[1.8.0] - 2026-08-26
This release reorganises the admin panel around subject areas and adds a Logs Center, a migration wizard that moves accounts off a cPanel server from inside the panel, Node.js, Python and Ruby applications on CloudLinux servers with a Runtime Manager behind them, PostgreSQL and MySQL Governor as optional modules, off-site server configuration backups with a one-command disaster restore, MailChannels inbound filtering, a domain ownership guard with an admin approval queue and a much wider client REST API.
Admin panel
- Simplified admin panel (AB-1322): The admin menu is reorganised around subject areas: fewer top-level entries, related screens gathered behind one destination with tabs and every old link redirected to its new home in one hop. Web Server and Email gain dashboards of their own. A failed action anywhere in the panel says why it failed and what to do next under one correlation id you can quote. An action that half succeeded is reported as such instead of as a flat success. A module operation you started re-attaches after a page reload while a stuck one no longer holds the page for other admins. The database health tab reports a live query rate and says when the query cache is switched off. A new SSL Certificate Issuance History records every issuance including the ones a DNS preflight declined.
- Logs Center (AB-1322): Every log this server writes is on one page with a tab per source, covering web server access and error logs, mail delivery, spam filtering, webmail, request filtering, intrusion prevention, FTP and Linux security, the panel's own error log, the agents and the execution log.
- Faster first install (AB-1322): Installation hands you a usable panel sooner. The installer sets up one PHP version, then the remaining versions, SecureBox and SymLock install in the background afterwards, one at a time, with progress on the dashboard and every step recorded in the execution log. A panel restart in the middle loses nothing.
- Bulk actions (AB-1249): Hosting account lists gain bulk suspend, unsuspend, change plan and delete. Domain lists gain bulk delete and bulk SSL issuance. A bulk delete asks you to type a confirmation first. The result separates completed, completed with warnings, failed and skipped and carries each next step. A batch in which nothing ran says so instead of reporting success.
Migration
- Panel-managed migration (AB-1375): A new Migration > External Migrations wizard moves accounts off a cPanel server without leaving the panel. You name the source host and approve its identity, then start the run from the source or from this server. The run outlives the browser, so the page can be closed and reopened at any time. The run view carries live status, the preflight, per-account state, the event log and the cleanup state of every credential the run held. You pick the accounts before the run starts and map each source hosting plan to an existing plan or let it be created from the package. The DNS cutover is a separate approval that states AdminBolt does not touch your registrar or external DNS and names the accounts left out. Every decision is recorded with the administrator, IP and timestamp. Notifications cover started, action required, stalled, failed and completed.
bolt-cli external-migration-disable ends every active run and releases what it holds, leaving already-imported accounts working.
Applications and runtimes
- Node.js, Python and Ruby applications (AB-1357): On CloudLinux servers, clients create applications from a wizard that ships a starter page serving immediately, with the application root taken relative to the domain folder, its own log, restart from the panel and full coverage in the client REST API. Applications run on Apache and on OpenLiteSpeed. The panel decides by what is serving. LiteSpeed Enterprise gets its own notice instead of configuration that does nothing.
- Runtime Manager (AB-1357): A new admin Runtime Manager under Runtimes lists the runtime versions the repositories offer for those servers next to the ones this server has, installs one version or all of them, reports what is running, says so when the application server is missing and carries an admin REST API of its own.
- CloudLinux settings (AB-1357): CloudLinux servers gain their own settings section, with Resource Usage, PHP Selector, X-Ray, AccelerateWP and LVE Manager available to the account through the hosting plan feature. X-Ray and AccelerateWP are panel modules that report their real availability.
Databases
- PostgreSQL (AB-1412): Install PostgreSQL from the Module Manager beside MariaDB and hand it to accounts through the PostgreSQL Databases feature on the hosting plan feature list. Clients create databases and roles, manage remote access, open Adminer on a PostgreSQL database as one of the account's roles and reach all of it over the client REST API. The PHP drivers are installed for every PHP family on the server. PostgreSQL data counts towards the account's disk usage, its databases ride along in account backups and are replayed on a full restore. A renamed database or role is reconciled on the server. Existing feature lists pick up the new feature on upgrade.
- MySQL Governor (AB-1360): CloudLinux servers get a Settings > Databases > MySQL Governor page that installs the Governor with the installer output shown as it runs, reports the running state once it is up and offers removal on its own page with the output streamed live.
Backups and disaster recovery
- Server configuration backup (AB-1383): A new Backups > Server Config surface takes the whole server configuration off-site to a backup destination, on a schedule you set, with its own retention and an optional passphrase you keep yourself. Export DR keys hands you the bootstrap secrets, asks the acting admin to confirm with a second factor first and records every export in the audit log. From those secrets alone
bolt-cli disaster-restore rebuilds a fresh box from the newest off-site snapshot, bolt-cli disaster-reprovision re-materialises modules, PHP versions and hosting accounts, bolt-cli restore-all-accounts restores the account files and bolt-cli restore-all-databases imports their dumps. Every destructive restore asks you to name the machine being overwritten and records the attempt. A snapshot listing that cannot be read names the destination and the reason instead of rendering an empty table.
- Client restore into the database (AB-1383): Clients gain Restore into the database next to the dump download, with the database's current contents snapshotted first so an accidental import can be undone. The client restore cooldown, the daily manual-backup cap and the restore concurrency are admin settings under Backups > Limits.
- Infrastructure database snapshots (AB-1005): Local snapshots of the mail and DNS databases are listed on the Server Backup page with Back up now, Restore showing the snapshot age and record counts before you commit and Delete.
bolt-cli backup-infra-databases and bolt-cli restore-infra-database do the same from the shell. A snapshot is taken before every panel-driven system update, aborting the update when the backup fails while skipping with a warning on a server that cannot take one.
- Server-wide backup policy (AB-530): A backup policy with no target is the server-wide default and covers every account that nothing more specific claims, so one server no longer needs one policy per hosting plan and a newly added plan is never left without backups. Resolution order is account, then reseller, then plan, then the server-wide default. The list names the row All accounts.
Email
- MailChannels inbound filtering (AB-1411): A new Email Settings > MailChannels tab for the Inbound API key and its subscription. Clients whose plan includes the feature get a per-domain filtering toggle and one-click sign-in to MailChannels. Enabling registers the domain and swaps the MX records only once the filter confirms the delivery route. Disabling restores them first. A domain is filtered by at most one of MailChannels and SpamExperts. The apex MX of a filtered domain stays with the filter against zone edits, imports and DNS templates. An hourly sync plus a daily verify repairs drift and retry unfinished changes. Access can be limited to selected resellers and the delivery addresses of both filters are trusted by the local spam scan.
- Mailbox restrictions (AB-1372): Incoming mail, outgoing mail and mailbox login can each be set to allow or suspend on the mailbox create and edit forms. The server enforces each direction on its own. The Restrictions column names what is suspended, the webmail button explains itself when login is suspended. A sending suspension is listed beside the manual restrictions with its expiry rather than masking them. Existing servers pick up the enforcement on upgrade. The Services re-configure action reports the real result of what it ran.
- Plan mailbox quotas (AB-1419): The hosting plan's mailbox quota fields are enforced on every path: the client panel, the admin panel and both REST APIs. A create without a quota takes the plan's default, a quota above the cap is refused with the cap named. A plan that caps mailboxes does not offer unlimited. Keeping a mailbox's current value always saves, so a mailbox left above the cap by a plan downgrade can still be edited. The plan and mailbox quota fields are labelled MiB, which is the unit they store.
- Lowercase mail addresses (AB-1378): Mailbox usernames, mailing list names and catch-all targets are stored in lowercase, folded live in the form as the client types and again in the service and duplicate checks ignore case. An upgrade sweeps the mail server and the panel for mixed-case rows already on the server, renames the mail directories with them and reports both what it repaired and what it could not.
- Panel mail exemption (AB-1391): The panel sends its own notifications and bounces through its own mailbox login, which is exempt from the outbound sending limits, so a busy server cannot silence the channel a mail problem is reported through. The Sending Limits page states the exemption, lists the exempt logins and raises a banner if the panel's own mail is ever throttled. Mail merely claiming the panel hostname is limited like any other customer mail.
- SLA-covered MX set (AB-1392): The SpamExperts Cluster MX hostnames help text names N-able's SLA-covered global set in priority order and warns that the records shown in the vendor panel sit outside its uptime guarantee, with a one-click action that fills the SLA-covered set for you.
Security and access
- Domain ownership guard (AB-1025): A domain being added is checked against the whole platform's namespace rather than an exact name only, so two accounts cannot end up serving overlapping names, while an account's own subdomains are unaffected. A rejected add is recorded on the new Domain Security page, where an admin approves or dismisses it and manages the approved overlaps, with the pending count on the navigation badge. DNS cluster zones overlapping an earlier claim by another owner are flagged rather than served. An optional ownership policy asks a domain new to the platform for a DNS record before it is provisioned, shows the exact record to add and verifies automatically on retry. Overlaps that already exist and overlaps arriving with a migration are carried over on upgrade, so nothing in the field stops resolving.
- Impersonation sessions (AB-1364): An administrator stays signed in to their own panel across an impersonation. Leaving it, logging out, signing in elsewhere or letting the session expire all end the impersonation and close its entry in the activity log, with the start and its end paired to each other.
API
- Client REST API (AB-1393): The client API gains cron job management that adopts hand-added lines before every write, address and domain forwarders with loop and duplicate rejection, the per-domain PHP directives to read and set, database user grants in the read payload, opt-in database size and mailbox usage and the account's IP address and home directory on the single-account read. A scoped file manager covers the account home: list, stat, download, upload, write, move, copy, chmod, symlink, archive, extract and delete, paginated and size-capped. WP-CLI runs against a domain document root behind a per-key switch that is off by default, with the commands that escape WordPress refused and every call audited. Single-use, short-lived sign-in URLs can be issued for phpMyAdmin and webmail, so an integration can create one server-side and hand it to a browser. Clients can create their own restricted keys, with the endpoint picker, the WP-CLI switch, the IP restriction and the active toggle on the client form.
- REST API review fixes (AB-964): Hosting plan create and update validate and persist the full field set instead of the name alone,
PUT /api/hosting-account/domains/{id} works, php_version_id is accepted on domain create and update and rebuilds the PHP configuration behind it. Admin keys gain DNS record, IP blocker and per-domain SSL certificate routes. Assigning a database user with an empty or malformed privilege list is refused with the allowed set named and a pointer at the detach endpoint. Mailbox local parts and passwords are validated. A write naming a field the panel does not apply is refused with the reason rather than answered with success. The per-key endpoint restriction applies to every key type, its picker lists every endpoint of the panel and its search box resolves what you type. An API secret is shown exactly once, in a notification right after the key is created.
Bug Fixes
- FTP settings invariants (AB-1349): The directives the panel's FTP stack depends on are applied on every write and are not offered as editable fields on the FTP Settings page, so saving that page cannot leave a server whose FTP accounts fail to log in, list files or transfer. The certificate path fields are validated as plain absolute paths before anything is stored, the passive port range is validated as a pair. An upgrade repairs a server whose stored or live configuration disagrees with those invariants, naming what it changed and taking no FTP restart where nothing was wrong.
- Web stack restarts (AB-1347): Web stack services come back on their own after a failure such as an out-of-memory kill, instead of staying down until someone starts them by hand. An upgrade applies the policy to every server already in the field and starts any of those services that is enabled but not running.
- Apache configuration validation (AB-1385): A vhost write is checked against Apache before the reload and rolled back when the check fails, with the offending file and Apache's own message reported, so a bad write leaves nothing behind that would fail every later Apache operation on the server.
- SSH access state (AB-1397): The SSH toggle on an account reflects what the server actually has. A failed server-side step leaves the stored value where it was and reports the reason. An edit that does not carry the toggle leaves SSH access alone.
- Domain rename and update (AB-1214): Renaming a domain carries its document root, PHP-FPM pool, log directories, parked domains and page cache with it, retires the old vhost and rolls the whole rename back and repairs the server when a step fails. The rename target is normalized like a created domain and refused when any account already holds it. Writes to one domain are serialized while writes to different domains stay parallel, a field the panel does not apply is refused with the reason instead of being absorbed under a success. The per-domain PHP settings are written into the document root the site actually serves.
- Web log permissions (AB-1367): Accounts read their real bandwidth and access log figures again. An upgrade repairs the web log ownership and permissions, installs per-account log rotation and
bolt-cli repair-web-log-permissions runs the same sweep on demand. OpenLiteSpeed logs are read for bandwidth as well.
- JetBackup restores (AB-1389, AB-1390): A restore replays the account's captured DNS zone, so custom records come back with it. The replay is all-or-nothing and refuses before applying anything when the capture holds records it cannot represent. The JetBackup page, the health check and the log warn when the reseller owner of an account is dropped from JetBackup's own account list. Reseller plans, plan limits and account metadata are now carried correctly through backup and restore.
- Database repository mirrors (AB-1417): Provisioning writes several mirror addresses for the database repository, so an installation continues when one of them does not answer and names the cause when none of them does.
Improvements
- Certificate expiry digests (AB-1404): When more certificates cross a warning threshold in one scan than the number you set on System Notifications, the whole cohort is delivered as a single digest naming every affected domain, over email, webhooks and the admin bell, instead of one notification per certificate.
- Onboarding and billing (AB-1318): Finishing the onboarding wizard registers the server with billing once provisioning has succeeded and the credentials are already on screen, so a slow or unreachable billing system cannot cost you passwords that exist nowhere else. A server licensed by the installer opens the wizard with that address filled in, a paid license is left alone rather than signed up for a trial and Email to me is delivered through the license. A trial is confirmed by a link in the confirmation mail: the License page shows an awaiting-confirmation notice that polls for the result and offers resending it, an address the panel cannot resolve is flagged with a suggested correction. A bounced confirmation is reported instead of waiting indefinitely.
Install
curl -sSL https://get.adminbolt.com/install.sh | bash
Upgrade from 1.7.0
- Log in to the Admin Panel.
- Open System, then System Updates.
- Click Check for updates and review the release notes.
- Start the update if a newer version is available.
The technical changelog can also be previewed in the admin panel by clicking the 1.8.0 version link in the footer.