NGINXwatch

Self-hosted edition

System requirements

NGINXwatch self-hosted has two parts: the NGINXwatch server (web dashboard, alerting, license) and an agent on each server running nginx. Both install from RPM packages that contain everything they need — no Node.js, npm, Java or other runtime has to be installed, and an existing Node.js on the machine is never used or changed.

Verified on clean RHEL 8.10 and RHEL 9 systems (Red Hat UBI with systemd), October 2026.

NGINXwatch server — nginx-monitor RPM

Operating system RHEL, Oracle Linux, Rocky Linux or AlmaLinux 8 or 9, x86_64 (glibc 2.28 or later), with systemd
CPU 1 vCPU (2 recommended above ~20 monitored instances)
Memory 63 MB measured idle right after install; allow 1 GB free for production use
Disk ~90 MB for the program; 1 GB recommended for data (/var/lib/nginx-monitor) and logs
Runs as Its own unprivileged nginx-monitor account (created by the package)
Listens on TCP 3030 (PORT in /etc/nginx-monitor/nginx-monitor.env) — browsers and agents connect here
Outbound HTTPS to the license server (devapex.cinnamonsservices.com:443): activation at start, a check every 12 h; it keeps running for 48 h if the license server is unreachable
Browser Current Chrome, Edge, Firefox or Safari

HTTPS: the server speaks plain HTTP on its port. For production, put it behind your existing reverse proxy (nginx, Apache httpd, a load balancer) with TLS, forwarding X-Forwarded-Proto; sign-in works on both.

Firewall: firewall-cmd --add-port=3030/tcp --permanent && firewall-cmd --reload (or open only the reverse proxy's port).

First start: sudo dnf install ./nginx-monitor-*.rpm starts the service and prints the address (http://<server>:3030/nginxmon/setup) and a one-time setup code. The setup wizard registers your license — a free key by email (one installation per key) or a paid key — and creates the first administrator.

Agent — nginx-agent package, on each nginx server

Operating system Same family as the server: RHEL / Oracle Linux / Rocky / AlmaLinux 8 or 9, x86_64, systemd
Footprint One small program, a few MB of memory
Runs as its own nginx-agent account
Network Outbound only: HTTPS to the NGINXwatch server, authenticated with the agent token shown on the dashboard's Agents page. No inbound port on the nginx host.

Needs on the monitored host:

  • nginx with ngx_http_stub_status_module enabled on a local URL (default http://127.0.0.1/nginx_status) for traffic metrics
  • Read access to the nginx configuration and log files

The agent package was not part of this test round — its requirements are from its configuration template.

SELinux

Leave SELinux enforcing — nothing needs to be disabled, and no extra policy package is required. The server and the agent are ordinary programs in /usr/bin started by systemd, which RHEL's targeted policy runs in the unconfined_service_t domain; what they can reach is limited by the account each runs as (see Runs as above).

The one setting you may need is for a reverse proxy. If nginx or Apache httpd forwards HTTPS traffic to the NGINXwatch server, SELinux blocks the web server's outgoing connection to port 3030 by default (the browser shows 502 Bad Gateway). Allow it once:

sudo setsebool -P httpd_can_network_connect 1

To check for SELinux denials: sudo ausearch -m avc -ts recent.

Not supported yet

  • Air-gapped installations — the server must reach the license server (first activation, and at least once every 48 h).
  • ARM (aarch64), other Linux families as packages (Debian/Ubuntu), Windows.