aaPanel in Docker: panel-only, single /www volume, multi-arch, no-privileged, auto-updated daily
1.1K
A clean, production-minded Docker packaging of aaPanel — the free, open web hosting control panel for Linux. One container, one volume, no privileged mode, multi-architecture, and rebuilt automatically every day to track the latest official aaPanel release.
This is an unofficial community image. aaPanel itself is developed by its respective owners; this repository only packages it for Docker.
/www volume. Easy to back
up, move, or snapshot.privileged: true — runs as an ordinary container with a plain
process model (no systemd-in-Docker gymnastics, no host cgroup mount).linux/amd64 and linux/arm64 images behind a
single tag.8.0.3).| Tag | Description |
|---|---|
latest | Most recent stable aaPanel release |
8.0.3, 8.0.2, … | Pinned to a specific aaPanel version |
Each version tag is a multi-arch manifest covering amd64 and arm64.
git clone https://github.com/toquanghieu/aapanel-docker.git
cd aapanel-docker
cp .env.example .env # optional — tweak the port or set fixed credentials
docker compose up -d
docker run -d \
--name aapanel \
-p 8888:8888 \
-p 80:80 -p 443:443 \
-v aapanel_data:/www \
--restart unless-stopped \
hieutq/aapanel:latest
On the first start the panel generates a random username, password, and a secured entry path, then prints them to the logs:
docker logs aapanel
============================================================
aaPanel is ready
------------------------------------------------------------
URL (host): http://<your-server-ip>:8888/a1b2c3d4
Username: aapanel_x7f9k2
Password: 3f8a1c9e2b7d4a06
------------------------------------------------------------
Open the printed URL and log in. The credentials are also stored inside the
volume at /www/.aapanel-credentials, and you can always re-display panel info
from inside the container:
docker exec -it aapanel bt 14
To set fixed credentials instead, provide the environment variables below before the first start.
All variables are optional. Credentials left unset are generated randomly on first run.
| Variable | Default | Description |
|---|---|---|
AAPANEL_PORT | 8888 | Panel web UI port |
AAPANEL_USERNAME | random | Panel login username |
AAPANEL_PASSWORD | random | Panel login password |
AAPANEL_ENTRY | random | Secured entry path, e.g. /my-secret-entry |
AAPANEL_SSL | off | Serve the panel over HTTPS (on/off) |
These apply only on first run, when the panel is initialized. To change them later, use the panel UI or the
btCLI inside the container.
| Port | Published by default | Description |
|---|---|---|
8888 | ✅ | aaPanel web UI |
80 | ✅ | HTTP — your websites (once a web server is installed) |
443 | ✅ | HTTPS |
888 | — | phpMyAdmin |
21 / 20 | — | FTP (control / data) |
3306 | — | MySQL |
The non-panel ports only carry traffic once you install the matching service
from the panel. Publish them by uncommenting the relevant lines in
docker-compose.yml (or adding -p flags) when you need them.
Everything aaPanel manages lives under a single /www volume:
| Path | Contents |
|---|---|
/www/server/panel | Panel application, config, and database |
/www/wwwroot | Your website files |
/www/server/data | MySQL data (after you install MySQL) |
/www/server/* | Other services you install (Nginx, PHP, …) |
Back up by snapshotting the aapanel_data volume. To use a host bind mount
instead, replace aapanel_data:/www with ./www:/www in the compose file and
drop the trailing volumes: block.
This image intentionally ships only the panel. After logging in:
80/443 (and 3306,
888, 21 as needed) on the container.privileged: true and without mounting the host cgroup.8888) with a firewall or reverse proxy.Lost your password?
# Re-display panel info (URL, user, entry path):
docker exec -it aapanel bt 14
# Reset the password:
docker exec -it aapanel bt 5
Panel not reachable? Confirm the daemon is up and you are hitting the secured entry path (the URL suffix from the logs), not just the bare port:
docker logs aapanel
docker exec -it aapanel /etc/init.d/bt status
A service you installed (Nginx/MySQL) isn't reachable from the host.
Make sure its port is published on the container — add the -p flag (or compose
line) and recreate the container.
ubuntu:22.04 base using the
official installer, then packs /www into a compressed first-run seed./www volume, sets the port and
secured entry path, generates (or applies) credentials, and starts the panel
daemon — no systemd required.vX.Y.Z, and
triggers a multi-arch build that publishes :X.Y.Z and :latest to Docker
Hub and refreshes this description automatically.git clone https://github.com/toquanghieu/aapanel-docker.git
cd aapanel-docker
docker build -t hieutq/aapanel:local .
docker run -d --name aapanel -p 8888:8888 -v aapanel_data:/www hieutq/aapanel:local
docker logs aapanel # grab the generated credentials
MIT. aaPanel is a trademark of its respective owners; this project is not affiliated with or endorsed by aaPanel.
Content type
Image
Digest
sha256:d897434e9…
Size
382.2 MB
Last updated
about 2 months ago
docker pull hieutq/aapanel