Guide

A Free Web Hosting Control Panel Built for Alpine Linux

Updated

On this page
  1. Why Alpine Linux is an excellent hosting OS
  2. Why hosting panels have ignored Alpine
  3. How Unicorn Panel is built on Alpine
  4. A hosting stack that respects small servers
  5. Requirements and sizing
  6. Firewall ports
  7. Installing Unicorn Panel on Alpine, step by step
  8. Per-site PHP from 5.6 to 8.5
  9. Alpine on ARM: Graviton, Ampere and Raspberry Pi
  10. Useful commands for Alpine administrators
  11. Security on an Alpine hosting server
  12. What it costs
  13. Things to know before you install
  14. Frequently asked questions
  15. Put a real control panel on Alpine today

Alpine Linux is the quiet workhorse of modern infrastructure. It sits underneath a huge share of the world's containers, it boots in moments, and it fits comfortably on hardware that heavier distributions would struggle on. Yet if you wanted to run a traditional web hosting control panel on it, you were out of luck. The big panels were built for glibc-based distributions and assumed the tools that come with them.

Unicorn Panel changes that. It is a free web hosting control panel built specifically for Alpine Linux, running every website in its own Podman container and shipping a complete hosting stack for web, mail, databases and DNS. The minimum footprint is 500 MB of RAM and 5 GB of disk.

This guide covers why Alpine makes such a good hosting base, how Unicorn Panel is built on top of it, the exact requirements and ports, and a step-by-step install you can finish in a few minutes.

Why Alpine Linux is an excellent hosting OS

Alpine is a security-oriented, lightweight distribution built on musl libc and BusyBox, with the apk package manager. Those choices add up to properties that matter a lot on a hosting server.

A small base means a small attack surface. A fresh Alpine install contains very little. Every package you do not have is a package you never have to patch, audit or worry about. On a server that hosts other people's websites, fewer moving parts is a real security advantage.

Low memory overhead leaves more room for customers. The operating system itself uses very little RAM, so more of every server goes to the sites you are actually paid to host. That is why a full hosting panel can run on a 500 MB box at all.

Fast boots and fast package installs. Alpine's apk is quick, and a minimal base boots quickly. When you are rebooting for a kernel update or rebuilding a server, minutes saved per host add up across a fleet.

It is the natural home for containers. Alpine has long been a popular base for container images because of its size. A container-first control panel on an Alpine host keeps the whole stack consistent, from the host OS to the tenant containers.

Predictable releases. Alpine ships stable releases on a regular schedule, which makes upgrade planning straightforward.

First-class ARM support. Alpine runs well on arm64 hardware, from cloud instances to single-board computers, which opens up cheaper and more efficient servers.

Why hosting panels have ignored Alpine

If Alpine is so well suited to hosting, why has nobody built a full control panel for it? Mostly history. The established panels grew up on RHEL-family distributions, Debian and Ubuntu, and they depend on glibc, on large language runtimes, and on the service conventions of those systems. Porting that much legacy code to musl and a minimal userland is a huge job, so it never happened.

That left Alpine users with two options: manage everything by hand with config files and scripts, or run a heavier distribution just to get a panel. Unicorn Panel removes that trade-off by starting on Alpine from day one rather than porting to it later.

How Unicorn Panel is built on Alpine

Unicorn Panel follows the Alpine philosophy: small pieces with predictable behavior.

One install path, no heavy runtimes

The panel installs as one Alpine apk install plus one unicorn binary, with no Python or Java runtime to break on upgrades. The same binary runs on every host, cross-compiled for amd64 and arm64. The Unicorn stack page covers what each service does.

Podman containers for every tenant

Every website runs in its own Podman container, with its own Linux user, ports, PHP-FPM pool and limits on CPU, memory, disk and processes. The Alpine host stays clean, because customer workloads never install packages onto it. PHP versions, web engines and database engines are packaged as swappable roles, so changing one site's PHP version never touches another site or the host. We cover why this matters in container-per-site hosting explained.

A native nftables firewall and Unicorn Shield

The installer configures an nftables firewall and installs Unicorn Shield, which watches for WordPress login attacks, SSH brute force, panel sign-in attempts and malicious request patterns, then bans offenders at the firewall itself. The firewall has guard rails: the panel's own rules are protected, a custom SSH port is detected and kept open, and IPv6 counterparts are added for you.

Disk quotas enabled at install

Per-site disk limits rely on filesystem quotas, and the installer enables them for you. No manual fstab editing.

Here is what the installer does on a fresh box, in order, as shown on the fleet page:

  1. Enable the Alpine community repository
  2. Install host packages
  3. Enable disk quotas
  4. Download and install Unicorn Core
  5. Install and configure the nftables firewall
  6. Install and configure Podman
  7. Install Unicorn Shield
  8. Build and configure the control panel
  9. Build and configure the reverse proxy
  10. Install the web terminal
  11. Install SSH/SFTP
  12. Install the Unicorn daemon
  13. Finalise installation and generate an SSL certificate

A hosting stack that respects small servers

Alpine's efficiency is wasted if the hosting software on top of it is bloated. Unicorn Panel ships its own first-party engines, designed to be lean and to integrate with the panel.

Hermes mail suite. Traditional mail stacks run several separate daemons: an MTA, an IMAP server, a spam filter and an antivirus daemon. Hermes replaces Postfix, Dovecot, rspamd and ClamAV with a single privilege-separated mail server written in C. Its virus scanning uses ClamAV's official signature databases as hash signatures without running clamd, the large resident scanning daemon. The database is loaded once and shared across listeners, so enabling scanning on more listeners costs almost no extra RAM. That is a big deal on a small Alpine box. (The trade-off: hash-based scanning blocks exact known-bad files, while polymorphic and macro malware need the full clamd engine. The documentation sets out both modes.)

Mimir SQL server. A lighter in-container SQL server aimed at typical sites such as WordPress and WooCommerce, with its own lightweight admin UI. When you need more, MariaDB, MySQL and PostgreSQL run alongside it on the same host with non-conflicting ports.

Heimdall DNS. In-house authoritative DNS with multi-host replication, built into the panel rather than bolted on.

Sleipnir web server. Unicorn's own web server, designed to sit behind the panel's proxy. NGINX, Apache and OpenLiteSpeed remain fully supported if you prefer them.

Because these engines share uniform logging, metrics and restart semantics, running them on Alpine feels like running one product rather than a collection of daemons.

Requirements and sizing

The installation guide lists these minimums:

RequirementMinimum
Operating systemAlpine Linux 3.20 or newer (latest recommended)
ServerA blank VPS or bare-metal server with no other software installed
Memory500 MB RAM (enable swap on low-memory servers)
Storage5 GB
Architectureamd64 or arm64

Where data lives. Everything, including customer data, is stored under /opt/upcp. Customer containers live in /opt/upcp/containers, so you can put /opt/upcp or /opt/upcp/containers on its own partition to make the most of your disks. Mailbox data for the email role is kept in /opt/upcp/services/upcp-ues/data, and a server with the backup role stores backups at /backups, which can be a partition, network mount or external storage.

Sizing advice. 500 MB is enough to run the panel and a small site. For real customer workloads, size memory to the sites you plan to host, give mail and database roles more headroom, and use a provider with snapshots so you have a disaster-recovery point beneath the panel's own backups.

Firewall ports

The installer opens the ports it needs automatically, and installing a role opens that role's ports. If your provider runs a network-level firewall, open these there too:

ServicePortsWhen needed
Unicorn Panel8727 TCPAlways, on every server
Web80 TCP, 443 TCP/UDPWeb roles
SSH22 TCPServer access
Databases3306, 3307, 3308, 5432 TCPOnly if databases must be reachable externally
DNS53 TCP/UDPServers acting as nameservers
Email25, 143, 465, 587, 993 TCPServers running the mail role

Installing Unicorn Panel on Alpine, step by step

1. Provision a fresh Alpine server. Choose Alpine 3.20 or later from your VPS provider, or install it on bare metal. Start from a blank server; the panel expects to own the box.

2. Update the system. Log in as root and bring packages up to date:

apk update && apk upgrade

3. Run the installer. One command does the rest:

wget -qO- https://unicornpanel.com/install | sh

The first server you install on automatically becomes the Primary control panel. When the installer finishes, it prints a login link and your admin credentials.

4. Log in. If the link does not load, check that port 8727 is open at your provider's firewall. Give the server a few minutes after install for CPU usage to settle.

5. Secure the admin account. Under My Account, change the password, then enable 2FA or passkeys under Login Security. Passkeys need the panel to be on a fully qualified domain name. If you ever lose the admin password, unicorn root reset-admin-password generates a new one from the terminal.

6. Set a control panel domain. Under Settings → Control Panel Domain, set a hostname such as panel.example.com. The panel issues a free SSL certificate, customers log in without a port number, and passkey support switches on.

7. Configure SMTP. Under Settings → SMTP Settings, set up outgoing mail so password resets and notifications are delivered.

8. Add your branding. Settings → Branding lets you change colors, icons and names.

9. Install roles. Go to Servers → your server → Roles and install what you need: a web engine, PHP versions, a database engine, Hermes for mail, Heimdall for DNS. Roles build in the background and stream their progress live.

10. Create your first site. The website wizard checks the domain as you type, builds the container and issues the certificate.

11. Add a second server (optional). From Servers → Add server, copy the register command onto another fresh Alpine box. It installs, registers and appears in your panel ready for roles. This is where Unicorn Panel's fleet design comes in; our multi-server pillar guide explains the Primary and Secondary model in depth.

Per-site PHP from 5.6 to 8.5

One of the most practical benefits of a container-based panel on Alpine is PHP flexibility. Unicorn Panel supports twelve major PHP versions, 5.6, 7.0 through 7.4, and 8.0 through 8.5, each packaged as a swappable role. You pick the version per site and can change it later without rebuilding the container. Legacy WordPress, Magento and Drupal installs keep working while modern sites run the latest release on the same server. Read more in running PHP 5.6 to 8.5 side by side.

Alpine on ARM: Graviton, Ampere and Raspberry Pi

Every Unicorn Panel binary is cross-compiled for amd64 and arm64, and ARM hosts are first-class citizens in the fleet. The FAQ names Ampere, Graviton, Raspberry Pi and Mac mini as supported hardware. Combined with Alpine's small footprint, that makes low-cost ARM instances a genuinely viable hosting platform. We cover ARM hosting in its own article: a hosting control panel for ARM servers.

Useful commands for Alpine administrators

If you like the terminal, the unicorn CLI mirrors what the panel manages. A few commands Alpine admins reach for most:

CommandWhat it does
unicorn host versionShows the Alpine release on this host
unicorn podman list-containersLists every tenant container and its status
unicorn podman recreate-container <UID>Rebuilds one site's container from panel settings
unicorn tools prune-imagesRemoves dangling and orphaned Podman images
unicorn tools recalculate-quotasRe-applies filesystem quotas from panel state
unicorn cron check-common-server-issuesScans logs for the most common problems
unicorn shield ban <IP> / unban <IP>Manage the firewall ban list
unicorn upgradeUpgrades the panel, snapshotting state first

Security on an Alpine hosting server

Alpine gives you a small, hardened base. Unicorn Panel adds the hosting-specific layers on top: a container per site, Unicorn Shield bans at the firewall, fleet-wide malware scanning with ClamAV and Linux Malware Detect, passkey sign-in, 2FA that also covers password reset, and sessions bound to the browser that created them. Host-to-host calls use per-server API keys instead of shared root SSH. Our hosting control panel security checklist walks through each layer.

What it costs

Unicorn Panel is free for 2 servers and 2 panel accounts, with unlimited websites, databases, mailboxes and DNS zones. Beyond that, $5 a month covers 3 servers and 10 accounts, with $1 per extra server and $0.30 per extra account (excluding tax). The $5 launch rate is locked in for as long as your subscription stays active, and there is a 30-day money-back guarantee. Full details are on the pricing page.

Things to know before you install

  • Start from a blank server. The panel is designed to own the machine, so do not install it on a box already running other services.
  • Use a domain for the panel. Passkeys and some browser features only work on a fully qualified domain name, not a bare IP.
  • Keep a bulk mail provider for newsletters. Hermes is a mail server, not a bulk sender, though it can relay outbound mail through a smarthost.
  • Migration import is coming. The wizard for importing cPanel, Plesk, DirectAdmin, Enhance and Duplicator archives is still in development; watch the releases page.
  • Docs are catching up. The product is moving fast, and the documentation marks each section as complete, awaiting updates or outdated.

Frequently asked questions

Does Unicorn Panel run on Alpine Linux only? Yes. It is built for Alpine Linux 3.20 or newer, and that focus is what keeps it light.

What is the minimum RAM for an Alpine hosting server with Unicorn Panel? 500 MB, with swap recommended on low-memory servers. Plan more for real customer workloads.

Do I need to know musl or Podman to use it? No. The panel manages containers, PHP versions and engines for you. The CLI is there if you want it.

Can I run WordPress on it? Yes. There is a built-in WordPress toolkit for core updates, plugins, URL search-and-replace, cache clearing and one-click wp-admin login.

Does it work on Raspberry Pi? Yes. Every binary ships for arm64, and Raspberry Pi is listed among supported hardware.

Is it really free? Two servers and two accounts are free forever with unlimited sites, databases, mailboxes and zones.

Put a real control panel on Alpine today

Alpine Linux deserved a proper hosting control panel, and now it has one. Unicorn Panel keeps Alpine's small, fast, secure character while giving you everything a hosting business needs: per-site containers, twelve PHP versions, mail, DNS, backups and multi-server management from one place.

Spin up a fresh Alpine server and run:

wget -qO- https://unicornpanel.com/install | sh

Or try the live demo first. It is free for your first two servers, and the $5 launch price stays yours when you grow.

Try it on your own servers.

Free for 2 servers and 2 accounts, with unlimited websites, databases, mailboxes and DNS zones.