Open source · Self-hosted · Docker

Nginx stays the engine.
NGX Ops runs the rest.

An open-source operations stack for Nginx reverse proxies: monitoring, GitOps deployment, SSL, live logs, CrowdSec and WAF — without a new configuration language to learn.

ngx-ops · deploy
  1. $ git push origin main
  2. → webhook received · deploying 3 changed files
  3. ✓ pull sites/app.example.com.conf
  4. ✓ backup snapshot 2026-10-05T14:02:11Z
  5. ✓ validate nginx: configuration file test is successful
  6. ✓ deploy 3 files applied
  7. ✓ reload signal process started
  8. live in 1.8s — 0 dropped connections
  9. $
100%
native Nginx config
3
images: standard, ModSecurity, Coraza
0
new DSL to learn
Self-hosted
your servers, your data

Philosophy

If you know Nginx, you already know NGX Ops.

Packaged reverse proxies make you learn their syntax, their conventions and their limits. NGX Ops does the opposite: your configuration is plain Nginx, in plain files.

Keep using map, limit_req, proxy_cache, GeoIP and every native directive. Disable a site by renaming site.conf to site.conf.DISABLE. NGX Ops adds the tooling around the engine — never a layer on top of it.

tree
nginx/config/
├── conf.d/      # http { } context
├── sites/       # virtual hosts
│   ├── app.example.com.conf
│   └── old-site.conf.DISABLE
├── snippets/    # reusable fragments
└── streams/     # TCP / UDP

Migration

Already running Nginx? You're already halfway there.

NGX Ops reads the same .conf files as your current server. No converter, no import wizard, no proprietary format: copy your files, validate, reload.

/etc/nginx — your current server

  • sites-enabled/app.conf
  • sites-enabled/api.conf
  • conf.d/rate-limit.conf
  • snippets/ssl-params.conf

nginx/config — NGX Ops

  • sites/app.conf
  • sites/api.conf
  • conf.d/rate-limit.conf
  • snippets/ssl-params.conf
  • Copy, don’t rewrite

    Vhosts, map, limit_req, proxy_cache, snippets: they keep working as they are — at most a path to adjust.

  • Validated before going live

    nginx -t runs from the dashboard before every reload. Move one site at a time, at your own pace.

  • No lock-in

    Want to leave? Your configuration is plain Nginx. Take your files and run them on any Nginx server.

Features

Everything you need to operate Nginx.

Configuration, monitoring, logs, security and deployment tools — together, around the Nginx you already trust.

Real-time monitoring

Requests, traffic, connections, status codes, upstreams and virtual hosts from live Nginx VTS metrics.

Native config management

Edit, test (nginx -t) and reload from the dashboard. Your files stay standard Nginx files.

GitOps deployment

Version your configuration and ship it through a controlled pull → validate → reload pipeline.

Let's Encrypt, HTTP or DNS

Issue certificates with the HTTP-01 challenge in a few clicks, or DNS-01 for wildcards and internal hosts. PEM/KEY import too.

Dynamic DNS with GoDNS

Your DNS records follow your public IP automatically — perfect for home labs and connections without a fixed IP.

Emulated WAF

The analysis agent reads your logs and flags brute force, scans, floods and scraping with detection rules — WAF-like protection without loading a WAF module.

CrowdSec & IP blocklists

Follow CrowdSec decisions and scenarios, and apply IP blocklists right next to your vhosts.

ModSecurity & Coraza

Need a real WAF? Switch to the ModSecurity image, or try the next-generation Coraza (experimental).

GoAccess analytics

Visitors, top URLs, referrers, bots, status codes — real-time web analytics built from your own access logs, with no tracker on your sites.

Live logs & traffic map

Tail access and error logs, detect volume and geographic anomalies, and see where requests come from.

Custom error pages

Replace bland Nginx 4xx/5xx pages with modern ones — enable it in the dashboard, add one include, done.

Docker auto-configuration

Expose containers with labels — locally or on a remote Docker host — no hand-written vhost needed.

Backend health checks

Monitor your upstream backends and get a clear diagnostic when something goes wrong.

Backups & cache

Automatic snapshots before every deployment, and file-cache management from the UI.

REST API & webhooks

Plug NGX Ops into your automation, CI pipelines and infrastructure workflows.

GitOps

Deploy with confidence.

Every change follows the same safe path. If validation fails, nothing touches production.

  1. 01

    Pull

    Fetch the latest configuration from your Git repository.

  2. 02

    Backup

    Snapshot the running configuration so you can roll back.

  3. 03

    Validate

    Run nginx -t against the new configuration.

  4. 04

    Deploy

    Apply the validated files.

  5. 05

    Reload

    Graceful reload — zero dropped connections.

Images

Pick the engine that fits.

Same configuration, same dashboard. Only the security layer changes.

nginx:1.30.4

Standard

Stable Nginx. Everything you need for a classic reverse proxy — with the emulated WAF from the analysis agent.

nginx:1.30.4-waf

ModSecurity

Adds a proven WAF layer with ModSecurity and its rule sets.

nginx:1.30.4-coraza Experimental

Coraza

The next-generation WAF, natively compatible with OWASP CRS.

NGX Ops Intelligence

A threat feed built by the community.

NGX Ops instances can share what they see. NGX Ops Intelligence aggregates those signals into a community IP reputation — published as plain-text lists any Nginx, firewall or CrowdSec setup can consume.

Open NGX Ops Intelligence

Integrations

One dashboard. Your tools.

  • Nginx
  • Git
  • Nginx VTS
  • Let's Encrypt
  • CrowdSec
  • ModSecurity
  • Coraza
  • GoAccess
  • GoDNS
  • GeoIP
  • Docker
  • REST API
  • Webhooks

Deployment

Simple to deploy. Simple to run.

A Linux server with Docker is all you need. The get.sh script fetches the stack, you fill in one .env, and you’re live. The installation guide covers every option.
  • One Docker Compose stackNothing to install on the host, no dependency to manage. Updating is a docker compose pull.
  • One .env fileDomains, ports and options live in a single, readable file.
  • Modular by designCrowdSec, GoAccess, GoDNS, error pages, WAF… enable only what you need.
bash
mkdir -p /containers/ngxopscd /containers/ngxopsbash <(wget -qO- https://forge.rdr-it.com/romain/Docker-Compose/raw/branch/main/get.sh) ngxopscp sample.env .envdocker compose up

Run the first start without -d: the generated admin password is printed in the output. Write it down, then Ctrl+C and restart with docker compose up -d.

Take control of your Nginx infrastructure.

Monitor. Manage. Deploy. Secure.