Deployment Overview of Zabbix server on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu 22.04 LTS (or compatible Debian-based distribution).
-
Privileges: Root or sudo access is required for package installation and service management.
-
Locales:
en_US.UTF-8must be generated on the system. -
Network/Ports:
-
Port
8080: Internal Apache port. -
Port
443: External HTTPS traffic via Nginx proxy.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | (None) |
| Domain | hostkey.in |
| Full template | {Server_ID}.hostkey.in/zabbix |
File and Directory Structure¶
The following directories are used for configuration and data management:
-
/root/nginx: Contains the Nginx Docker Compose configuration. -
/etc/zabbix: Location of Zabbix server configuration files. -
/etc/apache2: Configuration directory for the Apache web server. -
/data/nginx/user_conf.d: Custom Nginx user configurations. -
/data/nginx/nginx-certbot.env: Environment variables for the SSL container.
Application installation process¶
The application is installed using a combination of package management and manual configuration:
-
Repository Setup: The Zabbix official repository (
zabbix-release_latest+ubuntu22.04_all.deb) is downloaded and installed to enable access to Zabbix 7.0 packages. -
Package Installation: The following system packages are installed via
apt: -
zabbix-server-mysql -
zabbix-frontend-php -
zabbix-apache-conf -
zabbix-sql-scripts -
zabbix-agent -
python3-mysqldb -
mariadb-server -
locales -
Database Initialization:
-
MariaDB is installed and enabled.
-
A database named
zabbixis created withutf8mb4encoding. -
A dedicated user
zabbixis created for the application. -
The initial SQL schema is imported from
/usr/share/zabbix-sql-scripts/mysql/server.sql.gz. -
Service Configuration:
-
The Zabbix server configuration file (
/etc/zabbix/zabbix_server.conf) is updated with the database password. -
Apache is configured to listen on port
8080instead of the default port80.
Access Rights and Security¶
-
Database Security: The MySQL root user is secured, anonymous users are removed, and the test database is deleted.
-
Firewall/Ports: The application uses an internal port (
8080) for Apache, which is proxied through Nginx on port443. -
Service Permissions: Services are configured to start automatically upon system boot.
Databases¶
The application utilizes MariaDB as the backend database engine.
| Component | Detail |
|---|---|
| Database Name | zabbix |
| Character Set | utf8mb4 |
| Collation | utf8mb4_bin |
| Connection User | zabbix@localhost |
| Storage Location | Local MariaDB installation |
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to handle SSL termination via Nginx and Certbot.
Nginx Proxy Container
-
Image:
jonasal/nginx-certbot:latest -
Ports: Uses
hostnetwork mode (accesses host ports directly). -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Custom Nginx configurations) -
Environment Variables:
-
Restart Policy:
unless-stopped
Application Update Instructions¶
To update the main Zabbix application components, perform the following:
-
For the web proxy layer (Nginx/Certbot), navigate to
/root/nginxand run: -
For system packages and the Zabbix server, use the standard package manager:
Location of configuration files and data¶
| File/Directory | Purpose |
|---|---|
/etc/zabbix/zabbix_server.conf | Main Zabbix server settings |
/root/nginx/compose.yml | Docker Compose orchestration for Nginx |
/data/nginx/user_conf.d | Custom proxy and SSL routing rules |
Available ports for connection¶
-
443 (HTTPS): External access to the Zabbix web interface via Nginx.
-
8080 (HTTP): Internal communication between Nginx and Apache.