Cockpit is a lightweight web console for Linux servers maintained by Red Hat and the Cockpit community. It shows live CPU, memory, disk and network usage, and lets you manage systemd services, read the journal, create users, handle storage and open a terminal, all using your normal system accounts. In this tutorial you will install Cockpit on Ubuntu 24.04, lock down access, install a trusted certificate and add the Podman module for containers.
Prerequisites
To follow this guide you need:
- A server running Ubuntu 24.04 LTS, for example a CubePath VPS. Cockpit itself needs very little memory; 1 GB of RAM is plenty.
- A non-root user with
sudoprivileges and a password set (Cockpit logs in with system passwords, not SSH keys). - UFW enabled with SSH allowed.
- For the TLS step: a domain name (
your_domain) with an A record pointing to your server's IP (your_server_ip), and port 80 reachable.
Cockpit ships in the default repositories of Debian 12 and Rocky Linux 9 too. On Rocky it is usually preinstalled and only needs sudo systemctl enable --now cockpit.socket and sudo firewall-cmd --permanent --add-service=cockpit.
Step 1 - Installing Cockpit
Ubuntu 24.04 includes Cockpit in its archive, and the Cockpit project recommends installing it from the backports pocket, which carries newer releases that are still built and tested for Ubuntu. Backports is enabled by default on Ubuntu 24.04, but packages from it are only installed when you ask for them explicitly:
sudo apt update
. /etc/os-release
sudo apt install -t ${VERSION_CODENAME}-backports cockpit
The cockpit metapackage pulls in the web service (cockpit-ws), the system, storage, networking and software updates pages.
Cockpit uses systemd socket activation: cockpit.socket listens on port 9090 and starts the web service only when a connection arrives. Enable and start the socket:
sudo systemctl enable --now cockpit.socket
Verify that the socket is listening:
sudo systemctl status cockpit.socket
● cockpit.socket - Cockpit Web Service Socket
Loaded: loaded (...; enabled; preset: enabled)
Active: active (listening) since ...
Listen: [::]:9090 (Stream)
Step 2 - Allowing access through the firewall
Cockpit gives administrative access to the server, so open port 9090 only to the address you manage the server from (your_admin_ip):
sudo ufw allow from your_admin_ip to any port 9090 proto tcp
Check the rule:
sudo ufw status
To Action From
-- ------ ----
OpenSSH ALLOW Anywhere
9090/tcp ALLOW your_admin_ip
If you prefer not to expose the port at all, skip the rule and use an SSH tunnel from your workstation with ssh -L 9090:127.0.0.1:9090 your_user@your_server_ip, then browse to https://localhost:9090.
Step 3 - Logging in
Open https://your_server_ip:9090. Cockpit generates a self-signed certificate on first start, so accept the browser warning once (you will replace it in Step 4).
Log in with your sudo user and its password. Cockpit starts in limited access mode; click Limited access in the top bar and enter your password again to switch to Administrative access, which lets Cockpit run privileged actions through sudo.
NoteThe
rootuser cannot log in by default because it is listed in/etc/cockpit/disallowed-users. Keep it that way and use a sudo user.
The Overview page shows health, usage graphs and system information. The left menu gives access to:
| Page | What you can do |
|---|---|
| Logs | Filter the systemd journal by priority, service and time |
| Storage | View disks and partitions, mount file systems, create LVM volumes |
| Networking | View interfaces and traffic (editing requires NetworkManager) |
| Accounts | Create users, set passwords, add them to groups, lock accounts |
| Services | Start, stop, enable and disable systemd units and timers |
| Software updates | List and apply package updates |
| Terminal | A full shell in the browser as your user |
Step 4 - Installing a Let's Encrypt certificate
Cockpit reads certificates from /etc/cockpit/ws-certs.d/. It uses the file that sorts last alphabetically, and a .crt file needs a matching .key file with the same name.
Get a certificate with Certbot in standalone mode, which briefly uses port 80 for the HTTP-01 challenge:
sudo apt install certbot
sudo ufw allow 80/tcp
sudo certbot certonly --standalone -d your_domain
Create a deploy hook that copies the certificate into Cockpit's directory and restarts the web service. Certbot runs every executable file in /etc/letsencrypt/renewal-hooks/deploy/ after each successful renewal:
sudo nano /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh
#!/usr/bin/env bash
set -euo pipefail
domain="your_domain"
install -m 644 "/etc/letsencrypt/live/${domain}/fullchain.pem" "/etc/cockpit/ws-certs.d/50-${domain}.crt"
install -m 600 "/etc/letsencrypt/live/${domain}/privkey.pem" "/etc/cockpit/ws-certs.d/50-${domain}.key"
systemctl try-restart cockpit.service
Make the hook executable and run it once by hand to install the certificate you just obtained:
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh
sudo /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh
Confirm which certificate Cockpit will use. The output should name /etc/cockpit/ws-certs.d/50-your_domain.crt, which sorts after the self-signed 0-self-signed.crt:
sudo /usr/lib/cockpit/cockpit-certificate-ensure --check
Finally, test that automatic renewal works:
sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded:
/etc/letsencrypt/live/your_domain/fullchain.pem (success)
Keep port 80 open, since standalone renewals need it. Browse to https://your_domain:9090 and check that the browser no longer shows a warning.
Step 5 - Adjusting the configuration
Cockpit's main configuration file is /etc/cockpit/cockpit.conf. It does not exist by default. Create it to log out idle sessions after 15 minutes:
sudo nano /etc/cockpit/cockpit.conf
[Session]
IdleTimeout=15
Restart the web service to apply it:
sudo systemctl restart cockpit.service
The listening port is not set in cockpit.conf but in the systemd socket. To move Cockpit to port 9443, create an override:
sudo systemctl edit cockpit.socket
Add these lines in the editable area. The empty ListenStream= clears the default port before setting the new one:
[Socket]
ListenStream=
ListenStream=9443
Reload systemd and restart the socket, then update the firewall rule:
sudo systemctl daemon-reload
sudo systemctl restart cockpit.socket
sudo ufw allow from your_admin_ip to any port 9443 proto tcp
sudo ufw delete allow from your_admin_ip to any port 9090 proto tcp
Check the new port with sudo ss -tlnp | grep 9443.
Step 6 - Adding the Podman containers module
Extra pages are installed as separate packages. The most useful on a server is cockpit-podman, which manages Podman containers, images and pods:
sudo apt install cockpit-podman
Reload the Cockpit page in your browser and a Podman containers entry appears in the menu. Start the Podman service from that page when prompted, then pull an image and run a test container, for example docker.io/library/nginx:latest with port 8080 published to 80.
Verify from the terminal that the container exists:
sudo podman ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
3f1c2a9b8d7e docker.io/library/nginx:latest nginx -g daemon o... 1 minute ago Up 1 minute 0.0.0.0:8080->80/tcp web
Other modules available in Ubuntu 24.04 include cockpit-machines for KVM virtual machines (requires libvirt) and cockpit-pcp, which stores performance metrics so the Overview graphs show history instead of only live data.
NoteCockpit does not include a Docker module. If your server runs Docker instead of Podman, manage it from the Cockpit terminal or keep using the
dockerCLI.
Troubleshooting
The browser times out on port 9090. Check that the socket is listening with sudo systemctl status cockpit.socket and that UFW allows your current IP. For login errors, read the logs with sudo journalctl -u cockpit.
Networking shows interfaces as unmanaged. Ubuntu Server configures the network with netplan and systemd-networkd, while Cockpit's Networking page edits connections through NetworkManager. You can still see traffic, but change the configuration in /etc/netplan/ unless you move the server to NetworkManager.
Software updates cannot refresh the package cache. This page uses PackageKit, which also depends on NetworkManager to decide whether the machine is online. On servers configured with systemd-networkd, run sudo apt update && sudo apt upgrade from the terminal instead.
Conclusion
You installed Cockpit on Ubuntu 24.04, restricted it to your admin IP, replaced the self-signed certificate with a Let's Encrypt one that renews automatically, and added container management with Podman. As next steps, install cockpit-pcp to keep metrics history, or add other servers from the host switcher in the top-left corner so one Cockpit instance can manage several machines over SSH.
