UbuntuDebianFREE
A security panel for your Linux server FREE
Installs and enables UFW and fail2ban, then shows SSH logins, rejected connections, pending security updates, SSL expiry dates and disk space. The panel runs on your server and the data never comes to us. No sign-up needed.
- Install
- 2–5 minutes
- History
- 7 days
- Data collection
- every 5 minutes
- Checks
- 12
- Languages
- 34
- Price
- $0, business use included
dfcdcd9fba6a32e0e362f2317aa1f0b05502fdfae1db87018f6536a18f351f70
What the panel looks like
Three FREE screens in the language of this page. The data on the screenshots is test data.
What you need before installing
A clean VPS is enough. The installer sets up the web server, PHP, the firewall and fail2ban itself.
- System
- Ubuntu 22.04 or newer, Debian 12 or newer
- Access
- SSH as root or as a user with sudo
- Resources
- 1 GB RAM and 5 GB free disk space or moreWith less, the installer warns you but carries on.
- Domain
- Your own domain or subdomain with an A record pointing to the server’s IP, e.g. monitor.example.comThe panel takes the whole address, so a domain that already serves a website will not do: use a subdomain for that case. The A record is needed for the Let’s Encrypt HTTPS certificate.
- Ports
- 80 and 443 reachable from outsideIf UFW is not installed yet, the installer opens SSH, 80 and 443 and closes the database, mail and FTP ports.
- Web server
- Apache or nginxNo web server — it installs Apache. One is running — it adds a separate site to it.
- Not supported
- A server with a hosting control panel: Hestia, cPanel, Plesk, DirectAdmin, ISPmanager, aaPanel, CyberPanel, CloudPanel, FASTPANEL, ISPConfig, Virtualmin, Froxlor, Ajenti, KeyHelp, Webuzo, Sentora, VestaCP, 1Panel, RunCloud, Coolify, CapRover, Dokploy, Easypanel, Cloudron, YunoHost and othersSuch a panel manages the web server itself, and the installer refuses to continue. Servers with a hosting control panel are supported only by the full version of Arcivéo.
What happens after you run it
Six steps with progress in the terminal. Before any change the installer saves a copy of the file, and at the end it tells you how to roll everything back.
- 1/6Server checkSystem, permissions, free space, no hosting panel, the domain not taken
- 2/6Web server and PHPApache or your nginx, PHP-FPM with a pool of its own for the panel
- 3/6ProtectionEnables UFW, installs fail2ban with rules for SSH and the web server
- 4/6PanelFiles in /var/www/arciveo-free, the admin user and a password
- 5/6HTTPSA Let’s Encrypt certificate for the panel address
- 6/6Data collectionThe first run right away, then every 5 minutes
Example output at the end of the install
Monitor FREE · installation Log: /var/log/arciveo-free-install.log ──────────────────────────────────────────── [1/6] Server check (pre-flight) (16%) ✓ Ubuntu 24.04.1 LTS ✓ Panel address: https://monitor.example.com/ ✓ RAM 3915MB · disk 71GB free [2/6] Web server + PHP (33%) ✓ Apache installed ✓ PHP 8.3: php-fpm, sqlite3 [3/6] Security tools (50%) ✓ UFW (SSH 22, 80, 443 open; DB/mail/FTP denied) ✓ Fail2ban (active jails: 9; this server's IP in ignoreip) [4/6] Panel (66%) ✓ Code /var/www/arciveo-free · data /var/lib/arciveo-free · config /etc/arciveo-free ✓ PHP-FPM pool 'arciveo-free' (user arcfree, command execution disabled) ✓ Site monitor.example.com on apache → /var/www/arciveo-free/public ✓ Panel login guarded by fail2ban (5 failures in 10 min → address banned for 1 h) [5/6] HTTPS (Let's Encrypt) (83%) ✓ Certificate issued, HTTP redirects to HTTPS [6/6] Data collection (100%) ✓ Collected; next runs every 5 minutes Arcivéo Monitor FREE is installed ✓ Profile: all Installed: apache + PHP 8.3 (php-fpm, sqlite3) · certbot Tools: UFW, Fail2ban Fail2ban: 5 failed SSH logins within an hour ban the address permanently. Backup of every file this run modified: /var/lib/arciveo-install/backup/free-20261007-091204 Undo the configuration changes: sudo /var/lib/arciveo-install/backup/free-20261007-091204/restore.sh Self-check: ✓ apache: running ✓ PHP-FPM: panel pool socket present ✓ UFW: active ✓ Fail2ban: service active (jails loaded) ✓ Collector: data written ✓ Panel: login page answers on https://monitor.example.com/ All checks passed. ──────────────────────────────────────────── Panel: https://monitor.example.com/ User: admin Password: Xk29pQ7mLr4v8tNe ← example; save it, it will not be shown again Save the password now — it is not stored anywhere in plain text. Change password: sudo arciveo-free passwd Change user name: sudo arciveo-free user NAME Only your IP: sudo arciveo-free allow-ip add YOUR_IP Update FREE: sudo arciveo-free update Status: sudo arciveo-free status Remove FREE: sudo arciveo-free uninstall Log: /var/log/arciveo-free-install.log · Server IP: 203.0.113.10
After installing
Open the panel address and log in as admin. For the first five minutes the dashboard says data is being collected, then it shows a score and a list of what to fix, with a ready command for each item.
| Command on the server | What it does |
|---|---|
sudo arciveo-free status | What is installed and when data was last collected |
sudo arciveo-free collect | Collect data now instead of waiting five minutes |
sudo arciveo-free update | Update to the latest version. Settings, password and data are kept |
sudo arciveo-free passwd | Set a new panel password |
sudo arciveo-free user <name> | Change the panel user name |
sudo arciveo-free allow-ip add 203.0.113.7 | Open the panel only from the listed addresses |
sudo arciveo-free unban 203.0.113.7 | Lift a ban: five wrong passwords within ten minutes block the address for an hour |
sudo arciveo-free lang en | Change the panel’s default language |
sudo arciveo-free uninstall | Remove the panel completely. UFW and fail2ban keep working |
FREE and the full version
The full version installs 16 more security tools and brings their data into the same panel. You can remove FREE and install the full version on the same server.
| FREE | Full | |
|---|---|---|
| IN BOTH | ||
| SSH sessionslogins, addresses, sshd settings | shows | shows |
| UFW Firewalland fail2ban | sets up | sets up |
| Security updateshow many are waiting, which are security | shows | shows |
| SSL Certificatesexpiry and names | shows | shows |
| Performance and diskCPU, memory, disk | shows | shows |
| FULL VERSION ONLY | ||
| Suricatanetwork attacks recognised by the IDS | — | sets up |
| Falcosuspicious process activity | — | sets up |
| CrowdSecshared lists of attacking addresses | — | sets up |
| ModSecurityattacks on the website (WAF) | — | sets up |
| ClamAV and maldetmalicious files | — | sets up |
| AIDE and debsumschanges to system files | — | sets up |
| Lynis, auditd, psadconfiguration audit, action log, port scans | — | sets up |
| AppArmor, Monit, databases, web server, cronsix more screens | — | shows |
| WORKING WITH THE PANEL | ||
| Metrics historyresource charts | 7 days | 30 days |
| Events historyfeed and log | 7 days | 90 days |
| Daily reportan email with the day’s summary | — | yes |
| AlertsTelegram, email, webhook, browser push | — | yes |
| Userspanel accounts | one | several |
| WebAuthn key loginsecond factor: hardware key or fingerprint | — | yes |
| All servers in one windowa server overview in your account | — | yes |
| APIpanel data for your own scripts | — | yes |
| Support | FAQ | tickets |
| UNDER THE HOOD | ||
| InstallationFREE installs completely with one command. In the full version the installer prepares the server; you upload the distribution yourself (SFTP, e.g. FileZilla), fill in config.php, import the database and enter the license key | one command | step by step |
| Servers with a hosting control panelHestia, cPanel, Plesk, DirectAdmin, ISPmanager, aaPanel, CyberPanel, CloudPanel, FASTPANEL, ISPConfig, Virtualmin, Froxlor, Ajenti, KeyHelp, Webuzo, Sentora, VestaCP, 1Panel, RunCloud, Coolify, CapRover, Dokploy, Easypanel, Cloudron, YunoHost and others | — | yes |
| Security toolsinstalled and configured by the installer | 2 | 18 |
| DatabaseFREE keeps everything in one file; the full version needs a MySQL or MariaDB server | SQLite | MySQL |
| Server memoryfull version: light profile 2 GB, full profile 4 GB | 1 GB | 2–4 GB |
| Source codein the full version ionCube locks 2 of almost 400 files: the license check and the report builder | open | all but 2 files |
| Outside connectionswhat the panel itself sends from the server to the internet | nothing | what you have turned on, plus certificate checks · details |
FREE and the full version are separate distributions with their own structure. FREE cannot be updated into the full version: FREE is removed with sudo arciveo-free uninstall, the full version is installed by its own guide, and FREE history is not carried over.
Questions
01Do I need to sign up or get a key?
No. The command downloads the archive from arciveo.com, checks its checksum and runs the installer from it. No account, no token.
02What does the panel send to your servers?
Nothing. Data is collected on the server itself and the database stays in /var/lib/arciveo-free. The panel and the collector do not go online; only the system’s apt and certbot reach out.
03Can I install it on a server that already hosts websites?
Yes, with the “Websites already run on this server” box ticked. The installer adds a separate site for the panel, but it will not enable the firewall on its own or touch a fail2ban you already set up. It lists everything it skipped at the end.
04Can a company use FREE?
Yes. FREE is licensed under PolyForm Internal Use 1.0.0: you may install it on any servers of your own or your company’s, commercial ones included, and change the code for yourself. Personal servers are fine too. You may not redistribute FREE, as is or modified. The licence does not apply in Russia or Belarus. The full text is in the LICENSE file in the archive.
05How many servers can I install it on?
As many as you like. Each server gets its own panel at its own address. With the full version, your Account shows all servers on one screen.
06How do I remove it or roll back?
sudo arciveo-free uninstall removes the panel, its site, its certificate and its data. restore.sh in the backup folder returns the settings the installer changed; its path is printed at the end of the install.