DirectAdmin migration: move accounts from DirectAdmin to Jabali Panel

Last updated

The DirectAdmin ingest path. Status: production-supported.

Source archive

DirectAdmin’s standard backup tarball (backup-Jan-01-2026-12_00.tar.gz). Produce on the source host via:

da backup-all
# or per-user:
da backup-user <username>

The resulting tarballs land under /home/admin/admin_backups/.

What gets migrated

AssetBehavior
User accountRecreated under the destination panel.
Home directoryCopied to /home/<user>/.
Domains and subdomainsCreated as Domain rows. DirectAdmin’s subdomain directories are translated to subdomain Domain rows, not aliases.
DNS zonesTranslated from DirectAdmin’s BIND-style files to PowerDNS rows.
MySQL databasesRestored with password hashes preserved where the source used a hash format MariaDB accepts.
Email accountsCreated in Stalwart; passwords reset (DirectAdmin uses Exim+Dovecot password hash formats Stalwart cannot import).
Forwarders, autoresponders, catch-allTranslated to Stalwart equivalents.
Cron jobsTranslated to systemd-user timers if the command is on the Cron allowlist.
FTP accountsMapped to SFTP via Match Group; passwords do not transfer.

Source-side prep

For best results:

  1. On the source host, ensure the user is not actively writing during the backup window (file consistency).
  2. Capture the bind zones (/var/named/<domain>.db): DirectAdmin’s BIND format is what the panel parses.
  3. Note the per-domain SSL certificates being used; SSL is not migrated and will be reissued on the destination.

Operator workflow

Identical to the cPanel pipeline: upload, analyze, restore, communicate generated passwords, repoint DNS, issue SSL.

Commands cheat sheet

On the source DirectAdmin host:

# Per-user backup
da backup-user <username>

# Whole-server backup (one tarball per user)
da backup-all

# Output location
ls /home/admin/admin_backups/
#   -> backup-<username>-<YYYY-MM-DD>-<HHMMSS>.tar.gz

# Ship to Jabali host, resumably
rsync --partial --progress \
    /home/admin/admin_backups/*.tar.gz \
    root@<jabali-host>:/var/lib/jabali/migrations/incoming/

On the Jabali Panel host:

# List migrations
jabali migration list

# Analyze without restoring
jabali migration analyze <archive>

# Restore
jabali migration restore <archive>

# Batch-restore every archive in incoming/
jabali migration restore-all --parallel 4

Cutover playbook

Same shape as cPanel cutover:

  1. T-48h — lower DNS TTLs to 300s at the registrar.
  2. T-1h — freeze writes on the source; da backup-user <user>.
  3. T-45min — rsync --partial the archive.
  4. T-30min — Analyze + Restore in the panel.
  5. T-15min — smoke-test with curl --resolve against the new IP.
  6. T-0 — repoint A/AAAA/MX at the registrar.
  7. T+1h — issue SSL via per-domain toggle.
  8. T+24h — restore TTLs to 86400.

Limitations

  • Modsecurity rules: DirectAdmin’s per-user Modsec rules are not migrated (Modsec is removed; see Removed Features). Equivalent protection is provided by AppSec at the server level.
  • CSF allowlists: not migrated; carry over manually into CrowdSec Allowlists.
  • DirectAdmin Reseller: Jabali has no reseller construct; reseller-owned accounts migrate as individual users.

Per-user migration vs full-server

For one-off per-user moves, use the per-user backup. For server-cutover migrations, produce a backup per user with da backup-user, batch-upload to the destination, and run the pipeline against each.

Troubleshooting

Analyze fails with unrecognized DirectAdmin backup format. Backup was produced by DirectAdmin ≤ 1.61 (pre-2020). Rebuild the source archive on a supported DirectAdmin version, or extract manually and repackage the standard backup/ directory tree.

DNS zones restored, but records look empty. DirectAdmin BIND-format zones are parsed with the dns/plain reader; zones already migrated to DirectAdmin’s newer dns/named.conf format need the named-checkzone-compatible layout. Convert with named-checkzone -D <domain> <file> before archive.

Mailboxes missing after restore. DirectAdmin stores mail under /home/<user>/imap/<domain>/<local>/Maildir/. If your source deploys mail on a separate drive (/mnt/mail/...), symlink it into imap/ before running da backup-user, or the tarball skips the mail content.

Audit

Per-phase audit rows are emitted; per-domain creation produces one domain.create row per domain.

Frequently asked questions

Can I migrate from DirectAdmin to Jabali Panel?
Yes. Jabali Panel's Migrations section accepts standard DirectAdmin per-user backup tarballs produced by `da backup-user ` or `da backup-all`. The restore is per-account and tracks live progress in the UI. No cPanel-style manifest is required — the DirectAdmin archive layout is parsed directly.
What gets migrated from DirectAdmin?
Linux user account, home directory (`public_html`, `logs`, `mail`), hosted domains and subdomains (including DirectAdmin's `subdomain/` layout, which becomes proper Domain rows rather than aliases), BIND-format DNS zones translated to PowerDNS, MySQL databases with hashes preserved where compatible, email accounts (passwords reset), forwarders and catch-all, autoresponders, cron jobs (via the [Cron allowlist](../cron.md)), and SFTP access. FTP-only accounts do not transfer because Jabali does not host plaintext FTP.
Does DirectAdmin's Modsecurity ruleset carry over?
No. DirectAdmin's per-user Modsecurity rules do not translate. Jabali replaces mod_security with [AppSec](./appsec.md) at the server level (CrowdSec's WAF component), which runs across every domain uniformly. Rewrite domain-specific mod_security rules as AppSec bouncer scenarios if the ruleset was carrying real load.
How do I migrate a full DirectAdmin server (all accounts) at once?
Run `da backup-all` on the DirectAdmin host — that writes one backup tarball per user into `/home/admin/admin_backups/`. Copy them to the Jabali Panel host under `/var/lib/jabali/migrations/incoming/` and restore them individually or with `jabali migration restore-all --parallel 4`. There is no server-wide manifest step; each per-user backup is independent.
Are DirectAdmin CSF firewall rules migrated?
No. Jabali does not use CSF; it uses [UFW](./ufw-baseline.md) for the baseline firewall and [CrowdSec](./crowdsec-decisions.md) for dynamic bans and allowlists. Re-implement CSF allowlists as CrowdSec allowlist entries; the CrowdSec Console community blocklists usually replace the CSF-lfd deny lists.
Does DirectAdmin Reseller structure transfer?
No. Jabali Panel has no reseller construct. Reseller-owned accounts migrate as individual panel users with no parent-child relationship. If your billing system depended on the reseller hierarchy, re-model it in your billing tool (FOSSBilling, WHMCS, Blesta) instead of the panel.