HTTPDwatch

Self-hosted edition

Users and sign-in

Roles

Role Can
viewer see everything, change nothing
operator also run lifecycle commands (start, stop, restart, reload)
admin also manage instances, agents, settings, users and the license

Roles are enforced by the server on every request — hiding a button in the browser does not grant access to what it does.

How many users

Your license sets how many admins and operators you can have: Free is a single user, Starter up to 3, Professional up to 10 and Enterprise 20. Viewers are unlimited from Starter up. When the limit is reached, adding or promoting an admin/operator is refused — in the browser and in the users command — until you add the person as a viewer or upgrade. Need more Enterprise users? We raise the number on your license key; nothing to reinstall.

Managing users

Admins add, edit, disable and remove users on the Users page (from the Starter license up), and everyone can change their own name and password under Profile in the menu behind their name. From the server's command line you can do the same — useful if every admin is locked out:

sudo runuser -u httpd-monitor -- httpd-monitor users list
sudo runuser -u httpd-monitor -- httpd-monitor users add jane 'S3cure-Passw0rd' operator
sudo runuser -u httpd-monitor -- httpd-monitor users passwd jane 'N3w-Passw0rd'

Sign-in methods

Besides local usernames and passwords, an admin can enable these in Settings (Authentication). Duo needs a Professional or Enterprise license; LDAP, SAML and OpenID Connect need Enterprise. Methods the license doesn't include aren't shown and can't be used to sign in.

  • Duo Universal MFA — per user: set a user's sign-in type to Duo and they approve every sign-in on their phone. Needs a Duo "Web SDK" application (client ID, client secret, API hostname) with the redirect URI https://your-server/httpdmon/auth/duo/callback.
  • LDAP / Active Directory — users sign in with their directory password; their role comes from directory group membership.
  • SAML 2.0 and OpenID Connect — a "Sign in with …" button for your identity provider (Azure AD / Entra ID, Okta, Oracle IDCS, Keycloak, ADFS …). The role comes from the provider's group claim.

Authentication settings and their secrets are stored in /var/lib/httpd-monitor, which only the httpd-monitor service account can read.