Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

65 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Version Release License Docker Compose OpenSearch Grafana LibreNMS CI Tests Docker

πŸ”­ OpenHostingNOC

Self-hosted Network Operations Center for hosting providers
Monitor servers, network devices, customer bandwidth, and security threats β€” all from a single pane of glass.

Features β€’ Architecture β€’ Quick Start β€’ Documentation β€’ Contributing β€’ Code of Conduct


Features

πŸ“Š Infrastructure Monitoring

  • CPU, RAM, Disk, Temperature
  • RAID, SMART, Network Interfaces
  • Ping, Packet Loss, Latency
  • BGP Sessions, OSPF, WireGuard
  • Linux, Windows, Proxmox, VMware

πŸ”’ Security Detection

  • UDP/SYN/ICMP Floods
  • DNS/NTP/SSDP Amplification
  • Port Scanning, SSH Brute Force
  • DDoS Indicators
  • Suricata IDS/IPS (optional)

🌐 Traffic Analysis

  • NetFlow v5/v9, IPFIX, sFlow
  • Top Talkers, Top Ports, Top Protocols
  • 95th Percentile Billing
  • Per-IP Bandwidth Historical Graphs
  • Daily/Monthly Usage

πŸ“‘ Network Monitoring

  • LibreNMS SNMP Discovery
  • MikroTik, Cisco, Juniper, Arista
  • Fortinet, OPNsense, pfSense
  • Automated Config Backup (Oxidized)
  • Syslog Collection

🚨 Alerting

  • Telegram, Discord, Slack
  • Email, Webhook, PagerDuty
  • Warning / Critical / Emergency
  • Deduplication, Silencing
  • Maintenance Windows, Escalation

πŸ”§ Operations

  • Centralized Logging (Loki)
  • Container Monitoring (cAdvisor)
  • Automated Backups to S3
  • Health Checks & Self-Monitoring
  • LDAP/AD Authentication

Architecture

                    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                    β”‚      Traefik (HTTPS)      β”‚
                    β”‚  Reverse Proxy + TLS + LDAPβ”‚
                    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                               β”‚
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚                   β”‚                   β”‚
     β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”
     β”‚  Grafana   β”‚      β”‚  LibreNMS β”‚      β”‚   ntopng   β”‚
     β”‚ Dashboards β”‚      β”‚  Network  β”‚      β”‚   Traffic  β”‚
     β”‚ + Alerts   β”‚      β”‚ Monitoringβ”‚      β”‚  Analysis  β”‚
     β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
           β”‚                   β”‚                   β”‚
     β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”
     β”‚ Prometheus β”‚      β”‚ MariaDB   β”‚      β”‚  OpenSearchβ”‚
     β”‚  Metrics   β”‚      β”‚  + Redis  β”‚      β”‚  Security  β”‚
     β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
           β”‚                                       β”‚
     β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”                          β”Œβ”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”
     β”‚  Loki     β”‚                          β”‚  Suricata  β”‚
     β”‚  Logs     β”‚                          β”‚  (Optional)β”‚
     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Components

Service Role Port
Traefik Reverse proxy, TLS, rate limiting, LDAP auth 80, 443
Grafana Metrics dashboards, alerting UI 3000
Prometheus Metrics collection, alert evaluation 9090
Loki Log aggregation 3100
Alertmanager Alert routing, deduplication, notifications 9093
OpenSearch Security events, flow history, log analytics 9200
LibreNMS SNMP network discovery, syslog, billing 80
ntopng NetFlow/sFlow/IPFIX, DDoS detection 3000
MariaDB LibreNMS database 3306
Redis Cache and queue 6379

Supported Flow Protocols

Protocol Port Devices
NetFlow v5/v9 2055 UDP/TCP Cisco, Juniper, MikroTik, Linux (softflowd)
IPFIX 4739 UDP/TCP Cisco, Arista, Fortinet
sFlow 6343 UDP Arista, Fortinet, OPNsense

Quick Start

Prerequisites

  • Docker 24.0+ & Compose v2.20+
  • Ubuntu 22.04+ / Debian 12+ / Rocky Linux 9+
  • 4+ CPU cores, 16GB+ RAM, 200GB+ SSD

Option 0: Docker Image (all-in-one)

Pull the pre-built Docker image with all tools and configs included:

docker pull ghcr.io/samsesh/opennoc:latest
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock \
  -v "$(pwd)/.env:/opennoc/.env" \
  ghcr.io/samsesh/opennoc

Option 1: Quick Setup (no domain, no TLS, default passwords)

Try OpenHostingNOC in 2 commands β€” uses nip.io to auto-resolve your IP, HTTP only:

git clone https://github.com/samsesh/OpenHostingNOC.git
cd OpenHostingNOC
sudo ./scripts/install.sh    # Choose option 1 (Quick Setup)

Access at http://<YOUR_IP>:3000 (Grafana) β€” default credentials: admin / admin.

Option 2: Full Setup (production domain, Let's Encrypt TLS)

git clone https://github.com/samsesh/OpenHostingNOC.git
cd OpenHostingNOC
sudo ./scripts/install.sh    # Choose option 2 (Full Setup)

Requires a domain with wildcard DNS pointing to your server IP.

What the installer does

  1. Generates .env with your choice of quick or full settings
  2. Creates directory structure
  3. Pulls all Docker images
  4. Starts all 18+ services
  5. Waits for health checks
  6. Initializes LibreNMS
  7. Prints access URLs

Post-Install

./scripts/healthcheck.sh      # Check everything is healthy
docker compose ps             # View service status
docker compose logs -f        # Follow live logs

Access URLs

Quick setup (HTTP, no domain):

Service URL Default Credentials
Grafana http://<IP>:3000 admin / admin
Prometheus http://<IP>:9090 admin / admin (via SSO)
LibreNMS http://<IP>:8000 admin / admin (via LDAP)
ntopng http://<IP>:3003 admin / admin (via SSO)
Alertmanager http://<IP>:9093 via SSO
Loki http://<IP>:3100 via SSO
OpenSearch Dashboards http://<IP>:5601 admin / admin

Full setup (HTTPS, your domain):

Service URL Auth
Grafana https://grafana.$DOMAIN LDAP
LibreNMS https://librenms.$DOMAIN LDAP
ntopng https://ntopng.$DOMAIN LDAP via SSO
Prometheus https://prometheus.$DOMAIN LDAP via SSO
Alertmanager https://alertmanager.$DOMAIN LDAP via SSO
OpenSearch Dashboards https://dashboards.$DOMAIN admin + password

Use Cases

🏒 Hosting Provider NOC

  • Monitor hundreds of servers and thousands of customer IPs
  • Track per-customer bandwidth usage for billing (95th percentile)
  • Detect and alert on DDoS attacks targeting your infrastructure
  • SLA monitoring with ping/latency probes

🌐 ISP Network Operations

  • Monitor BGP sessions, OSPF neighbors, interface utilization
  • Collect NetFlow from core routers for traffic analysis
  • Config backup for all network devices via Oxidized
  • Security event correlation from Suricata and ntopng

🏭 Enterprise IT Operations

  • Unified monitoring across Linux/Windows/VMware/Proxmox
  • Centralized logging with Loki
  • Container monitoring with cAdvisor
  • RBAC via LDAP for team access control

Documentation

Full documentation is in the docs/ directory and GitHub Wiki:

Topic Docs Wiki
Installation Guide docs/installation Wiki
Configuration docs/configuration Wiki
NetFlow Examples docs/configuration/netflow-examples.md Wiki
Upgrade Guide docs/upgrade Wiki
Backup & Restore docs/backup Wiki
Troubleshooting docs/troubleshooting Wiki
High Availability docs/ha Wiki
Scaling docs/scaling Wiki
Security docs/security Wiki
Disaster Recovery docs/disaster-recovery Wiki

Scripts

Script Purpose
scripts/install.sh Full installation of all services
scripts/update.sh Update services with rollback support
scripts/backup.sh Backup all configs, databases, volumes
scripts/restore.sh Restore from any backup
scripts/healthcheck.sh Comprehensive system health check
scripts/cert-renew.sh Manual TLS certificate renewal trigger
scripts/db-optimize.sh MariaDB/OpenSearch index optimization
scripts/cleanup.sh Remove old data, logs, Docker artifacts
scripts/logrotate.sh Log rotation for non-Docker services

Alerting

Emergency ──── Telegram ──── Discord (@everyone) ──── Slack (@channel) ──── Email ──── Webhook
Critical ───── Telegram ──── Discord ──── Slack ──── Email ──── Webhook
Warning ────── Telegram ──── Email (digest)
Security ───── Telegram ──── Email (dedicated security channel)
Maintenance ── Silenced via Alertmanager

Security

  • TLS 1.3 with strong ciphers, HSTS preload
  • LDAP/AD authentication for all services
  • Rate limiting (100 req/s per IP)
  • Security headers (CSP, X-Frame-Options, etc.)
  • Network segmentation β€” 6 isolated Docker networks
  • Non-root containers with resource limits
  • Fail2Ban for SSH brute force protection
  • Suricata optional IDS/IPS with OpenSearch export
  • Automated backups with S3 off-site sync

Performance Sizing

Capacity RAM Storage OpenSearch Nodes
1 Gbps 16 GB 1 TB 1
10 Gbps 48 GB 4 TB 3
25 Gbps 96 GB 10 TB 3
40 Gbps 192 GB 20 TB 3+
100 Gbps 384 GB+ 40 TB+ 5+

Tech Stack

Traefik 3.7     β†’ Reverse Proxy
Grafana 11      β†’ Dashboards
Prometheus 3.13 β†’ Metrics
Loki 3.8        β†’ Logs
OpenSearch 2.19 β†’ Search & Analytics
LibreNMS 26.6   β†’ Network Monitoring
ntopng (latest) β†’ Traffic Analysis
MariaDB 11      β†’ SQL Database
Redis 7         β†’ Cache
Alertmanager    β†’ Alert Routing
cAdvisor 0.60   β†’ Container Metrics
Suricata 7      β†’ IDS/IPS (optional)

CI/CD

Workflow Description Status
CI ShellCheck, yamllint, hadolint, Compose validation, JSON lint CI
Tests BATS test suite for configs, scripts, and Docker Tests
Docker Build & push multi-arch image to GHCR Docker
Wiki Sync Sync .github/wiki/ to GitHub Wiki Wiki
Discussions Release announcements, weekly status, test failure alerts Discussions

Push to Localhost or main triggers all workflows automatically.

Contributing

Please read CONTRIBUTING.md for details on our code of conduct, commit conventions, development workflow, and how to submit pull requests.

We welcome bug reports, feature requests, documentation improvements, and new integrations.


License

MIT License β€” see LICENSE for details.

Support

Donate

If you find this project useful, consider supporting development:

About

OpenHostingNOC is a complete, self-hosted Network Operations Center (NOC) platform for hosting providers, ISPs, and enterprise IT. It combines infrastructure monitoring, per-IP traffic analytics, NetFlow/IPFIX collection, security monitoring, alerting, and Grafana dashboards into a modern, Docker-based, fully open-source solution.

Topics

Resources

Code of conduct

Contributing

Stars

Watchers

Forks

Packages

Contributors

Languages