Skip to content

Use website bulk tools and server utilities

Use Tools & Utilities for website changes and server administration. These cPFence v4+ instructions require the relevant action permission and access to the selected servers/sites.

ApiMachine runs from the Enhance main control panel server and needs an Enhance Super Admin API key. Follow Generate and save an Enhance API key. Configure it privately with API key on the ApiMachine Bulk Tools tab, or cpfence --set-enhance-api-key from root on the main control panel server.

  1. Open ApiMachine Bulk Tools, choose Cluster scope, or use Select servers for a subset.
  2. Filter with Search, Server, Owner, and Application, then Apply filters.
  3. Check the intended rows. Select all visible selects the current page; Select all … filtered websites includes other pages. Filtering alone does not select websites. Use Clear selection to start over.
  4. Select Choose action, choose the category/action, and fill any parameters. Select Review action when a form appears.
  5. Review Selected websites and parameters in Confirm ApiMachine action, then Confirm and run. Read each target’s output and check its resulting panel/application state.

Back up affected websites before disruptive changes. A stale scope or changed selection requires a fresh deliberate selection. Cancel closes confirmation without dispatch.

ApiMachine Bulk Tools with website filters and selection controls.

Select the intended websites before choosing an action. Identities are blurred. Select the image to enlarge it; use browser Back to return.

Use root on the Enhance main control panel server, with a valid cPFence license and a configured Enhance API key.

  1. Generate the current selection:

    Terminal window
    cpfence --generate-cluster-sites-list
  2. Edit /var/log/cpfenceav/cluster-sites-list.txt to remove rows you want excluded. Preserve the remaining CSV fields and keep a copy of your edited selection.

  3. Run the task’s CLI command, read the listed targets, and answer yes only for the intended action.

Group Actions and what to check
Provisioning Install WordPress apps on selected websites with empty application inventories. Review version, path and private administrator details.
SSL & HTTPS Enable Force SSL, Disable Force SSL, Generate website SSL, Generate mail SSL: verify hostname/DNS eligibility and the resulting redirect/certificate. A submitted certificate request is not proof of issuance.
DNS & Email Enable DNSSEC, Disable DNSSEC, Enable DKIM, Disable DKIM: coordinate with authoritative DNS and check the resulting settings.
Cloudflare Manage Cloudflare tokens: add/remove organization tokens or link/unlink selected domains. Organization changes can affect other domains; keep tokens private.
Caching Enable Redis caching, Disable Redis caching, Enable PHP Opcache, Disable PHP Opcache: check application compatibility and normal requests afterward.
PHP Update PHP version, Restart PHP container, Manage PHP extensions: see the steps below. Version changes and restarts can interrupt requests.
Nginx Enable FastCGI cache, Disable FastCGI cache, Purge FastCGI cache, Add cache exclusion, Remove cache exclusion: use applicable Nginx sites and the intended URL path, such as /cart. Purge discards cached responses.
Backups Bulk create website backups, Bulk report website backups, Bulk delete website backups: creation/deletion continue in the background. Deletion requires Delete My Backups and permanently removes selected website backups; keep independent recovery copies first.

Caching action menu showing Redis and PHP Opcache enable and disable choices.

Choose the intended Redis or PHP Opcache action for the selected websites. Select the image to enlarge it; use your browser's Back command to return.

Enhance backups are separate from cPFence settings archives and WordPress snapshot backups.

Use this action for existing Enhance websites with no installed applications. Refresh and select the intended empty websites; this does not create new websites or upgrade an existing WordPress installation.

  1. Follow the website selection steps, then choose Provisioning → Install WordPress apps.

  2. Fill the form, or use the blank-field defaults below:

    Field What to choose
    WordPress Version A listed version, or Auto-select latest version.
    Install Path An intended path such as /blog; blank uses /.
    WP Admin Username Your intended username; blank generates one.
    WP Admin Password Your private password; blank generates one. Use letters, numbers and the special characters shown in the form; spaces and commas are not allowed.
    WP Admin Email Your administrator address; blank uses admin@domain for each target domain.

Install WordPress apps form showing version, path, administrator fields and target sections.

Choose the version and installation path, enter administrator details privately or use the blank defaults, and check the target websites and servers. Select the image to enlarge it; use your browser's Back command to return.
  1. Select Review action. Check Target websites, Target servers, the version and path. If asked to confirm all filtered websites, type Install WordPress Everywhere only when that scope is intended.
  2. Select Confirm and run, then read the created, skipped and failed counts. Verify the resulting application in Enhance and the website itself.
  3. Retrieve successful installations’ administrator details privately from /var/log/cpfenceav/cluster-wordpress-apps-credentials.log on the main control panel server. Secure your own copy promptly; never paste this file into shared output or screenshots.

If an application was added after you selected a website, refresh and make a new selection. After interrupted output or a partial result, check which applications were created and select only the intended empty websites for a retry.

  1. Select a small intended site set and check the table’s PHP column. A dash means metadata was unavailable.
  2. Choose PHP → Update PHP version, set Select PHP version, then Review action and confirm the targets. Check the new version and application behavior afterward.
  3. For extensions, choose Manage PHP extensions, select the intended boxes, and choose Enable selected extensions or Disable selected extensions under Operation. Review and confirm.

Manage PHP extensions form showing extension checkboxes, Operation and target sections.

Check each intended extension and choose whether to enable or disable it before reviewing the selected targets. Select the image to enlarge it; use your browser's Back command to return.

The extensions offered are Brotli, Xmlrpc, Oauth, PdoDblib, and Apcu. Review every selected box. Use Restart PHP container only when a runtime restart is intended. If a change fails, check which sites changed before restoring a previous version/extension setting.

  • Finished: the foreground command succeeded; read per-target output and verify the change.
  • Needs attention: inspect failures and changed targets before retrying.
  • Dispatched: backup work continues. Follow the success/error logs named in the output and check Enhance backup status or Bulk report website backups. Request completion is not completed backup creation/deletion.
  • Queued: a cPFence update is waiting/running; use Refresh Update Status.

After a lost output stream, check actual state before repeating provisioning, deletion, or restore. Background backup jobs do not automatically retry failed targets.

Open System Utilities, inspect Server scope or Select servers, open the utility, and confirm its exact server targets. Website filters do not limit these operations.

Tools and Utilities with System Utilities selected and the server-scope selector above its action groups.

Server utilities use their own server scope. Select the image to enlarge it; use your browser's Back command to return.
Utility Steps and effects
Backup & restore cPFence settings Use Backup Settings or Restore Settings; follow settings backup and restore.
Fix ownership and permissions Start with Preview Changes. Review the full scope before Apply Fix; this acts across the server, beyond selected website rows.

Open Sync server IPs, then select Sync IPs for per-website licensing. This requires the appropriate license/account setup; it does not repair server connections.

Sync server IPs submenu showing its per-website-license scope and Sync IPs button.

Use Sync IPs for the per-website license task. Select the image to enlarge it; use your browser's Back command to return.

Export domains and list website identifiers

Section titled “Export domains and list website identifiers”

Open Export cluster domains (CSV), select Export CSV, and inspect the reported output/location. Keep customer inventory private.

Export cluster domains submenu showing Export all cluster domains in CSV format and Export CSV.

Export the cluster domain inventory and read the reported output location afterward. Select the image to enlarge it; use your browser's Back command to return.

For website identifiers, open List website UUIDs, then select Run to list them.

List Website UUIDs submenu with its Run button.

Use the identifier list when you need website UUIDs. Select the image to enlarge it; use your browser's Back command to return.

Open Update cPFence and follow licensing and updates for software/signatures, automatic installation and queued-job status.

Update cPFence submenu with software and signature update and status choices.

Choose the intended update action and inspect its selected server scope. Select the image to enlarge it; use your browser's Back command to return.

Open Check installed cPFence version, then select Run to inspect each target’s version. Follow the version steps to interpret the results.

Check Installed cPFence Version submenu with Run and server scope.

Check the selected servers before running the version tool. Select the image to enlarge it; use your browser's Back command to return.

Open Manage support access. Add Support Key grants temporary SSH support access for six hours; Remove Support Key ends it earlier. This is separate from WebUI Support Users.

Support access submenu with Add Support Key, Remove Support Key and the six-hour expiry notice.

Use the intended server scope when granting temporary support access or ending it early. Select the image to enlarge it; use your browser's Back command to return.

Open Manage user homelinks. Create Homelinks adds username-based links under /var/www; Remove Homelinks removes cPFence-owned links while preserving unrelated links.

Manage User Homelinks submenu showing Create Homelinks and Remove Homelinks.

Choose whether to create the username-based links or remove cPFence-owned links. Select the image to enlarge it; use your browser's Back command to return.

Open Bulk update server packages. Run Update upgrades OS packages and Enhance components. Schedule maintenance and recovery; any reboot is a separate administrator decision.

Bulk Update Server Packages submenu with Run Update and selected server scope.

Review the selected servers and schedule maintenance before running package updates. Select the image to enlarge it; use your browser's Back command to return.

MultiRun opens synchronized SSH terminal panes, including a local pane. Commands you type can affect every connected pane. Use root, a valid license, an interactive terminal, and tested passwordless SSH access to each target. Follow SSH access first.

  1. Review /etc/cpfcli/remote/multirun.txt if it already exists. On the main control panel server, MultiRun can fetch the Enhance cluster addresses; elsewhere, provide the server entries manually.

  2. Start the mode that retains setup prompts:

    Terminal window
    cpfence --multirun manual
  3. Read the confirmation. When an existing list is offered, use s to preserve your deliberate list or choose to refresh it. Verify the connected panes before typing an administrative command.

  4. Wait for every server to finish before entering the next command. Type exit to close the synchronized shells, or press Ctrl+B, then D to detach and leave the session running.

Bare cpfence --multirun skips the setup confirmations and reuses an existing list. Detaching does not cancel work already running. Check actual server state after an interrupted or uncertain command before retrying.

Check API-key permissions, site eligibility, server availability, and the exact error. For a partial result, verify successful targets before selecting a retry set. Wait for busy operations; do not widen scope or replay an uncertain action to work around an error.

For workload-specific protection choices, see Secondary server settings. For host access, follow server hostname, SSH access, and WebUI browser access.