Real-time monitoring
Requests, traffic, connections, status codes, upstreams and virtual hosts from live Nginx VTS metrics.
Open source · Self-hosted · Docker
An open-source operations stack for Nginx reverse proxies: monitoring, GitOps deployment, SSL, live logs, CrowdSec and WAF — without a new configuration language to learn.
Philosophy
Packaged reverse proxies make you learn their syntax, their conventions and their limits. NGX Ops does the opposite: your configuration is plain Nginx, in plain files.
Keep using map, limit_req, proxy_cache, GeoIP and every native directive. Disable a site by renaming site.conf to site.conf.DISABLE. NGX Ops adds the tooling around the engine — never a layer on top of it.
nginx/config/
├── conf.d/ # http { } context
├── sites/ # virtual hosts
│ ├── app.example.com.conf
│ └── old-site.conf.DISABLE
├── snippets/ # reusable fragments
└── streams/ # TCP / UDP
Migration
NGX Ops reads the same .conf files as your current server. No converter, no import wizard, no proprietary format: copy your files, validate, reload.
/etc/nginx — your current server
nginx/config — NGX Ops
Vhosts, map, limit_req, proxy_cache, snippets: they keep working as they are — at most a path to adjust.
nginx -t runs from the dashboard before every reload. Move one site at a time, at your own pace.
Want to leave? Your configuration is plain Nginx. Take your files and run them on any Nginx server.
Features
Configuration, monitoring, logs, security and deployment tools — together, around the Nginx you already trust.
Requests, traffic, connections, status codes, upstreams and virtual hosts from live Nginx VTS metrics.
Edit, test (nginx -t) and reload from the dashboard. Your files stay standard Nginx files.
Version your configuration and ship it through a controlled pull → validate → reload pipeline.
Issue certificates with the HTTP-01 challenge in a few clicks, or DNS-01 for wildcards and internal hosts. PEM/KEY import too.
Your DNS records follow your public IP automatically — perfect for home labs and connections without a fixed IP.
The analysis agent reads your logs and flags brute force, scans, floods and scraping with detection rules — WAF-like protection without loading a WAF module.
Follow CrowdSec decisions and scenarios, and apply IP blocklists right next to your vhosts.
Need a real WAF? Switch to the ModSecurity image, or try the next-generation Coraza (experimental).
Visitors, top URLs, referrers, bots, status codes — real-time web analytics built from your own access logs, with no tracker on your sites.
Tail access and error logs, detect volume and geographic anomalies, and see where requests come from.
Replace bland Nginx 4xx/5xx pages with modern ones — enable it in the dashboard, add one include, done.
Expose containers with labels — locally or on a remote Docker host — no hand-written vhost needed.
Monitor your upstream backends and get a clear diagnostic when something goes wrong.
Automatic snapshots before every deployment, and file-cache management from the UI.
Plug NGX Ops into your automation, CI pipelines and infrastructure workflows.
GitOps
Every change follows the same safe path. If validation fails, nothing touches production.
Fetch the latest configuration from your Git repository.
Snapshot the running configuration so you can roll back.
Run nginx -t against the new configuration.
Apply the validated files.
Graceful reload — zero dropped connections.
Images
Same configuration, same dashboard. Only the security layer changes.
nginx:1.30.4Stable Nginx. Everything you need for a classic reverse proxy — with the emulated WAF from the analysis agent.
nginx:1.30.4-wafAdds a proven WAF layer with ModSecurity and its rule sets.
nginx:1.30.4-coraza
ExperimentalThe next-generation WAF, natively compatible with OWASP CRS.
NGX Ops Intelligence
NGX Ops instances can share what they see. NGX Ops Intelligence aggregates those signals into a community IP reputation — published as plain-text lists any Nginx, firewall or CrowdSec setup can consume.
Open NGX Ops IntelligenceIntegrations
Deployment
get.sh script fetches the stack, you fill in one .env, and you’re live. The installation guide covers every option.docker compose pull..env fileDomains, ports and options live in a single, readable file.mkdir -p /containers/ngxopscd /containers/ngxopsbash <(wget -qO- https://forge.rdr-it.com/romain/Docker-Compose/raw/branch/main/get.sh) ngxopscp sample.env .envdocker compose upRun the first start without -d: the generated admin password is printed in the output. Write it down, then Ctrl+C and restart with docker compose up -d.
Monitor. Manage. Deploy. Secure.