GuidesBusiness and monitoringMonitoring with Zabbix

Monitor your servers with Zabbix and rootless Podman

Zabbix 7.0 LTS on Debian 13 in rootless Podman under a user of its own behind Caddy, watching the server itself and your other servers through agents that send their data encrypted.

Tested on Zabbix 7.0.31 on Debian 13 (trixie) on a Melonslab server Updated September 26, 2026

Recommended server for this guide

VC-S Micro · 2 vCPU · 8 GB Memory · 250 GB Storage

Month to month, no lock-in 7-day money-back guarantee

€7.99/mo

Deploy now
On this page

What you will set up

Zabbix collects figures from your servers, such as CPU, memory, disk space and network traffic, draws graphs of them, and opens a problem when something goes wrong, such as a full disk or a server that stops answering.

Here the Zabbix server, its web interface and its PostgreSQL database run in a pod under a user of its own called monitoring, behind Caddy from the Podman guide. Each server you watch runs the Zabbix agent, which sends its figures to Zabbix. The agent on another server sends them encrypted with a key you create, which is called PSK.

Every step below was run on a Melonslab server with Debian 13:

  • Zabbix 7.0.31 set up its database by itself, and its web interface logged each visitor's real address.
  • The agent on the server collected its CPU, memory and disk figures. When it was stopped, Zabbix opened the problem Zabbix agent is not available after three minutes, and closed it within a minute of the agent starting again.
  • An agent on a Debian 13 machine at another address sent its figures encrypted with PSK.
  • Everything came back by itself after a reboot.

The pod used about 115 MB of memory while watching two servers.

Before you start

You need:

  • a server set up as in the Podman guide, with Caddy running, and ufw from the security guide;
  • an A record and an AAAA record for zabbix.example.com pointing at your server.

The examples use zabbix.example.com for Zabbix, 203.0.113.10 for your server's IPv4 address, which ip -brief address show eth0 shows, and 198.51.100.30 for another server you want to watch. Replace them throughout.

This guide uses Zabbix 7.0, the current long-term support release, with full support until June 2027 and security fixes until June 2029.

1. Create the user

As root:

useradd -m -s /bin/bash monitoring
loginctl enable-linger monitoring
machinectl shell monitoring@

The user is not called zabbix, because the agent in step 7 creates a system user with that name.

2. Create the database password

openssl rand -hex 24 | tr -d '\n' | podman secret create zabbix-db-password -

3. Describe the pod

mkdir -p ~/.config/containers/systemd
cd ~/.config/containers/systemd

Create zabbix.pod:

[Pod]
PodName=zabbix
# The web interface, reached through Caddy only
PublishPort=127.0.0.1:8094:8080
# Agents send their data here
PublishPort=10051:10051

[Install]
WantedBy=default.target

Create zabbix-db.container:

[Container]
ContainerName=zabbix-db
Image=docker.io/library/postgres:16-alpine
Pod=zabbix.pod
Volume=zabbix-db:/var/lib/postgresql/data
Environment=POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry

[Service]
Restart=always

Create zabbix-server.container:

[Unit]
After=zabbix-db.service

[Container]
ContainerName=zabbix-server
Image=docker.io/zabbix/zabbix-server-pgsql:alpine-7.0-latest
Pod=zabbix.pod
Environment=DB_SERVER_HOST=127.0.0.1 POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry

[Service]
Restart=always

And zabbix-web.container:

[Unit]
After=zabbix-server.service

[Container]
ContainerName=zabbix-web
Image=docker.io/zabbix/zabbix-web-nginx-pgsql:alpine-7.0-latest
Pod=zabbix.pod
Environment=DB_SERVER_HOST=127.0.0.1 POSTGRES_USER=zabbix POSTGRES_DB=zabbix
Environment=ZBX_SERVER_HOST=127.0.0.1 PHP_TZ=Europe/Stockholm
# Caddy's connections reach the pod from the server's own IPv4 address.
Environment=WEB_REAL_IP_FROM=203.0.113.10 WEB_REAL_IP_HEADER=X-Forwarded-For
Secret=zabbix-db-password,type=env,target=POSTGRES_PASSWORD
AutoUpdate=registry

[Service]
Restart=always

The tag alpine-7.0-latest follows every release of Zabbix 7.0. PHP_TZ sets the time zone the web interface shows times in.

4. Start it

systemctl --user daemon-reload
systemctl --user start zabbix-pod
podman logs -f zabbix-server

On the first start, the server creates Zabbix's tables in the database, which takes a minute. When the log shows server #0 started, press Ctrl+C.

5. Put Caddy in front

Go back to root with exit, switch to machinectl shell caddy@, and add this block at the end of ~/Caddyfile:

zabbix.example.com {
    reverse_proxy 127.0.0.1:8094
}

Restart Caddy with systemctl --user restart caddy.

6. Log in and change the password

Open https://zabbix.example.com, and log in as Admin with the password zabbix. Change it at once:

  • Open User settings, then Profile, and choose Change password.
  • Enter zabbix as Current password, and your new password under Password and Password (once again).
  • Choose Update, and OK when Zabbix says that you will be logged out of all active sessions.

Then log in again with the new password.

7. Watch the server itself

As root, install the Zabbix agent from Zabbix's own repository:

cd /tmp
wget https://repo.zabbix.com/zabbix/7.0/debian/pool/main/z/zabbix-release/zabbix-release_latest_7.0+debian13_all.deb
dpkg -i zabbix-release_latest_7.0+debian13_all.deb
apt update
apt install -y zabbix-agent2

The agent already sends to 127.0.0.1 and calls itself Zabbix server, the host Zabbix created for itself. Zabbix also connects to the agent to ask for figures, and with rootless Podman its connections come from the server's own IPv4 address, so allow that address:

sed -i 's/^Server=127.0.0.1$/Server=203.0.113.10/' /etc/zabbix/zabbix_agent2.conf
systemctl restart zabbix-agent2

Then, in Zabbix:

  • Open Data collection, then Hosts, and choose Zabbix server.
  • Under Interfaces, enter host.containers.internal as the DNS name, and set Connect to to DNS.
  • Choose Update.

Inside the pod, host.containers.internal is the server outside it, where the agent runs. Within a minute, the red ZBX in the host list turns green, and Monitoring, Latest data shows the server's figures.

8. Watch another server

On the Zabbix server, as root, let the other server send to Zabbix:

ufw allow from 198.51.100.30 to any port 10051 proto tcp

On the other server, as root, install the agent as in step 7. For a system other than Debian 13, pick yours on Zabbix's download page. Then name it, point it at Zabbix, and create its key:

sed -i -e 's/^ServerActive=.*/ServerActive=zabbix.example.com/' -e 's/^Hostname=.*/Hostname=web1/' /etc/zabbix/zabbix_agent2.conf
openssl rand -hex 32 > /etc/zabbix/zabbix_agent2.psk
chown zabbix: /etc/zabbix/zabbix_agent2.psk
chmod 600 /etc/zabbix/zabbix_agent2.psk
printf 'TLSConnect=psk\nTLSPSKIdentity=web1\nTLSPSKFile=/etc/zabbix/zabbix_agent2.psk\n' >> /etc/zabbix/zabbix_agent2.conf
systemctl restart zabbix-agent2
cat /etc/zabbix/zabbix_agent2.psk

This agent only sends, so nothing on the other server needs to be opened. In Zabbix:

  • Open Data collection, then Hosts, and choose Create host.
  • Enter web1 as the Host name, the same as Hostname on the agent.
  • Under Templates, type Linux by Zabbix agent active, and pick it. Under Host groups, pick Linux servers.
  • Open the Encryption tab. Under Connections from host, untick No encryption and tick PSK. Enter web1 as the PSK identity, and the key that cat printed as the PSK.
  • Choose Add.

Within a couple of minutes, the new host's figures show under Monitoring, Latest data. From now on, Zabbix refuses data for web1 that is not encrypted with its key.

9. See the problems

Dashboards shows current problems, and Monitoring, Problems lists them all, with when each started and ended. The templates come with sensible limits, such as for disk space and memory. To get problems by email, set up Alerts, Media types, and add your address to your user under User settings, Profile, Media, as Zabbix's documentation describes.

10. Keep it up to date

As monitoring, turn on Podman's daily updates:

systemctl --user enable --now podman-auto-update.timer

That keeps Zabbix on the newest 7.0 release, and PostgreSQL on the newest 16. The agents come from Zabbix's repository, so run apt upgrade on each server for them: the unattended upgrades from the security guide install only Debian's own security updates. When a newer long-term support release of Zabbix comes out, read its upgrade notes before you change the tags.

11. Back up

As monitoring:

mkdir -p ~/backup
podman exec zabbix-db pg_dump -U zabbix -Fc zabbix > ~/backup/zabbix-db.dump

The database holds the hosts, templates, users and all the figures collected. Copy ~/backup to another machine.

Troubleshooting

The agent's log, /var/log/zabbix/zabbix_agent2.log, says connection from "203.0.113.10" rejected. The Server= line from step 7 still says 127.0.0.1.

The server's ZBX stays red. Check the interface from step 7: host.containers.internal, connected to DNS, port 10050.

Another server's agent log says connection of type "unencrypted" is not allowed. The TLS lines from step 8 are missing from the agent's configuration.

Another server's agent log says ssl/tls alert handshake failure. Zabbix does not know that agent yet, or its PSK identity or key differs from the one in step 8. Check that the host name in Zabbix is exactly the agent's Hostname.

Run it on your own server

VC-S Micro

€7.99/mo

vCPU
2
Memory
8 GB
Storage
250 GB
Transfer
10 TB
Standard
HDD · RAID 10
  • Full root access
  • Native /64 IPv6
  • RAID-protected storage
  • Malmö, Sweden
  • Month to month, no lock-in
  • 7-day money-back guarantee
All guides