Dari server baru hingga toko yang live · Langkah 3 dari 8
First login and the setup wizard
What this page is for. Open the secret panel address for the first time, and walk through the guided setup — password, panel address, two-factor login and email alerts.
You need
- The panel URL, the username and the password the installer printed. If you lost any of them, see Install SixPanel — all three can be recovered from the server.
- A free authenticator app on your phone (Google Authenticator, Aegis, Authy, 1Password, or the one built into your password manager).
- The three ports open at your hosting provider (The three ports).
1. Open the whole address
Paste the entire URL into your browser, including the code at the end:
https://203.0.113.10:41397/8ec0896a1f2b...The last part is the secret entry code. Without it the address returns a blank "not found" page. That is not a fault — it is what hides your login page from people scanning the internet.
Bookmark the address now.
The panel is always https. There is no http version.
2. Click through the certificate warning — once
Your browser shows a warning like "Your connection is not private". This is expected. Until you give the panel its own domain and certificate, it uses a certificate it made for itself, and browsers do not trust those.
Choose your browser's "Advanced" option and then continue to the site. Your connection is still encrypted.
The warning also appears when you reach the panel by IP address after getting a certificate, because the certificate is issued for a name, not a number. That too is normal.
3. Log in
The login page asks for two things: a username and a password.
The username was made for you when SixPanel was installed. It is not simply admin — it is admin with a few random characters after it, so that a robot which finds your login page has nothing to aim at. Both the username and the password were printed by the installer.
Lost the username? On the server:
sudo sixpanel usernameYou can change it later on the Security page.
4. Walk through the setup wizard
On a new server, logging in opens the setup wizard rather than the panel. It has four steps and a finish screen — Welcome, Password, Panel address and Two-factor — and it is about the panel itself, not about your project. Your first project comes right after it, with its own guided flow. Until the wizard is finished, the login can run the wizard and nothing else.
Moving on without doing a step. Each open step has one button at the bottom that moves on without doing it: Skip this step, or, on the panel-address step, Set the panel address later. A step that is already done says so and shows Continue instead. Two steps can also be answered with a no that the panel remembers, so it stops asking: Keep the current password and Not now — continue without two-factor login. Exit setup, under the list of steps, leaves the wizard altogether. Nothing is lost either way; the same work is available on the normal pages afterwards.
Welcome
Three fields: Language, Timezone and Your email address. All three arrive pre-filled — the language from your browser, the timezone from your browser's clock — so usually you only check them and press Save and continue.
The email address matters more than it looks. Free certificates are issued against it, and server alerts are sent to it.
The timezone is the clock your backups, scheduled tasks and logs follow. Pick it now rather than later.
Expected result: the step is marked done and the wizard moves on.
Password
Type the password you logged in with under Current password, then your own under New password, and repeat it.
Press Suggest a strong password and the panel generates one and shows it once, so you can copy it into your password manager. Then press Change password.
Changing the password signs out every other browser. Your username is not affected.
Would rather keep the one the installer made? Press Keep the current password and confirm. It is 24 random characters made for this server alone, so that is a reasonable choice — but it was printed to your terminal, so change it if that screen or its log could be read by someone else.
Expected result: the step is marked done.
Panel address
This step moves the panel off https://IP:PORT/CODE and onto a name of your own, like panel.example.com, with a real certificate.
- Type the Panel domain — just the name, no
https://and no slash. - Press Check. The panel looks the name up and tells you which of three situations you are in:
- it is on Cloudflare and your connected account manages it — one click does everything;
- it is on Cloudflare under a different account — enter that account's Account ID and API token, and it becomes the first case. The token field hides what you paste, like a password field; press Show beside it to check the token, and Hide to cover it again;
- it is not on Cloudflare — the panel shows the exact A record to create at your DNS provider, and a check again button.
- Press Make the panel live on this address. The panel creates the DNS record (when it manages your Cloudflare account), waits for the name to point here, gets the certificate and rewrites the web server — all as one job with a live progress list you watch.
Expected result: Your panel has a new address, with a button to open it. Bookmark the new address.
This is the most common way people lock themselves out. Once the panel domain has a certificate, the panel answers only on that name — the address with the IP and the port stops working, on purpose, so nobody can find it by scanning ports. Your way back is always SSH:
sudo sixpanel domain none, thensudo sixpanel info.
Not ready? Press Set the panel address later at the bottom of the step. The panel keeps its IP address and port, and you can do this any time from the Security page.
Two-factor
The last step: a 6-digit code from your phone, on top of the password. This panel controls your whole server, so a password on its own is not enough.
- Open your authenticator app and scan the QR code on screen. Cannot scan? Choose "enter a setup key" in the app and type the key shown under the code.
- The app starts showing a 6-digit code that changes every 30 seconds.
- Type the current code and press Turn on two-factor login.
No phone to hand right now? The step also offers Not now — continue without two-factor login, and it is a real way through. It asks you to confirm once, then the panel opens on your password alone from then on. It is written to your activity log, the Security page shows two-factor as off, and you can turn it on there in about a minute. Skip it only if you have to, and come back to it the same day.
Set it up on a phone you keep, not a phone you are about to replace. If you lose it, the way back is one command over SSH on the server:
sudo sixpanel 2fa off. That forgets the old phone, and your next login shows a fresh QR code to scan with the new one.
Once it is on, every login asks for the username, the password and the 6-digit code. If you leave the wizard before this step, your next login asks for it before the panel opens — with the same Not now choice.
Finished
The last screen says Panel setup complete and lists what now runs by itself — and each line says what is true on your server, not what could be:
- certificates renew on their own (or: none has been issued yet — one is, as soon as the panel or a project has a domain);
- a failed service is restarted, and you get an email about it;
- automatic backups.
Two of those lines carry their own button while they are not true yet:
- Set up email alerts opens the mail form from Settings → Alerts in a dialog, over the finish screen. Pick your mail provider — the panel fills in the server, the port and the security for it — add your user name, password, a send from address and where alerts should go, and press Send a test email. A test that passes saves the settings it just proved. Close the dialog and the line now says you get an email. What each provider wants as user name and password is in the table below, and in the form itself.
- Turn on daily backups switches automatic backups on (kept 7 daily, 4 weekly, 3 monthly), onto encrypted storage on this server; add storage somewhere else later on the Backups page — see Backups.
It ends with Create your first project. That is the next thing to do, and it has its own guided flow — see Domains and HTTPS and Install your 6ammart code.
Email alerts: what each provider needs
The same form lives on Settings → Alerts. A provider button fills in the server, the port and the security; you add the rest.
| Provider | The button fills | User name | Password |
|---|---|---|---|
| Resend | smtp.resend.com, 2465, SSL/TLS | resend (filled in) | an API key from Resend |
| Brevo | smtp-relay.brevo.com, 2525, STARTTLS | the SMTP login on Brevo's SMTP & API page | an SMTP key from that page — not an API key |
| SendGrid | smtp.sendgrid.net, 2525, STARTTLS | apikey (filled in) | an API key with Mail Send permission |
| Mailgun | smtp.mailgun.org, 2525, STARTTLS | your sending domain's SMTP login, like [email protected] | its SMTP password |
| Amazon SES | email-smtp.us-east-1.amazonaws.com, 2587, STARTTLS | SES SMTP credentials — change us-east-1 to your region | the SES SMTP password, not your AWS keys |
| Gmail | smtp.gmail.com, 587, STARTTLS | your Gmail address | an app password — your normal one is refused |
| Outlook / Microsoft 365 | smtp.office365.com, 587, STARTTLS | your Microsoft 365 address | its password, with Authenticated SMTP allowed for the mailbox |
| Zoho Mail | smtp.zoho.com, 587, STARTTLS | your Zoho address | an app-specific password if two-factor sign-in is on |
Why those ports. Most hosting companies block outbound 25, 465 and 587 on a new server, and the test then times out with nothing wrong on your side. So where a provider also answers on a port that is rarely blocked, the button picks that one. Gmail, Microsoft and Zoho have no such port: if their test times out, ask your host to open 587, or use one of the providers above.
The security setting follows the port. 465 and 2465 speak SSL/TLS from the first byte; 587, 2587 and 2525 start plain and switch on encryption with STARTTLS. Typing one of those ports sets the matching choice, and the panel also corrects a mismatch saved earlier — the other way round, nothing can connect.
The password stays. Leave the password field empty when you save again and the saved one is kept — for the same mail server only. Change the server and you type its password again; the panel never hands one server's password to another.
5. Create your first project
Pressing Create your first project opens the create dialog on the Projects page, and it asks one thing: what to call this project — the label you will recognise it by, like Grocery One. Press Create the project and the panel builds it: its own database, its own Linux user, its own PHP pool and services, its own folders.
There is no address question here. The web addresses, their DNS records and their certificates are asked for once, in Put 6amMart on this project on the Deploys page, while your code uploads — so the address is answered in the same place the site is actually put up, rather than twice in two flows that can disagree.
Then press Continue to install the app — Install your 6ammart code, which covers the address, the DNS records (always proxied, so your server's address stays hidden) and both certificates. If the domain is not on Cloudflare, the panel shows you the exact records to add at your DNS provider and you come back for the certificates afterwards.
How to check it worked
- The Home page opens and shows your server's processor, memory and disk.
- Open Server → Health. It runs more than thirty checks. Green is good, and every problem carries a one-line fix.
- Signing out and back in asks for the username, the password and a 6-digit code.
If it went wrong
"I cannot reach the panel at all"
In order:
- The ports. The panel port, 80 and 443 must be allowed at your hosting provider. This is the most common cause by a wide margin. See The three ports.
- The whole address. A blank "not found" page means the secret code at the end is missing or wrong.
- On the server, run
sudo sixpanel doctor --self. It runs every check that does not need the panel, and prints a fix under each failure.
"I gave the panel my own domain and now nothing opens"
This is the most common lock-out, and it is by design. Once your panel domain has a certificate, the panel answers only on that domain. Reaching it by IP address and port stops working, so nobody can find it by scanning ports.
If the domain has a typo, or its DNS breaks, you appear to be locked out. You are not. Log in to the server over SSH and run:
sudo sixpanel domain noneThat clears the panel's custom domain and brings the IP address back. Then run sudo sixpanel info for the address to open. This works even when nginx is broken.
"I lost the panel URL"
sudo sixpanel info"I lost the username"
sudo sixpanel username"I lost the password"
sudo sixpanel password resetIt tells you what it will change, asks you to confirm, then prints a new password. The old one cannot be recovered — only a hash of it is stored.
"I lost the phone with the 6-digit codes"
sudo sixpanel 2fa offThis forgets the phone you set up; it does not switch the feature off for good. Log in with your username and password as usual, and the panel offers you a fresh QR code to scan with the new phone. If you have no phone at that moment, that screen also offers Not now — continue without two-factor login, so losing a phone can never lock you out of your own panel.
"The site shows a 500 error"
If you have not finished installing your 6ammart code yet, this is normal — see Install your 6ammart code. Otherwise read When something is broken.
"The setup wizard keeps coming back"
The wizard shows while any of its steps is still open. Finish them, or press Exit setup under the list of steps and confirm; it does not open by itself again. If something is still unfinished, the dashboard offers a link back to it.
Ada yang kurang jelas?Tanya Tia