//Servers

Consolidate cPanel, Plesk & Bare‑Metal VPS into One Manageable Fleet

Panel‑agnostic workflow: central management node, SSH bastion, Prometheus monitoring, Ansible updates, Rclone backups, and a unified API gateway for mixed cPanel, Plesk, and bare‑metal VPS.

7 min read
Consolidate cPanel, Plesk & Bare‑Metal VPS into One Manageable Fleet

Managing a fleet of VPS that run different control panels—cPanel, Plesk, or custom bare-metal nodes—can become a complex task. Each panel has its own update cadence, licensing model, and command-line interface. This article outlines a single, panel-agnostic workflow that consolidates monitoring, automation, and backups, making the entire environment easier to manage.

1. Create a Central Management Node

Start by provisioning a lightweight “management node.” This host does not serve customer traffic; it runs orchestration scripts, monitoring agents, and a secure bastion for SSH access.

  • Choose a small VPS (1 vCPU, 2 GB RAM). Ubuntu 22.04 LTS or AlmaLinux 9 are both suitable.
  • Secure the node with a non-standard SSH port and key-based authentication.

Ubuntu/Debian (apt) – Initial Setup

# Update packages
sudo apt update && sudo apt upgrade -y

# Install essential tools
sudo apt install -y curl wget gnupg2 ca-certificates

# Create a user for automation
sudo adduser --disabled-password --gecos "" fleetadmin
sudo usermod -aG sudo fleetadmin

# Set up SSH key authentication
mkdir -p /home/fleetadmin/.ssh
chmod 700 /home/fleetadmin/.ssh
# (Copy your public key into authorized_keys)

AlmaLinux/Rocky/RHEL (dnf) – Initial Setup

# Update packages
sudo dnf update -y

# Install essential tools
sudo dnf install -y curl wget gnupg2 ca-certificates

# Create a user for automation
sudo adduser fleetadmin
sudo passwd -l fleetadmin   # lock password
sudo usermod -aG wheel fleetadmin

# Set up SSH key authentication
mkdir -p /home/fleetadmin/.ssh
chmod 700 /home/fleetadmin/.ssh
# (Copy your public key into authorized_keys)

After these steps, the management node is ready to run fleet scripts.

2. Deploy a Uniform SSH Bastion

All panel servers should be reachable only through the bastion. This limits exposure, simplifies firewall rules, and provides a single audit point for login activity.

  • Configure the bastion to allow ssh -J (jump host) connections.
  • Use ssh-agent forwarding so private keys never reside on the panel hosts.

SSH Config Example (client side)

Host bastion
    HostName bastion.example.com
    User fleetadmin
    Port 2222
    IdentityFile ~/.ssh/id_rsa_fleet

Host *.vps.example.com
    ProxyJump bastion
    User root
    IdentityFile ~/.ssh/id_rsa_fleet

With this configuration, ssh web01.vps.example.com automatically tunnels through the bastion.

3. Standardize Monitoring with Prometheus & Grafana

All VPS expose system metrics (CPU, RAM, disk I/O) via standard Linux interfaces. Installing a Prometheus node exporter on each host provides a single source of truth regardless of the control panel.

Installation on Debian/Ubuntu

# Download latest exporter
wget https://github.com/prometheus/node_exporter/releases/download/v1.8.0/node_exporter-1.8.0.linux-amd64.tar.gz
tar xzf node_exporter-1.8.0.linux-amd64.tar.gz
sudo mv node_exporter-1.8.0.linux-amd64/node_exporter /usr/local/bin/

# Create a systemd service
cat > /etc/systemd/system/node_exporter.service <<EOF
[Unit]
Description=Prometheus Node Exporter
After=network.target

[Service]
User=nobody
ExecStart=/usr/local/bin/node_exporter

[Install]
WantedBy=default.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable --now node_exporter

Installation on AlmaLinux/Rocky/RHEL

# Download latest exporter
wget https://github.com/prometheus/node_exporter/releases/download/v1.8.0/node_exporter-1.8.0.linux-amd64.tar.gz
tar xzf node_exporter-1.8.0.linux-amd64.tar.gz
sudo mv node_exporter-1.8.0.linux-amd64/node_exporter /usr/local/bin/

# Create a systemd service (same as above)
cat > /etc/systemd/system/node_exporter.service <<EOF
[Unit]
Description=Prometheus Node Exporter
After=network.target

[Service]
User=nobody
ExecStart=/usr/local/bin/node_exporter

[Install]
WantedBy=default.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable --now node_exporter

On the management node, install Prometheus and Grafana (via Docker or native packages). Add each VPS's exporter endpoint (http://vps-ip:9100/metrics) to the scrape_configs section of prometheus.yml. Grafana can then query Prometheus and display unified dashboards for all panels.

4. Automate Updates Across Panels

Each control panel provides its own CLI for updates:

  • /usr/local/cpanel/scripts/upcp – cPanel
  • plesk installer update – Plesk
  • Standard apt or dnf – bare-metal nodes

Use Ansible to run the appropriate command on each host. Ansible's inventory can group servers by panel type, allowing you to target them with a single playbook.

Sample Ansible Inventory

[cpanel]
cpanel01.vps.example.com
cpanel02.vps.example.com

[plesk]
plesk01.vps.example.com
plesk02.vps.example.com

[baremetal]
bare01.vps.example.com
bare02.vps.example.com

Playbook (update.yml)

- hosts: cpanel
  become: yes
  tasks:
    - name: Run cPanel update
      command: /usr/local/cpanel/scripts/upcp
      async: 7200
      poll: 0

- hosts: plesk
  become: yes
  tasks:
    - name: Run Plesk update
      command: plesk installer update
      async: 7200
      poll: 0

- hosts: baremetal
  become: yes
  tasks:
    - name: Update OS packages (Debian/Ubuntu)
      apt:
        upgrade: dist
        update_cache: yes
      when: ansible_os_family == "Debian"

    - name: Update OS packages (RHEL family)
      dnf:
        name: "*"
        state: latest
      when: ansible_os_family == "RedHat"

Run the playbook from the management node with ansible-playbook -i inventory update.yml. The async directive allows each server to update in the background, keeping the playbook responsive.

5. Centralize Backups with Rclone and Object Storage

cPanel and Plesk support remote backups to FTP, SFTP, or cloud storage. Bare-metal nodes can use rsync or tar. To keep the process uniform, use Rclone on the management node to push all backup archives to an S3-compatible bucket (AtoZNode offers Object Storage in the India region).

Step-by-step

  1. Install Rclone on the management node.
  2. Configure a remote named atoznode with your access key and secret.
  3. On each VPS, schedule a cron job that creates a tarball of the site data and uploads it via Rclone.

Rclone Installation (both OS families)

curl https://rclone.org/install.sh | sudo bash

Configure Remote (run on management node)

rclone config
# Choose "n" for new remote, name it atoznode, select "s3", then provide:
#   provider: Other
#   endpoint: https://your-object-storage-endpoint
#   access_key_id: YOUR_KEY
#   secret_access_key: YOUR_SECRET

Backup Script Example (placed on each VPS)

#!/bin/bash
DATE=$(date +%F)
BACKUP_DIR="/backup"
mkdir -p "$BACKUP_DIR"

# cPanel example – archive /home
tar -czf "$BACKUP_DIR/cpanel_$DATE.tar.gz" /home

# Plesk example – archive /var/www/vhosts
tar -czf "$BACKUP_DIR/plesk_$DATE.tar.gz" /var/www/vhosts

# Bare-metal – archive custom app directory
tar -czf "$BACKUP_DIR/app_$DATE.tar.gz" /opt/myapp

# Upload to object storage
rclone copy "$BACKUP_DIR" atoznode:myvpsbackups/$(hostname) --log-file=/var/log/rclone-backup.log

Make the script executable and add it to crontab -e (e.g., daily at 02:00). Centralizing the uploads means you only need one set of credentials and can monitor transfer logs from the management node.

6. Use a Single API Gateway for Panel Operations

When you need to perform ad-hoc actions—creating a new account, resetting a password, or provisioning a database—relying on each panel's web UI is inefficient. Both cPanel and Plesk expose RESTful APIs, while bare-metal nodes can be controlled via SSH commands. A lightweight API gateway (for example, FastAPI) running on the management node can wrap these calls into a uniform endpoint.

Minimal FastAPI Example (Python 3)

from fastapi import FastAPI, HTTPException
import subprocess
import paramiko

app = FastAPI()

def run_ssh(host, command):
    ssh = paramiko.SSHClient()
    ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
    ssh.connect(hostname=host, username='root', key_filename='/home/fleetadmin/.ssh/id_rsa_fleet')
    stdin, stdout, stderr = ssh.exec_command(command)
    exit_code = stdout.channel.recv_exit_status()
    output = stdout.read().decode() + stderr.read().decode()
    ssh.close()
    if exit_code != 0:
        raise Exception(output)
    return output

@app.post("/create_account/")
def create_account(vps: str, panel: str, user: str, domain: str):
    if panel == "cpanel":
        cmd = f"/usr/local/cpanel/scripts/createacct {user} {domain}"
    elif panel == "plesk":
        cmd = f"/usr/local/psa/bin/user --create {user} -domain {domain}"
    elif panel == "baremetal":
        cmd = f"adduser {user} && mkdir -p /var/www/{domain}"
    else:
        raise HTTPException(status_code=400, detail="Unsupported panel")
    try:
        result = run_ssh(vps, cmd)
        return {"status": "success", "output": result}
    except Exception as e:
        raise HTTPException(status_code=500, detail=str(e))

Deploy this script with uvicorn main:app --host 0.0.0.0 --port 8000. Your internal tools can now POST to http://gateway.example.com:8000/create_account/ without worrying about which panel is behind the VPS.

Conclusion

Managing a mixed fleet of cPanel, Plesk, and bare-metal nodes does not have to be a collection of disconnected chores. By establishing a dedicated management node, funneling all SSH traffic through a bastion, standardizing monitoring with Prometheus, automating updates via Ansible, centralizing backups with Rclone, and exposing a single API gateway, you gain visibility and control across the entire environment. The approach works on both Debian/Ubuntu and AlmaLinux/RHEL families, so it applies to any VPS you provision from AtoZNode.

Implement these steps gradually—start with the bastion, add monitoring, then layer automation and backups. Over time the operational overhead drops dramatically, letting you focus on delivering reliable hosting services rather than juggling disparate control panels.

vps managementbastion hostansible automationprometheus monitoringgrafana dashboardsrclone backupsfastapi gatewaymixed control panels

Try it on your own server

Follow along on a Cloud VPS with full root access, or read the step-by-step knowledge base guides.