Self-hosted edition
System requirements
ApacheWatch self-hosted has two parts: the ApacheWatch server (web dashboard, alerting, license) and an agent on each server running Apache httpd. Both install from RPM packages that contain everything they need — no Node.js, npm, Java or other runtime has to be installed, and an existing Node.js on the machine is never used or changed.
Verified on clean RHEL 8.10 and RHEL 9 systems (Red Hat UBI with systemd), October 2026.
ApacheWatch server — apache-monitor RPM
| Operating system | RHEL, Oracle Linux, Rocky Linux or AlmaLinux 8 or 9, x86_64 (glibc 2.28 or later), with systemd |
| CPU | 1 vCPU (2 recommended above ~20 monitored instances) |
| Memory | 71 MB measured idle right after install; allow 1 GB free for production use |
| Disk | ~90 MB for the program; 1 GB recommended for data (/var/lib/apache-monitor) and logs |
| Runs as | Its own unprivileged apache-monitor account (created by the package) |
| Listens on | TCP 3100 (PORT in /etc/apache-monitor/apache-monitor.env) — browsers and agents connect here |
| Outbound | HTTPS to the license server (devapex.cinnamonsservices.com:443): activation at start, a check every 12 h; it keeps running for 48 h if the license server is unreachable |
| Browser | Current Chrome, Edge, Firefox or Safari |
HTTPS: the server speaks plain HTTP on its port. For production, put it
behind your existing reverse proxy (nginx, Apache httpd, a load balancer) with
TLS, forwarding X-Forwarded-Proto; sign-in works on both.
Firewall: firewall-cmd --add-port=3100/tcp --permanent && firewall-cmd --reload
(or open only the reverse proxy's port).
First start: sudo dnf install ./apache-monitor-*.rpm starts the service and
prints the address (http://<server>:3100/apachemon/setup) and a one-time setup code. The setup
wizard registers your license — a free key by email (one installation per key)
or a paid key — and creates the first administrator.
Agent — apache-agent package, on each Apache httpd server
| Operating system | Same family as the server: RHEL / Oracle Linux / Rocky / AlmaLinux 8 or 9, x86_64, systemd |
| Footprint | One small program, a few MB of memory |
| Runs | as root in the current package (a dedicated account is planned) |
| Network | Outbound HTTPS to the ApacheWatch server and inbound TCP 7200 from the ApacheWatch server (configs and logs are fetched from the agent) — open it only to the server's address. |
Needs on the monitored host:
- Apache httpd with
mod_statusenabled on a local URL (ExtendedStatus On, e.g.http://localhost/server-status?auto) - Read access to the httpd configuration, logs and SSL certificate directory
The agent package was not part of this test round — its requirements are from its configuration template.
SELinux
Leave SELinux enforcing — nothing needs to be disabled, and no extra
policy package is required. The server and the agent are ordinary programs in
/usr/bin started by systemd, which RHEL's targeted policy runs in the
unconfined_service_t domain; what they can reach is limited by the
account each runs as (see Runs as above).
The one setting you may need is for a reverse proxy. If nginx or Apache httpd forwards HTTPS traffic to the ApacheWatch server, SELinux blocks the web server's outgoing connection to port 3100 by default (the browser shows 502 Bad Gateway). Allow it once:
sudo setsebool -P httpd_can_network_connect 1
To check for SELinux denials: sudo ausearch -m avc -ts recent.
Not supported yet
- Air-gapped installations — the server must reach the license server (first activation, and at least once every 48 h).
- ARM (aarch64), other Linux families as packages (Debian/Ubuntu), Windows.