What you will set up
Zabbix collects figures from your servers, such as CPU, memory, disk space and network traffic, draws graphs of them, and opens a problem when something goes wrong, such as a full disk or a server that stops answering.
Here the Zabbix server, its web interface and its PostgreSQL database run in a pod under a user of its own called monitoring, behind Caddy from the Podman guide. Each server you watch runs the Zabbix agent, which sends its figures to Zabbix. The agent on another server sends them encrypted with a key you create, which is called PSK.
Every step below was run on a Melonslab server with Debian 13:
- Zabbix 7.0.31 set up its database by itself, and its web interface logged each visitor's real address.
- The agent on the server collected its CPU, memory and disk figures. When it was stopped, Zabbix opened the problem
Zabbix agent is not availableafter three minutes, and closed it within a minute of the agent starting again. - An agent on a Debian 13 machine at another address sent its figures encrypted with PSK.
- Everything came back by itself after a reboot.
The pod used about 115 MB of memory while watching two servers.
Before you start
You need:
- a server set up as in the Podman guide, with Caddy running, and ufw from the security guide;
- an A record and an AAAA record for
zabbix.example.compointing at your server.
The examples use zabbix.example.com for Zabbix, 203.0.113.10 for your server's IPv4 address, which ip -brief address show eth0 shows, and 198.51.100.30 for another server you want to watch. Replace them throughout.
This guide uses Zabbix 7.0, the current long-term support release, with full support until June 2027 and security fixes until June 2029.
1. Create the user
As root:
useradd -m -s /bin/bash monitoring
loginctl enable-linger monitoring
machinectl shell monitoring@
The user is not called zabbix, because the agent in step 7 creates a system user with that name.
2. Create the database password
openssl rand -hex 24 | tr -d '\n' | podman secret create zabbix-db-password -
3. Describe the pod
mkdir -p ~/.config/containers/systemd
cd ~/.config/containers/systemd
Create zabbix.pod:
[Pod]
PodName=zabbix
# The web interface, reached through Caddy only
PublishPort=127.0.0.1:8094:8080
# Agents send their data here
PublishPort=10051:10051
[Install]
WantedBy=default.target
Create zabbix-db.container:
[Container]
ContainerName=zabbix-db
Image=docker.io/library/postgres:16-alpine
Pod=zabbix.pod
Volume=zabbix-db:/var/lib/postgresql/data
Environment=POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry
[Service]
Restart=always
Create zabbix-server.container:
[Unit]
After=zabbix-db.service
[Container]
ContainerName=zabbix-server
Image=docker.io/zabbix/zabbix-server-pgsql:alpine-7.0-latest
Pod=zabbix.pod
Environment=DB_SERVER_HOST=127.0.0.1 POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry
[Service]
Restart=always
And zabbix-web.container:
[Unit]
After=zabbix-server.service
[Container]
ContainerName=zabbix-web
Image=docker.io/zabbix/zabbix-web-nginx-pgsql:alpine-7.0-latest
Pod=zabbix.pod
Environment=DB_SERVER_HOST=127.0.0.1 POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Environment=ZBX_SERVER_HOST=127.0.0.1 PHP_TZ=Europe/Stockholm
# Caddy's connections reach the pod from the server's own IPv4 address.
Environment=WEB_REAL_IP_FROM=203.0.113.10 WEB_REAL_IP_HEADER=X-Forwarded-For
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry
[Service]
Restart=always
The tag alpine-7.0-latest follows every release of Zabbix 7.0. PHP_TZ sets the time zone the web interface shows times in.
4. Start it
systemctl --user daemon-reload
systemctl --user start zabbix-pod
podman logs -f zabbix-server
On the first start, the server creates Zabbix's tables in the database, which takes a minute. When the log shows server #0 started, press Ctrl+C.
5. Put Caddy in front
Go back to root with exit, switch to machinectl shell caddy@, and add this block at the end of ~/Caddyfile:
zabbix.example.com {
reverse_proxy 127.0.0.1:8094
}
Restart Caddy with systemctl --user restart caddy.
6. Log in and change the password
Open https://zabbix.example.com, and log in as Admin with the password zabbix. Change it at once:
- Open User settings, then Profile, and choose Change password.
- Enter
zabbixas Current password, and your new password under Password and Password (once again). - Choose Update, and OK when Zabbix says that you will be logged out of all active sessions.
Then log in again with the new password.
7. Watch the server itself
As root, install the Zabbix agent from Zabbix's own repository:
cd /tmp
wget https://repo.zabbix.com/zabbix/7.0/debian/pool/main/z/zabbix-release/zabbix-release_latest_7.0+debian13_all.deb
dpkg -i zabbix-release_latest_7.0+debian13_all.deb
apt update
apt install -y zabbix-agent2
The agent already sends to 127.0.0.1 and calls itself Zabbix server, the host Zabbix created for itself. Zabbix also connects to the agent to ask for figures, and with rootless Podman its connections come from the server's own IPv4 address, so allow that address:
sed -i 's/^Server=127.0.0.1$/Server=203.0.113.10/' /etc/zabbix/zabbix_agent2.conf
systemctl restart zabbix-agent2
Then, in Zabbix:
- Open Data collection, then Hosts, and choose Zabbix server.
- Under Interfaces, enter
host.containers.internalas the DNS name, and set Connect to to DNS. - Choose Update.
Inside the pod, host.containers.internal is the server outside it, where the agent runs. Within a minute, the red ZBX in the host list turns green, and Monitoring, Latest data shows the server's figures.
8. Watch another server
On the Zabbix server, as root, let the other server send to Zabbix:
ufw allow from 198.51.100.30 to any port 10051 proto tcp
On the other server, as root, install the agent as in step 7. For a system other than Debian 13, pick yours on Zabbix's download page. Then name it, point it at Zabbix, and create its key:
sed -i -e 's/^ServerActive=.*/ServerActive=zabbix.example.com/' -e 's/^Hostname=.*/Hostname=web1/' /etc/zabbix/zabbix_agent2.conf
openssl rand -hex 32 > /etc/zabbix/zabbix_agent2.psk
chown zabbix: /etc/zabbix/zabbix_agent2.psk
chmod 600 /etc/zabbix/zabbix_agent2.psk
printf 'TLSConnect=psk\nTLSPSKIdentity=web1\nTLSPSKFile=/etc/zabbix/zabbix_agent2.psk\n' >> /etc/zabbix/zabbix_agent2.conf
systemctl restart zabbix-agent2
cat /etc/zabbix/zabbix_agent2.psk
This agent only sends, so nothing on the other server needs to be opened. In Zabbix:
- Open Data collection, then Hosts, and choose Create host.
- Enter
web1as the Host name, the same asHostnameon the agent. - Under Templates, type
Linux by Zabbix agent active, and pick it. Under Host groups, pickLinux servers. - Open the Encryption tab. Under Connections from host, untick No encryption and tick PSK. Enter
web1as the PSK identity, and the key thatcatprinted as the PSK. - Choose Add.
Within a couple of minutes, the new host's figures show under Monitoring, Latest data. From now on, Zabbix refuses data for web1 that is not encrypted with its key.
9. See the problems
Dashboards shows current problems, and Monitoring, Problems lists them all, with when each started and ended. The templates come with sensible limits, such as for disk space and memory. To get problems by email, set up Alerts, Media types, and add your address to your user under User settings, Profile, Media, as Zabbix's documentation describes.
10. Keep it up to date
As monitoring, turn on Podman's daily updates:
systemctl --user enable --now podman-auto-update.timer
That keeps Zabbix on the newest 7.0 release, and PostgreSQL on the newest 16. The agents come from Zabbix's repository, so run apt upgrade on each server for them: the unattended upgrades from the security guide install only Debian's own security updates. When a newer long-term support release of Zabbix comes out, read its upgrade notes before you change the tags.
11. Back up
As monitoring:
mkdir -p ~/backup
podman exec zabbix-db pg_dump -U zabbix -Fc zabbix > ~/backup/zabbix-db.dump
The database holds the hosts, templates, users and all the figures collected. Copy ~/backup to another machine.
Troubleshooting
The agent's log, /var/log/zabbix/zabbix_agent2.log, says connection from "203.0.113.10" rejected. The Server= line from step 7 still says 127.0.0.1.
The server's ZBX stays red. Check the interface from step 7: host.containers.internal, connected to DNS, port 10050.
Another server's agent log says connection of type "unencrypted" is not allowed. The TLS lines from step 8 are missing from the agent's configuration.
Another server's agent log says ssl/tls alert handshake failure. Zabbix does not know that agent yet, or its PSK identity or key differs from the one in step 8. Check that the host name in Zabbix is exactly the agent's Hostname.