# cPanel Tab

Use the **cPanel** member tab to manage a WHM server in a ServersCTL hosting pool. It brings server health, WHM accounts, account transfers, recovery actions, and cPanel service controls into one workspace for the selected server.

The cPanel tab is for WHM/cPanel servers. OpenLiteSpeed-only servers use the OpenLiteSpeed tab instead.

## Free and Pro

<div id="bkmrk-feature-community-pr-3"><div><table><thead><tr><th>Feature</th><th>Community</th><th>Pro</th></tr></thead><tbody><tr><td>View cPanel overview and service state</td><td>Included</td><td>Included</td></tr><tr><td>View Operations health, metrics, logs, and WHM API status</td><td>Included</td><td>Included</td></tr><tr><td>View all WHM accounts and account details</td><td>Included</td><td>Included</td></tr><tr><td>Manual Agent Transfer between cPanel servers</td><td>Included</td><td>Included</td></tr><tr><td>Create, suspend, unsuspend, modify, or terminate accounts</td><td>Upgrade required</td><td>Included</td></tr><tr><td>One-time cPanel login links</td><td>Upgrade required</td><td>Included</td></tr><tr><td>cPanel account backups and AutoSSL actions</td><td>Upgrade required</td><td>Included</td></tr><tr><td>cPanel service restarts, config checks, hardening, and config backup</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Automatic DNS update during Agent Transfer</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Migrate &amp; Recovery live WHM transfers</td><td>Upgrade required</td><td>Included</td></tr><tr><td>Pool Protection and scheduled replication</td><td>Upgrade required</td><td>Included</td></tr></tbody></table>

</div></div>Community is enough for visibility and manual account copy workflows. Pro is for production hosting operations: account management, automated DNS cutover, recovery, live transfers, backups, and service control.

## Requirements

For the full cPanel workspace:

- The server must be enrolled as a pool member.
- The balctl agent must be checking in.
- cPanel/WHM must be detected.
- WHM must be linked for account and migration tools.
- A second compatible cPanel member is needed for transfer workflows.
- Saved DNS keys are needed for automatic DNS updates.

If the tab is visible but actions are unavailable, check the member **Status** tab, WHM link state, and plan level.

## Subtabs

<div id="bkmrk-subtab-what-you-use--1"><div><table><thead><tr><th>Subtab</th><th>What you use it for</th></tr></thead><tbody><tr><td>**Overview**</td><td>See cPanel protection state, service badges, quick actions, WHM links, and account recovery topology.</td></tr><tr><td>**Operations**</td><td>Check cPanel service health, disk, network, WHM API status, metrics, logs, and server-level actions.</td></tr><tr><td>**Accounts**</td><td>List WHM accounts, inspect account details, create accounts, suspend, unsuspend, back up, log in, run AutoSSL, and terminate accounts.</td></tr><tr><td>**Agent Transfer**</td><td>Copy one account directly to another compatible cPanel server using the installed agents.</td></tr><tr><td>**Migrate &amp; Recovery**</td><td>Start and monitor WHM live transfer sessions between cPanel members.</td></tr></tbody></table>

</div></div>Some subtabs only appear after the server is detected as cPanel and WHM is linked for the pool.

### Overview subtab

Use **Overview** as the first stop for a cPanel member.

The Overview subtab shows:

- The cPanel protection and recovery topology.
- Whether accounts are protected or have standby coverage.
- Service stack badges.
- Quick links to WHM and Webmail when available.
- Quick actions such as account creation or backup where available.
- WHM audit information when the server is linked.

Use this subtab to understand whether the selected server is acting as the live source, standby, or an unprotected cPanel host.

### Operations subtab

Use **Operations** for server-level cPanel health and maintenance.

The Operations subtab shows:

- cPanel health and license state.
- Web, mail, cPanel, database, and related service state.
- Listener and network information.
- Disk usage and server metrics.
- WHM API status and DNS drift information.
- cPanel and mail log tails.

Common Pro actions:

<div id="bkmrk-action-use-it-when-r-1"><div><table style="width: 72.8571%;"><thead><tr><th style="width: 24.3446%;">Action</th><th style="width: 75.6554%;">Use it when</th></tr></thead><tbody><tr><td style="width: 24.3446%;">**Restart web**</td><td style="width: 75.6554%;">Apache/httpd is down or web traffic needs a controlled restart.</td></tr><tr><td style="width: 24.3446%;">**Restart mail**</td><td style="width: 75.6554%;">Exim or Dovecot needs a controlled restart.</td></tr><tr><td style="width: 24.3446%;">**Restart cPanel**</td><td style="width: 75.6554%;">WHM/cPanel services are unhealthy.</td></tr><tr><td style="width: 24.3446%;">**Config check**</td><td style="width: 75.6554%;">You want to check cPanel configuration health before changes.</td></tr><tr><td style="width: 24.3446%;">**Backup config**</td><td style="width: 75.6554%;">You want a cPanel metadata/config recovery point.</td></tr><tr><td style="width: 24.3446%;">**Harden ports**</td><td style="width: 75.6554%;">You want supported cPanel firewall/service hardening.</td></tr><tr><td style="width: 24.3446%;">**Refresh snapshot**</td><td style="width: 75.6554%;">You want the latest WHM service snapshot and DNS drift state.</td></tr></tbody></table>

</div></div>Check **Cron &amp; Jobs** after starting any action.

### Accounts subtab

Use **Accounts** to work with WHM accounts on the selected server.

The Accounts subtab shows:

- All WHM accounts returned for the member.
- Domain, username, IP, plan, email, disk usage, and status where available.
- Filters for all, active, and suspended accounts.
- Account details in a drawer or modal.
- Protection and DNS hints when configured.

Community users can view the full list and inspect details. Pro users can also run account actions.

Pro account actions:

<div id="bkmrk-action-what-it-does-"><div><table><thead><tr><th>Action</th><th>What it does</th></tr></thead><tbody><tr><td>**Create account**</td><td>Creates a WHM account with username, domain, password, plan, and contact email.</td></tr><tr><td>**Suspend / Unsuspend**</td><td>Changes whether an account can be used.</td></tr><tr><td>**Login**</td><td>Opens a one-time cPanel login session.</td></tr><tr><td>**Backup**</td><td>Creates a cPanel account backup.</td></tr><tr><td>**Change package**</td><td>Moves the account to another WHM package.</td></tr><tr><td>**Reset password**</td><td>Generates and shows a new password once.</td></tr><tr><td>**Run AutoSSL check**</td><td>Starts an AutoSSL check for accounts.</td></tr><tr><td>**Terminate**</td><td>Permanently removes the account after confirmation.</td></tr></tbody></table>

</div></div>Termination is destructive. The confirmation asks you to type the domain so accidental deletion is harder.

### Agent Transfer subtab

**Agent Transfer** is the member **cPanel** inner tab for one-shot **cPanel → cPanel** account copies between enrolled pool members. Agents package the source account, move the archive over a direct route or through user storage, restore on the destination with `restorepkg`, and optionally swing the DNS after the copy succeeds.

#### Direct Transfer security model

Direct Transfer is not an open file receiver and it is not general-purpose SSH access. The API acts as the control plane for a single copy operation:

1. **The authenticated operator starts a transfer.** The dashboard calls the Worker with the selected source member, destination member, cPanel username, route mode, and DNS handling choice. The Worker checks plan access, pool ownership, WHM/cPanel compatibility, account state, agent versions, destination disk, and route availability before creating the run.
2. **API creates a one-use session.** The Worker mints a random session ID, records the exact source node, destination node, account username/domain, expected byte count, destination address, source IP filter, status, and expiry. Session APIs reject unknown, expired, terminal, wrong-role, or wrong-status sessions.
3. **Only enrolled agents can advance it.** Source and destination agents call back using their normal enrolled heartbeat credentials. The Worker verifies that the calling node is the recorded source or destination for that session before accepting prepare, public-key registration, progress, transfer-complete, or restore-complete updates.
4. **The source generates an ephemeral SSH key.** The source agent creates a session-scoped keypair for this transfer. The private key stays on the source server. The public key is sent to the Worker, which queues an authorised job for the destination agent.
5. **Destination installs a restricted receiver key.** The destination agent writes the public key to root `authorized_keys` with a forced command for chunk receive only, plus `from=<source-ip>`, `no-port-forwarding`, `no-X11-forwarding`, `no-agent-forwarding`, `no-pty`, and `no-user-rc`. A matching `session.json` must exist before any chunk is accepted.
6. **Chunks are individually checked.** The source agent streams fixed-size chunks over SSH. The forced receiver accepts only `sessionId`, chunk index, and chunk SHA-256, reads the chunk from stdin, verifies the chunk hash, and writes it under that session's temporary receive directory.
7. **Archive integrity is checked before restore.** After transfer, the destination agent assembles the archive and verifies the final SHA-256 recorded on the session/run before calling `restorepkg`.
8. **Session cleanup is automatic.** On success, failure, expiry, or revoke, the destination removes the matching `authorized_keys` line and deletes the temporary session directory. The Worker will also queue `cpanel_account_sync_revoke` if the run fails before normal cleanup.

The session lifetime is time-limited. It has a 30-minute minimum and scales with package size using a conservative transfer-rate estimate, so a large package has enough time to complete without leaving a permanent receiver open.

This is the direct account transfer workspace. It is separate from scheduled Protection and separate from the WHM live transfer wizard.

To transfer an account:

1. Open **Agent Transfer** on the source cPanel member.
2. Choose or drag an active account.
3. Choose a compatible destination cPanel member.
4. Review the route preflight.
5. Choose DNS handling.
6. Start the transfer.
7. Watch the transfer spotlight until it completes.

DNS handling:

<div id="bkmrk-option-availability--1"><div><table><thead><tr><th>Option</th><th>Availability</th><th>What happens</th></tr></thead><tbody><tr><td>**Manual DNS update**</td><td>Community and Pro</td><td>The account is copied. You update DNS yourself when ready.</td></tr><tr><td>**Update A record automatically**</td><td>Pro</td><td>ServersCTL uses a saved Cloudflare or cPanel DNS key after restore succeeds.</td></tr></tbody></table>

</div></div>The direct route is preferred. If direct transfer cannot work and user storage is available, the transfer can use storage as the fallback route. If storage is required but unavailable, add storage or use another transfer method.

After a successful direct transfer, the temporary transfer access is cleaned up. The account archive may remain on the destination server for the user to remove when they are finished with it.

### Migrate &amp; Recovery subtab

Use **Migrate &amp; Recovery** for live WHM transfer sessions between cPanel members.

This is a Pro workflow for native WHM transfers. It shows outgoing and incoming sessions for the selected server, including route, direction, status, DNS cutover state, and last update time.

To start a live WHM transfer:

1. Open **Migrate &amp; Recovery**.
2. Choose **Start transfer**.
3. Pick the account.
4. Pick the target cPanel server.
5. Review preflight checks.
6. Decide whether DNS cutover should run.
7. Confirm and monitor the session.

Use the refresh button to update transfer sessions. If a completed transfer had DNS cutover enabled but DNS failed, use the retry option after fixing the DNS key or zone issue.

#### Agent Transfer vs Migrate &amp; Recovery vs Protection

<div id="bkmrk-tool-best-for-agent-"><div><table style="width: 97.1429%;"><thead><tr><th style="width: 27.841%;">Tool</th><th style="width: 72.159%;">Best for</th></tr></thead><tbody><tr><td style="width: 27.841%;">**Agent Transfer**</td><td style="width: 72.159%;">One-off account copy using ServersCTL agents. Community can use manual DNS; Pro can automate DNS.</td></tr><tr><td style="width: 27.841%;">**Migrate &amp; Recovery**</td><td style="width: 72.159%;">Pro live WHM transfer sessions between cPanel members.</td></tr><tr><td style="width: 27.841%;">**Pool Protection**</td><td style="width: 72.159%;">Pro scheduled standby replication and failover readiness across protected accounts.</td></tr></tbody></table>

</div></div>Use Agent Transfer when you want a direct copy now. Use Protection when you want ongoing standby coverage. Use Migrate &amp; Recovery when you specifically want the WHM transfer workflow.

#### WHM Binding

Full WHM API when member matches pool `host`. Run <span class="font-semibold" data-streamdown="strong">WHM link check</span> recipe after DNS connect.