Cockpit Web Console
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
Cockpit is the web-based server management console that ships with Enterprise Linux. Once you log in from a browser, you can check system status, manage services, read logs, configure the network, apply updates, and even open a built-in terminal — all from a graphical interface. It does not replace the SSH command line; the two complement each other. Routine checks and graphical operations are more intuitive in Cockpit, while complex tasks can still drop back to the terminal. If you are new to Linux, it makes a friendly starting point.
What You Will Learn
Section titled “What You Will Learn”- What Cockpit is and how it relates to the SSH command line
- How to install, enable Cockpit, and open the firewall
- How to log in from a browser and tour the feature panels
- How to install common add-on plugins (containers, virtual machines, storage, and more)
- How to harden it: replace the certificate, restrict logins, and change the port
Prerequisites
Section titled “Prerequisites”- An EL 9 or EL 10 system that is installed and has completed initial setup
- A system account with sudo privileges
- A computer with a browser that can reach the server over the network
Install Cockpit
Section titled “Install Cockpit”Many EL systems already include cockpit and cockpit-ws from installation, especially those installed with a graphical interface. On a minimal install, install it manually.
$ sudo dnf install cockpitIf the system reports it is already installed, just move on to the next step.
Enable and Start
Section titled “Enable and Start”Cockpit runs via systemd socket activation — it is not resident in the background; systemd only wakes it when someone connects to port 9090, so it uses almost no resources. What you enable is cockpit.socket, not cockpit.service.
$ sudo systemctl enable --now cockpit.socketConfirm the socket is listening:
$ systemctl status cockpit.socketThe output should show Active: active (listening), meaning it is now listening on port 9090:
● cockpit.socket - Cockpit Web Service Socket Loaded: loaded (/usr/lib/systemd/system/cockpit.socket; enabled; ...) Active: active (listening) since ... Listen: [::]:9090 (Stream)Open the Firewall
Section titled “Open the Firewall”EL enables firewalld by default. Cockpit ships with a predefined service named cockpit (mapped to 9090/tcp), so you can open it directly.
$ sudo firewall-cmd --add-service=cockpit --permanent$ sudo firewall-cmd --reloadConfirm the rule took effect:
$ sudo firewall-cmd --list-servicesThe output should include cockpit.
Log In From a Browser
Section titled “Log In From a Browser”On another computer, open the server’s address in a browser, on port 9090, over HTTPS:
https://<server-IP>:9090Replace <server-IP> with your server’s actual IP address or hostname. On the first visit the browser will show a security warning — this is because Cockpit uses a self-signed certificate by default, so the browser cannot verify its identity. This is expected on an internal network; once you have confirmed the address is correct, choose to proceed. The Hardening section below explains how to switch to a proper certificate.
On the login page, use your system account — the same username and password you use for SSH.
Feature Overview
Section titled “Feature Overview”Once logged in, the left navigation bar gathers the panels you will reach for most in day-to-day operations:
- Overview: CPU, memory, and disk load, hardware information, and pending update reminders
- Logs: Browse the systemd journal, filtered by time, priority, or service
- Services: Manage systemd units graphically — start, stop, enable, and disable at a glance
- Networking: Configure interfaces, bonds, bridges, and the firewall via NetworkManager, with live traffic
- Storage: Manage disks, partitions, LVM, filesystems, and mounts
- Accounts: Create and manage users, set passwords, and configure SSH public keys
- Software Updates: Check for and install system updates (provided by cockpit-packagekit)
- Terminal: A full shell built right into the browser, so the command line is always within reach
After you install the matching add-on plugins, panels such as Podman containers and Virtual machines appear as well.
Install Add-on Plugins
Section titled “Install Add-on Plugins”Cockpit’s functionality extends on demand through plugins. Each plugin is a separate DNF package; once installed, its panel appears automatically in the navigation bar without restarting the service.
$ sudo dnf install \ cockpit-podman \ cockpit-machines \ cockpit-storaged \ cockpit-networkmanager \ cockpit-packagekit \ cockpit-sosreport \ cockpit-selinuxWhat each plugin provides:
| Plugin | What it provides |
|---|---|
cockpit-podman | Graphical management of Podman containers and images |
cockpit-machines | Manage KVM/libvirt virtual machines |
cockpit-storaged | Disk, partition, LVM, and filesystem management |
cockpit-networkmanager | Network interface, bond, and bridge configuration |
cockpit-packagekit | Check for and install software updates |
cockpit-sosreport | Generate an sosreport diagnostic bundle in one click |
cockpit-selinux | View SELinux status and troubleshoot alerts |
Manage Multiple Hosts
Section titled “Manage Multiple Hosts”If you run several servers that all have Cockpit installed, you can add the other hosts into one Cockpit interface and switch between them centrally, instead of opening a browser tab for each.
-
Make sure the target host also has
cockpit.socketinstalled and enabled, and that port 9090 is reachable from the host you are currently logged in to. -
In the top-left of Cockpit, click the dropdown arrow next to the hostname and choose “Add new host”.
-
Enter the target host’s address and a login user. On the first connection you will need to confirm its SSH host fingerprint.
Once added, you can switch between hosts from the dropdown within the same interface.
Hardening
Section titled “Hardening”Cockpit directly exposes the server’s management capabilities, so take access control seriously.
Open Only on the Internal Network or Behind a Reverse Proxy
Section titled “Open Only on the Internal Network or Behind a Reverse Proxy”The safest approach is to expose port 9090 only on an internal network or VPN, never directly on the public internet. If you genuinely need public access, put Cockpit behind a reverse proxy (such as Nginx) and let the proxy handle proper TLS certificates and access control.
Switch to a Proper TLS Certificate
Section titled “Switch to a Proper TLS Certificate”To eliminate the browser certificate warning, place your proper certificate and private key in Cockpit’s certificate directory. Cockpit automatically loads the alphabetically last .cert (and matching .key) file in that directory.
$ sudo cp fullchain.pem /etc/cockpit/ws-certs.d/50-mydomain.cert$ sudo cp privkey.pem /etc/cockpit/ws-certs.d/50-mydomain.key$ sudo systemctl restart cockpitRestrict Who Can Log In
Section titled “Restrict Who Can Log In”root is blocked from logging in to Cockpit by default; the rule lives in this file:
$ sudo cat /etc/cockpit/disallowed-usersTo block more accounts, add their usernames to this file, one per line.
Change the Listening Port
Section titled “Change the Listening Port”If you want to change the default 9090 to another port, create a socket override configuration.
-
Create the override directory:
Terminal window $ sudo mkdir -p /etc/systemd/system/cockpit.socket.d -
Write the new port into
/etc/systemd/system/cockpit.socket.d/listen.conf(using 9999 as an example):/etc/systemd/system/cockpit.socket.d/listen.conf [Socket]ListenStream=ListenStream=9999The first empty
ListenStream=clears the default 9090 and is required. -
Reload, restart the socket, then open the new port:
Terminal window $ sudo systemctl daemon-reload$ sudo systemctl restart cockpit.socket$ sudo firewall-cmd --add-port=9999/tcp --permanent$ sudo firewall-cmd --reload
EL 9 vs. EL 10
Section titled “EL 9 vs. EL 10”On EL 9 and EL 10, Cockpit’s installation, enablement, firewall, and usage are identical — every command in this article works on both. The Cockpit version bundled with EL 10 is newer, with slightly enhanced interface and plugin features, but the operational logic is unchanged, so you can apply this guide with confidence.
Frequently Asked Questions
Section titled “Frequently Asked Questions”The browser cannot open https://server-IP:9090
First confirm on the server that the socket is listening: systemctl status cockpit.socket should show active (listening); if not, run sudo systemctl enable --now cockpit.socket. Then confirm the firewall is open: sudo firewall-cmd --list-services should include cockpit, otherwise open it again as shown above. Also double-check that the IP/port and the HTTPS protocol you typed are correct.
The browser keeps warning that the certificate is not secure
This is because Cockpit uses a self-signed certificate by default, which the browser cannot verify the issuer of — it is normal. For internal use, confirm the address and proceed; to remove the warning entirely, install a trusted certificate as shown in Switch to a Proper TLS Certificate.
Logging in as root says “Permission denied”
This is the default security policy: root is listed in /etc/cockpit/disallowed-users and blocked from logging in to Cockpit. Log in with a regular account that has sudo privileges instead, then enable “Administrative access” in the top-right corner to perform privileged operations.
I want to change the default 9090 port
See Change the Listening Port above: override ListenStream via cockpit.socket.d/listen.conf, restart the socket, and open the new port in the firewall.
Further Reading
Section titled “Further Reading”- SSH Remote Access — Cockpit’s command-line companion
- Initial Setup — Prepare the system before deploying Cockpit
- Podman Basics — Manage containers graphically with
cockpit-podman