Self-hosted edition
System requirements
NGINXwatch self-hosted has two parts: the NGINXwatch server (web dashboard, alerting, license) and an agent on each server running nginx. Both install from RPM packages that contain everything they need — no Node.js, npm, Java or other runtime has to be installed, and an existing Node.js on the machine is never used or changed.
Verified on clean RHEL 8.10 and RHEL 9 systems (Red Hat UBI with systemd), October 2026.
NGINXwatch server — nginx-monitor RPM
| Operating system | RHEL, Oracle Linux, Rocky Linux or AlmaLinux 8 or 9, x86_64 (glibc 2.28 or later), with systemd |
| CPU | 1 vCPU (2 recommended above ~20 monitored instances) |
| Memory | 63 MB measured idle right after install; allow 1 GB free for production use |
| Disk | ~90 MB for the program; 1 GB recommended for data (/var/lib/nginx-monitor) and logs |
| Runs as | Its own unprivileged nginx-monitor account (created by the package) |
| Listens on | TCP 3030 (PORT in /etc/nginx-monitor/nginx-monitor.env) — browsers and agents connect here |
| Outbound | HTTPS to the license server (devapex.cinnamonsservices.com:443): activation at start, a check every 12 h; it keeps running for 48 h if the license server is unreachable |
| Browser | Current Chrome, Edge, Firefox or Safari |
HTTPS: the server speaks plain HTTP on its port. For production, put it
behind your existing reverse proxy (nginx, Apache httpd, a load balancer) with
TLS, forwarding X-Forwarded-Proto; sign-in works on both.
Firewall: firewall-cmd --add-port=3030/tcp --permanent && firewall-cmd --reload
(or open only the reverse proxy's port).
First start: sudo dnf install ./nginx-monitor-*.rpm starts the service and
prints the address (http://<server>:3030/nginxmon/setup) and a one-time setup code. The setup
wizard registers your license — a free key by email (one installation per key)
or a paid key — and creates the first administrator.
Agent — nginx-agent package, on each nginx server
| Operating system | Same family as the server: RHEL / Oracle Linux / Rocky / AlmaLinux 8 or 9, x86_64, systemd |
| Footprint | One small program, a few MB of memory |
| Runs | as its own nginx-agent account |
| Network | Outbound only: HTTPS to the NGINXwatch server, authenticated with the agent token shown on the dashboard's Agents page. No inbound port on the nginx host. |
Needs on the monitored host:
- nginx with
ngx_http_stub_status_moduleenabled on a local URL (defaulthttp://127.0.0.1/nginx_status) for traffic metrics - Read access to the nginx configuration and log files
The agent package was not part of this test round — its requirements are from its configuration template.
SELinux
Leave SELinux enforcing — nothing needs to be disabled, and no extra
policy package is required. The server and the agent are ordinary programs in
/usr/bin started by systemd, which RHEL's targeted policy runs in the
unconfined_service_t domain; what they can reach is limited by the
account each runs as (see Runs as above).
The one setting you may need is for a reverse proxy. If nginx or Apache httpd forwards HTTPS traffic to the NGINXwatch server, SELinux blocks the web server's outgoing connection to port 3030 by default (the browser shows 502 Bad Gateway). Allow it once:
sudo setsebool -P httpd_can_network_connect 1
To check for SELinux denials: sudo ausearch -m avc -ts recent.
Not supported yet
- Air-gapped installations — the server must reach the license server (first activation, and at least once every 48 h).
- ARM (aarch64), other Linux families as packages (Debian/Ubuntu), Windows.