CloudLinux 10 is the current release for shared hosting servers that need per-user isolation and resource limits, and cPanel has supported it since version 134 alongside AlmaLinux 10. For an administrator moving from CloudLinux 9 the concepts are unchanged: CageFS gives each user a virtualised filesystem, LVE enforces CPU, memory, I/O and process limits, and PHP Selector lets users pick a version inside the cage. What has changed is the kernel, the supported software matrix and a few defaults. This guide walks through a fresh setup and the differences that matter.
Applies to CloudLinux 10 with cPanel 134+; MySQL 8.4 or MariaDB 10.11 to 11.8
Table of Contents
Short answer: CloudLinux 10 needs cPanel 134 or later with MySQL 8.4 or MariaDB 10.11 to 11.8. After installation run cagefsctl --init, cagefsctl --enable-all and cagefsctl --update to cage every user, then set limits with lvectl set default --speed=100% --pmem=1G --nproc=100 --ep=20 and override per package in WHM » LVE Manager. The limit semantics match CloudLinux 9; the differences are the RHEL 10 kernel, cgroup v2 throughout and a narrower database matrix.
Supported combinations
cPanel on CloudLinux 10 requires cPanel 134 or later; 138 is the current release line. Database support is narrower than on CloudLinux 8 and 9: MySQL 8.4 only on the MySQL side, and MariaDB 10.11, 11.4 or 11.8, with 10.11 the default. There is no MySQL 8.0 and no MariaDB below 10.11 on this platform, so a server migrating from CloudLinux 8 with MariaDB 10.6 must upgrade the database before or during the move. cPanel’s ELevate process handles 8 to 9 to 10 in stages and is covered in our ELevate guide; for CloudLinux the same tool is used with the CloudLinux conversion step.
The kernel is the RHEL 10 series with CloudLinux’s LVE patches. The 2026 local privilege escalations, Copy Fail, Dirty Frag and Fragnesia, were live-patched through KernelCare on CloudLinux; confirm the patch state rather than assuming:
kcarectl --info
kcarectl --update
Enable CageFS
On a fresh install, CageFS is present but users are not caged until you initialise it:
cagefsctl --init
cagefsctl --enable-all
cagefsctl --update
--init builds the skeleton the cages are based on; --update refreshes it after any package installation that users need, such as a new PHP extension or a CLI tool. Add new users to the cage automatically by keeping cagefsctl --enable-all as the default; cPanel’s account creation hook does this on CloudLinux. Confirm a user is caged:
cagefsctl --list-enabled | head
cagefsctl --user-status USER
Inside a cage, /etc/passwd shows only the user’s own entry and other accounts’ home directories do not exist. That is the property that stops a compromised site harvesting a neighbour’s wp-config.php, which is why we treat CageFS as mandatory on any server with more than one customer.
On CloudLinux 10 the cage skeleton is generated from the newer package set, so custom files added to /etc/cagefs/conf.d/ on a CloudLinux 9 server need reviewing; paths for some libraries moved with the RHEL 10 base. Run cagefsctl --check-cagefs after migrating custom configurations.
Set LVE limits
Limits are stored in /etc/container/ve.cfg and managed with lvectl. Set a sensible server default first, then override per package or per user:
lvectl set default --speed=100% --pmem=1G --nproc=100 --io=1024 --iops=1024 --ep=20
lvectl set USER_ID --speed=200% --pmem=2G --nproc=150
lvectl list
--speed is CPU as a percentage of one core, so 200 percent is two cores. --pmem is physical memory, which is the limit that matters since CloudLinux 7; virtual memory limits are legacy. --ep is entry processes, meaning concurrent PHP requests, and is the limit most often hit by busy WordPress sites. Apply limits per cPanel package from WHM » LVE Manager » Packages so that a plan upgrade changes limits automatically.
CloudLinux 10 keeps the same limit semantics as 9. One behavioural change worth knowing: the I/O accounting uses the newer cgroup v2 controllers throughout, so tools that read /proc/lve/list directly still work but third-party scripts parsing cgroup v1 paths under /sys/fs/cgroup/blkio will find nothing there. Use lveinfo for reporting:
lveinfo --period=1d --by-fault=any --limit=20
That prints the users who hit any limit in the last day, which is the daily report to watch.
PHP Selector and MySQL Governor
PHP Selector on CloudLinux 10 offers PHP 8.1 through 8.5 as alt-php packages, with 8.1 marked for retirement in line with cPanel’s EA4 schedule. Users switch versions in cPanel’s Select PHP Version; the server default is set with:
cloudlinux-selector set --json --interpreter=php --version=8.3 --default
MySQL Governor works with MariaDB 10.11, 11.4 and 11.8 on this platform and applies LVE-style limits to database load per user. Install it after the database is at its final version, not before, since the governor replaces the server packages with CloudLinux builds:
/usr/share/lve/dbgovernor/mysqlgovernor.py --install
dbctl list
Verify
Confirm the platform and kernel, then test isolation from a user’s shell:
cat /etc/cloudlinux-release
uname -r
su - USER -s /bin/bash -c 'ls /home; cat /etc/passwd | wc -l'
The ls /home should show only that user’s directory and /etc/passwd should have a handful of lines. Check that limits bite by running a CPU burner as the user and watching lvetop; the user’s CPU should cap at the configured speed. The common pitfall on a migrated server is CageFS reporting enabled while users are not actually caged because the mount points were lost during the OS conversion; cagefsctl --user-status USER says enabled, but mount | grep cagefs shows nothing for that user. Run cagefsctl --remount-all and re-check.
CloudLinux 10 cPanel at a glance

Official documentation: CloudLinux documentation, cPanel & WHM documentation, AlmaLinux wiki.
Related guides: Update, force-update or roll back Imunify360 (staged rollouts explained) · Hardening a shared cPanel server with CageFS, ModSecurity (OWASP CRS) and Imunify/ClamAV · MariaDB won’t start after an upgrade: InnoDB recovery, mariadb-upgrade and sql_mode issues.
Frequently asked questions
Does CloudLinux 10 support MariaDB 10.6 or MySQL 8.0 on cPanel?
No. The supported databases on CloudLinux 10 are MySQL 8.4 and MariaDB 10.11, 11.4 and 11.8, so a server on an older version must upgrade the database before or during the migration.
How long does enabling CageFS take on an existing server?
cagefsctl --init builds the skeleton in a few minutes and --enable-all cages users without a reboot; users pick up the change on their next process start, so no downtime is needed.
Can I undo CageFS or an LVE limit for a single user?
Yes. cagefsctl --disable USER removes that user from the cage, and lvectl delete USER_ID drops a per-user override so the default limits apply again; both take effect immediately.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- CloudLinux 10 with cPanel 134+; MySQL 8.4 or MariaDB 10.11 to 11.8
- Last full review
- Next review