You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/nms/nginx-agent/install-nginx-agent.md
+23-23
Original file line number
Diff line number
Diff line change
@@ -17,7 +17,7 @@ This section lists the prerequisites for installing and configuring NGINX Agent.
17
17
18
18
1.[F5 NGINX Management Suite is installed on a server]({{< relref "/nim/deploy/_index.md" >}}).
19
19
20
-
{{<note>}} When installing and configuring NGINX Management Suite, take note of the fully qualified domain name (FQDN) and gRPC port number. You'll need this information to properly configure the NGINX Agent to communicate with NGINX Management Suite.
20
+
{{<note>}} When installing and configuring NGINX Management Suite, take note of the fully qualified domain name (FQDN) and gRPC port number. You'll need this information to properly configure NGINX Agent to communicate with NGINX Management Suite.
21
21
{{</note>}}
22
22
23
23
2. Make sure NGINX is running on your instance:
@@ -26,13 +26,13 @@ This section lists the prerequisites for installing and configuring NGINX Agent.
26
26
ps aux | grep nginx
27
27
```
28
28
29
-
3. If a previous version of NGINX Agent was installed, you must stop the current NGINX Agent process before running the NGINX Agent install script. To check if any NGINX Agent processes are running, run the following command:
29
+
3. If a previous version of NGINX Agent was installed, you must stop the current NGINX Agent process before running NGINX Agent install script. To check if any NGINX Agent processes are running, run the following command:
30
30
31
31
```bash
32
32
ps aux | grep nginx-agent
33
33
```
34
34
35
-
4. If a previous version of NGINX Agent was installed, make sure to uninstall `nginx-agent-selinux` before running the NGINX Agent install script.
35
+
4. If a previous version of NGINX Agent was installed, make sure to uninstall `nginx-agent-selinux` before running NGINX Agent install script.
36
36
To see if`nginx_agent_selinux` is installed, run the following command:
37
37
38
38
{{<tabs name="install_repo">}}
@@ -58,7 +58,7 @@ To see if `nginx_agent_selinux` is installed, run the following command:
58
58
59
59
## Install NGINX Agent
60
60
61
-
You can choose one of the following two methods to install the NGINX Agent on your data plane host:
61
+
You can choose one of the following two methods to install NGINX Agent on your data plane host:
62
62
63
63
- Install via the NGINX Management Suite API Gateway
64
64
- Install from packages downloaded from [MyF5 Customer Portal](https://account.f5.com/myf5) or from your NGINX/F5 sales team.
@@ -79,7 +79,7 @@ You can choose one of the following two methods to install the NGINX Agent on yo
79
79
80
80
## Enable and Start NGINX Agent
81
81
82
-
Run the following command to enable and start the NGINX Agent service:
82
+
Run the following command to enable and start NGINX Agent service:
Once you've verified the NGINX Agent is running on your data plane, you should confirm it's registered with NGINX Management Suite. You can do this two ways:
105
+
Once you've verified NGINX Agent is running on your data plane, you should confirm it's registered with NGINX Management Suite. You can do this two ways:
106
106
107
107
{{<tabs name="verify-nginx">}}
108
108
@@ -128,35 +128,35 @@ In a web browser, go to the FQDN for your NGINX Management Suite host and log in
128
128
129
129
<br>
130
130
131
-
Once you've verified the NGINX Agent instance is registered with NGINX Management Suite, no additional action is required for monitoring the instance.
131
+
Once you've verified NGINX Agent instance is registered with NGINX Management Suite, no additional action is required for monitoring the instance.
132
132
133
133
{{<note>}}
134
-
If you need to remove the instance, ensure that the NGINX Agent service is stopped first. Then you can remove the instance from the inventory.
134
+
If you need to remove the instance, ensure that NGINX Agent service is stopped first. Then you can remove the instance from the inventory.
135
135
{{</note>}}
136
136
137
137
---
138
138
139
139
## Configuring the NGINX Agent
140
140
141
-
The following sections explain how to configure the NGINX Agent using configuration files, CLI flags, and environment variables.
141
+
The following sections explain how to configure NGINX Agent using configuration files, CLI flags, and environment variables.
142
142
143
143
{{<note>}}
144
144
145
-
- The NGINX Agent interprets configuration values set by configuration files, CLI flags, and environment variables in the following priorities:
145
+
- NGINX Agent interprets configuration values set by configuration files, CLI flags, and environment variables in the following priorities:
146
146
147
147
1. CLI flags overwrite configuration files and environment variable values.
3. Config files are the lowest priority and config settings are superseded if either of the other options is used.
150
150
151
-
- The NGINX Agent is configured by default to connect to the NGINX Management Suite on port 443 based on the address used to download the install script. If this setting doesn't work, you can change the `server` fields in the `nginx-agent.conf` file. Instructions are provided in the following sections.
151
+
- NGINX Agent is configured by default to connect to the NGINX Management Suite on port 443 based on the address used to download the install script. If this setting doesn't work, you can change the `server` fields in the `nginx-agent.conf` file. Instructions are provided in the following sections.
152
152
153
153
- Open any required firewall ports or SELinux/AppArmor rules for the ports and IPs you want to use.
154
154
155
155
{{</note>}}
156
156
157
157
### Configure with Config Files
158
158
159
-
The configuration files forthe NGINX Agent are `/etc/nginx-agent/nginx-agent.conf` and `/var/lib/nginx-agent/agent-dynamic.conf`. These files have comments at the top indicating their purpose.
159
+
The configuration files for NGINX Agent are `/etc/nginx-agent/nginx-agent.conf` and `/var/lib/nginx-agent/agent-dynamic.conf`. These files have comments at the top indicating their purpose.
160
160
161
161
{{<note>}}If you're running Instance Manager 2.10.1 or earlier or NGINX Agent 2.25.1 or earlier, the `agent-dynamic.conf` file is located in `/etc/nginx-agent/`.{{</note>}}
162
162
@@ -168,7 +168,7 @@ Examples of the configuration files are provided below:
168
168
{{<note>}}
169
169
In the following example `nginx-agent.conf` file, you can change the `server.host` and `server.grpcPort` to connect to the NGINX Management Suite.
170
170
171
-
If NGINX Agent was previously installed for data reporting purposes only, you may need to find and remove the following line from the NGINX Agent configuration file:
171
+
If NGINX Agent was previously installed for data reporting purposes only, you may need to find and remove the following line from NGINX Agent configuration file:
172
172
173
173
```none
174
174
features: registration,dataplane-status
@@ -231,7 +231,7 @@ extensions:
231
231
232
232
# Enable reporting NGINX App Protect details to the control plane.
233
233
nginx_app_protect:
234
-
# Report interval for NGINX App Protect details - the frequency the NGINX Agent checks NGINX App Protect for changes.
234
+
# Report interval for NGINX App Protect details - the frequency NGINX Agent checks NGINX App Protect for changes.
235
235
report_interval: 15s
236
236
# Enable precompiled publication from the NGINX Management Suite (true) or perform compilation on the data plane host (false).
237
237
precompiled_publication: true
@@ -271,7 +271,7 @@ tags:
271
271
272
272
## CLI Flags & Environment Variables
273
273
274
-
This section details the CLI flags and corresponding environment variables used to configure the NGINX Agent.
274
+
This section details the CLI flags and corresponding environment variables used to configure NGINX Agent.
275
275
276
276
### Usage
277
277
@@ -323,7 +323,7 @@ If you are upgrading from an older version, update your configuration accordingl
323
323
|`--nginx-exclude-logs`|`NGINX_AGENT_NGINX_EXCLUDE_LOGS`| Specifies paths of NGINX access logs to exclude from metrics collection. |
324
324
|`--nginx-socket`|`NGINX_AGENT_NGINX_SOCKET`| Specifies the location of the NGINX Plus counting Unix socket. Default: *unix:/var/run/nginx-agent/nginx.sock*|
325
325
|`--nginx-treat-warnings-as-errors`|`NGINX_AGENT_NGINX_TREAT_WARNINGS_AS_ERRORS`| Treats warnings as failures on configuration application. |
326
-
|`--queue-size`|`NGINX_AGENT_QUEUE_SIZE`| Specifies the size of the NGINX Agent internal queue. |
326
+
|`--queue-size`|`NGINX_AGENT_QUEUE_SIZE`| Specifies the size of NGINX Agent internal queue. |
327
327
|`--server-command`|| Specifies the name of the command server sent in the TLS configuration. |
328
328
|`--server-grpcport`|`NGINX_AGENT_SERVER_GRPCPORT`| Sets the desired GRPC port for NGINX Agent traffic. |
329
329
|`--server-host`|`NGINX_AGENT_SERVER_HOST`| Specifies the IP address of the server host. |
@@ -402,7 +402,7 @@ Additionally, you can use the agent installation script to add these fields:
402
402
403
403
## SELinux for NGINX Agent
404
404
405
-
This section explains how to install and configure the SELinux policy for the NGINX Agent.
405
+
This section explains how to install and configure the SELinux policy for NGINX Agent.
406
406
407
407
### Installing NGINX Agent SELinux Policy Module
408
408
@@ -412,13 +412,13 @@ The NGINX Agent package includes the following SELinux files:
To load the NGINX Agent policy, run the following commands:
415
+
To load NGINX Agent policy, run the following commands:
416
416
417
417
{{< include "installation/agent-selinux.md" >}}
418
418
419
419
### Adding Ports for NGINX Agent SELinux Context
420
420
421
-
You can configure the NGINX Agent to work with SELinux. Make sure you add external ports to the firewall exception list.
421
+
You can configure NGINX Agent to work with SELinux. Make sure you add external ports to the firewall exception list.
422
422
423
423
The following example shows how to allow external ports outside the HTTPD context. You may need to enable NGINX to connect to these ports.
424
424
@@ -430,11 +430,11 @@ For additional information on using NGINX with SELinux, refer to the guide [Usin
430
430
431
431
---
432
432
433
-
## Secure the NGINX Agent with mTLS
433
+
## Secure NGINX Agent with mTLS
434
434
435
-
{{< important >}}By default, communication between the NGINX Agent and NGINX Management Suite is unsecured.{{< /important >}}
435
+
{{< important >}}By default, communication between NGINX Agent and NGINX Management Suite is unsecured.{{< /important >}}
436
436
437
-
For instructions on how configure mTLS to secure communication between the NGINX Agent and NGINX Management Suite, see [NGINX Agent TLS Settings](https://docs.nginx.com/nginx-agent/configuration/encrypt-communication/).
437
+
For instructions on how configure mTLS to secure communication between NGINX Agent and NGINX Management Suite, see [NGINX Agent TLS Settings](https://docs.nginx.com/nginx-agent/configuration/encrypt-communication/).
0 commit comments