🇺🇸 English | 🇸🇦 العربية | 🇪🇸 Català | 🇨🇿 Čeština | 🇩🇪 Deutsch | 🇪🇸 Español | 🇫🇮 Suomi | 🇫🇷 Français | 🇮🇹 Italiano | 🇯🇵 日本語 | 🇧🇷 Português (Brasil) | 🇷🇺 Русский | 🇹🇭 ไทย | 🇹🇷 Türkçe | 🇺🇦 Українська | 🇻🇳 Tiếng Việt | 🇨🇳 简体中文 | 🇹🇼 繁體中文
Checkmate
An open source uptime and infrastructure monitoring application
This repository contains both the frontend and the backend of Checkmate, an open-source, self-hosted monitoring tool for tracking server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Checkmate regularly checks whether a server/website is accessible and performs optimally, providing real-time alerts and reports on the monitored services' availability, downtime, and response time.
Checkmate also has an agent, called Capture, to retrieve data from remote servers. While Capture is not required to run Checkmate, it provides additional insights about your servers' CPU, RAM, disk, and temperature status. Capture can run on Linux, Windows, Mac, Raspberry Pi, or any device that can run Go.
Checkmate has been stress-tested with 1000+ active monitors without any particular issues or performance bottlenecks.
📚 Table of contents
- 📦 Demo
- 🔗 User's guide
- 🛠️ Installation
- 🚀 Performance
- 💚 Questions & Ideas
- 🧩 Features
- 🏗️ Screenshots
- 🏗️ Tech stack
- 🔗 A few links
- 🤝 Contributing
Demo
You can see the latest build of Checkmate in action.
The username is [email protected] and the password is Demouser1! (just a note that we update the demo server from time to time, so if it doesn't work for you, please ping us on the Discussions channel).
User's guide
Usage instructions can be found here.
Prerequisites
Installation
The quickest way to run Checkmate is the reference Docker Compose file. It starts two services: the all-in-one Checkmate application image (ghcr.io/bluewave-labs/checkmate) and a separate MongoDB service.
What “all-in-one” means: the Checkmate application is packaged in a single image; MongoDB is not embedded in that image and remains required. The reference Compose file starts MongoDB for you. For custom deployments, configure
DB_CONNECTION_STRINGto use an external MongoDB instance.
curl -O https://raw.githubusercontent.com/bluewave-labs/checkmate/master/docker/docker-compose.yaml
JWT_SECRET="$(openssl rand -hex 32)" docker compose up -d
Then open http://localhost:52345. If the app is reached at another origin (domain or LAN IP), set CLIENT_HOST accordingly. To build the image yourself, run docker build -f docker/Dockerfile -t checkmate . from a checkout. For TLS, put any reverse proxy (Caddy, Traefik, nginx) in front of port 52345.
There are also 1-click installation options like Repocloud, Pikapods, Coolify, Elestio, K8s, Sive Host or Cloudzy.
Configuration
The image is configured entirely through environment variables on the server container:
| Variable | Required | Description |
|---|---|---|
DB_CONNECTION_STRING |
Yes | MongoDB connection string, e.g. mongodb://mongodb:27017/uptime_db |
JWT_SECRET |
Yes | Secret used to sign auth tokens; generate one with openssl rand -hex 32 |
ENCRYPTION_KEY |
No | Encrypts stored Docker TLS client keys at rest; generate one with openssl rand -base64 32. Comma-separated list: the first key encrypts, every key decrypts. Must be identical on the API and every worker. To rotate without downtime, deploy OLD_KEY,NEW_KEY everywhere, then NEW_KEY,OLD_KEY everywhere, wait for the worker to re-encrypt every row, then drop OLD_KEY. |
CLIENT_HOST |
Yes | The URL users reach the app at, e.g. https://checkmate.example.com; used for CORS and for links in notifications and emails |
LOG_LEVEL |
No | Server log level: error, warn, info, or debug (default debug) |
The web client needs no configuration by default: it calls the API on the same origin it was served from (/api/v1). For setups where the defaults don't apply — for example, the API is reached through a different origin than the page — the server renders overrides into the client at runtime via these optional variables:
| Variable | Description |
|---|---|
CLIENT_CONFIG_API_BASE_URL |
Full base URL the client calls the API at, e.g. https://api.example.com/api/v1; defaults to same-origin /api/v1 |
CLIENT_CONFIG_CLIENT_HOST |
Origin used when the client builds absolute links (invites, status pages); defaults to the browser's current origin |
CLIENT_CONFIG_LOG_LEVEL |
Browser console log level: error, warn, info, or debug (default error) |
Upgrading from an older image? The
UPTIME_APP_*variables (UPTIME_APP_API_BASE_URL,UPTIME_APP_CLIENT_HOST,UPTIME_APP_LOG_LEVEL) are no longer read. In most setups no replacement is needed — the same-origin defaults cover them; if you pointed the client at a different origin, use theCLIENT_CONFIG_*equivalents above. Thecheckmate-client,checkmate-backend,checkmate-mongo, andcheckmate-backend-mono-multiarchimages are no longer updated — switch toghcr.io/bluewave-labs/checkmate, keeping your existing MongoDB service and data volume.
See full installation instructions in the Checkmate documentation portal.
Alternatively, you can also use Coolify, Elestio, K8s, Sive Host (South Africa), Cloudzy or Pikapods to quickly spin off a Checkmate instance. If you would like to monitor your server infrastructure, you'll need Capture agent. Capture repository also contains the installation instructions.
Using a Custom CA
If you need to monitor internal HTTPS endpoints with certificates from private Certificate Authorities (like Smallstep), see our Custom CA Trust Guide for Docker configuration options.
For more documentation, see the docs directory.
Performance
Thanks to extensive optimizations, Check