Monitoring with Netdata
Netdata provides real-time system metrics (CPU, RAM, disk, network, services) with a lightweight web dashboard. This guide covers installation via script on a HolyCloud Linux VPS and hardening the firewall on port 19999.
Prerequisites
- Linux VPS with root SSH access
- At least 512 MB free RAM for the agent
- Ports: 19999 (local web interface or restricted)
Installation via the official script
Update the system, then run the one-liner installer (check the official Netdata page for the latest command):
apt update && apt install -y curl
curl https://get.netdata.cloud/kickstart.sh -o /tmp/netdata-kickstart.sh
sh /tmp/netdata-kickstart.sh --non-interactive
Variant with common options (no cloud claim if you do not use Netdata Cloud):
sh /tmp/netdata-kickstart.sh --non-interactive --stable-channel
Verify the service:
systemctl enable --now netdata
systemctl status netdata
Local dashboard access
By default, Netdata listens on all interfaces:
ss -tlnp | grep 19999
curl -s http://127.0.0.1:19999/api/v1/info | head
Test from your workstation via SSH tunnel (recommended before opening the port):
ssh -L 19999:127.0.0.1:19999 root@VOTRE_IP_VPS
Then open http://localhost:19999 in the browser.
Restrict listening (optional)
To listen only locally, edit /etc/netdata/netdata.conf ([web] section):
[web]
bind to = 127.0.0.1
Restart:
systemctl restart netdata
Firewall: allow port 19999 carefully
UFW (Ubuntu/Debian)
Allow the port only from a fixed admin IP:
ufw allow from VOTRE_IP_ADMIN to any port 19999 proto tcp comment 'Netdata'
ufw deny 19999/tcp
ufw reload
ufw status numbered
firewalld (if used)
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="VOTRE_IP_ADMIN" port port="19999" protocol="tcp" accept'
firewall-cmd --reload
Security: do not expose 19999 publicly without authentication. Prefer SSH tunnel or a reverse proxy with authentication.
Metrics and retention
Check configuration:
grep -E 'memory mode|history' /etc/netdata/netdata.conf
Useful logs:
journalctl -u netdata -f --no-pager
Uninstall
/opt/netdata/bin/uninstall-netdata.sh --yes
# or per the method indicated by the install script
Troubleshooting
| ---------- | -------- |
|---|---|
| Page unreachable | systemctl restart netdata, check bind to and UFW |
| Disk space | Adjust retention in netdata.conf |
Need help?
For centralized monitoring (Prometheus, Grafana), contact HolyCloud support for best practices on your plan.