cloudlinux logo

CloudLinux Components

Everything included with your CloudLinux license: stability controls, security isolation, performance tools, and fleet-wide monitoring.

Stability

CloudLinux prevents one account or site from affecting others on your server. Resource isolation eliminates the noisy neighbor problem and reduces support load.

Resource Limits||LVE isolates each hosting account's resources with hard limits, preventing any single account from affecting server performance for others.

What it controls:

  • CPU speed and core allocation
  • Physical and virtual memory
  • I/O throughput and operations per second
  • Number of processes and concurrent connections
  • Inodes (file and folder limits)

Key capabilities:

  • Per-account hard limits enforced at the kernel level
  • Real-time visibility into which accounts are hitting limits
  • Package-level limit templates for easy bulk management

Outcome: One resource-hungry account can’t take down your server. Only that account slows down, not everyone else. Limit templates reduce the time spent on per-account configuration.

MySQL Governor||Monitors and controls MySQL resource usage per hosting account, preventing database-heavy accounts from degrading performance for others.

What it controls:

  • CPU and I/O consumed by MySQL queries per account
  • Query throttling thresholds and restriction modes
  • Duration and behavior of restrictions

Key capabilities:

  • Automatic throttling when an account exceeds database limits
  • Four configurable modes, from monitor-only to full LVE enforcement
  • Historical data to identify chronically abusive accounts

Outcome: Heavy database queries from one account no longer slow MySQL for everyone. Persistent abusers are easy to identify and move to higher-tier plans.

Reseller Limits||Caps cumulative resources available to each reseller and their end customers.

What it controls:

  • Total CPU, memory, and I/O allocated to each reseller
  • Resource distribution across a reseller’s end user accounts
  • Per-package limits within reseller plans

Key capabilities:

  • Reseller-level caps enforced independently from account-level LVE limits
  • Resellers can manage their own end users within their allocated pool
  • Admin retains full visibility across all reseller accounts

Outcome: One reseller’s traffic spike can’t consume resources belonging to another. Resellers take ownership of their customers without the admin losing control of the server.

Security

CloudLinux hardens the server against common attack vectors. It also isolates accounts and sites from each other, so if one gets compromised, attackers are contained.

CageFS||A virtualized, per-account file system that isolates each hosting account from others on the same server.

What it controls:

  • Visibility of system files and other accounts’ files
  • Access to binaries and scripts at the per-account level
  • The environment each account’s processes run in

Key capabilities:

  • Each account sees only its own file system view
  • Prevents information disclosure even if an account is compromised
  • Required for PHP Selector to function

Outcome: A compromised account can’t be used to probe or attack other accounts on the same server. Lateral movement between accounts is blocked at the file system level.

Website Isolation (Beta)||Extends account-level isolation to individual websites within the same hosting account. Each site operates in its own isolated environment, includes per-site resource limits and PHP Selector.

What it controls:

  • File system visibility per individual website
  • Resource limits at the site level, not just the account level
  • PHP version selection per site within the same account

Key capabilities:

  • Site-level CageFS isolation within a single hosting account
  • Independent resource limits per website
  • Per-site PHP version selection

Outcome: One compromised or misbehaving site within an account can’t affect the account’s other sites. Providers can offer site-level isolation as a premium differentiator.

SecureLinks||Kernel-level protection against symlink attacks, where an attacker tricks the web server into reading another user's files.

What it controls:

  • Symlink resolution behavior at the kernel level
  • Access to files outside an account’s own directory via symbolic links

Key capabilities:

  • Blocks symlink attacks before they reach the application layer
  • Operates at the kernel level with no application configuration required
  • Protects against both targeted and automated symlink exploits

Outcome: Attackers can’t use symlinks to read configuration files, credentials, or other accounts’ data — even if they have partial access to the server.

HardenedPHP||Backports security patches to older PHP versions that no longer receive official support.

What it controls:

  • Security patch coverage for end-of-life PHP versions (5.x, 7.x, 8.x)

Key capabilities:

  • Patches applied to PHP versions no longer maintained upstream
  • Regular updates as new vulnerabilities are discovered
  • No forced PHP version upgrades required

Outcome: Sites running legacy PHP versions stay protected against known vulnerabilities without requiring migration to a newer PHP version. Reduces risk for providers hosting older applications.

Performance

CloudLinux helps servers handle more requests and deliver faster sites through efficient PHP processing, diagnostic tools, and optimization for WordPress.

Apache mod_lsapi PRO||A high-performance PHP handler that processes requests faster and with less memory than traditional methods.

What it controls:

  • How Apache hands off PHP requests for processing
  • PHP process lifecycle and memory management

Key capabilities:

  • Drop-in replacement for mod_php, suPHP, FCGID, and RUID2
  • CRIU support for faster PHP process warm-up
  • Lower memory footprint per PHP process

Outcome: Servers handle more concurrent PHP requests without adding hardware. Sites load faster and PHP processes consume less memory per request.

PHP X-Ray with Autotracing||Performance diagnostics tool that identifies exactly why PHP sites are slow.

What it controls:

  • PHP request tracing and profiling per website

Key capabilities:

  • Traces slow PHP requests to specific functions, database queries, or plugins
  • Autotracing triggers automatically when slow requests are detected
  • Feeds SmartAdvice in AccelerateWP with site-specific optimization recommendations

Outcome: Support teams stop guessing why a site is slow. Root causes are identified at the function and query level, cutting time-to-resolution for performance complaints.

Selectors (PHP, Python, Ruby, Node.js)||Lets each hosting account choose their own version of PHP, Python, Ruby, or Node.js.

What it controls:

  • Runtime version per hosting account for PHP, Python, Ruby, and Node.js
  • Available versions offered to end users

Key capabilities:

  • Per-account version selection without server-wide changes
  • Over 120 PHP extensions available per PHP version
  • Admin controls which versions are available to users

Outcome: Accounts run the language version their application requires, without version conflicts between accounts. Providers can support legacy and modern applications on the same server.

AccelerateWP||Optimization for WordPress suite that improves site performance through caching, asset optimization, and intelligent recommendations.

What it controls:

  • WordPress-level caching, asset delivery, and performance optimization per site

Key capabilities:

  • Full-page caching, browser caching, and object caching (Redis)
  • SmartAdvice analyzes each site and recommends only relevant optimizations
  • Premium features (Critical CSS, Image Optimization, CDN) available as paid upsell per user

Outcome: WordPress sites load faster with minimal manual configuration. Providers can offer performance as a differentiator and generate additional revenue through automated upsell of premium features.

MAx Cache||Apache module that serves cached WordPress pages directly without invoking PHP. Works alongside AccelerateWP to deliver additional performance gains.

What it controls:

  • How cached WordPress pages are served at the web server level

Key capabilities:

  • Serves cached pages from Apache or Nginx, bypassing PHP entirely
  • Works in combination with AccelerateWP caching
  • Reduces server load for high-traffic WordPress sites

Outcome: Cached pages are delivered faster and with significantly less server overhead. High-traffic WordPress sites stay responsive without requiring additional infrastructure.

Monitoring

CloudLinux provides visibility into server health and site performance across your entire fleet, so you can spot problems before customers complain.

Centralized Monitoring||Single interface to monitor server health and performance across all your servers.

What it controls:

  • Server-level metrics across the entire fleet

Key capabilities:

  • Real-time visibility into CPU, memory, I/O, and LVE fault data across all servers
  • Alert notifications when servers approach or exceed thresholds
  • Historical data for trend analysis and capacity planning

Outcome: Issues are spotted across the fleet from one place, without logging into each server individually. Capacity problems are identified before they affect customers.

Website Monitoring Tool||Tracks uptime and performance for individual websites hosted on your servers.

What it controls:

  • Availability and response time monitoring per hosted website

Key capabilities:

  • Automated uptime checks with configurable intervals
  • Alert notifications for downtime and slow response times
  • Daily reports identifying the slowest and most error-prone sites

Outcome: Providers know which sites are down or degraded before customers report it. Daily reports make it easy to prioritize and act on performance issues across the server.

Compatibility

CloudLinux works with your existing infrastructure.

AlmaLinux

Ubuntu

cpanel

cPanel

plesk

Plesk

directadmin

DirectAdmin

interworx

InterWorx

cyberpanel

CyberPanel

webuzo

Webuzo

Custom panels

No-panel environments

apache

Apache

litespeed

Litespeed

nginx

NGINX