NGINXwatch

Self-hosted edition

Users and sign-in

Roles

Role Can
viewer see everything, change nothing
operator also run lifecycle commands (start, stop, restart, reload)
admin also manage servers, agents, settings, users and the license

Roles are enforced by the server on every request — hiding a button in the browser does not grant access to what it does.

How many users

Your license sets how many admins and operators you can have: Free is a single user, Starter up to 3, Professional up to 10 and Enterprise 20. Viewers are unlimited from Starter up. When the limit is reached, adding or promoting an admin/operator is refused — in the browser and in the users command — until you add the person as a viewer or upgrade. Need more Enterprise users? We raise the number on your license key; nothing to reinstall.

Managing users

Admins add, edit and remove users in Settings. From the server's command line you can do the same — useful if every admin is locked out:

sudo runuser -u nginx-monitor -- nginx-monitor users list
sudo runuser -u nginx-monitor -- nginx-monitor users add jane 'S3cure-Passw0rd' operator
sudo runuser -u nginx-monitor -- nginx-monitor users passwd jane 'N3w-Passw0rd'

Sign-in methods

Besides local usernames and passwords, an admin can enable these in Settings (Authentication):

  • Duo Universal MFA — per user: set a user's sign-in type to Duo and they approve every sign-in on their phone. Needs a Duo "Web SDK" application (client ID, client secret, API hostname) with the redirect URI https://your-server/nginxmon/auth/duo/callback.
  • LDAP / Active Directory — users sign in with their directory password; their role comes from directory group membership.
  • SAML 2.0 and OpenID Connect — a "Sign in with …" button for your identity provider (Azure AD / Entra ID, Okta, Oracle IDCS, Keycloak, ADFS …). The role comes from the provider's group claim.

Authentication settings and their secrets are stored in /var/lib/nginx-monitor, which only the nginx-monitor service account can read.