The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / traefik / traefik-dashboard-404 ▌

Operations Guides

Traefik dashboard returns 404: reaching the API and dashboard correctly

You opened a browser to what you think is the dashboard address and got a bare “404 page not found”. Or the dashboard HTML loads but every panel is empty because the underlying /api calls all return 404. This almost always comes down to one of three things: the API is not enabled, you are hitting the wrong port or path, or secure mode is on but no router was ever defined for the internal API service.

The dashboard and API do not live on your traffic entrypoints (80/443) by default. They live on a separate internal entrypoint, they must be explicitly enabled in static configuration, the URL requires a trailing slash, and the secure (recommended) way of exposing them requires a dynamic-config router that many setups never create. Any one of those being wrong produces the same unhelpful 404.

What this means

A 404 from Traefik means “no router matched this request”. Traefik returns 404 at the entrypoint level when a request arrives but no router rule matches it, visible in traefik_entrypoint_requests_total{code="404"}, not in any service metric, because no service was ever selected.

The dashboard and API are themselves served through the routing pipeline. In insecure mode Traefik auto-generates internal routers for them; in secure mode you must define the router yourself, pointing at the special internal service api@internal. If that router does not exist, does not match your request (wrong host, wrong path, wrong entrypoint), or the feature is disabled entirely, you get the standard Traefik 404. The same applies to /ping, a separate feature enabled independently with ping: {} or --ping in static config.

One nuance: the dashboard is a frontend that calls the API. If the dashboard page loads but the API routes 404, the static assets router matched but the API router did not. That points at router rule logic, not at whether the feature is enabled.

Common causes

CauseWhat it looks likeFirst thing to check
API/dashboard not enabled404 on every /dashboard/ and /api/* request, on every portStatic config: is api.dashboard (or api: {}) set?
Wrong port or entrypoint404 or connection refused on 80/443; works on the internal port (typically 8080)Which entrypoint is the dashboard bound to?
Missing trailing slash/dashboard returns 404, /dashboard/ worksRetry with the trailing slash
Secure mode without a routerAPI enabled, api.insecure false or unset, 404 everywhereDoes a router for api@internal exist in dynamic config?
Router rule logic wrong (OR instead of AND)Dashboard loads on any Host, or API routes 404 while the page loadsInspect the actual rule via /api/http/routers
api.basePath set with insecure modeEndpoints 404 at the prefixed path; basePath is silently ignoredAre api.basePath and api.insecure=true both set?
Docker Swarm missing dummy port labelDashboard router exists but 404s on SwarmIs the dummy service port label present?

Quick checks

All of these are read-only and safe to run on a production instance.

# 1. Is the dashboard reachable on the internal entrypoint at all?
curl -s -o /dev/null -w '%{http_code}\n' http://localhost:8080/dashboard/

# 2. Compare with and without the trailing slash
curl -s -o /dev/null -w '%{http_code}\n' http://localhost:8080/dashboard

# 3. Does the API respond?
curl -s -o /dev/null -w '%{http_code}\n' http://localhost:8080/api/http/routers

# 4. Which ports is Traefik actually listening on?
ss -ltnp | grep traefik

# 5. Is /ping enabled (independent feature, useful reference point)?
curl -s -o /dev/null -w '%{http_code}\n' http://localhost:8080/ping

# 6. If the API responds anywhere, dump what routers Traefik actually loaded
curl -s http://localhost:8080/api/http/routers

Interpretation shortcuts:

  • Checks 1 and 3 both 404 on every port: the API is almost certainly not enabled in static config.
  • Checks 1 and 3 are 404 on :8080 but return 200 on another port from check 4: wrong entrypoint.
  • Check 2 is 404 but check 1 returns 200: trailing slash. Expected behavior, not a bug.
  • Check 5 returns 200 but 1 and 3 return 404: ping is enabled but the API is not. They are independent features.
  • Check 6 returns a router list with no router for api@internal: secure mode is missing its router.

How to diagnose it

flowchart TD
  A[404 on /dashboard/ or /api/*] --> B{API enabled in static config?}
  B -- No --> C[Set api.dashboard=true or api: {}]
  B -- Yes --> D{api.insecure=true?}
  D -- Yes --> E[Hit the traefik entrypoint, typically :8080, path /dashboard/ with trailing slash]
  D -- No --> F{Router for api@internal exists?}
  F -- No --> G[Add dynamic-config router to api@internal]
  F -- Yes --> H{Rule matches your Host and path?}
  H -- No --> I[Fix rule: Host AND grouped PathPrefix OR]
  H -- Yes --> J[Check basePath conflict or provider-specific issues]

Work through the steps in order. Each step eliminates one layer.

  1. Confirm the API is enabled in static config. This cannot be enabled via dynamic config, labels on another container, or middleware. Look for api.dashboard=true (CLI flag --api.dashboard=true) or simply api: {}, which also enables the dashboard. If neither is present, every other step is moot.

  2. Determine which mode you are in. Check whether api.insecure=true is set. This changes where the dashboard lives:

    • Insecure mode: Traefik auto-generates internal routers with hardcoded rules, PathPrefix('/api') for the API and PathPrefix('/') for the dashboard, served on the entrypoint named traefik. You must define that entrypoint yourself; the conventional port is 8080, but it only exists if you declared it.
    • Secure mode (default): nothing is exposed until you create a router in dynamic config pointing to the service api@internal.
  3. Verify the path. The dashboard path is /dashboard/ and the trailing slash is mandatory. There is a redirect from / to /dashboard/, but the Traefik documentation warns not to rely on it. If you bookmarked /dashboard without the slash, that alone explains the 404.

  4. In secure mode, inspect the router you defined. The recommended rule shape is Host(`traefik.example.com`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`)). Two failure patterns are common:

    • Using || between the Host and the path prefixes instead of && with a grouped OR. That makes the dashboard match on any Host, which can expose it unintentionally and also produces confusing matches.
    • The router is attached to the wrong entrypoint, so requests on the port you are testing never reach it.
  5. Check what Traefik actually loaded. Query /api/http/routers from wherever the API does respond and look for the dashboard/API router: its rule, entrypoints, and status. Traefik silently ignores unknown or malformed labels and annotations, so the config you wrote and the config Traefik loaded can differ without any error. Compare loaded state against intended state.

  6. Check for the basePath trap. If you set api.basePath together with api.insecure=true, the base path is silently ignored: the auto-generated internal routers are hardcoded to PathPrefix('/api') and PathPrefix('/') and never incorporate the prefix. The option is documented as incompatible with insecure mode, but nothing warns you at startup. Endpoints stay at the unprefixed paths.

  7. Provider-specific checks. On Docker Swarm, the dashboard router needs a dummy service port label for Swarm’s port detection, for example traefik.http.services.dummy-svc.loadbalancer.server.port=9999; without it the router 404s. On Kubernetes, verify labels or annotations landed on the object Traefik actually watches.

  8. Rule out a version regression. If the dashboard broke immediately after an upgrade with no config change, check the version history and issue tracker before assuming your config is wrong. Pin and test upgrades against the dashboard before rolling them out broadly.

Metrics and signals to monitor

SignalWhy it mattersWarning sign
traefik_entrypoint_requests_total{code="404"} per entrypointDistinguishes “no router matched” (config problem) from backend 404s404s concentrated on the dashboard/API entrypoint after a config change
/api/http/routers contentGround truth for what routing rules Traefik loadedDashboard router missing, wrong entrypoints, or unexpected rule
External probe of /dashboard/ and /api/rawdataDetects unintended public exposure (no Prometheus metric exists for this)200 from an external network
traefik_config_last_reload_successConfirms dynamic config (where your secure-mode router lives) is actually being appliedTimestamp not advancing after you added the router

The last row matters in secure mode: the dashboard router is dynamic config. If your provider is disconnected or your file never reloads, the router you just wrote never takes effect and you keep getting 404 no matter how correct the YAML is. Check config freshness before blaming the router rule.

Fixes

Enable the API and dashboard

Static configuration change, requires a restart of Traefik:

# static config
api:
  dashboard: true

or api: {}, which enables both API and dashboard. Static config cannot be toggled at runtime, so plan for the restart.

Hit the right entrypoint and path (insecure mode, local/dev only)

Define the internal entrypoint and use it:

# static config
entryPoints:
  traefik:
    address: ":8080"
api:
  insecure: true
  dashboard: true

Then browse to http://<host>:8080/dashboard/ with the trailing slash. Treat insecure mode as a local-development convenience, not a production pattern: it exposes the API with no authentication.

Expose it properly (secure mode)

Keep api.insecure off. Add a router pointing to the internal service in dynamic config:

# dynamic config
http:
  routers:
    dashboard:
      rule: "Host(`traefik.example.com`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`))"
      service: api@internal
      entryPoints:
        - traefik
      middlewares:
        - dashboard-auth

Put authentication (BasicAuth or ForwardAuth) and ideally an IP allowlist in front of it. The API discloses your entire routing table, backend addresses, and configuration; /api/rawdata alone is a complete map of your infrastructure.

Fix router rule logic

If the dashboard page loads but /api/* calls 404, or the dashboard answers on hosts it should not, rewrite the rule as Host(...) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`)). Do not chain the three clauses with bare ||.

Resolve basePath conflicts

Do not combine api.basePath with api.insecure=true. If you need the API under a prefix, use secure mode with an explicit router whose rule includes the prefix.

Swarm: add the dummy service port

Add traefik.http.services.dummy-svc.loadbalancer.server.port=9999 to the dashboard router’s service labels so Swarm port detection succeeds.

Prevention

  • Never expose the dashboard or API publicly. The API reveals all routes, backend addresses, health status, middleware configuration, and TLS certificate details, and /debug/pprof exposes Go profiling data. Bind the internal entrypoint to localhost or an internal interface, firewall it, and put auth middleware in front even internally.
  • Probe from outside periodically. There is no metric for dashboard exposure; detecting it requires an external probe or network policy audit. A 200 on /dashboard/, /api/rawdata, or /debug/pprof/ from an untrusted network is an immediate remediation item.
  • Use secure mode in production. Insecure mode exists for local development. Production exposure should go through an explicit router with authentication.
  • Verify loaded state, not intended state. After any config change touching the dashboard router, confirm via /api/http/routers that the router exists with the rule and entrypoints you expect, and confirm traefik_config_last_reload_success advanced.
  • Test the dashboard during upgrades. Version-specific regressions happen. A smoke check on /dashboard/ and /api/http/routers after each upgrade catches them before you need the dashboard during an incident.

How Netdata helps

  • Netdata’s Traefik collector scrapes the Prometheus endpoint and charts traefik_entrypoint_requests_total by status code and entrypoint, so you can see 404s isolated to the dashboard/API entrypoint versus 404s on your traffic entrypoints, which have completely different meanings.
  • Per-code request charts make the “dashboard loads but API 404s” pattern visible: successful responses on the dashboard path alongside 404s on /api/*.
  • Config reload metrics show whether a newly added secure-mode router was actually applied, which separates “router rule wrong” from “provider never delivered the config”.
  • Correlating entrypoint 404 rate with reload timestamps after a config change tells you immediately whether a change took effect or silently failed.
  • Alerting on sustained entrypoint-level 404 rates catches route loss broadly, including the case where a botched change removes the dashboard router you depend on during incidents.