---
title: "Install Grafana and Prometheus on a VPS with node_exporter | StreetHosting"
description: "Install Prometheus, node_exporter and Grafana on Ubuntu, import dashboard 1860 and publish Grafana over HTTPS without exposing ports 9090 and 9100."
url: "https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps"
type: "page"
language: "en-US"
---

VPS · 10 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# Grafana and Prometheus on a VPS: CPU, RAM, disk and network dashboard

node\_exporter publishes the machine's numbers, Prometheus scrapes them and keeps the history, and Grafana turns it all into graphs. Here is how to build the stack on Ubuntu 24.04 without leaving sensitive ports open to the internet.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Monitoring and alerts](https://streethosting.com.br/en/guides/topics/monitoring) [Hardware and datacenter](https://streethosting.com.br/en/guides/topics/hardware) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Deploying and running apps](https://streethosting.com.br/en/guides/topics/deploy)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=Install%20Grafana%20and%20Prometheus%20on%20a%20VPS%20with%20node%5Fexporter&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps "Share on LinkedIn") [](https://wa.me/?text=Install%20Grafana%20and%20Prometheus%20on%20a%20VPS%20with%20node%5Fexporter%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-grafana-prometheus-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps.md)

In this guide 8 sections

* [How the pieces fit together](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#como-funciona)
* [Prometheus and node\_exporter](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-prometheus)
* [Close ports 9090 and 9100](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#fechar-portas)
* [Install Grafana](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-grafana)
* [Grafana behind Nginx with HTTPS](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#nginx-https)
* [Node Exporter Full dashboard](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#dashboard-1860)
* [Multiple VPS and alerts](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#varias-vps-alertas)
* [Which VPS to use for monitoring](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#qual-vps)

Quick answer

To **install Grafana and Prometheus on a VPS**, install node\_exporter (port 9100) to expose the machine's metrics, Prometheus (port 9090) to scrape and store the history, and Grafana (port 3000) to draw the graphs. Keep 9090 and 9100 listening only on localhost, publish Grafana behind Nginx with HTTPS and import the Node Exporter Full dashboard, ID 1860, to see CPU, RAM, disk and network within minutes.

## How the pieces fit together[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#como-funciona)

The stack has three pieces with clearly separated roles, and understanding who talks to whom avoids half of the configuration mistakes. No metric is actively sent: Prometheus is the one that goes and fetches the numbers from each target, at the interval you define. This model is called pull, and it changes how you think about the firewall, because the only thing that needs to reach the exporter's port is Prometheus.

| Component               | Default port | Role                                                                                        | Recommended exposure                           |
| ----------------------- | ------------ | ------------------------------------------------------------------------------------------- | ---------------------------------------------- |
| node\_exporter          | 9100 TCP     | Reads Linux CPU, memory, disk, network and filesystems and publishes everything at /metrics | localhost only, or only for the Prometheus IP  |
| Prometheus              | 9090 TCP     | Scrapes the metrics, stores the history on disk and answers PromQL queries                  | localhost only, accessed through an SSH tunnel |
| Grafana                 | 3000 TCP     | Queries Prometheus, draws dashboards and fires alerts                                       | Behind Nginx with HTTPS                        |
| Alertmanager (optional) | 9093 TCP     | Groups and sends alerts generated by Prometheus rules                                       | localhost only                                 |

On a VPS that monitors itself, the three services together usually take up a few hundred MB of RAM. The resource that grows the most over time is Prometheus's disk, proportional to the number of series, the scrape interval and the retention, which defaults to 15 days. If you only need a snapshot of the moment or a ready-made dashboard without building anything, the lighter path is [monitoring resources with htop and Netdata](https://streethosting.com.br/en/guides/vps/monitor-vps-resources-htop-netdata). Grafana and Prometheus pay off when you want long history, your own queries and several machines on the same dashboard.

## Prometheus and node\_exporter[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-prometheus)

On Ubuntu 24.04, the shortest path is to use the packages from the distribution's own repository. They ship a Prometheus 2.x release, older than the latest one published, but stable and updated through apt along with the rest of the system. If you need a feature from the 3.x series, download the official binaries from prometheus.io and create your own systemd units; the rest of this guide still applies.

`sudo apt update sudo apt install -y prometheus prometheus-node-exporter systemctl status prometheus prometheus-node-exporter --no-pager`

Both services come up enabled to start at boot. Before moving on, confirm that the exporter is responding on the machine itself:

`curl -s http://localhost:9100/metrics | grep "^node_load"`

If the load average lines show up, the scrape has something to read. The Prometheus configuration lives in `/etc/prometheus/prometheus.yml`. The package's file usually already includes a job pointing at localhost:9100. Check it and leave the scrape section looking like this, including a label that identifies the machine on the dashboards:

`global: scrape_interval: 15s evaluation_interval: 15s scrape_configs: - job_name: "prometheus" static_configs: - targets: ["localhost:9090"] - job_name: "node" static_configs: - targets: ["localhost:9100"] labels: servidor: "vps-principal"`

YAML is indentation-sensitive, and one space out of place takes the service down on restart. `promtool` ships in the same package and points out the error with a line number before it becomes a problem:

`promtool check config /etc/prometheus/prometheus.yml sudo systemctl restart prometheus`

## Close ports 9090 and 9100[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#fechar-portas)

By default, node\_exporter and Prometheus listen on all interfaces. On a VPS with a public IP, that means anyone can read your machine's metrics (kernel version, mount points, interfaces, system processes) and query Prometheus, which has no login on its web interface. It is free information for whoever is looking for a way in. The fix is to make both listen only on 127.0.0.1.

In the Ubuntu package, each service's command-line parameters live in a file under `/etc/default`, in the ARGS variable. Edit the ARGS line of each one (if it already has options, append the new ones at the end):

`# /etc/default/prometheus-node-exporter ARGS="--web.listen-address=127.0.0.1:9100" # /etc/default/prometheus ARGS="--web.listen-address=127.0.0.1:9090 --storage.tsdb.retention.time=30d"`

The second Prometheus option raises retention from 15 to 30 days. Adjust it to your disk: after a few days of scraping, the command `sudo du -sh /var/lib/prometheus` shows how much the history is taking up, and you can project the rest from there. Restart and check which address each port ended up on:

`sudo systemctl restart prometheus-node-exporter prometheus sudo ss -tlnp | grep -E ':9090|:9100'`

The output must show 127.0.0.1:9090 and 127.0.0.1:9100. If you see 0.0.0.0 or an asterisk, the change was not applied. As a second layer, keep the firewall denying every inbound connection that was not deliberately allowed. With UFW on its default policy, it is enough not to create a rule for these ports; the step by step is in [UFW firewall on an Ubuntu VPS](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps).

If you run Prometheus or exporters in Docker and publish the port with `-p 9090:9090`, Docker creates its own iptables rules that bypass UFW, and the port becomes public even with the firewall denying it. Always publish in the `127.0.0.1:9090:9090` format.

To open the Prometheus interface without exposing anything, use an SSH tunnel from your computer. With the session open, go to http://localhost:9090 in your browser and, in the Status menu, open Targets: the prometheus and node jobs must show up as UP.

`ssh -L 9090:localhost:9090 usuario@IP_DA_VPS`

## Install Grafana[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-grafana)

Grafana is not in the Ubuntu repository. Use Grafana Labs' official APT repository, which delivers updates through apt like any other package:

`sudo apt install -y wget gpg sudo mkdir -p /etc/apt/keyrings wget -q -O - https://apt.grafana.com/gpg.key | gpg --dearmor | sudo tee /etc/apt/keyrings/grafana.gpg > /dev/null echo "deb [signed-by=/etc/apt/keyrings/grafana.gpg] https://apt.grafana.com stable main" | sudo tee /etc/apt/sources.list.d/grafana.list sudo apt update sudo apt install -y grafana`

Before starting the service for the first time, make Grafana listen only on localhost and tell it the public address it will have. Edit `/etc/grafana/grafana.ini` in the server section:

`[server] http_addr = 127.0.0.1 http_port = 3000 domain = grafana.seu-dominio.com.br root_url = https://grafana.seu-dominio.com.br/`

In the original file these lines start with a semicolon, which is the comment marker in the ini format. Remove the semicolon from every line you change, otherwise Grafana ignores the change and keeps listening on all interfaces. Then enable and start it:

`sudo systemctl daemon-reload sudo systemctl enable --now grafana-server sudo ss -tlnp | grep :3000`

Grafana's first login is admin with password admin, and it asks you to change it right away. Do that first access through an SSH tunnel, with `ssh -L 3000:localhost:3000 usuario@IP_DA_VPS` and your browser at http://localhost:3000, before publishing the domain. While the default password is active, whoever reaches the login screen first gets in as administrator.

Once logged in, connect Grafana to Prometheus: under Connections, Data sources, click Add data source, choose Prometheus and enter http://localhost:9090 as the server address. Click Save and test. Since both are on the same VPS, localhost resolves, and port 9090 stays closed to the outside.

## Grafana behind Nginx with HTTPS[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#nginx-https)

With Grafana pinned to 127.0.0.1:3000, Nginx becomes the only way in, and that is where the certificate lives. Create an A record in DNS for the subdomain, such as `grafana.seu-dominio.com.br`, pointing at the VPS IP. Then install Nginx and Certbot and create the site file:

`sudo apt install -y nginx certbot python3-certbot-nginx sudo nano /etc/nginx/sites-available/grafana`

`map $http_upgrade $connection_upgrade { default upgrade; '' close; } server { listen 80; server_name grafana.seu-dominio.com.br; location / { proxy_set_header Host $host; proxy_pass http://127.0.0.1:3000; } location /api/live/ { proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_set_header Host $host; proxy_pass http://127.0.0.1:3000; } }`

The /api/live/ block follows Grafana's official documentation: that is where the WebSocket connections used by the real-time features go through. Enable the site, test the syntax and issue the certificate. Certbot rewrites the server block to listen on 443 and redirect HTTP:

`sudo ln -s /etc/nginx/sites-available/grafana /etc/nginx/sites-enabled/ sudo nginx -t && sudo systemctl reload nginx sudo ufw allow "Nginx Full" sudo certbot --nginx -d grafana.seu-dominio.com.br`

If this is your first time setting up a reverse proxy, the details of each directive are in [Nginx as a reverse proxy on a VPS](https://streethosting.com.br/en/guides/vps/nginx-reverse-proxy-vps), and automatic certificate renewal in [SSL with Let's Encrypt and Nginx](https://streethosting.com.br/en/guides/vps/lets-encrypt-ssl-certificate-vps).

A monitoring dashboard rarely needs to be open to the world. If only your team accesses it, restrict it in the location block itself with `allow SEU_IP;` followed by `deny all;`, or make Grafana reachable only through the VPN.

## Node Exporter Full dashboard[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#dashboard-1860)

Building a system dashboard from scratch is not worth the time. The community dashboard Node Exporter Full, ID 1860, already organizes CPU per core, load average, memory, swap, disk usage and latency, network traffic and filesystem usage into sections you expand as needed.

1. In Grafana, open Dashboards, click New and then Import.
2. Type 1860 in the dashboard ID field and click Load.
3. Select the Prometheus data source you created earlier and click Import.
4. At the top of the dashboard, pick the node job and the instance you want to see.

If the panels show up empty, the problem is almost always the job selector or a target that is down. Check that the target is UP on the Prometheus Targets page and that the job name at the top of the dashboard matches the one in prometheus.yml. The dashboard page is at [grafana.com/grafana/dashboards/1860](https://grafana.com/grafana/dashboards/1860).

### Useful PromQL queries[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#consultas-promql)

Even with the dashboard ready, it is worth having the basic queries on hand. They are what you will use to create your own alerts and panels. Paste them into the Prometheus or Grafana query field:

`# CPU in use (%), average across all cores 100 - (avg by (instance) (rate(node_cpu_seconds_total{mode="idle"}[5m])) * 100) # Available memory (%) node_memory_MemAvailable_bytes / node_memory_MemTotal_bytes * 100 # Free space on the root filesystem (%) node_filesystem_avail_bytes{mountpoint="/"} / node_filesystem_size_bytes{mountpoint="/"} * 100 # Inbound traffic per interface, in bits per second rate(node_network_receive_bytes_total{device!="lo"}[5m]) * 8 # CPU steal (%), time the VM waited for the physical processor avg by (instance) (rate(node_cpu_seconds_total{mode="steal"}[5m])) * 100`

## Multiple VPS and alerts[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#varias-vps-alertas)

When you have more than one VPS, do not install Grafana and Prometheus on each one. The design that scales is a central monitoring server with Prometheus and Grafana and only node\_exporter on each monitored machine. That way there is a single dashboard, a single place to configure alerts, and the history disk stays concentrated where you planned it.

In this design, the exporter on the other VPS needs to accept connections from outside, but only from the Prometheus IP. On the monitored machines, leave the exporter's ARGS empty (or with the interface IP) and open the port only for the monitoring server:

`# on the monitored VPS sudo ufw allow from IP_DO_MONITORAMENTO to any port 9100 proto tcp # in the monitoring server's prometheus.yml - job_name: "node" static_configs: - targets: ["localhost:9100"] labels: servidor: "monitoramento" - targets: ["IP_DA_VPS_APP:9100"] labels: servidor: "app"`

An even more locked-down alternative is to connect the machines over a [WireGuard VPN](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps) and make the exporter listen only on the VPN IP, so that 9100 does not even show up on the public interface. node\_exporter also supports TLS and basic authentication through a file passed in `--web.config.file`, useful when scraping crosses the internet.

### Alerts in Grafana[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#alertas-grafana)

Grafana has its own alerting. Under Alerting, Contact points, register a destination, such as email, Discord or Telegram. Under Alert rules, create rules on the same queries the panels use. For email, fill in the smtp section of grafana.ini first. Three rules cover most VPS incidents:

* **Disk:** free space on the root filesystem below 15% for 10 minutes. That leaves time to clean up before the database stops writing.
* **Memory:** available memory below 10% for 5 minutes, a sign that the OOM killer is about to act.
* **Scraping:** `up == 0` for 2 minutes, which indicates a stopped exporter or a VPS that is down.

These alerts have a clear limit: if the monitoring server goes down, it does not warn about anything. That is why complete monitoring combines internal metrics with availability checks done from outside. The whole strategy, with alert thresholds and what to monitor at each layer, is in [how to monitor a VPS 24 hours a day](https://streethosting.com.br/en/guides/vps/monitor-vps-24-7).

## Which VPS to use for monitoring[](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#qual-vps)

Monitoring does not depend on a high clock speed. It depends on stable memory for Grafana and fast disk for Prometheus to write series without choking. That is why the [Xeon VPS](https://streethosting.com.br/en/vps/xeon) line, with more vCPU for the money, DDR4 and NVMe, fits well as a monitoring server separate from the applications. It also comes with Enterprise Anti-DDoS, a 1 Gbps uplink and 20 ms average latency in Brazil.

| Scenario                                                     | Suggested plan                                 | Monthly price |
| ------------------------------------------------------------ | ---------------------------------------------- | ------------- |
| One to three VPS, 15-day retention                           | Xeon with 2 vCPU, 2 GB and 20 GB NVMe          | R$ 26.00      |
| Up to a few dozen VPS, 30-day retention                      | Xeon with 3 vCPU, 4 GB and 40 GB NVMe          | R$ 43.00      |
| Many hosts, long retention and several Grafana users         | Xeon with 4 vCPU, 6 GB and 60 GB NVMe          | R$ 60.00      |
| Stack alongside an application that needs a high clock speed | Ryzen 9 9950X with 2 vCPU, 4 GB and 40 GB NVMe | R$ 66.00      |

The Xeon line goes from R$ 26.00 to R$ 553.00 per month, with up to 24 vCPU, 64 GB of RAM and 640 GB of NVMe. The Ryzen 9 9950X, with DDR5 and up to 5.7 GHz, goes from R$ 40.00 to R$ 846.00. Both are in São Paulo, with root access, Anti-DDoS included and activation within 60 seconds. If retention grows beyond what you planned, upgrading through the control panel increases memory, vCPU and disk and charges only the prorated difference for the cycle. Compare the tiers on the [VPS page](https://streethosting.com.br/en/vps).

In this guide

* [How the pieces fit together](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#como-funciona)
* [Prometheus and node\_exporter](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-prometheus)
* [Close ports 9090 and 9100](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#fechar-portas)
* [Install Grafana](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#instalar-grafana)
* [Grafana behind Nginx with HTTPS](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#nginx-https)
* [Node Exporter Full dashboard](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#dashboard-1860)
* [Multiple VPS and alerts](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#varias-vps-alertas)
* [Which VPS to use for monitoring](https://streethosting.com.br/en/guides/vps/install-grafana-prometheus-vps#qual-vps)

## Frequently asked questions

What is the difference between Prometheus and Grafana?

Prometheus scrapes metrics at fixed intervals, stores the history on disk and answers queries. Grafana does not store metrics: it queries Prometheus and turns the result into dashboards and alerts. Together they cover collection, history and visualization.

Do I need to open ports 9090 and 9100 in the firewall?

No. When everything runs on the same VPS, Prometheus reads node\_exporter over the machine itself, so both ports can listen only on 127.0.0.1. Open 9100 only when a Prometheus on another server needs to scrape it, and only for that server's IP.

How much RAM do Grafana and Prometheus use?

Monitoring a few VPS, the three components together usually stay within a few hundred MB. Usage grows with the number of series scraped, the retention and the number of open dashboards. A 2 GB VPS handles a small setup and 4 GB leaves headroom for dozens of servers.

Which dashboard should I use with node\_exporter?

Node Exporter Full, ID 1860, is the most widely used. Import it through Dashboards, New, Import, enter the ID and pick the Prometheus data source. It already includes CPU per core, memory, swap, disk, network and filesystems.

Does Grafana replace an uptime monitor?

Not entirely. If Grafana and Prometheus run on the same VPS that went down, no alert leaves it. To know about an outage for sure, also keep an external monitor, such as Uptime Kuma installed on another machine.

Next step

See Xeon VPS

Xeon VPS for steady workloads, automation and long-running projects.

[See Xeon VPS](https://streethosting.com.br/en/vps/xeon)

[See VPS plans Root VPS in Brazil with NVMe and Anti-DDoS.](https://streethosting.com.br/en/vps)

## Related guides

[VPS Intermediate How to monitor a VPS 24/7: metrics, alerts and uptime An uptime monitor on its own will not tell you the disk is filling up or that backups stopped three weeks ago. Here is how to combine availability, resources, scheduled jobs and alerts into a routine that works day and night. 10 min Read guide](https://streethosting.com.br/en/guides/vps/monitor-vps-24-7) [VPS Intermediate How to monitor VPS resources with htop and Netdata You only know you need a bigger plan once you can see the numbers. htop gives you a quick snapshot in the terminal, and Netdata gives you a full dashboard with CPU, RAM and disk history. 3 min Read guide](https://streethosting.com.br/en/guides/vps/monitor-vps-resources-htop-netdata) [VPS Intermediate How to set up Nginx as a reverse proxy on a VPS Your app runs on an internal port and you want to serve it on a domain with HTTPS. Nginx as a reverse proxy solves that and also brings several apps together in one place. 3 min Read guide](https://streethosting.com.br/en/guides/vps/nginx-reverse-proxy-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
