# CloudLinux 10 cPanel: CageFS and LVE Limits, Upgrade Notes

Source: https://srvscripts.com/guides/cloudlinux-10-cpanel-cagefs-lve/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

CloudLinux 10 is the current release for shared hosting servers that need per-user isolation and resource limits, and cPanel has supported it since version 134 alongside AlmaLinux 10. For an administrator moving from CloudLinux 9 the concepts are unchanged: CageFS gives each user a virtualised filesystem, LVE enforces CPU, memory, I/O and process limits, and PHP Selector lets users pick a version inside the cage. What has changed is the kernel, the supported software matrix and a few defaults. This guide walks through a fresh setup and the differences that matter.

In short: CloudLinux 10 needs cPanel 134 or later with MySQL 8.4 or MariaDB 10.11 to 11.8.

**Short answer:** CloudLinux 10 needs cPanel 134 or later with MySQL 8.4 or MariaDB 10.11 to 11.8. After installation run `cagefsctl --init`, `cagefsctl --enable-all` and `cagefsctl --update` to cage every user, then set limits with `lvectl set default --speed=100% --pmem=1G --nproc=100 --ep=20` and override per package in WHM » LVE Manager. The limit semantics match CloudLinux 9; the differences are the RHEL 10 kernel, cgroup v2 throughout and a narrower database matrix.

## Supported combinations

cPanel on CloudLinux 10 requires cPanel 134 or later; 138 is the current release line. Database support is narrower than on CloudLinux 8 and 9: MySQL 8.4 only on the MySQL side, and MariaDB 10.11, 11.4 or 11.8, with 10.11 the default. There is no MySQL 8.0 and no MariaDB below 10.11 on this platform, so a server migrating from CloudLinux 8 with MariaDB 10.6 must upgrade the database before or during the move. cPanel’s ELevate process handles 8 to 9 to 10 in stages and is covered in [our ELevate guide](/guides/cpanel-elevate-almalinux-8-9-10/); for CloudLinux the same tool is used with the CloudLinux conversion step.

The kernel is the RHEL 10 series with CloudLinux’s LVE patches. The 2026 local privilege escalations, Copy Fail, Dirty Frag and Fragnesia, were live-patched through KernelCare on CloudLinux; confirm the patch state rather than assuming:

```
kcarectl --info
kcarectl --update
```

## Enable CageFS

On a fresh install, CageFS is present but users are not caged until you initialise it:

```
cagefsctl --init
cagefsctl --enable-all
cagefsctl --update
```

`--init` builds the skeleton the cages are based on; `--update` refreshes it after any package installation that users need, such as a new PHP extension or a CLI tool. Add new users to the cage automatically by keeping `cagefsctl --enable-all` as the default; cPanel’s account creation hook does this on CloudLinux. Confirm a user is caged:

```
cagefsctl --list-enabled | head
cagefsctl --user-status USER
```

Inside a cage, `/etc/passwd` shows only the user’s own entry and other accounts’ home directories do not exist. That is the property that stops a compromised site harvesting a neighbour’s `wp-config.php`, which is why we treat CageFS as mandatory on any server with more than one customer.

On CloudLinux 10 the cage skeleton is generated from the newer package set, so custom files added to `/etc/cagefs/conf.d/` on a CloudLinux 9 server need reviewing; paths for some libraries moved with the RHEL 10 base. Run `cagefsctl --check-cagefs` after migrating custom configurations.

## Set LVE limits

Limits are stored in `/etc/container/ve.cfg` and managed with `lvectl`. Set a sensible server default first, then override per package or per user:

```
lvectl set default --speed=100% --pmem=1G --nproc=100 --io=1024 --iops=1024 --ep=20
lvectl set USER_ID --speed=200% --pmem=2G --nproc=150
lvectl list
```

`--speed` is CPU as a percentage of one core, so 200 percent is two cores. `--pmem` is physical memory, which is the limit that matters since CloudLinux 7; virtual memory limits are legacy. `--ep` is entry processes, meaning concurrent PHP requests, and is the limit most often hit by busy WordPress sites. Apply limits per cPanel package from **WHM » LVE Manager » Packages** so that a plan upgrade changes limits automatically.

CloudLinux 10 keeps the same limit semantics as 9. One behavioural change worth knowing: the I/O accounting uses the newer cgroup v2 controllers throughout, so tools that read `/proc/lve/list` directly still work but third-party scripts parsing cgroup v1 paths under `/sys/fs/cgroup/blkio` will find nothing there. Use `lveinfo` for reporting:

```
lveinfo --period=1d --by-fault=any --limit=20
```

That prints the users who hit any limit in the last day, which is the daily report to watch.

## PHP Selector and MySQL Governor

PHP Selector on CloudLinux 10 offers PHP 8.1 through 8.5 as alt-php packages, with 8.1 marked for retirement in line with cPanel’s EA4 schedule. Users switch versions in cPanel’s Select PHP Version; the server default is set with:

```
cloudlinux-selector set --json --interpreter=php --version=8.3 --default
```

MySQL Governor works with MariaDB 10.11, 11.4 and 11.8 on this platform and applies LVE-style limits to database load per user. Install it after the database is at its final version, not before, since the governor replaces the server packages with CloudLinux builds:

```
/usr/share/lve/dbgovernor/mysqlgovernor.py --install
dbctl list
```

## Verify

Confirm the platform and kernel, then test isolation from a user’s shell:

```
cat /etc/cloudlinux-release
uname -r
su - USER -s /bin/bash -c 'ls /home; cat /etc/passwd | wc -l'
```

The `ls /home` should show only that user’s directory and `/etc/passwd` should have a handful of lines. Check that limits bite by running a CPU burner as the user and watching `lvetop`; the user’s CPU should cap at the configured speed. The common pitfall on a migrated server is CageFS reporting enabled while users are not actually caged because the mount points were lost during the OS conversion; `cagefsctl --user-status USER` says enabled, but `mount | grep cagefs` shows nothing for that user. Run `cagefsctl --remount-all` and re-check.

## CloudLinux 10 cPanel at a glance

**Official documentation:** [CloudLinux documentation](https://docs.cloudlinux.com/), [cPanel & WHM documentation](https://docs.cpanel.net/), [AlmaLinux wiki](https://wiki.almalinux.org/).

**Related guides:** [Update, force-update or roll back Imunify360 (staged rollouts explained)](https://srvscripts.com/guides/imunify360-force-update-rollback/) · [Hardening a shared cPanel server with CageFS, ModSecurity (OWASP CRS) and Imunify/ClamAV](https://srvscripts.com/guides/harden-shared-cpanel-server/) · [MariaDB won’t start after an upgrade: InnoDB recovery, mariadb-upgrade and sql_mode issues](https://srvscripts.com/guides/mariadb-not-starting-after-upgrade/).

## Frequently asked questions

### Does CloudLinux 10 support MariaDB 10.6 or MySQL 8.0 on cPanel?

No. The supported databases on CloudLinux 10 are MySQL 8.4 and MariaDB 10.11, 11.4 and 11.8, so a server on an older version must upgrade the database before or during the migration.

### How long does enabling CageFS take on an existing server?

`cagefsctl --init` builds the skeleton in a few minutes and `--enable-all` cages users without a reboot; users pick up the change on their next process start, so no downtime is needed.

### Can I undo CageFS or an LVE limit for a single user?

Yes. `cagefsctl --disable USER` removes that user from the cage, and `lvectl delete USER_ID` drops a per-user override so the default limits apply again; both take effect immediately.
