ZefiraZEFIRA Docs Changelog Donate GitHub ↗

ZEFIRA Installation

From empty server to working panel in about 5 minutes.

Requirements

One-line install

bash <(curl -fsSL https://raw.githubusercontent.com/mrlurix/zefira-panel/main/install.sh)
Piped scripts run non-interactively with safe defaults and print a random admin password at the end. For the guided setup, download the script first and run sudo bash install.sh.

The 7 guided steps

StepWhat you choose
1 · PortPanel port (default 8000)
2 · DomainDomain for links & SSL, or empty to use the server IP
3 · AdminAdmin username + password (empty = strong random password; typed passwords need 10+ chars with letters AND digits, 3 tries)
4 · DatabaseSQLite (zero setup), MySQL, MariaDB or PostgreSQL
5 · SubscriptionSubscription URL path (default /sub)
6 · TelegramOptional bot token + chat ID for notifications
7 · Nginx + SSLReverse proxy + Let's Encrypt certificate (needs port 80 free)

What the installer does

  1. Installs Python, Nginx and Certbot
  2. Clones Zefira to /opt/zefira
  3. Creates a virtualenv and installs dependencies
  4. Writes a locked-down .env (mode 600, admin password one-time — auto-scrubbed on first boot)
  5. Creates a zefira system user, chowns /opt/zefira, installs a passwordless sudoers rule scoped to systemctl restart zefira only
  6. Registers a non-root systemd service (zefira.service: User=zefira, ProtectSystem=strict, PrivateDevices, UMask=0077)
  7. Optionally configures Nginx and issues the SSL certificate with auto-renew cron

After install

# your URL, login and paths are printed at the end, e.g.
# URL   : https://vpn.example.com
# Local : http://127.0.0.1:8000

systemctl status zefira
journalctl -u zefira -n 100 --no-pager   # logs
sudo cat /opt/zefira/instance/first-run-credentials.txt   # first-run login
sudo rm /opt/zefira/instance/first-run-credentials.txt    # then delete it
First login: open Settings and change the password. Do this before creating users.

Non-interactive install

# Read a password from a hidden prompt - never type it on the command line,
# where it lands in your shell history and in /proc/*/cmdline.
read -rsp "Admin password: " ZEFIRA_ADMIN_PASSWORD; echo

curl -fsSLO https://raw.githubusercontent.com/mrlurix/zefira-panel/main/install.sh
less install.sh          # it runs as root: read it first
sudo env ZEFIRA_DOMAIN=vpn.example.com \
  ZEFIRA_SSL_EMAIL=admin@example.com \
  ZEFIRA_SETUP_NGINX=y ZEFIRA_USE_SSL=y \
  ZEFIRA_ADMIN_USERNAME=admin \
  ZEFIRA_ADMIN_PASSWORD="$ZEFIRA_ADMIN_PASSWORD" \
  bash install.sh
unset ZEFIRA_ADMIN_PASSWORD
Download the installer before running it. sudo bash <(curl ...) hands whatever is on the branch to root with no review step; pinning a tag (for example /v1.13.6/install.sh) also makes the install reproducible.

Uninstall

sudo bash install.sh --uninstall