DirectAdmin migration: move accounts from DirectAdmin to Jabali Panel
Last updated
The DirectAdmin ingest path. Status: production-supported.
Source archive
DirectAdmin’s standard backup tarball (backup-Jan-01-2026-12_00.tar.gz). Produce on the source host via:
da backup-all
# or per-user:
da backup-user <username>
The resulting tarballs land under /home/admin/admin_backups/.
What gets migrated
| Asset | Behavior |
|---|---|
| User account | Recreated under the destination panel. |
| Home directory | Copied to /home/<user>/. |
| Domains and subdomains | Created as Domain rows. DirectAdmin’s subdomain directories are translated to subdomain Domain rows, not aliases. |
| DNS zones | Translated from DirectAdmin’s BIND-style files to PowerDNS rows. |
| MySQL databases | Restored with password hashes preserved where the source used a hash format MariaDB accepts. |
| Email accounts | Created in Stalwart; passwords reset (DirectAdmin uses Exim+Dovecot password hash formats Stalwart cannot import). |
| Forwarders, autoresponders, catch-all | Translated to Stalwart equivalents. |
| Cron jobs | Translated to systemd-user timers if the command is on the Cron allowlist. |
| FTP accounts | Mapped to SFTP via Match Group; passwords do not transfer. |
Source-side prep
For best results:
- On the source host, ensure the user is not actively writing during the backup window (file consistency).
- Capture the bind zones (
/var/named/<domain>.db): DirectAdmin’s BIND format is what the panel parses. - Note the per-domain SSL certificates being used; SSL is not migrated and will be reissued on the destination.
Operator workflow
Identical to the cPanel pipeline: upload, analyze, restore, communicate generated passwords, repoint DNS, issue SSL.
Commands cheat sheet
On the source DirectAdmin host:
# Per-user backup
da backup-user <username>
# Whole-server backup (one tarball per user)
da backup-all
# Output location
ls /home/admin/admin_backups/
# -> backup-<username>-<YYYY-MM-DD>-<HHMMSS>.tar.gz
# Ship to Jabali host, resumably
rsync --partial --progress \
/home/admin/admin_backups/*.tar.gz \
root@<jabali-host>:/var/lib/jabali/migrations/incoming/
On the Jabali Panel host:
# List migrations
jabali migration list
# Analyze without restoring
jabali migration analyze <archive>
# Restore
jabali migration restore <archive>
# Batch-restore every archive in incoming/
jabali migration restore-all --parallel 4
Cutover playbook
Same shape as cPanel cutover:
- T-48h — lower DNS TTLs to 300s at the registrar.
- T-1h — freeze writes on the source;
da backup-user <user>. - T-45min —
rsync --partialthe archive. - T-30min — Analyze + Restore in the panel.
- T-15min — smoke-test with
curl --resolveagainst the new IP. - T-0 — repoint A/AAAA/MX at the registrar.
- T+1h — issue SSL via per-domain toggle.
- T+24h — restore TTLs to 86400.
Limitations
- Modsecurity rules: DirectAdmin’s per-user Modsec rules are not migrated (Modsec is removed; see Removed Features). Equivalent protection is provided by AppSec at the server level.
- CSF allowlists: not migrated; carry over manually into CrowdSec Allowlists.
- DirectAdmin Reseller: Jabali has no reseller construct; reseller-owned accounts migrate as individual users.
Per-user migration vs full-server
For one-off per-user moves, use the per-user backup. For server-cutover migrations, produce a backup per user with da backup-user, batch-upload to the destination, and run the pipeline against each.
Troubleshooting
Analyze fails with unrecognized DirectAdmin backup format.
Backup was produced by DirectAdmin ≤ 1.61 (pre-2020). Rebuild the source archive on a supported DirectAdmin version, or extract manually and repackage the standard backup/ directory tree.
DNS zones restored, but records look empty.
DirectAdmin BIND-format zones are parsed with the dns/plain reader; zones already migrated to DirectAdmin’s newer dns/named.conf format need the named-checkzone-compatible layout. Convert with named-checkzone -D <domain> <file> before archive.
Mailboxes missing after restore.
DirectAdmin stores mail under /home/<user>/imap/<domain>/<local>/Maildir/. If your source deploys mail on a separate drive (/mnt/mail/...), symlink it into imap/ before running da backup-user, or the tarball skips the mail content.
Audit
Per-phase audit rows are emitted; per-domain creation produces one domain.create row per domain.
Related reading
- cPanel migration — same pipeline, cPanel
cpmove-<user>.tar.gzas input. - HestiaCP migration — same pipeline,
v-backup-userarchive as input. - WHM migration — cPanel-style server-wide dump.
- cPanel migrations to Jabali Panel: end-to-end guide — same DNS + cutover playbook applies to DirectAdmin.