Self-hosted edition
Users and sign-in
Roles
| Role | Can |
|---|---|
| viewer | see everything, change nothing |
| operator | also run lifecycle commands (start, stop, restart, reload) |
| admin | also manage instances, agents, settings, users and the license |
Roles are enforced by the server on every request — hiding a button in the browser does not grant access to what it does.
How many users
Your license sets how many admins and operators you can have: Free is a
single user, Starter up to 3, Professional up to 10 and Enterprise 20.
Viewers are unlimited from Starter up. When the limit is reached, adding or
promoting an admin/operator is refused — in the browser and in the
users command — until you add the person as a viewer or upgrade. Need more
Enterprise users? We raise the number on your license key; nothing to reinstall.
Managing users
Admins add, edit, disable and remove users on the Users page (from the Starter license up), and everyone can change their own name and password under Profile in the menu behind their name. From the server's command line you can do the same — useful if every admin is locked out:
sudo runuser -u httpd-monitor -- httpd-monitor users list
sudo runuser -u httpd-monitor -- httpd-monitor users add jane 'S3cure-Passw0rd' operator
sudo runuser -u httpd-monitor -- httpd-monitor users passwd jane 'N3w-Passw0rd'
Sign-in methods
Besides local usernames and passwords, an admin can enable these in Settings (Authentication). Duo needs a Professional or Enterprise license; LDAP, SAML and OpenID Connect need Enterprise. Methods the license doesn't include aren't shown and can't be used to sign in.
- Duo Universal MFA — per user: set a user's sign-in type to Duo and they
approve every sign-in on their phone. Needs a Duo "Web SDK" application
(client ID, client secret, API hostname) with the redirect URI
https://your-server/httpdmon/auth/duo/callback. - LDAP / Active Directory — users sign in with their directory password; their role comes from directory group membership.
- SAML 2.0 and OpenID Connect — a "Sign in with …" button for your identity provider (Azure AD / Entra ID, Okta, Oracle IDCS, Keycloak, ADFS …). The role comes from the provider's group claim.
Authentication settings and their secrets are stored in /var/lib/httpd-monitor,
which only the httpd-monitor service account can read.