Skip to main content
Installation

Requirements and network

Before installing, confirm the host size, Docker version, Zabbix version and API token, LLM endpoint and hostname, and the inbound and outbound ports to open.

RST AI Copilot for Zabbix is delivered as Docker containers. A standard deployment has two: the gateway and a Caddy reverse proxy. Caddy terminates TLS and passes requests to the gateway, which handles sign-in and accounts. The product does not include Zabbix; the gateway connects to your existing Zabbix over JSON-RPC with one API token. The gateway's own state (settings, license, audit, alert copies, analysis records and so on) lives in the Docker volume gateway_state; nothing is stored on the Zabbix side.

The archive carries the images for both containers, so the installation never contacts an image registry.

Host

ItemRequirement
Operating systemA Linux that runs Docker; Ubuntu 22.04 or later, Kylin or UOS recommended
Size2 vCPU, 4 GB RAM, 20 GB SSD recommended; at least 1 vCPU, 2 GB RAM, 10 GB disk. The gateway container is capped at 2 CPU and 2 GB RAM by default; change it with RST_GATEWAY_CPUS and RST_GATEWAY_MEM in .env
RuntimeDocker Engine 24 or later, Docker Compose v2
PrivilegesAn account that can run docker. The one-command install needs root

The gateway is a single process that keeps rate limits and license state in memory. Run exactly one replica and do not scale it with --scale. It comfortably serves an operations team of a few dozen people; the bottleneck is usually the LLM endpoint's throughput.

Zabbix

ItemRequirement
Version6.0, 6.4, 7.0, 7.2 or 7.4. After start-up the gateway reads the version with apiinfo.version and adapts its calls to it. Versions older than 6.0 are refused; unlisted versions such as 6.2 run, with a warning in the UI that they are not verified
URLThe JSON-RPC URL, ending in /api_jsonrpc.php, for example https://zabbix.corp.local/api_jsonrpc.php. The gateway only talks to the Zabbix frontend, never to the Zabbix server or proxies
CertificateWith an https:// URL the gateway verifies the certificate
CredentialsAn API token is recommended; a user name and password also work. See Zabbix permissions

"Open in Zabbix" links send the user's browser to the Zabbix frontend. If ZABBIX_URL is an internal address the browser cannot reach, set ZABBIX_PUBLIC_URL in .env.

LLM

Any OpenAI-compatible endpoint: Volcengine Ark, DeepSeek, Qwen, Azure OpenAI, self-hosted vLLM or Ollama. Installation asks for the URL, the API key and the model name. After installation you can add more providers in AI settings.

If data must not leave your network, host the model internally and set field masking to air-gapped. The model does not run on the gateway host; a self-hosted model needs its own GPU server.

A single model call times out after 180 seconds. When investigation, correlation and reports use a reasoning model, one call can take from tens of seconds to a few minutes.

The knowledge base needs a separate embedding endpoint. Without one the knowledge base is unavailable and everything else keeps working.

Hostname

Set CADDY_SITE_ADDRESS to the hostname users open, for example copilot.corp.local; several names can be given, separated by spaces. Users open https://<hostname>/v2/. Without internal DNS, add a hosts entry on the users' machines.

Ports

Inbound (to the gateway host):

PortSourcePurpose
443/TCPUser networkshttps://<hostname>/v2/, the only entry point
80/TCPUser networksHTTP redirect to HTTPS; optional

The gateway's port 8000 exists only on the compose internal network and is never exposed. The gateway must sit behind Caddy and only honors forwarded and identity headers from trusted proxies.

Outbound (from the gateway host):

DestinationPortPurposeRequired
Zabbix frontend (ZABBIX_URL)443, 80 or a custom portJSON-RPC reads and writesYes
LLM endpoint443InferenceYes. A local model stays on the internal network
license.reallysec.com443Online activation, daily heartbeatFor online-activated commercial licenses. Not needed for an unactivated Community install or offline activation
github.com, objects.githubusercontent.com, release-assets.githubusercontent.com443Online update: check for new versions and content packs, download the archiveWhen you use online update. Offline-activated hosts never connect
Feishu, DingTalk, WeCom, Teams, Slack, SMTP443, 465, 587Outbound channelsOptional
syslog or webhook receiver514, 6514 or customAudit forwarding, EnterpriseOptional

On a fully air-gapped network, host the LLM internally, use offline activation (Enterprise), and upgrade from the archive. See Upgrade, rollback and backup.

On this page