1Panel
Manage Linux servers, containers, websites, and AI agents from one web interface.
The evidence provides a vulnerability-reporting address, a supported-version statement, backup and restore claims, and one workflow restricted to pull-requests: write. Repository naming, community links, and a maintenance contact provide basic attribution. Deductions apply because no least-privilege model for Agent or server operations, confirmation gates for hazardous actions, data-flow inventory, credential lifecycle, or secrets-handling policy is shown. Installation relies on an uninspected remote script, while workflows use third-party Actions and custom tokens without evidence of dependency scanning, commit-digest pinning, or supply-chain mitigation. External effects are described but their authorization boundaries and safeguards are not. Backup and restoration merit a higher score, although scope, validation, and failure behavior are undocumented. Unknown publisher identity is not itself penalized, but the supplied attribution evidence is not thorough enough for full marks.
The README is broadly internally consistent about server management, AI management, product tiers, and support routes, while SECURITY.md clearly limits support to v1.x. Deductions apply because the main installation path depends on a live remote script, external resources, and third-party Actions without mirrors, checksums, a compatibility matrix, or availability fallbacks. No error-message examples, diagnostic guidance, or failure-recovery instructions appear, so failure_messages receives zero. Missing runtime testing was not used to reduce these static criteria.
The material identifies Linux self-hosters and covers website, container, database, file, backup, and AI-management scenarios. The OSS/Pro/Ent table gives reasonably clear commercial capability boundaries. Deductions apply because no Agent trigger conditions, routing logic, false-trigger controls, or tool-selection rules are supplied, leaving trigger_precision unsupported. Environment guidance stops at a generic Linux server and access URL, without distributions, architectures, resource requirements, ports, container-runtime prerequisites, or network constraints.
The README has clear sections for overview, features, quick start, editions, support, security, and licensing, plus many language entry points; 1Panel naming is stable in the supplied material. GPL-3.0 metadata, the README statement, and the full LICENSE agree, justifying full license marks. Deductions apply because installation is essentially a curl-to-shell command without verification, prerequisites, or uninstall guidance; there is a screenshot but no Agent example or FAQ; stated limitations mostly concern paid tiers rather than technical constraints. A releases link and the v1.x support table establish an update path, but no actual changelog content is provided. Issues, Discord, and the security email show maintenance channels, although publisher registry identity is unverified and ownership responsibilities are not detailed.
The repository describes a unified web GUI, one-click deployment, an app store, backup and restoration, and AI management, while the edition table communicates free and paid choices. This supports some prospective usability and cost comparison. Deductions apply because no concrete Agent inputs, outputs, workflows, or resulting artifacts are shown, so direct output usability cannot be established statically. The competitor table lacks methodology or supporting evidence, making marginal-value claims largely promotional. OSS availability and tier differences are clear, but hardware, operations, model usage, storage, and migration costs are not disclosed.
The license, supported version, security contact, and installation command are directly traceable to supplied files, and README, LICENSE, and SECURITY.md provide limited corroboration on those matters. Deductions apply because major claims such as 2.5M+ users, 165+ applications, enterprise-grade security, reduced vulnerability exposure, and competitor advantages lack accompanying static substantiation. AI Agent functionality is represented only by overview and tier statements. Facts, inferences, and promotional language are not systematically separated, while cross-file corroboration is largely confined to licensing and maintenance routes.
- The quick-start command downloads and immediately executes a remote script; the supplied evidence contains neither that script, an immutable version, nor a checksum, so it should be reviewed and verified separately before deployment.
- The product can affect servers, files, databases, containers, certificates, and backups, but the material does not show permission boundaries or confirmation gates for Agent-driven hazardous operations.
- AI gateways, agents, models, and cloud storage may transmit sensitive data, yet the supplied files do not describe destinations, retention, encryption, or deletion policies.
- Claims about community size, security, application count, and competitor advantages are not adequately substantiated within the supplied material.
- Workflows reference actions/checkout@v3 and a third-party Action by tag rather than immutable commit digests, with no shown dependency audit or supply-chain controls.
What does this agent do, and when should you use it?
1Panel is a self-hosted, open-source Linux server control panel with a lightweight AI management layer. Its primary interface is a web GUI for host monitoring, files, databases, containers, websites, backups, and security operations. The AI side follows a “Metal-to-Agent” model, combining centralized agent and model management with a Skills Hub and, in the Enterprise edition, an AI Gateway; the OSS edition supports five OpenClaw agents. Container-based application deployment is paired with a marketplace of more than 165 applications and website integrations such as WordPress and Halo. It is a practical fit for self-hosters seeking one control plane for infrastructure and AI workloads, while teams needing multi-node management, unlimited agents, the AI Gateway, or advanced production controls must consider Pro or Ent.
The operator runs quick_start.sh from a shell on a Linux server, then opens http://<your-server-ip>:<port>/<security-path> in a browser. The web GUI reads and presents host monitoring data and provides operations for server files, databases, and containers, including installing and upgrading containerized applications from the built-in store. Its website workflow installs software such as WordPress or Halo, binds a domain, and configures an SSL certificate. Backup operations create and restore backups and can connect to multiple cloud-storage solutions. Security functions include WAF and log auditing, with availability varying by edition. The AI layer centrally manages agents and models and includes a Skills Hub; AI Gateway is limited to Ent. The 1pctl user-info command retrieves access credentials over SSH when needed.
- A self-hoster wants a graphical interface for monitoring a Linux machine and administering its files, databases, and Docker containers.
- A website administrator needs to deploy WordPress or Halo quickly, then bind a domain and configure an SSL certificate.
- An operations engineer wants one-click installation and upgrades for curated open-source services instead of configuring every container manually.
- A small AI lab wants to manage models and up to five OpenClaw agents on its own server using the OSS edition.
- A server owner needs one-click backup and restoration with the option to connect backups to cloud storage.
- A production team needs WAF controls, log auditing, multi-node management, or an AI Gateway and is prepared to evaluate the Pro or Ent editions.
What are this agent's strengths and limitations?
- One web GUI spans host, file, database, container, website, backup, and AI administration, consolidating several operational workflows.
- The built-in marketplace lists more than 165 one-click applications and explicitly supports WordPress and Halo deployment, domain binding, and SSL setup.
- Its Metal-to-Agent scope adds centralized model and agent management plus a Skills Hub; even the OSS edition supports five OpenClaw agents.
- Backup and restoration, cloud-storage integration, WAF, and log auditing place data protection and security controls alongside routine administration.
- The documented deployment target is a Linux server; supported distributions, minimum hardware, and non-Linux options are not specified.
- The quick-start method pipes a network download directly into Bash, requiring shell and network access and placing script-execution review on the adopter.
- OSS is capped at five OpenClaw agents; unlimited agents, multi-node management, tamper protection, and uptime monitoring require Pro or above.
- AI Gateway and the KVM Web UI are Ent-only, so the GPL-3.0 edition does not include every production-oriented capability.
- No native ChatGPT, Codex, Claude, OpenAI API, or Anthropic API integration is documented, and concrete model or cloud-storage setup examples are absent.
How do you install or deploy this agent?
Prepare a network-connected Linux server and run this command in its shell:
bash -c "$(curl -sSL https://resource.1panel.pro/v2/quick_start.sh)"This downloads and immediately executes the installation script from resource.1panel.pro. The supplied material does not specify supported Linux distributions, minimum hardware, or prerequisite packages.
How do you use this agent?
After installation, open http://<your-server-ip>:<port>/<security-path> in a browser, replacing the placeholders with the address, port, and security path produced during setup, then sign in with the installation credentials. If those credentials are unavailable, connect over SSH and run:
1pctl user-infoFrom the web GUI, select host monitoring, file, database, container, website, app-store, backup, or AI management functions. For a website, install an application such as WordPress or Halo, bind its domain, and configure SSL. For AI workloads, add and manage agents and models centrally. The supplied material does not document the exact credential fields or a first configuration example for models, cloud storage, or AI Gateway.
How does this agent compare with similar options?
The repository's comparison table positions 1Panel against cPanel/Plesk, aaPanel, and Webmin. It lists 1Panel as the only option in that table combining AI management, a modern post-2020 UI, Docker/container management, and a marketplace with more than 165 one-click applications. cPanel/Plesk is shown as neither free nor open source and without the listed AI, marketplace, or Docker features; aaPanel is marked only partially open source and partially modern, with no AI or Docker management; Webmin is shown as free and open source but without the listed AI, marketplace, or container features and with slower development. These are repository-provided product comparisons rather than independently documented benchmarks.