Consolidate cPanel, Plesk & Bare‑Metal VPS into One Manageable Fleet
Panel‑agnostic workflow: central management node, SSH bastion, Prometheus monitoring, Ansible updates, Rclone backups, and a unified API gateway for mixed cPanel, Plesk, and bare‑metal VPS.
7 min read
Managing a fleet of VPS that run different control panels—cPanel, Plesk, or custom bare-metal nodes—can become a complex task. Each panel has its own update cadence, licensing model, and command-line interface. This article outlines a single, panel-agnostic workflow that consolidates monitoring, automation, and backups, making the entire environment easier to manage.
1. Create a Central Management Node
Start by provisioning a lightweight “management node.” This host does not serve customer traffic; it runs orchestration scripts, monitoring agents, and a secure bastion for SSH access.
Choose a small VPS (1 vCPU, 2 GB RAM). Ubuntu 22.04 LTS or AlmaLinux 9 are both suitable.
Secure the node with a non-standard SSH port and key-based authentication.
Ubuntu/Debian (apt) – Initial Setup
# Update packages
sudo apt update && sudo apt upgrade -y
# Install essential tools
sudo apt install -y curl wget gnupg2 ca-certificates
# Create a user for automation
sudo adduser --disabled-password --gecos "" fleetadmin
sudo usermod -aG sudo fleetadmin
# Set up SSH key authentication
mkdir -p /home/fleetadmin/.ssh
chmod 700 /home/fleetadmin/.ssh
# (Copy your public key into authorized_keys)
AlmaLinux/Rocky/RHEL (dnf) – Initial Setup
# Update packages
sudo dnf update -y
# Install essential tools
sudo dnf install -y curl wget gnupg2 ca-certificates
# Create a user for automation
sudo adduser fleetadmin
sudo passwd -l fleetadmin # lock password
sudo usermod -aG wheel fleetadmin
# Set up SSH key authentication
mkdir -p /home/fleetadmin/.ssh
chmod 700 /home/fleetadmin/.ssh
# (Copy your public key into authorized_keys)
After these steps, the management node is ready to run fleet scripts.
2. Deploy a Uniform SSH Bastion
All panel servers should be reachable only through the bastion. This limits exposure, simplifies firewall rules, and provides a single audit point for login activity.
Configure the bastion to allow ssh -J (jump host) connections.
Use ssh-agent forwarding so private keys never reside on the panel hosts.
SSH Config Example (client side)
Host bastion
HostName bastion.example.com
User fleetadmin
Port 2222
IdentityFile ~/.ssh/id_rsa_fleet
Host *.vps.example.com
ProxyJump bastion
User root
IdentityFile ~/.ssh/id_rsa_fleet
With this configuration, ssh web01.vps.example.com automatically tunnels through the bastion.
3. Standardize Monitoring with Prometheus & Grafana
All VPS expose system metrics (CPU, RAM, disk I/O) via standard Linux interfaces. Installing a Prometheus node exporter on each host provides a single source of truth regardless of the control panel.
On the management node, install Prometheus and Grafana (via Docker or native packages). Add each VPS's exporter endpoint (http://vps-ip:9100/metrics) to the scrape_configs section of prometheus.yml. Grafana can then query Prometheus and display unified dashboards for all panels.
4. Automate Updates Across Panels
Each control panel provides its own CLI for updates:
/usr/local/cpanel/scripts/upcp – cPanel
plesk installer update – Plesk
Standard apt or dnf – bare-metal nodes
Use Ansible to run the appropriate command on each host. Ansible's inventory can group servers by panel type, allowing you to target them with a single playbook.
Run the playbook from the management node with ansible-playbook -i inventory update.yml. The async directive allows each server to update in the background, keeping the playbook responsive.
5. Centralize Backups with Rclone and Object Storage
cPanel and Plesk support remote backups to FTP, SFTP, or cloud storage. Bare-metal nodes can use rsync or tar. To keep the process uniform, use Rclone on the management node to push all backup archives to an S3-compatible bucket (AtoZNode offers Object Storage in the India region).
Step-by-step
Install Rclone on the management node.
Configure a remote named atoznode with your access key and secret.
On each VPS, schedule a cron job that creates a tarball of the site data and uploads it via Rclone.
Rclone Installation (both OS families)
curl https://rclone.org/install.sh | sudo bash
Configure Remote (run on management node)
rclone config
# Choose "n" for new remote, name it atoznode, select "s3", then provide:
# provider: Other
# endpoint: https://your-object-storage-endpoint
# access_key_id: YOUR_KEY
# secret_access_key: YOUR_SECRET
Backup Script Example (placed on each VPS)
#!/bin/bash
DATE=$(date +%F)
BACKUP_DIR="/backup"
mkdir -p "$BACKUP_DIR"
# cPanel example – archive /home
tar -czf "$BACKUP_DIR/cpanel_$DATE.tar.gz" /home
# Plesk example – archive /var/www/vhosts
tar -czf "$BACKUP_DIR/plesk_$DATE.tar.gz" /var/www/vhosts
# Bare-metal – archive custom app directory
tar -czf "$BACKUP_DIR/app_$DATE.tar.gz" /opt/myapp
# Upload to object storage
rclone copy "$BACKUP_DIR" atoznode:myvpsbackups/$(hostname) --log-file=/var/log/rclone-backup.log
Make the script executable and add it to crontab -e (e.g., daily at 02:00). Centralizing the uploads means you only need one set of credentials and can monitor transfer logs from the management node.
6. Use a Single API Gateway for Panel Operations
When you need to perform ad-hoc actions—creating a new account, resetting a password, or provisioning a database—relying on each panel's web UI is inefficient. Both cPanel and Plesk expose RESTful APIs, while bare-metal nodes can be controlled via SSH commands. A lightweight API gateway (for example, FastAPI) running on the management node can wrap these calls into a uniform endpoint.
Deploy this script with uvicorn main:app --host 0.0.0.0 --port 8000. Your internal tools can now POST to http://gateway.example.com:8000/create_account/ without worrying about which panel is behind the VPS.
Conclusion
Managing a mixed fleet of cPanel, Plesk, and bare-metal nodes does not have to be a collection of disconnected chores. By establishing a dedicated management node, funneling all SSH traffic through a bastion, standardizing monitoring with Prometheus, automating updates via Ansible, centralizing backups with Rclone, and exposing a single API gateway, you gain visibility and control across the entire environment. The approach works on both Debian/Ubuntu and AlmaLinux/RHEL families, so it applies to any VPS you provision from AtoZNode.
Implement these steps gradually—start with the bastion, add monitoring, then layer automation and backups. Over time the operational overhead drops dramatically, letting you focus on delivering reliable hosting services rather than juggling disparate control panels.
vps managementbastion hostansible automationprometheus monitoringgrafana dashboardsrclone backupsfastapi gatewaymixed control panels
Try it on your own server
Follow along on a Cloud VPS with full root access, or read the step-by-step knowledge base guides.