Deployment Overview of Zabbix proxy on Server¶
Prerequisites and Basic Requirements¶
The following requirements must be met for a successful deployment:
-
Operating System: Ubuntu (22.04 recommended)
-
Privileges: Root or sudo access is required to install packages and manage services.
-
Dependencies: The system must have
ca-certificates,curl,gnupg, andapt-transport-httpsinstalled. -
Network Access: Outbound access to
repo.zabbix.comfor package installation and outbound access for SSL certificate verification via Certbot.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template within the hostkey.in domain.
| Parameter | Value |
|---|---|
| Prefix | zabbixproxy |
| Domain | hostkey.in |
| Full template | zabbixproxy{Server_ID}.hostkey.in |
Application installation process¶
The application is installed using the system package manager (apt) on Ubuntu systems. The installation follows these steps:
-
Repository Setup: The Zabbix release repository for version 7.0 is added to the system's package sources.
-
Package Installation: Depending on the configured backend, one of the following packages is installed:
-
For SQLite:
zabbix-proxy-sqlite3andzabbix-sql-scripts. -
For MySQL/MariaDB:
zabbix-proxy-mysql. -
For PostgreSQL:
zabbix-proxy-pgsql. -
Service Configuration: The configuration file
/etc/zabbix/zabbix_proxy.confis modified to include the following parameters: -
Connection settings for the Zabbix Server (
Server). -
Proxy Hostname (
Hostname). -
Database connection details (DBName, DBUser, DBPassword, and DBHost).
-
Service Initialization: The
zabbix-proxyservice is enabled to start on boot and is started immediately after configuration.
Access Rights and Security¶
-
Database Directory Permissions: For SQLite deployments, the directory
/var/lib/zabbixis created with ownership assigned to thezabbixuser and permissions set to0750. -
Nginx Configuration: Nginx configuration files are managed in
/data/nginx/user_conf.d/to handle reverse proxying for the application.
Databases¶
The application supports multiple database backends. The current implementation uses SQLite by default, but MySQL and PostgreSQL are also supported.
| Backend | Connection Method | Storage Location / Host |
|---|---|---|
| SQLite | Local File | /var/lib/zabbix/zabbix_proxy.db |
| MySQL/PostgreSQL | Network/Local Socket | 127.0.0.1 |
Docker Containers and Their Deployment¶
The deployment utilizes a Docker container to manage SSL certificates and Nginx reverse proxying via Docker Compose.
Nginx-Certbot Container
-
Image:
jonasal/nginx-certbot:latest -
Ports: Uses
hostnetwork mode (mapping directly to host ports). -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(User configuration files) -
Environment Variables:
-
Restart Policy:
unless-stopped
Application Update Instructions¶
To update the Zabbix Proxy application, perform the following steps:
-
Update the local package index:
-
Upgrade the installed packages:
-
Restart the service to apply changes:
Location of configuration files and data¶
| Component | Path |
|---|---|
| Main Configuration File | /etc/zabbix/zabbix_proxy.conf |
| SQLite Database File | /var/lib/zabbix/zabbix_proxy.db |
| Nginx User Configs | /data/nginx/user_conf.d/ |
| Docker Compose (Nginx) | /root/nginx/compose.yml |
Available ports for connection¶
-
External HTTPS:
443(via Nginx proxy) -
Internal Proxy Port:
8083(used for internal routing between Nginx and the application)