KryoHost
Blog
Client Area Get Started
340+ articles, kept current

Documentation written by the people who answer tickets

Every article here started as a support conversation. When the same question arrives three times, it becomes documentation, which is why these guides answer the question people actually ask rather than the one a marketing department imagined.

  • Written and revised by the engineers on the support rota
  • Every article dated, with the platform version it was tested against
  • Copy-paste commands that work on our actual images
  • Linked from ticket replies, so you get the answer and the reasoning
99.99%
Uptime SLA, with credits
47
Global locations
< 15 min
Support first response
60 sec
Average deployment time
On every plan, including the cheapest

Six categories, 340+ articles

Start here, or search from any page in your client area.

Hosting & cPanel

Account setup, file management, subdomains, redirects, PHP versions, cron jobs and error logs.

WordPress

Caching, staging, database optimisation, migration, malware recovery and plugin conflict isolation.

VPS & Linux

First-hour hardening, firewall configuration, Docker, control panels and rescue mode.

Domains & DNS

Record types, propagation, nameserver changes, transfers, subdomain delegation and CAA records.

Email

SPF, DKIM and DMARC, client configuration, deliverability triage and spam-folder diagnosis.

Security & SSL

Certificate installation, mixed content, HSTS, malware cleanup and post-compromise hardening.

The most-read guides, by category

These are the articles our customers open most often. If you are new to the platform, the first three in the hosting list will save you the most time.

Hosting and cPanel

  • Setting up your account for the first time: DNS, SSL, email and backups in the right order
  • Understanding cPanel error logs and what a 500 response is actually telling you
  • Switching PHP versions and extensions per domain without breaking a legacy site
  • Creating redirects properly: 301 versus 302, and when each is correct
  • Cron jobs: syntax, common mistakes, and why yours is not firing
  • Reading your resource usage graphs and telling contention from a genuine ceiling

WordPress

  • Configuring LiteSpeed Cache correctly, including the exclusions WooCommerce requires
  • Finding and shrinking a bloated autoload: the silent tax on every request
  • Isolating a plugin conflict in under ten minutes without taking the site down
  • Migrating WordPress by hand when the plugin fails, including serialised-data search and replace
  • Recovering from a malware infection and closing the hole that let it in
  • Database optimisation: post revisions, orphaned metadata and transient cleanup

VPS and Linux

  • The first hour on a new VPS: ten steps before you install anything
  • Firewall configuration with ufw and firewalld, with a sane default policy
  • Installing Docker and Compose correctly on Ubuntu and AlmaLinux
  • Using rescue mode to repair a server you have locked yourself out of
  • Setting up your own off-site backup on a VPS, since none is included
  • Diagnosing high load: separating CPU, I/O wait and steal time

Email

  • SPF, DKIM and DMARC explained, with records you can copy
  • Why your mail lands in spam: a triage checklist in order of likelihood
  • Configuring Outlook, Apple Mail and Thunderbird against our servers
  • Reading a bounce message and knowing whether it is your problem
  • Moving to a dedicated email service and keeping your domain records consistent

Support that answers the question you actually asked

Support is where hosting companies quietly differ most, and where the difference is hardest to evaluate before you buy. Every provider claims 24/7 availability. Far fewer will tell you who is on the other end at 03:00 on a Sunday, how many tickets that person is holding, or what percentage get resolved without being escalated into a queue you cannot see.

KryoHost staffs Linux system administrators across three timezones. There is no offshore first line whose job is to send you a knowledgebase link and close the ticket. Our commitment is a first response inside < 15 min on anything service-affecting, escalating automatically to on-call if that is missed. When something does need a second pair of hands it moves to a named senior engineer and you are told who owns it, not dropped into a silent queue.

What is included, and what is genuinely out of scope

Being clear about scope up front prevents the most common support frustration: discovering after an incident that the thing you assumed was covered never was.

RequestIncludedNotes
Server, network and platform faultsYesAlways our responsibility, always free
Migration from another hostYesUnlimited sites on standard control panels
Email deliverability (SPF, DKIM, DMARC)YesWe configure the records and verify alignment
SSL installation and renewalYesAutomatic for free certificates, assisted for third-party
CMS core, plugin and theme updatesYesOn managed WordPress plans
Malware cleanup after a compromiseYesOne free deep clean per year, per account
Performance triage and cache tuningYesWe will tell you honestly if the fix is in your code
Writing or debugging your application codeNoWe will point at the failing query or function
Custom theme and design workNoAvailable through our partner network
Third-party SaaS integrationsNoWe support the server side of the connection

Support reaches you through live chat, tickets and email, and (on business and VPS plans) a scheduled screen-share call when something genuinely needs a live conversation. The same standard of engineer answers at any hour, which matters more than it sounds when you are describing an intermittent fault under pressure at two in the morning.

Performance, Core Web Vitals and what actually moves rankings

Search engines have been explicit that page experience is a ranking input, and Core Web Vitals are the measurable part of that signal. What gets lost in most hosting knowledgebase marketing is which of those metrics hosting can genuinely influence. Being precise about it saves you money, because it tells you when to buy a bigger article and when to fix your front end instead.

How much hosting influences each Core Web Vital
MetricWhat it measuresHosting influenceWhat actually fixes it
TTFBTime to first byte from the serverVery highFaster CPU/disk, server-side caching, closer region, HTTP/3
LCPLargest contentful paintHighLow TTFB, image compression, CDN delivery, preloading the hero asset
CLSCumulative layout shiftNoneWidth/height attributes on media, reserved ad slots, font-display strategy
INPInteraction to next paintLowLess blocking JavaScript, smaller third-party bundles, deferred scripts
FCPFirst contentful paintMediumTTFB plus render-blocking CSS removal and critical-CSS inlining

Read that table honestly and a useful rule emerges: hosting owns the first 200–400 milliseconds and your front end owns most of what follows. That is not an argument for cheap hosting (those first milliseconds are a floor that nothing downstream can undo) but it is an argument against believing a plan upgrade will rescue a page carrying eleven tracking scripts and a 4 MB uncompressed hero image.

The caching layers we ship enabled

KryoHost our documentation ships with a caching stack that is configured on day one rather than left as an exercise. Requests are answered at the shallowest layer that can serve them correctly, and each layer that handles a request is one your origin never sees.

  1. Edge CDN: 120+ points of presence serve static assets from the PoP nearest your visitor, typically within 10–30 ms.
  2. Full-page cache: LiteSpeed Cache stores rendered HTML in RAM, so repeat visits skip PHP and the database entirely.
  3. Object cache: Redis keeps expensive query results and transients in memory instead of round-tripping to MySQL.
  4. OPcache: compiled PHP bytecode is held in memory, removing parse and compile cost from every request.
  5. Browser cache: long-lived immutable headers on fingerprinted assets mean returning visitors re-download almost nothing.

Compression and protocol choices are handled at the edge too. Brotli is preferred over gzip where the client supports it, HTTP/3 with QUIC is enabled by default so lossy mobile networks stop paying the TCP head-of-line penalty, and TLS 1.3 removes a full round trip from the handshake. None of these require a support ticket; they are the default configuration on every article.

A realistic benchmark, not a hero number

A default WordPress install with a commercial theme, tested from a cold cache in the same region as the server, consistently returns in 180–260 ms TTFB on our NVMe nodes. With the full-page cache warm, that drops to 40–70 ms. We publish the ranges rather than the single best run, because the best run is the number every host quotes and none of them reproduce.

Security, backups and disaster recovery

Most sites are not compromised by a determined attacker studying them for weeks. They are compromised by automated scanners walking the entire IPv4 space, trying known plugin vulnerabilities and credential lists against everything that answers on port 443. Defence against that reality is layered and mostly boring, which is exactly why it works, and why it should already be switched on when your article is delivered rather than sold as an upsell after the incident.

What runs by default

  • Web application firewall: ModSecurity with continuously updated OWASP and vendor rule sets, tuned per stack to keep false positives low.
  • Malware scanning: Imunify360 scans on write and on schedule, quarantines known-bad files and can auto-clean common injections.
  • Brute-force protection: progressive rate limiting and automatic IP throttling on login endpoints, SSH and mail services.
  • DDoS mitigation: always-on L3/L4 scrubbing at the network edge, with L7 protection available on request.
  • Account isolation: CageFS confines each account to its own virtualised filesystem, so one compromised neighbour cannot read another's data.
  • Free TLS: automatically issued and renewed certificates with modern cipher suites and HSTS available in one click.
  • Patched kernels: KernelCare applies security patches without reboots, removing the trade-off between staying current and staying up.

Backups, and what they actually cover

Website files on every article are backed up twice a week, with email accounts backed up on a separate schedule so both are protected without either job blocking the other. You can also generate and download a full account backup at any time from cPanel, and our support team can help with a restore if you need one.

A twice-weekly schedule is not the same as continuous protection, and we would rather you knew that than assumed otherwise. If you publish or sell something several times a day, keep your own more frequent backup for the hours between our scheduled runs, particularly for a database that changes constantly, such as an order table.

Compliance-wise, our infrastructure supports GDPR data-residency requirements through EU-only regions, and we sign Data Processing Agreements on request. For workloads touching payment data, our environment is PCI-DSS ready, you still own the compliance of your own application, but the platform underneath will not be the reason an assessment fails.

Migrating to KryoHost without downtime

The single biggest reason people stay with hosting they dislike is the fear of a broken move. It is a rational fear, a badly executed migration means missing emails, a checkout that silently fails for a day, and a certificate mismatch that greets every visitor with a browser warning. KryoHost migrates our documentation accounts free of charge, and we do it in an order designed so the risky steps happen while your existing site is still serving traffic.

  1. Discovery: we inventory domains, subdomains, databases, cron jobs, mailboxes, PHP versions and any custom server configuration. Cron jobs and mailboxes are the two things almost every self-service migration tool quietly drops.
  2. Staged copy: a full copy is restored onto your new KryoHost account and made reachable on a temporary hostname. Your live site is untouched throughout.
  3. Verification: we walk the checkout, the contact forms, the login flow and the admin area on the staged copy, and hand you the temporary URL so you can do the same.
  4. Delta sync: immediately before cutover we re-sync anything that changed since the copy: new orders, new posts, new uploads.
  5. DNS cutover: TTL is lowered in advance, records are switched, and both origins stay live during propagation so no visitor lands on a dead host.
  6. Post-cutover watch: we monitor error rates and mail delivery for 48 hours and keep the old copy intact for 14 days as a rollback path.

Most single-site moves complete within four hours of you sending credentials. Larger estates (a reseller with 60 cPanel accounts, or a store with a 40 GB media library) are scheduled into a maintenance window you choose, typically running overnight in your local timezone. There is no per-site fee and no cap on the number of sites for standard cPanel-to-cPanel moves.

Overlap your billing, on purpose

Keep your old hosting active for two weeks after cutover. The overlap costs a few dollars and buys you a guaranteed rollback that does not depend on anyone's backup working correctly. We would rather you spend that than trust a restore under pressure.

KryoHost Knowledgebase terminology, decoded

Hosting vocabulary is unusually good at making simple ideas sound complicated, and occasionally at making limited products sound generous. Here is what the terms on a hosting knowledgebase comparison page actually mean in practice.

TermWhat it means in practice
Unmetered bandwidthNo hard transfer cap, but a fair-use policy applies. Normal sites never approach it; a file-distribution service will.
Unlimited storageUnlimited for ordinary website files. Backup archives, media libraries and mail spools usually have separate soft caps in the terms.
NVMeFlash storage on the PCIe bus rather than a SATA cable. Several times the throughput and a fraction of the latency of a SATA SSD.
vCPUA virtual core mapped to a physical thread. A dedicated vCPU is reserved for you; a shared vCPU competes with neighbours.
TTFBTime to first byte, how long the server takes to start answering. The clearest single indicator of hosting quality.
LiteSpeedA web server that is API-compatible with Apache but handles concurrency with an event-driven model, plus a built-in full-page cache.
Object cacheA memory store (Redis or Memcached) holding query results so the database is not asked the same question repeatedly.
CDNA network of edge servers caching your static assets close to visitors, cutting both latency and origin load.
SLAA contractual uptime commitment with defined compensation. Without service credits attached, it is a marketing number.
Soft limitA threshold that throttles rather than stops you. Read these carefully, they are where "unlimited" actually ends.
CageFSPer-account filesystem virtualisation. It is what stops one compromised account on a shared node reading another's files.
Steal timeCPU cycles your VM wanted but the host gave to someone else. Persistent steal time means the node is oversold.

If a provider will not define its soft limits in writing, treat that as the answer. Ours are published in the Terms of Use, in plain language, with the numbers included.

The infrastructure behind KryoHost KryoHost Knowledgebase

Every conversation about hosting knowledgebase eventually comes back to hardware, and for good reason. You can tune a stack endlessly, but you cannot compensate in software for a disk that is queueing, a CPU that is oversubscribed four times over, or an upstream carrier that routes your visitors halfway around the planet before delivering the first byte. KryoHost builds from the metal upward precisely because the metal sets the ceiling on everything above it.

Our our documentation fleet runs on dual-socket AMD EPYC and Intel Xeon Scalable nodes with ECC memory, paired exclusively with enterprise NVMe drives in RAID-10. There is no SATA tier hiding behind the marketing copy, and no "NVMe-accelerated" wording that quietly means a small cache in front of spinning disks. NVMe changes the character of a server rather than simply making it faster: random read latency drops from milliseconds to microseconds, so the database queries that dominate page-generation time on websites, servers and email stop being the bottleneck. In our own benchmarks, moving an unchanged WordPress install from a SATA SSD node to an NVMe node cut median time-to-first-byte by 38% without a single line of code being touched.

Capacity planning is the unglamorous half of the story. We cap node density well below what the hardware could theoretically carry and we alarm on sustained CPU steal, disk queue depth and memory pressure rather than waiting for customers to open tickets. When a node crosses its threshold, new provisioning stops on that node and workloads are rebalanced. That is why the phrase "the server was fine, your site is just heavy" is one you will not hear from our team, if steal time is climbing, that is our problem to solve, not yours to absorb.

Network, peering and routing

KryoHost operates across Tier-III and Tier-IV facilities in 47 customer-selectable countries. Each core site is multi-homed across at least three Tier-1 carriers and connected to the dominant regional internet exchange, so traffic reaches your visitors through the shortest sensible path rather than the cheapest available one. Blended transit is convenient for a provider and mediocre for a customer; direct peering costs more and is the reason a visitor in Dubai does not have their packets tour Europe before they see your homepage.

  • Redundant power: N+1 UPS with diesel generators tested under load monthly, not merely started and logged.
  • Redundant cooling: hot/cold aisle containment with N+1 CRAC units and independent chilled-water loops.
  • Redundant network: no single upstream carries more than 40% of a site's traffic, so losing one is a re-route, not an outage.
  • Physical security: biometric access control, mantraps, 24/7 on-site security and 90-day CCTV retention.
  • Independent audit: facilities hold SOC 2 Type II and ISO 27001 certification, with reports available to enterprise customers under NDA.

The practical effect of all this is measurable rather than decorative. Our published 99.99% uptime SLA is backed by service credits, and our public status page records every incident, including the ones that lasted four minutes and that nobody noticed. A provider that only publishes its good quarters is not publishing anything useful.

Asked before you buy

Frequently asked questions

Still unsure? Our team answers pre-sales questions 24/7, usually in under 15 minutes.

Every article carries a last-reviewed date and the platform version it was tested against. Articles referencing a control panel screen are re-checked after each major cPanel release, and command-line guides are verified against our current OS images. If you find something stale, there is a "this is out of date" link on every article that opens a ticket with our documentation team, those get actioned within a week.

Yes, and we act on suggestions regularly. If you worked something out the hard way and think others would benefit, tell us. We will write it up, credit you if you would like, and occasionally offer account credit for genuinely useful contributions. A good proportion of our best articles started as a customer explaining what they had figured out.

They are graded, and each article states its level at the top. Beginner articles assume nothing beyond being able to log into cPanel. Intermediate ones assume you understand DNS records and can edit a configuration file. Advanced ones assume comfort in a terminal. We try hard not to write the kind of guide that says "simply configure your reverse proxy" as though that were one step.

Provisioning is automatic and normally completes in under 60 seconds. You receive your control panel login, nameservers and connection details by email the moment the article is live. Orders paid by bank transfer activate once the payment clears, which usually takes one to two business days.

Yes. Upgrades within the same product family are applied in place, take effect within minutes and are billed pro-rata against your remaining term. Downgrades take effect at your next renewal date, provided your current usage fits within the smaller plan's limits. Moving between product families (shared to VPS, for example) is handled by our migration team at no charge.

It is, with no limit on the number of sites for standard control-panel migrations. Our team handles the copy, verification and DNS cutover, keeps your existing site serving traffic throughout, and retains a rollback copy for 14 days after the switch. Complex custom-stack migrations are quoted individually, and we will tell you before any work starts if yours falls into that category.

You are notified by email well before anything is enforced, with the specific metric and figure included. Brief spikes (a post going viral, a promotion landing) are absorbed rather than punished. Only sustained overuse leads to throttling, and we will always propose a right-sized plan before that point. Nothing is suspended without prior written notice except in cases of active abuse.

Every domain and subdomain on every plan gets a free DV certificate, issued automatically at setup and renewed automatically for as long as the site is hosted with us. Paid OV, EV and wildcard certificates are available if you need a warranty, organisation validation or a single certificate covering unlimited subdomains.

We operate in 47 customer-selectable countries across Europe, Asia, North America, South America, Africa and Oceania. You pick your region at checkout, and you can relocate later at no cost. Choose the region closest to the majority of your visitors, it is the single cheapest performance improvement available to you.

Our published SLA is 99.99% measured monthly at the network edge, and it is backed by automatic service credits rather than a claims process. Historical uptime, including every incident and its duration, is on our public status page, the bad months are there alongside the good ones.

Live in about sixty seconds

Cannot find the answer?

Open a ticket. If your question turns out to be one we should have documented, it becomes an article, and you get credit for finding the gap.

Free migration  ·  No setup fees  ·  Cancel any time