Virtualmin is one of those tools that’s been around so long people forget it exists. It’s the open-source web hosting control panel that sits on top of Webmin, and it lets you run a multi-tenant LAMP stack on a single Linux server with a UI for managing virtual hosts, databases, mailboxes, and one-click app installs. Think cPanel but free.
For a solo operator hosting 5–20 small client sites on one Droplet, it’s still the fastest path I know. Docker Compose works too; it just takes longer to set up and is less friendly to whoever takes over the server next.
Install on Ubuntu LTS
Provision a Droplet (or AWS / Hetzner box). 2 GB RAM is the comfortable minimum because Virtualmin runs MySQL, Postfix, Dovecot, Apache, and a few other things by default. SSH in as root:
apt update && apt upgrade -y
wget https://software.virtualmin.com/gpl/scripts/install.sh
chmod +x install.sh
./install.sh
The installer takes 10–15 minutes and asks you a few questions (hostname, whether to use a bundled MariaDB or external MySQL, etc.). Defaults are fine.
When it finishes, open https://your-server-ip:10000 in a browser and log in as root. The first-run wizard tunes memory settings. Let it.
Point a domain at it via Cloudflare
- In Cloudflare, add an A record for the apex (and a CNAME for
www) pointing at the server’s public IP. Orange-cloud it for CDN + DDoS protection. - Set Cloudflare SSL mode to Full (strict).
- In Virtualmin, create a new Virtual Server for the domain. Virtualmin sets up the Apache vhost, the database, and the file system.
- Issue a Let’s Encrypt cert from inside Virtualmin: Server Configuration → SSL Certificate → Let’s Encrypt → Request. You may need to temporarily grey-cloud the domain on Cloudflare for the HTTP-01 challenge; alternatively, use Cloudflare’s Origin Certificate and skip Let’s Encrypt on the origin entirely.
Install apps with one click
Inside each virtual server, Install Scripts gives you a maintained catalog: WordPress, Drupal, Joomla, NextCloud, Discourse, phpMyAdmin, and a few dozen others. Pick one, fill in the database name, click Install. Virtualmin handles the download, unzip, DB creation, and config file writes.
This is the killer feature. Spinning up a new WordPress site for a new client is “create virtual server, install WP script, done”. 5 minutes total.
When Virtualmin is the right call
- You’re hosting 5–20 small PHP-based sites on one server and want a UI for managing them.
- You want a hand-off-friendly server. The next person can log into Virtualmin and figure out what’s deployed without reading Docker compose files.
- You’re running mail (or used to) and want Postfix + Dovecot set up correctly without doing it manually.
When to use something else
- Single-app deployments. If you have one site on one server, Virtualmin is overkill. Plain nginx + the app is simpler.
- Node / Python / Go apps. Virtualmin’s sweet spot is PHP + MySQL. It can run other stacks, but it’s fighting you the whole way.
- You want strict isolation between sites. Virtualmin shares MySQL/Apache between virtual hosts. If a client’s vulnerable WP install gets compromised, the blast radius is the whole server. Docker per-container is more contained.
- You don’t want to update a control panel. Virtualmin is more software you have to keep patched.
If you want help setting one up
I run Virtualmin across a couple of Tiempo client deployments. If you want one set up or want to migrate a few WordPress sites onto one, drop me a line.