@@PRODUCT@@

Files, FTP and SSH

There are three ways to reach the files of your account: the file manager in the panel, an FTP client, and SFTP/SSH with a key. This page covers all three and says which one you want when.

Written for: Customer, Reseller, Administrator

There are three ways to reach the files of your account: the file manager in the panel, an FTP client, and SFTP/SSH with a key. This page covers all three and says which one you want when.

Screenshot — Panel → Hosting → Accounts → your account → Files, FTP and backups. Screenshots are captured with openwolf designqc into .wolf/designqc-captures/.

What your account looks like

When you sign in you land in your account's home. What is there:

$ ls -la ~
domains/     the web roots of your websites
home/        your personal directory (where FTP lands by default)
backups/     your own backups, if you keep them locally
logs/        the access and error logs of your websites
.ssh/        your SSH keys

A website's files live in domains/<domainname>/public_html. That is the directory you put WordPress or your HTML into.

It no longer has to be that directory: a website's document root has become a choice, and can be any directory inside this home — handy for a framework that wants only a public directory online, or for a rollout that works with releases. Your administrator or reseller sets it on the website itself; see Extra names and subdomains. Five directories stay refused, because a document root shows everything in it: your home itself, domains, logs, tmp and .ssh.

The same boundary holds in the file manager: anything inside your home is fine, and a path that climbs out of it with .. or a link pointing outside is refused — with the reason attached, rather than quietly doing something else.

1. The file manager in the panel

The quickest route for "just one file". Here you can:

ButtonWhat it does
Uploadfiles from your computer into the directory you are in
Downloadfetch a file
New folder / New filean empty directory or an empty text file
Editchange text files right in the browser
Renamea different name, in the same directory
Compress / Extractmake or open a .zip or .tar.gz
Permissionsthe octal permissions of a file, 644 or 755 say
Deletegoes to the wastebasket; recoverable for 30 days
Restore default permissionsputs a whole directory back on 755/644

Select several rows to compress or delete them in one action. At the top is your disk usage, so you can see how much still fits.

Besides disk space you also have a limit on the number of files. It is a separate ceiling and it is reached more often than you would expect: one modern web application easily brings tens of thousands of files. Run into it and writing fails while the disk meter is nowhere near full. Below the disk meter is how many files you are using of how many you may have.

Was that number wrong before? Up to and including panel version 0.19.40 the files-used figure was always zero, and the limit shown was not the ceiling a write is actually refused at. From 0.19.41 both numbers are the real ones. If it is tight, ask your provider to raise the limit.

Every directory row ends in a three-dots button, and in it is Protect folder: it puts a login name and a password in front of that directory for visitors of your website, without going to Websites first. The panel works out which website the directory belongs to and opens the management panel with it already filled in. See Password-protecting a folder, which also covers what happens when a directory belongs to two websites, or to none.

Where is that button? At the far right of the row, in the last column. Only directories have one — for a file that place stays empty, and the row keeps the same height, so the list lines up. Clicking the row itself opens the detail panel with every action for that file or directory.

Rule of thumb for permissions: 644 for files, 755 for directories. 777 is never the answer — it is how a compromised plugin also gets to change your other files.

A file whose name starts with .corecp-part-

Come across one and it is an upload that got stuck half way. Some screens — the database import page, for one — send a large file in pieces, so a connection that drops does not mean starting over. What has arrived so far sits in one of these, beside the place it is eventually going.

It counts against your disk space and you may simply delete it; send the same file again from the start and it is overwritten by itself.

Editing files

Edit opens the file in a real editor: with line numbers, colours that follow the language (PHP, JavaScript, CSS, HTML, YAML, JSON, INI and configuration files), and find and replace on Ctrl+F. The editor follows your theme — light or dark — and works on a phone too.

The editor appears below the file list, and the panel takes you straight to it: the page scrolls to the editor and your cursor is already in it, also in a directory with dozens of files. Close it with Cancel and you are back at the list.

Two things to know:

  • The editor opens files up to 2 MB. That is comfortably more than any .htaccess, wp-config.php or stylesheet anybody edits by hand. Anything larger: download it, change it on your own computer and upload it again — or use SFTP.
  • Your changes are not lost quietly. While you have typed something that is not saved, "Unsaved changes" sits beside the Save button, and clicking into a directory, following a link or closing the tab asks first whether you want to throw those changes away.

Save does not close the editor: the file stays open at the line you were working on.

The wastebasket

What you delete moves to ~/.trash and stays there for 30 days. Right after deleting, a message appears at the bottom of the screen with Undo — one click and the file is back exactly where it was, with the same permissions.

After that you find it under Open wastebasket in the file manager's menu. Each row shows where the file came from, how big it is, when you threw it away and when the server will clear it for good. Per row you can put it back or delete it for good; Empty the wastebasket clears everything at once.

Three things worth knowing, which the panel also puts on the screen:

  • The wastebasket counts towards your disk space. The files are still in your account, so deleting only frees room once the wastebasket is empty. Under the disk meter it says how much of your space is wastebasket. Running tight? Empty it, or tick Delete for good straight away when you delete — that skips the wastebasket.
  • The wastebasket is left out of your backups. Exactly like your own backups folder: a backup carrying what you threw away would grow with every deletion and put those files back on a restore.
  • After 30 days it really is gone. The server sweeps daily. To keep something longer, put it back or make a backup of it.

On the command line:

corectl files remove --account web1 --path old-directory          # to the wastebasket
corectl files remove --account web1 --path secret.txt --permanent # gone at once
corectl files trash list    --account web1
corectl files trash restore --account web1 --id 20260816T091200-old-directory
corectl files trash empty   --account web1 --id 20260816T091200-old-directory
corectl files trash empty   --account web1                        # all of it

Restoring the default permissions

After a migration, an extracted archive or somebody else's upload, permissions are sometimes wrong: a directory on 700 the web server cannot enter, or a file on 777 that is far too open. Restore default permissions puts every directory on 755 and every file on 644 in one action, in the directory you choose or across your whole home.

What deliberately does not happen:

  • Symbolic links are skipped — a symlink's own permissions mean nothing, and the file it points at may not be yours.
  • Files carrying setuid or setgid are left as they are. That is a security bit; you turn it on or off deliberately, not by accident during a tidy-up.
  • .trash, backups, .ssh, imap and mail are left alone. Those have stricter permissions on purpose: your backups and your wastebasket are private, and SSH refuses a private key anybody else can read.
corectl files fixperms --account web1 --path domains/yoursite.com
corectl files fixperms --account web1                     # the whole home

What about ownership?

Other panels have a "reset ownership" button next to "reset permissions", because files there easily end up with the wrong owner — usually root instead of your account, after something ran as root. A file like that is one you can no longer change yourself.

CoreCP does not have that button, and it is not a missing feature: the state it repairs can, by construction, barely arise here. Everything that writes on your behalf really runs as your account — the panel's file manager (the server does the work in a separate, unprivileged session of your own account), FTP, SFTP, PHP-FPM and the WordPress tools. And every path that does write as root — creating an account, adding a domain, restoring a backup, running a migration — sets the ownership itself as it writes.

If the owners are wrong anyway, something went wrong that a button should not hide: contact your hosting provider.

The same actions exist on the command line:

corectl files list   --account web1 --path domains/yoursite.com/public_html
corectl files read   --account web1 --path .env
corectl files mkdir  --account web1 --path uploads
corectl files rename --account web1 --path old.html --to new.html
corectl files chmod  --account web1 --path wp-config.php --mode 640
corectl files compress --account web1 --paths domains --to site.tar.gz --format tar.gz
corectl files extract  --account web1 --path site.tar.gz
corectl files remove   --account web1 --path old-directory --recursive

2. FTP

For moving many files at once an FTP client (FileZilla, Cyberduck, Transmit) is nicer than the browser.

Creating an FTP login

  1. Go to the Access section (the FTP half) and click New FTP login.
  2. Login — the name the client signs in with. An email-shaped name (deploy@yoursite.com) is allowed.
  3. Directory — where this login lands and may not leave. Fill in domains/yoursite.com/public_html, say, if somebody only needs that one website.
  4. Click Create. The password is generated by the server and shown once.
corectl ftp add web1 deploy@yoursite.com --scope domains/yoursite.com/public_html --create-dir
corectl ftp list
corectl ftp passwd deploy@yoursite.com     # new password
corectl ftp remove deploy@yoursite.com     # the login goes, the files stay
corectl ftp status                         # service, certificate and logins

What to fill in in your client

value
Hostyoursite.com (or the server name the panel shows)
Port21
ProtocolFTP with explicit TLS (FTPS)
Userthe login you created
Passwordthe password that was shown once

TLS is mandatory. A client that will not upgrade to TLS is refused — on purpose: plain FTP sends your password across the internet in the clear.

If the panel shows no certificate on the service, report that to your hosting provider; FTPS is then configured but not usable.

How many FTP logins may you make?

Your package can set a maximum for FTP logins. Once you are at it, the New FTP login button is greyed out with the reason beside it: "Your package allows 1 FTP logins, and all of them are in use."

The panel's own file manager does not count. It keeps working whether or not you have an FTP login left — your files are never out of reach because of an FTP limit.

If you are stuck there are two ways out: remove a login you no longer use (the button comes straight back), or ask your hosting provider for a larger package. If your package sets no maximum, there is no limit.

3. SFTP and SSH

If your account has SSH access you need no FTP login at all: the same username works over SFTP, on port 22, with your SSH key. That is safer as well as faster than FTP.

Access: off, files only, or shell

The panel has three states (Accounts → your account → Access → SFTP and SSH):

  • Off — nobody gets in, not even with a key. The keys are kept.
  • Files only (SFTP) — transfer files, run no commands.
  • Shell — a full shell inside this account's environment.
corectl ssh show    --account web1
corectl ssh enable  --account web1              # shell
corectl ssh enable  --account web1 --sftp-only  # files only
corectl ssh disable --account web1              # closed, keys are kept

Adding a key

Passwords do not work for SSH — only keys. Make one on your own computer if you have none yet:

ssh-keygen -t ed25519 -C "Anna's laptop"
cat ~/.ssh/id_ed25519.pub

Paste that single line (it starts with ssh-ed25519) into the panel under Public key, give it a label that tells you where it lives, and click Add key. Under Advanced you can restrict it to one IP address or range.

The private key stays on your own computer. You never share it, with anybody.

# on the server
corectl sshkey add --account web1 --label "Anna's laptop" < ~/.ssh/id_ed25519.pub
corectl sshkey list --account web1
corectl sshkey remove --account web1 --label "Anna's laptop"

Connecting

sftp web1@yoursite.com         # files
ssh  web1@yoursite.com         # shell

# handy: synchronise a whole directory
rsync -avz --delete ./site/ web1@yoursite.com:domains/yoursite.com/public_html/

Which do you use when?

SituationTake
Changing one small filethe file manager in the panel
Uploading a websiteSFTP, or FTP if your client cannot do SFTP
Giving an outside party temporary access to one directoryan FTP login with a Directory
A deploy scriptSFTP/rsync with a key
Running something on the serverthe web terminal, or SSH with a shell

When something is not right

What you seeWhat it usually is
FTP: "530 Login incorrect"Wrong password, or the login was removed. Generate a new password.
FTP: the connection drops after signing inPassive mode is off in your client. Turn it on.
FTP: "TLS required"Your client is on plain FTP. Choose FTP with explicit TLS.
SSH: "Permission denied (publickey)"The key is not there, or SSH is off for this account.
SSH connects but commands do nothingThe account is on files only. Set it to Shell.
Your site returns 403 after an uploadPermissions. Files to 644, directories to 755.
"This directory is empty" while there are filesYou are in the home, not in the web root. Go to domains/<domain>/public_html.
Suddenly nothing: FTP, SSH and the website unreachableYou are probably blocked — see below.

When everything drops at once

If it is not only FTP but the website and SSH too, and only from one place (the office, home), your address is blocked. The server watches for failed sign-ins: five failures within ten minutes — on FTP, on SSH or on mail — and the address is out for an hour. A block applies to everything from that address, not only to the service where it went wrong.

The usual cause is a program retrying an old password in the background: a mail client, a backup job, a stale FTP profile. Find that first, or the block comes back the moment it is lifted.

Then ask your administrator to release the address. They can see on the server's firewall screen which address is blocked and which watcher did it, and can put a fixed office address on the allow list — an allowed address is never blocked.

See also

  • The web terminal — the same shell, without a client, in your browser.
  • Your own backups — before you throw something big away.
  • Securing your account — why a key beats a password.

If your server's SSH port has been moved

By default SSH listens on port 22 and you need do nothing. If your administrator moves it — which is allowed, and happens on some servers to get rid of the background noise of scanners — you add the number:

ssh -p 2222 youraccount@yourserver.com
sftp -P 2222 youraccount@yourserver.com

Mind the difference: ssh takes a lowercase -p, while sftp and scp take an uppercase -P. In a graphical client (FileZilla, Cyberduck) it is simply a field beside the server name.

Not sure? Ask your administrator, or look in the panel under Servers → the server → Server settings. During a port change both ports are open for a while, so if your old connection suddenly stops working and the new one does, that is not an outage but a change that finished.

If your server has an SSH list

Some servers do not let everybody reach SSH: there is a list of addresses that may come in, and everything else is dropped before the SSH server ever sees it. That is usual on management servers and rare on a server customers work on.

You can tell by the way it fails: a connection the list stops hangs and gets nothing back (Connection timed out), while a wrong key or a wrong password answers immediately (Permission denied). So if you get a timeout while you believe everything is right, ask your administrator whether your address is on the list — and tell them which IP address you work from.

Passwords over SSH are switched off in any case; keys are the only way in (see above).

A new password: where it appears

Passwords the server makes for you are shown once. So they always appear where you asked for them, and not somewhere else on the screen:

  • Ask for a new password in an FTP login's own panel and that panel stays open, with the card carrying the password in the middle of it, above the button you just pressed.
  • Create something new and that panel closes itself the moment it worked, and the card is on the page underneath — which is what you are looking at by then.

Copy it or write it down straight away. If you lose it there is no way to get it back; there is only a way to have a new one made.

If something goes wrong you see it in exactly the same place: the message is in the panel where you pressed the button, not on the page behind it.

When a name or a change is refused

If you create a folder or a file, or make an archive, and the server will not take the name, the dialog stays open — with the reason in it and with the name you typed. It used to close as though it had worked.

In one file's panel the same is true of extracting, renaming, changing permissions and deleting: the answer is in that panel. Three dialogs on this page deliberately do the opposite and close themselves first — deleting a selection, repairing permissions and emptying the wastebasket — because after those you are looking at the list itself.

"There is no room": which room?

Your account has two allowances, and they run out separately.

  • Disk space — how many megabytes your files take together.
  • The number of files — how many files and folders you may have at all. Every file counts as one, whether it is a holiday photo or an empty text file. A modern website is tens of thousands of small files, so this is the one that fills up first surprisingly often.

Both allowances are on your account's own screen, beside each other.

When a save, an upload or an unpack is refused, the message now says which of the two you ran into:

photos/holiday.jpg could not be written: this account has reached the number of files it may hold — 250000 of 250000. Deleting a few large files will not help; it is the count that is full, not the disk (3.0 GiB of 10.0 GiB used).

That sentence matters. If it is the file count, deleting one big video changes nothing — you need to remove many files (an old backup folder, a copy of a website you no longer use, a cache directory) or ask for a bigger allowance. If it is the disk space, one big file is exactly the right thing to delete.

There is a third message, and it is not about you:

… the disk on this server is full. Deleting your own files does not free it up — the server needs attention.

If you see that one, your own allowance is fine and the machine is out of room. Your hosting provider has to solve it; there is nothing to tidy on your side.

Occasionally the message says only "this account has reached one of its limits" and gives both figures. That happens when the refused write was undone before we could measure which ceiling it hit, and we would rather say that than send you after the wrong one.

Your account is paused: why your files are still there but will not open

When your hosting account is paused — suspended, shown in the panel as "suspended" — all of your files stay exactly where they are. Nothing is deleted. What does happen is that your doors to them close: the file manager in the panel, FTP, SFTP and the web terminal all answer the same thing:

account … is suspended

This is not a fault and it is not something you can fix by trying again. An account is paused because your hosting provider decided to pause it — usually an unpaid invoice, sometimes abuse coming from your site. Once the reason is gone your provider turns it back on and everything works exactly as it did; you do not have to restore anything.

Two things that often confuse people:

  • Your provider can still reach your files. Administrators reach them outside the panel. That is deliberate: it means a backup can be taken or a mistake repaired while your account is paused.
  • A move pauses your account too. If your hosting moves to another of your provider's servers, your account is paused briefly for the length of that move — otherwise the changes you make during that quarter of an hour would be lost. See Your hosting is moving to another server. The same applies there: nothing goes away, and your doors open again by themselves after the switchover.

If you see the message and have heard nothing from your provider, ask them. We cannot tell from the message itself why the pause was put on — only that it is there.