Kubernetes can replace cPanel, but not as a drop-in. cPanel runs a complete hosting stack (Apache, Exim and Dovecot for mail, a DNS server, MySQL or MariaDB, AutoSSL and backups) on one server under one licence. Kubernetes schedules containers across many servers and ships none of those services, so a move from cPanel to Kubernetes means giving every cPanel job its own replacement, and email usually leaves the stack altogether. It pays off for agencies and hosts with dozens of sites and someone who can run a cluster. With fewer sites, a VPS or VDS with a lighter panel is the smarter next step.
The decision in five lines:
- cPanel licences are per server and, since September 2019, priced by the number of accounts on it, so giving each client its own account gets more expensive as you grow.
- There is no supported way to run cPanel inside Kubernetes. cPanel's own container feature, ea-podman, is Podman on a single server.
- The Kubernetes version of cPanel is a set of parts: a Gateway API controller, cert-manager, containers per site, a managed database, object storage and DNS with an API.
- Keep mail out of the cluster. Move it to hosted mail or a separate mail server with imapsync.
- Under roughly 30 sites, with nobody on call who knows kubectl, a VPS running HestiaCP, CloudPanel or Enhance beats Kubernetes on everything except fashion.
Can cPanel run on Kubernetes or in Docker?
Not in any way cPanel supports. cPanel & WHM installs onto a fresh operating system and expects to own it, running the web server, mail, DNS and disk quotas itself. Version 134, the 2026 long-term release, blocks new installs and upgrades on Rocky Linux, and from version 136 new installs on Ubuntu 22.04 are blocked too. A short list of approved operating systems is the opposite of an image you can schedule on any node.
What cPanel does offer is ea-podman, an EasyApache 4 package that lets a cPanel user run Podman containers on the same server, from cPanel's own packages or registries such as Docker Hub. It's handy for a Redis next to a PHP site. It is not orchestration: when that server fails, nothing starts anywhere else.
Some blogs describe a cPanel screen for creating Kubernetes clusters; cPanel's documentation has no such feature. The closest open-source attempt, KubeCP, turns one k3s node into cPanel-style hosting, and its own README says it is not production-ready or security-audited. As of October 2026 there is no mature "cPanel for Kubernetes", so this is a rebuild, not an upgrade.
Don't plan to convert a cPanel box in place, either: build clean nodes, move the workloads, wipe the old server. Since Kubernetes 1.35 (December 2025) the kubelet refuses to start on a cgroup v1 host by default, and CentOS 7 and EL8 use cgroup v1 out of the box, so an old cPanel server needs a reinstall (AlmaLinux 9, Debian 12 or 13, Ubuntu 22.04 or later) before it can be a node.
Why are hosts and agencies leaving cPanel?
Three reasons come up again and again: the licence, the one-server design, and the way changes get made.
The licence counts your clients
Until 2019 a cPanel licence covered one server with unlimited accounts. On 27 June 2019 cPanel announced account-based pricing, effective 1 September 2019, and hosts with hundreds of accounts per server saw their bills multiply. After the backlash it added an in-between tier and one-time credits, and admitted, as HostingJournalist reported, that its "analysis of use cases was incomplete". The current tiers on cpanel.net are Solo (1 account), Admin (up to 5), Pro (up to 30) and Premier (up to 100, plus a fee for each account above that), and each licence belongs to one server. Prices have risen nearly every year since, most recently on 1 January 2026, as WebHosting.Today reported. Plesk is no escape hatch: it has the same owner, WebPros, and raised its prices for 2026 as well.
The account model has a nasty side effect. The clean way to host 40 clients is 40 cPanel accounts, each its own Linux user, so one hacked WordPress can't read the others' files. Per-account pricing makes that isolation the expensive option, so plenty of agencies put clients in as addon domains under one account instead. If that describes your server, the licence has already changed your security model.
One server, one island
cPanel is built around one machine. A DNS cluster can share zones and a linked node can take over mail, but a second web server still means a second licence and a second island. WHM's Transfer Tool moves accounts between islands, yet no site runs on two servers at once, and when a box dies, every site on it waits for a restore. For per-account CPU and memory limits, most cPanel hosts add CloudLinux, another licence on top.
Changes live in clicks
On a typical cPanel server, deploys are FTP uploads or File Manager edits, and the real configuration is a history of clicks nobody wrote down. In Kubernetes every site is a manifest in Git, a rolling update replaces pods only once the new ones pass their health checks, and a bad release rolls back with one command. PHP adds pressure: 8.1 reached end of life on 31 December 2025 and 8.2 gets security fixes only until 31 December 2026, according to php.net. cPanel 134 sells extended support for old PHP through TuxCare; in containers, each site simply pins its own supported image.
What replaces cPanel in a Kubernetes stack?
Map every job cPanel does today to its replacement. Any job without a row is one you will discover in the middle of an outage.
| cPanel job | Kubernetes replacement | What to watch in 2026 |
|---|---|---|
| Apache or LiteSpeed virtual hosts | A Deployment per site (PHP-FPM with Nginx, or the app's own image) behind a Service | Pin a supported PHP image: 8.3, 8.4 or 8.5 |
| Ports 80 and 443 | A Gateway API controller, one HTTPRoute per site | ingress-nginx is retired; don't start new on it |
| AutoSSL | cert-manager with Let's Encrypt | cert-manager 1.21 supports Kubernetes up to 1.36 |
| Accounts and Linux users | A namespace per client, RBAC, NetworkPolicies, Pod Security Standards | Secrets are not encrypted by default |
| CloudLinux limits | Requests, limits and a ResourceQuota per namespace | Set them on day one, not after the first noisy neighbour |
| MySQL and MariaDB | A managed database, a database server outside the cluster, or an operator | Bitnami's free versioned images stopped getting updates in August 2025 |
| Home directories | PersistentVolumes (Longhorn, Ceph RBD through Rook) plus S3 object storage for uploads | MinIO's community repository is archived |
| Exim and Dovecot | Outside the cluster: hosted mail or a mail server | See the email section below |
| DNS zone editor | A DNS provider with an API, records created by ExternalDNS | Move zones first, before any site |
| WHM backups | Manifests in Git, database dumps and volume backups copied off-site | Test a restore into an empty namespace |
The front door: Gateway API, now that ingress-nginx is retired
For years the default answer was the community ingress-nginx controller. Kubernetes SIG Network and the Security Response Committee retired it: maintenance ended in March 2026, with no more releases or security patches, though existing installs keep running. A January 2026 statement from the Kubernetes Steering and Security Response Committees put its share at about half of cloud native environments, so plenty of tutorials still assume it. Build on the Gateway API instead: a Gateway owns the listeners and each site gets an HTTPRoute. Version 1.5 (February 2026) made ListenerSet stable, so tenants can attach their own listeners and one Gateway can carry more than 64, which a host with hundreds of customer domains needs. Ingress2Gateway 1.0 (March 2026) converts existing Ingress objects and over 30 common ingress-nginx annotations.
Certificates: cert-manager instead of AutoSSL
cert-manager issues Let's Encrypt certificates for annotated Gateways and answers HTTP-01 challenges with a temporary HTTPRoute; Gateway support has been beta since version 1.15. Check versions first. The cert-manager release page lists 1.21 (July 2026) for Kubernetes 1.33 to 1.36. Kubernetes 1.37, released on 26 August 2026, isn't listed yet, so a hosting cluster built this month is better off on 1.36, which gets patches until June 2027. Automation stops being optional soon anyway: Let's Encrypt's default lifetime drops from 90 to 64 days on 10 February 2027 and to 45 days on 16 February 2028.
Isolation, and a correction
A namespace per client, RBAC, Pod Security Standards and NetworkPolicies give each client a fence a shared cPanel server never had, provided the network plugin enforces the policies (k3s includes a policy controller). One correction: an earlier version of this article said Kubernetes Secrets encrypt credentials. By default they don't. The Kubernetes documentation on Secrets says they are stored unencrypted in etcd, and anyone allowed to create a pod in a namespace can read every Secret in it. Enable encryption at rest, keep RBAC tight, and consider an external secret store through the Secrets Store CSI Driver.
Databases and storage
Running MySQL inside Kubernetes is possible, and for a small team often a mistake. A managed database or a database server outside the cluster takes the hardest stateful part off the table; our guide to running PostgreSQL, MySQL and Redis on a VPS covers that route. If databases do go inside, use an operator, such as CloudNativePG for PostgreSQL (in the CNCF Sandbox since January 2025). Be wary of "WordPress on Kubernetes" tutorials built on Bitnami charts: since 28 August 2025 Bitnami's free versioned images sit in a legacy repository that gets no updates. For uploads, S3-compatible object storage keeps pods stateless; with MinIO's community repository archived in April 2026, look at Ceph RGW through Rook, Garage or SeaweedFS.
Is Kubernetes overkill for web hosting?
Often, yes. The CNCF's 2025 annual survey, published in January 2026, found that 82% of container users run Kubernetes in production, and their top problems were cultural change with development teams (47%), lack of training (36%), security (36%) and complexity (34%). Those teams already chose containers. A web agency with 25 WordPress sites gets the same problems without the developers who absorb them.
Ask one question: who gets the call at 3 a.m. when etcd loses quorum? If the answer is nobody, or the person who also does the design work, stop here. Kubernetes trades clicking in WHM for reading YAML, logs and release notes, forever: three minor releases a year, each patched for about 14 months, plus cert-manager, the Gateway controller, networking and storage on schedules of their own.
| Your situation | Better fit | Why |
|---|---|---|
| Under 30 sites, mostly WordPress, no cluster skills in-house | A VPS or VDS with HestiaCP or CloudPanel | Same panel workflow, no per-account licence |
| 30 to a few hundred sites, staff used to a panel, isolation wanted | Enhance on one or more servers | Licensed per website, a container per site, cPanel import built in |
| A handful of custom apps, small team | Docker Compose on a VPS | One file per app and most of the container benefits |
| Developers deploying from Git, one location | k3s on one server, then three | The real Kubernetes API, with an HA control plane at three servers |
| Hundreds of sites or SaaS tenants, CI/CD, an ops person or team | Multi-node Kubernetes or OKD with Gateway API and cert-manager | Scheduling, self-healing and per-tenant policy repay the effort |
| Email hosting is part of what you sell | Separate mail servers, whatever runs the web | Mail fits a cluster badly |
If your staff want a web console, OKD, the community distribution behind Red Hat OpenShift, has one, plus built-in builds and an image registry. Its nodes have run CentOS Stream CoreOS instead of Fedora CoreOS since the 4.16 and 4.17 releases of December 2024, and the current OKD 5.0, released in September 2026, runs Kubernetes 1.36. It is heavier than k3s, as our article on OKD and Kubernetes scalability on any infrastructure explains.
What are the lighter steps between cPanel and a cluster?
Leaving cPanel doesn't mean leaving panels. Three are worth a test install:
- HestiaCP is free (GPLv3, version 1.10.5) for Debian 11 to 13 and Ubuntu 22.04, 24.04 and 26.04 LTS, with Nginx or Apache, PHP-FPM from 5.6 to 8.5, mail with antispam and webmail, DNS with clustering, MariaDB, MySQL or PostgreSQL, and Let's Encrypt. It is the closest to cPanel's all-in-one feel.
- CloudPanel is free and leaner, for Debian 12 and 13 and Ubuntu 22.04, 24.04 and 26.04 on x86 or ARM64, according to its requirements page. It hosts PHP, Node.js, Python, static sites and reverse proxies, and its documentation says it does not provide email, so plan mail elsewhere. Our guide to running WordPress on a VPS with CloudPanel installs it.
- Enhance is commercial and licensed per website, with no per-server fee. Each site runs in its own container with its own system user, on one server or many, and it imports cPanel accounts.
Our pick for an agency under 30 sites: HestiaCP on a VDS if you host clients' mail, CloudPanel with hosted mail if you don't. Teams that already write Dockerfiles can skip panels; our guide to Docker Compose and a single k3s node on a VPS covers both and is a gentle way into the Kubernetes API.
How do you migrate sites from cPanel to Kubernetes?
Move DNS first, sites in small batches next, and mail on its own schedule. In that order, every cutover is a DNS record change you can undo in minutes.
-
Take an inventory of every account, domain, PHP version, database, cron job and mailbox. WHM's MultiPHP Manager shows each domain's PHP version. From the shell, list the accounts and package one of them, files and databases together:
# as root on the cPanel server whmapi1 --output=jsonpretty listaccts /usr/local/cpanel/scripts/pkgacct USERNAMEThe first command prints each account's user, domain, disk use and suspension status. pkgacct writes
cpmove-USERNAME.tar.gzto the home partition with the most free space, holding the account's files, database dumps and DNS zones. Without root, note that a full backup from cPanel's Backup Wizard can only be restored through WHM; the partial backups (home directory, databases, forwarders and filters) are plain files you can use anywhere. -
Move DNS to a provider with an API. If the cPanel server is also your nameserver, every site move is tied to it. Recreate the zones at a provider such as Cloudflare or Route 53, lower the TTLs to 300 seconds and switch nameservers while nothing else changes. Later, ExternalDNS can create records straight from your HTTPRoutes.
-
Build one typical site end to end, not the easiest one, and test it under a temporary hostname. Sites that rely on
.htaccessrewrites lose them on an Nginx-based image, so give those the official PHP image's Apache variant. Search config files, cache plugins and.user.inifor hard-coded/home/paths. And authenticate image pulls: Docker Hub allows 100 anonymous pulls per 6 hours per IPv4 address, which a few nodes pulling per-site images use up quickly.USER/ public_html -
Rehearse the copy: restore the dump, sync the files and time it. That number is the length of your final freeze.
-
Cut over. Put the site in maintenance mode, do a final file sync and database dump, then change the A and AAAA records. HTTP-01 validation can't succeed until DNS points at the cluster, so either accept a minute of certificate warnings or issue the certificate beforehand with DNS-01 through your DNS provider's API.
-
Leave the old server untouched for a week or two, then move the next batch of five or ten sites.
What happens to email and DNS when you leave cPanel?
Email: take it out of the plan
Mail is where most cPanel to Kubernetes plans go wrong. A mail server needs the real client IP for spam and DNS checks, a fixed public IP whose PTR record matches the mail hostname, and outbound port 25. docker-mailserver, the project most people try first, states in its Kubernetes guide that it does not officially support Kubernetes. Keeping client IPs means either PROXY protocol through the ingress, with changes to Postfix, Dovecot and Fail2Ban, or a fixed IP (with externalTrafficPolicy: ) or the host's network, and those last two tie mail to the single node the pod runs on. That is a lot of machinery to rebuild what one virtual machine already does.
So pick hosted mail, such as Google Workspace or Microsoft 365, or a mail server of its own; our guide to a self-hosted mail server with mailcow covers the second route. imapsync copies mailboxes from one IMAP server to another, keeps read, unread and deleted flags, and on a second run copies only what is new. Run it a few days early, switch the MX record, then run it once more. It moves messages only, so recreate forwarders and filters by hand. Plan for new DKIM keys too: the new system signs with its own, so the DKIM TXT record changes along with the MX.
DNS: the records people forget
Once web and mail live apart, the SPF record that listed the cPanel server's IP is wrong twice: it must cover the new mail system and drop the old server. Check autodiscover and autoconfig records, and any CAA record: one that leaves out Let's Encrypt stops cert-manager cold. Keep TTLs low until the last mailbox has moved.
Where RS Computers fits
RS Computers rents KVM virtual servers: VPS plans on a 1 Gb/s port and VDS plans on a 10 Gb/s port, all on NVMe storage, each with its own IPv4 and IPv6 address and free weekly backups, in Amsterdam (Netherlands), Dublin (Ireland) and Prishtina (Kosovo). The vCPUs are shared. The VPS and VDS plans page has the same plans and prices in all three cities. They suit the pieces around a migration, or the simpler route when a cluster is more than your sites need:
- A proof-of-concept cluster: three VDS Small servers (4 vCPU, 8 GB RAM, 240 GB NVMe each) in one city running k3s with embedded etcd, which per the k3s documentation needs at least three server nodes, in an odd number, to keep quorum. Break it and rebuild it before a client site goes near it.
- A staging or lab node: one VDS Medium (8 vCPU, 16 GB RAM, 480 GB NVMe) with a single-node k3s or Compose copy of your sites. One node is not high availability; the weekly backup is your safety net.
- The mail server you take out of cPanel, on VPS Mini or VDS Small. Outbound port 25 is closed on new servers and opened when you ask us on Telegram. You set the IPv4 PTR in the client area; if that doesn't work, ask on Telegram.
- The simpler answer: HestiaCP or CloudPanel on a VDS, when the table above pointed you there.
Tell us how many sites you host and how mail works today: message us on Telegram or email info@rscomputers-ks.com, and we will suggest a plan and quote the setup.
Frequently asked questions
Does cPanel support containers?
Only on one server. cPanel's ea-podman package for EasyApache 4 lets a cPanel user run Podman containers, with ports assigned by cPanel. It has no Kubernetes integration and cannot spread a site across servers.
What is the difference between cPanel and Kubernetes?
cPanel is a commercial control panel that runs a full hosting stack (web, mail, DNS, databases, SSL and backups) on one server, licensed per server by number of accounts. Kubernetes is a free, open-source container orchestrator that runs workloads across many servers and provides none of those hosting services itself.
How are cPanel accounts counted for licensing?
Each cPanel account on a server counts toward that server's tier: Solo covers 1, Admin up to 5, Pro up to 30 and Premier up to 100, with a fee for every account above 100. cPanel defines an account as one cPanel user, which can hold several domains, so addon domains and subdomains inside it are not extra accounts, while WHM reseller accounts do count.
Can you host WordPress on Kubernetes?
Yes, with a pinned PHP image per site, a managed or operator-run database, and a ReadWriteMany volume or object storage for uploads once a site has more than one replica. For a handful of sites, a VPS with a panel is quicker to run.
Can you run an email server on Kubernetes?
You can, but few should. Mail needs the real client IP, a fixed IP with a matching PTR record and outbound port 25, and docker-mailserver says it does not officially support Kubernetes. Hosted mail or a separate mail server is simpler and more reliable.
What replaces ingress-nginx now that it is retired?
The Gateway API, with any maintained controller that implements it; k3s ships Traefik v3. Ingress2Gateway 1.0 converts Ingress objects and common ingress-nginx annotations. Existing ingress-nginx installs keep working but have had no security patches since March 2026.
Is there a control panel for Kubernetes web hosting?
Not a mature open-source one as of October 2026. KubeCP's README says it is not production-ready, and the OKD console manages workloads, not hosting accounts. Teams that want per-site containers behind a panel can look at Enhance, a commercial panel that installs on ordinary Ubuntu servers and gives each site its own isolated container, with no Kubernetes to run.
A first month that doesn't break anything
Week one: run the inventory, move DNS to a provider with an API and lower the TTLs. Week two: build a three-node test cluster, or one HestiaCP server if the table sent you there, and move one typical site under a temporary hostname. Week three: move mail, publish the new DKIM and SPF records, then migrate the first five low-risk sites. Week four: the rest in batches, with the cPanel server untouched until the last account has been quiet for a week. Then cancel the licence.