Skip to content
Nicholas Antinori edited this page Aug 4, 2026 · 1 revision

This page explains Administration → Web (embedded agent with local UI).

Central has a separate web stack — see Central properties below.


Embedded: port and bind address

Setting Default Notes
Port 4000 Same port serves the UI and /backend/… API.
Bind address 127.0.0.1 Localhost only. To reach the UI from another machine, set 0.0.0.0 (or a specific interface IP) and restart the JVM.

Startup logs call this out when bound to localhost.

JVM override: -Dglowroot.agent.port=<port> fixes the port at startup. The UI shows the port as read-only while that property is set.

Port 0: the OS assigns an ephemeral port at bind time. This is not a way to disable the UI — Glowroot always tries to serve the web interface when embedded.


Embedded: HTTPS and context path

HTTPS is optional. When enabled, place certificate and key files under the agent conf/ directory (ui-cert.pem, ui-key.pem) — the UI validates them before saving.

Context path defaults to /. Change only if you front Glowroot behind a reverse proxy that expects a sub-path.

Session timeout and cookie name are also on this page; they affect how long UI/API sessions stay logged in.


Central collector

On Central, web settings live in glowroot-central.properties (not the per-agent Web page):

Property Purpose
ui.port UI port (default 4000)
ui.bindAddress Bind address (default often 0.0.0.0 on Central — check your file)
ui.https Enable HTTPS
ui.contextPath Context path

Agent gRPC uses separate grpc.* settings. Agents do not talk to Central over the UI port.

See Central Collector Installation for the full properties list.


Practical tips

  1. Cannot open UI remotely? Check bind address (127.0.0.1 vs 0.0.0.0) and firewall rules on the UI port.
  2. Port conflict on startup? Change port in Administration → Web, or set -Dglowroot.agent.port before restart.
  3. Automating against /backend/…? Same host/port as the UI — see HTTP API and export.
  4. Want no UI at all? Glowroot embedded is designed around the local UI/API — there is no supported “turn off web” switch. Use network binding and auth instead.

See also

Clone this wiki locally