Install Playkeeper

What your VPS needs, the one-line install and every change it makes, the ports to open, and the setup link it prints.

From README.md in the repository, for Playkeeper 0.4.2.

On the VPS:

curl -fsSL https://playkeeper.io/install | sudo sh

No sudo, as on a Debian installed with a root password? Run su -, then the same command without sudo.

https://playkeeper.io/install redirects to get.sh from the latest release. The script downloads the tarball for your VPS's CPU from that release, playkeeper-linux-amd64.tar.gz on x86_64 or playkeeper-linux-arm64.tar.gz on 64-bit ARM, and its .sha256, stops unless the SHA-256 matches, then runs the installer, which asks before changing anything. Installer options go after sh -s --, for example … | sudo sh -s -- --yes --game-port 25566. To read the script first: curl -fsSL https://playkeeper.io/install | less.

If playkeeper.io is unreachable, the same script comes straight from GitHub:

curl -fsSL https://github.com/CIYAhq/playkeeper/releases/latest/download/get.sh | sudo sh

To skip the script, download the tarball for the VPS's CPU and its .sha256 from the releases page to the VPS: playkeeper-linux-amd64.tar.gz if uname -m says x86_64, playkeeper-linux-arm64.tar.gz if it says aarch64. Then:

ARCH=amd64   # arm64 on a 64-bit ARM VPS
sha256sum -c playkeeper-linux-$ARCH.tar.gz.sha256 && tar -xzf playkeeper-linux-$ARCH.tar.gz
sudo ./playkeeper-*-linux-$ARCH/install.sh

How big a VPS? The sizing guide answers for how many friends play at once and what you'll run.

Runs on: Ubuntu 20.04 or later, Debian 12 or later, the RHEL family 9 or later (AlmaLinux, Rocky Linux, Oracle Linux, RHEL and CentOS Stream), or Amazon Linux 2023 or later, on x86_64 or 64-bit ARM with systemd. Before every release it is installed, played on, backed up, restored, updated and uninstalled on Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS, Debian 12 and 13, AlmaLinux and Rocky Linux 9 and 10, Oracle Linux 9, CentOS Stream 9 and Amazon Linux 2023, each in a fresh x86_64 KVM guest built from its official cloud image (3 GB RAM, 2 vCPU, 20 GB disk), with SELinux enforcing where the image enforces it. RHEL itself and CentOS Stream 10 aren't booted there: AlmaLinux and Rocky Linux rebuild RHEL's packages, and CentOS Stream 10 is where RHEL 10 is developed. Every change also runs on GitHub-hosted ubuntu-24.04 runners, and the owner has installed it on a real provider VPS (see the status above). On 64-bit ARM, before each release, it runs on Ubuntu 24.04 LTS on GitHub-hosted ubuntu-24.04-arm runners: install, onboarding, play with test bots, backup, restore on a second runner, every server type with the hand-picked add-ons, the map, pre-generation and a modpack, and uninstall. The other systems haven't been tried on ARM yet, nor have the ARM servers the arm64 build is for, such as Oracle Cloud's free Ampere A1, Hetzner's and AWS's (Graviton) ARM machines and a Raspberry Pi 4 or 5 with a 64-bit OS. A newer release of a supported distribution than these gets a warning, not a refusal. Ubuntu 20.04 still works, but its standard security updates ended in May 2025 (Ubuntu Pro has more), and the installer says so. Debian 11 isn't supported: since its long-term support ended in August 2026, Debian's archive no longer has the Docker packages its package lists point to, so Docker can't be installed from it. The installer refuses a 32-bit system on a 64-bit CPU, and other distributions and older releases need --allow-untested-os.

You need: root (sudo) on the VPS; an x86_64 or 64-bit ARM CPU with a 64-bit OS; at least 2 vCPUs (the size that was tested; the installer does not check the count); at least 3 GB RAM (2.3 GB is the hard minimum the installer accepts) and 5 GB free disk (3 GB minimum). Open these in your provider's firewall (the installer opens them in ufw or firewalld itself when one is on, as on Oracle Cloud's images):

  • TCP 8443 for the dashboard;
  • TCP 25565 for the first Minecraft server, plus one more from 25566 for each further server;
  • UDP 24454 (or the next free port) for each server with voice chat;
  • TCP 80 only if you give the dashboard your own domain: Let's Encrypt checks it there while it issues or renews the certificate.

When ufw or firewalld is on, the installer allows 8443, 25565 and 80 in it (in firewalld, in the zone of the network interface with the default route, saved and running). Another firewall on the server, such as nftables on Debian, needs its own rules: the installer's check says which one it found and how to allow the ports.

On Oracle Cloud, allow the dashboard's port in the VM's own firewall too: its Ubuntu images block every port but SSH with iptables (Troubleshooting).

Outbound, Playkeeper needs your system's package repositories if it installs Docker (and Docker's, download.docker.com, on the RHEL family), and HTTPS to GitHub, Docker Hub, PaperMC and Mojang and, for the features you use, to Modrinth and Hangar (plugins, mods and modpacks; a Modrinth modpack may also fetch files from GitHub or GitLab), CurseForge, the download sites of Purpur, Fabric, Quilt, NeoForge and Forge, the websites a template's data packs come from, Discord, Let's Encrypt with Playkeeper's names service or public DNS-over-HTTPS (addresses), and your own storage (off-site copies). If Docker is missing, the installer installs Ubuntu's or Debian's docker.io package (with docker-cli on Debian 13, which packages the docker command on its own), Amazon Linux's docker package, or on AlmaLinux, Rocky Linux, Oracle Linux, RHEL and CentOS Stream Docker Engine (docker-ce) from Docker's repository, checked with Docker's signing key, which the installer carries. An existing Docker is used as it is; Podman can stay alongside, and the installer never removes it or what it needs. To check a server without changing it, extract the tarball as above and run sudo ./playkeeper-*-linux-$ARCH/playkeeper preflight.

The installer checks the server first (changing nothing), lists every change it will make and how to undo it, and asks before continuing. It never takes over an existing Minecraft, Crafty or panel install. When it finishes it prints:

  • an https://<your-ip>:8443/setup#code=… link with a one-time setup code (24 hours), and
  • the SHA-256 fingerprint of the dashboard's self-signed certificate. Your browser will warn about the certificate; continue only if the fingerprint it shows matches. A name with a real certificate (below) makes the warning go away.

Everything else happens in the browser: create the admin account, pass the check of the VPS, then create your first server or skip it for now. The first server gets the newest stable Paper and a memory size for how you'll play; Change picks others. The Get started card in the sidebar and First steps on each server's Overview walk you through inviting a friend and making and downloading your first backup.

Can't find it?

Ask in GitHub Discussions. Answers are public, so the next person finds them too.

Ask in GitHub Discussions