CONTENTS