Requirements and network
Before installing, confirm the host size, Docker version, Zabbix version and API token, LLM endpoint and hostname, and the inbound and outbound ports to open.
RST AI Copilot for Zabbix is delivered as Docker containers. A standard deployment has two: the gateway and a Caddy reverse proxy. Caddy terminates TLS and passes requests to the gateway, which handles sign-in and accounts. The product does not include Zabbix; the gateway connects to your existing Zabbix over JSON-RPC with one API token. The gateway's own state (settings, license, audit, alert copies, analysis records and so on) lives in the Docker volume gateway_state; nothing is stored on the Zabbix side.
The archive carries the images for both containers, so the installation never contacts an image registry.
Host
| Item | Requirement |
|---|---|
| Operating system | A Linux that runs Docker; Ubuntu 22.04 or later, Kylin or UOS recommended |
| Size | 2 vCPU, 4 GB RAM, 20 GB SSD recommended; at least 1 vCPU, 2 GB RAM, 10 GB disk. The gateway container is capped at 2 CPU and 2 GB RAM by default; change it with RST_GATEWAY_CPUS and RST_GATEWAY_MEM in .env |
| Runtime | Docker Engine 24 or later, Docker Compose v2 |
| Privileges | An account that can run docker. The one-command install needs root |
The gateway is a single process that keeps rate limits and license state in memory. Run exactly one replica and do not scale it with --scale. It comfortably serves an operations team of a few dozen people; the bottleneck is usually the LLM endpoint's throughput.
Zabbix
| Item | Requirement |
|---|---|
| Version | 6.0, 6.4, 7.0, 7.2 or 7.4. After start-up the gateway reads the version with apiinfo.version and adapts its calls to it. Versions older than 6.0 are refused; unlisted versions such as 6.2 run, with a warning in the UI that they are not verified |
| URL | The JSON-RPC URL, ending in /api_jsonrpc.php, for example https://zabbix.corp.local/api_jsonrpc.php. The gateway only talks to the Zabbix frontend, never to the Zabbix server or proxies |
| Certificate | With an https:// URL the gateway verifies the certificate |
| Credentials | An API token is recommended; a user name and password also work. See Zabbix permissions |
"Open in Zabbix" links send the user's browser to the Zabbix frontend. If ZABBIX_URL is an internal address the browser cannot reach, set ZABBIX_PUBLIC_URL in .env.
LLM
Any OpenAI-compatible endpoint: Volcengine Ark, DeepSeek, Qwen, Azure OpenAI, self-hosted vLLM or Ollama. Installation asks for the URL, the API key and the model name. After installation you can add more providers in AI settings.
If data must not leave your network, host the model internally and set field masking to air-gapped. The model does not run on the gateway host; a self-hosted model needs its own GPU server.
A single model call times out after 180 seconds. When investigation, correlation and reports use a reasoning model, one call can take from tens of seconds to a few minutes.
The knowledge base needs a separate embedding endpoint. Without one the knowledge base is unavailable and everything else keeps working.
Hostname
Set CADDY_SITE_ADDRESS to the hostname users open, for example copilot.corp.local; several names can be given, separated by spaces. Users open https://<hostname>/v2/. Without internal DNS, add a hosts entry on the users' machines.
Ports
Inbound (to the gateway host):
| Port | Source | Purpose |
|---|---|---|
| 443/TCP | User networks | https://<hostname>/v2/, the only entry point |
| 80/TCP | User networks | HTTP redirect to HTTPS; optional |
The gateway's port 8000 exists only on the compose internal network and is never exposed. The gateway must sit behind Caddy and only honors forwarded and identity headers from trusted proxies.
Outbound (from the gateway host):
| Destination | Port | Purpose | Required |
|---|---|---|---|
Zabbix frontend (ZABBIX_URL) | 443, 80 or a custom port | JSON-RPC reads and writes | Yes |
| LLM endpoint | 443 | Inference | Yes. A local model stays on the internal network |
license.reallysec.com | 443 | Online activation, daily heartbeat | For online-activated commercial licenses. Not needed for an unactivated Community install or offline activation |
github.com, objects.githubusercontent.com, release-assets.githubusercontent.com | 443 | Online update: check for new versions and content packs, download the archive | When you use online update. Offline-activated hosts never connect |
| Feishu, DingTalk, WeCom, Teams, Slack, SMTP | 443, 465, 587 | Outbound channels | Optional |
| syslog or webhook receiver | 514, 6514 or custom | Audit forwarding, Enterprise | Optional |
On a fully air-gapped network, host the LLM internally, use offline activation (Enterprise), and upgrade from the archive. See Upgrade, rollback and backup.
Editions
Compare the Community, Professional and Enterprise editions, their prices, and which one fits.
Installing from the archive
Install the gateway with one command or from a downloaded archive, install on an air-gapped host, answer the deploy.sh prompts, verify the install, and install without deploy.sh.