Migrate from HestiaCP to Jabali Panel: files, DBs, DNS, mail
Last updated
The HestiaCP ingest path. Status: partial, files, databases, DNS, and a subset of mail are supported. Complex Exim ACL rules require manual re-implementation.
Source archive
HestiaCP’s per-user backup produced by:
v-backup-user <user>
The resulting archive lands under /backup/<user>.<timestamp>.tar.
What gets migrated
| Asset | Behavior |
|---|---|
| User account | Recreated. |
| Home directory | Copied. |
| Web domains | Created as Domain rows. The vhost is rendered fresh from the panel template, Apache/nginx fragments from the source are not preserved. |
| DNS zones | BIND zones translated to PowerDNS rows. |
| MySQL / PostgreSQL databases | Restored with password hashes. |
| Email accounts | Created in Stalwart with generated passwords. |
| Forwarders / autoresponders | Translated to Stalwart. |
| Cron jobs | Translated to systemd-user timers via the allowlist filter. |
What requires manual work
- Exim ACL rules: HestiaCP often carries non-trivial Exim acl_smtp_data / acl_check_recipient rules. These do not translate directly to Stalwart’s expression filter syntax; rewrite under Server Settings → Mail → Stalwart expressions.
- Per-domain Roundcube identities: Roundcube installations on the source are not migrated; the destination ships its own Roundcube.
- Spamassassin / rspamd thresholds: Stalwart spam scoring is independent; recalibrate if your Hestia setup had custom thresholds.
Operator workflow
- Produce a per-user backup on the Hestia host.
- Upload to
/jabali-admin/migrations. - Analyze → review the report for any Exim ACL warnings.
- Restore.
- For each Exim ACL warning, manually re-author the equivalent Stalwart expression filter.
- Communicate generated mail passwords to mailbox owners.
- Issue SSL via the per-domain SSL toggle.
Limitations
- Hestia Apache+nginx fronted setups: Hestia frequently runs nginx in front of Apache. Jabali serves nginx directly with PHP-FPM. Apache-specific directives in
.htaccessfiles that depend onmod_rewritetranslate; directives that depend onmod_phpormod_setenvifdo not and must be rewritten. - Hestia firewall (iptables) rules: not migrated. Use UFW plus CrowdSec for the equivalent surface.
Audit
Standard per-phase audit rows.
Related reading
- cPanel migrations to Jabali Panel: end-to-end guide — same UI + workflow; different source format. Read for the cutover playbook and DNS TTL prep steps.
Frequently asked questions
Can I migrate a HestiaCP account to Jabali Panel?
Yes. Jabali Panel's Migrations section accepts HestiaCP per-user backups produced by `v-backup-user `. Files, MariaDB and PostgreSQL databases, DNS zones (translated from BIND to PowerDNS), and a subset of mail configuration transfer. Complex Exim ACL rules require manual re-implementation as Stalwart expression filters.
What is the HestiaCP backup command?
`v-backup-user ` on the HestiaCP host produces `/backup/..tar`. It runs against a single user; for a whole-server move, run it once per user in a shell loop, then rsync the resulting archives to `/var/lib/jabali/migrations/incoming/` on the Jabali Panel host.
Which HestiaCP features do not migrate automatically?
Custom Exim ACL rules (`acl_smtp_data`, `acl_check_recipient`) do not translate directly and need to be re-authored as Stalwart expression filters. Per-domain Roundcube identities do not carry over (Jabali ships its own Roundcube). Spamassassin/rspamd threshold overrides need recalibration in Stalwart's spam scoring config. Hestia iptables rules are not migrated — use UFW + CrowdSec for the equivalent surface.
Does Hestia's Apache+nginx setup translate to Jabali?
Jabali serves nginx directly with PHP-FPM — there is no Apache. `.htaccess` files with `mod_rewrite` directives translate (nginx supports rewrite via the panel's vhost template). Directives that depend on `mod_php` or `mod_setenvif` do not translate and need to be re-implemented in the nginx `location` block or the PHP-FPM pool config.
Are PostgreSQL databases migrated from HestiaCP?
Yes. HestiaCP is one of the sources that ships PostgreSQL alongside MySQL/MariaDB. The Jabali pipeline restores Postgres databases into the panel-managed PostgreSQL instance with role and password metadata intact where the hash format is compatible.