Cockpit is a lightweight web console for Linux servers maintained by Red Hat and the Cockpit community. It shows live CPU, memory, disk and network usage, and lets you manage systemd services, read the journal, create users, handle storage and open a terminal, all using your normal system accounts. In this tutorial you will install Cockpit on Ubuntu 24.04, lock down access, install a trusted certificate and add the Podman module for containers.

Prerequisites

To follow this guide you need:

  • A server running Ubuntu 24.04 LTS, for example a CubePath VPS. Cockpit itself needs very little memory; 1 GB of RAM is plenty.
  • A non-root user with sudo privileges and a password set (Cockpit logs in with system passwords, not SSH keys).
  • UFW enabled with SSH allowed.
  • For the TLS step: a domain name (your_domain) with an A record pointing to your server's IP (your_server_ip), and port 80 reachable.

Cockpit ships in the default repositories of Debian 12 and Rocky Linux 9 too. On Rocky it is usually preinstalled and only needs sudo systemctl enable --now cockpit.socket and sudo firewall-cmd --permanent --add-service=cockpit.

Step 1 - Installing Cockpit

Ubuntu 24.04 includes Cockpit in its archive, and the Cockpit project recommends installing it from the backports pocket, which carries newer releases that are still built and tested for Ubuntu. Backports is enabled by default on Ubuntu 24.04, but packages from it are only installed when you ask for them explicitly:

sudo apt update
. /etc/os-release
sudo apt install -t ${VERSION_CODENAME}-backports cockpit

The cockpit metapackage pulls in the web service (cockpit-ws), the system, storage, networking and software updates pages.

Cockpit uses systemd socket activation: cockpit.socket listens on port 9090 and starts the web service only when a connection arrives. Enable and start the socket:

sudo systemctl enable --now cockpit.socket

Verify that the socket is listening:

sudo systemctl status cockpit.socket
● cockpit.socket - Cockpit Web Service Socket
     Loaded: loaded (...; enabled; preset: enabled)
     Active: active (listening) since ...
     Listen: [::]:9090 (Stream)

Step 2 - Allowing access through the firewall

Cockpit gives administrative access to the server, so open port 9090 only to the address you manage the server from (your_admin_ip):

sudo ufw allow from your_admin_ip to any port 9090 proto tcp

Check the rule:

sudo ufw status
To                         Action      From
--                         ------      ----
OpenSSH                    ALLOW       Anywhere
9090/tcp                   ALLOW       your_admin_ip

If you prefer not to expose the port at all, skip the rule and use an SSH tunnel from your workstation with ssh -L 9090:127.0.0.1:9090 your_user@your_server_ip, then browse to https://localhost:9090.

Step 3 - Logging in

Open https://your_server_ip:9090. Cockpit generates a self-signed certificate on first start, so accept the browser warning once (you will replace it in Step 4).

Log in with your sudo user and its password. Cockpit starts in limited access mode; click Limited access in the top bar and enter your password again to switch to Administrative access, which lets Cockpit run privileged actions through sudo.

The Overview page shows health, usage graphs and system information. The left menu gives access to:

PageWhat you can do
LogsFilter the systemd journal by priority, service and time
StorageView disks and partitions, mount file systems, create LVM volumes
NetworkingView interfaces and traffic (editing requires NetworkManager)
AccountsCreate users, set passwords, add them to groups, lock accounts
ServicesStart, stop, enable and disable systemd units and timers
Software updatesList and apply package updates
TerminalA full shell in the browser as your user

Step 4 - Installing a Let's Encrypt certificate

Cockpit reads certificates from /etc/cockpit/ws-certs.d/. It uses the file that sorts last alphabetically, and a .crt file needs a matching .key file with the same name.

Get a certificate with Certbot in standalone mode, which briefly uses port 80 for the HTTP-01 challenge:

sudo apt install certbot
sudo ufw allow 80/tcp
sudo certbot certonly --standalone -d your_domain

Create a deploy hook that copies the certificate into Cockpit's directory and restarts the web service. Certbot runs every executable file in /etc/letsencrypt/renewal-hooks/deploy/ after each successful renewal:

sudo nano /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh
#!/usr/bin/env bash
set -euo pipefail

domain="your_domain"
install -m 644 "/etc/letsencrypt/live/${domain}/fullchain.pem" "/etc/cockpit/ws-certs.d/50-${domain}.crt"
install -m 600 "/etc/letsencrypt/live/${domain}/privkey.pem" "/etc/cockpit/ws-certs.d/50-${domain}.key"
systemctl try-restart cockpit.service

Make the hook executable and run it once by hand to install the certificate you just obtained:

sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh
sudo /etc/letsencrypt/renewal-hooks/deploy/cockpit.sh

Confirm which certificate Cockpit will use. The output should name /etc/cockpit/ws-certs.d/50-your_domain.crt, which sorts after the self-signed 0-self-signed.crt:

sudo /usr/lib/cockpit/cockpit-certificate-ensure --check

Finally, test that automatic renewal works:

sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/your_domain/fullchain.pem (success)

Keep port 80 open, since standalone renewals need it. Browse to https://your_domain:9090 and check that the browser no longer shows a warning.

Step 5 - Adjusting the configuration

Cockpit's main configuration file is /etc/cockpit/cockpit.conf. It does not exist by default. Create it to log out idle sessions after 15 minutes:

sudo nano /etc/cockpit/cockpit.conf
[Session]
IdleTimeout=15

Restart the web service to apply it:

sudo systemctl restart cockpit.service

The listening port is not set in cockpit.conf but in the systemd socket. To move Cockpit to port 9443, create an override:

sudo systemctl edit cockpit.socket

Add these lines in the editable area. The empty ListenStream= clears the default port before setting the new one:

[Socket]
ListenStream=
ListenStream=9443

Reload systemd and restart the socket, then update the firewall rule:

sudo systemctl daemon-reload
sudo systemctl restart cockpit.socket
sudo ufw allow from your_admin_ip to any port 9443 proto tcp
sudo ufw delete allow from your_admin_ip to any port 9090 proto tcp

Check the new port with sudo ss -tlnp | grep 9443.

Step 6 - Adding the Podman containers module

Extra pages are installed as separate packages. The most useful on a server is cockpit-podman, which manages Podman containers, images and pods:

sudo apt install cockpit-podman

Reload the Cockpit page in your browser and a Podman containers entry appears in the menu. Start the Podman service from that page when prompted, then pull an image and run a test container, for example docker.io/library/nginx:latest with port 8080 published to 80.

Verify from the terminal that the container exists:

sudo podman ps
CONTAINER ID  IMAGE                           COMMAND               CREATED        STATUS        PORTS                 NAMES
3f1c2a9b8d7e  docker.io/library/nginx:latest  nginx -g daemon o...  1 minute ago   Up 1 minute   0.0.0.0:8080->80/tcp  web

Other modules available in Ubuntu 24.04 include cockpit-machines for KVM virtual machines (requires libvirt) and cockpit-pcp, which stores performance metrics so the Overview graphs show history instead of only live data.

Troubleshooting

The browser times out on port 9090. Check that the socket is listening with sudo systemctl status cockpit.socket and that UFW allows your current IP. For login errors, read the logs with sudo journalctl -u cockpit.

Networking shows interfaces as unmanaged. Ubuntu Server configures the network with netplan and systemd-networkd, while Cockpit's Networking page edits connections through NetworkManager. You can still see traffic, but change the configuration in /etc/netplan/ unless you move the server to NetworkManager.

Software updates cannot refresh the package cache. This page uses PackageKit, which also depends on NetworkManager to decide whether the machine is online. On servers configured with systemd-networkd, run sudo apt update && sudo apt upgrade from the terminal instead.

Conclusion

You installed Cockpit on Ubuntu 24.04, restricted it to your admin IP, replaced the self-signed certificate with a Let's Encrypt one that renews automatically, and added container management with Podman. As next steps, install cockpit-pcp to keep metrics history, or add other servers from the host switcher in the top-left corner so one Cockpit instance can manage several machines over SSH.