The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / haproxy / haproxy-how-it-works-in-production

Operations Guides

How HAProxy actually works in production: a mental model for operators

Most HAProxy incidents come from an operator applying the wrong mental model: treating HAProxy like a web server, like nginx, or like a black box that either works or does not. HAProxy is an event-driven state machine that multiplexes hundreds of thousands of connections across a small number of threads, and almost every confusing symptom traces back to one of a handful of internal mechanisms: the accept pipeline, the maxconn hierarchy, the buffer and connection pools, the health check engine, or a subsystem you forgot was running.

This article is the mental model. It does not fix a specific symptom. It explains what HAProxy is doing at all times, so that when a runbook tells you to check qcur or Idle_pct or show table, you know which internal mechanism that signal belongs to and why it matters.

What it is and why it matters

HAProxy is an event-driven Layer 4 (TCP) and Layer 7 (HTTP/HTTPS) proxy and load balancer. It accepts connections on frontends, evaluates ACL rules to route them to backends, and forwards traffic to individual servers within those backends. That three-level object model is the skeleton everything else hangs on. Almost every stat HAProxy exposes is scoped to one of these three.

Two properties of the engine shape everything operationally:

Event-driven, not process-per-connection. The core event loop uses the kernel’s most efficient poller (epoll on Linux) to multiplex connections across a configurable number of threads (nbthread). There is no thread per connection. One thread handles thousands of concurrent connections by waking only when a socket is ready. This is why CPU cost is driven by events (new connections, TLS handshakes, header parsing) rather than by connection count, and why Idle_pct (time spent waiting in poll()) is a more honest CPU saturation measure than system CPU. In current versions, threads are the only scaling model: nbproc was deprecated and scheduled for removal in the 2.4 manual, and multi-process directives no longer appear in current configuration documentation.

Two sides per proxied connection. For every proxied request, HAProxy holds a client-side connection (to the frontend) and a server-side connection (to the backend). These are independent. HAProxy can hold a client connection open while waiting for a server slot, and it can reuse a persistent server connection across many client requests. This asymmetry explains the resource math: roughly two file descriptors per proxied connection, two buffers per connection, and a connection pool on the backend side that behaves nothing like the frontend side.

How it works: the request pipeline

For an HTTP request, the internal pipeline looks like this:

flowchart LR
  A[Client] --> B[Accept on frontend socket]
  B --> C[TLS handshake]
  C --> D[Parse request, evaluate ACLs]
  D --> E[Backend selection and stick lookup]
  E --> F{Server slot free?}
  F -- no --> G[Queue]
  G --> F
  F -- yes --> H[Connect or reuse pooled connection]
  H --> I[Forward request and response]
  I --> J[Log at session end]

Step by step:

  1. Accept. The connection arrives on a frontend listener socket and enters the OS accept queue (net.core.somaxconn). If that queue overflows, SYNs are dropped in the kernel and HAProxy never sees the connection at all. This is the classic “HAProxy looks fine but clients time out” case; it shows up in /proc/net/netstat as ListenOverflows and ListenDrops, not in any HAProxy counter.
  2. TLS handshake. If the frontend terminates SSL, the handshake runs here. It is the most CPU-intensive operation HAProxy performs, and it consults the session cache or ticket. High new-connection rates with low session reuse are how frontends melt without any backend involvement.
  3. Request parsing. Headers are read into a per-connection buffer (default 16KB, tune.bufsize). Request rules and ACLs are evaluated here. Requests that cannot be parsed become ereq and HAProxy-generated 400s.
  4. Backend selection. The routing decision: ACLs, stick-table lookup, balancing algorithm. Session persistence and rate-limit state are consulted here.
  5. Queue. If the chosen server or backend has reached its maxconn, the request enters a per-server or per-backend queue and waits. Queuing is backpressure, not an error. With maxqueue at its default of 0 the queue is unbounded; the request waits until a slot frees or a timeout fires.
  6. Connect to server. Either a new TCP connection or reuse of an idle connection from the connection pool (http-reuse). Reuse is what keeps ctime near zero and backend TLS handshake cost down.
  7. Forward request, receive response, forward response. Response rules are evaluated on the way back.
  8. Logging. The log line is emitted at session close, or at request end in HTTP mode. If the log target cannot keep up, HAProxy drops log lines and only the DroppedLogs counter tells you.

The pipeline explains the latency decomposition HAProxy exposes: ttime (total) is approximately qtime (queue) + ctime (connect) + rtime (server response) + data transfer. When you know which pipeline stage each timer belongs to, a latency incident localizes itself.

The maxconn hierarchy

HAProxy enforces connection limits at four levels, independently:

  • Global maxconn. The process-wide ceiling. HAProxy derives it from the file descriptor limit at startup if you do not set it explicitly.
  • Frontend maxconn. Caps concurrent sessions per frontend. If unset, it inherits from the global limit.
  • Backend maxconn. Caps connections into a backend as a whole.
  • Per-server maxconn. Caps concurrent connections to one server. Default is no limit, which is often a misconfiguration: most application servers cannot absorb unbounded concurrency and degrade silently instead.

The operational consequence: any one of these can be the binding constraint while the other three look fine. A per-server limit can cause queuing (qcur rising) while the frontend has plenty of headroom. This is why saturation runbooks check scur/slim at every row type, not just the global CurrConns/Maxconn. Saturation against one of these limits, where the process is alive and healthy but new work queues or is rejected, is the single most common HAProxy operational issue.

The subsystems that matter

These run continuously, independent of any single request, and each owns a failure archetype.

Buffer pools. Pre-allocated memory for connection buffers, two per connection (request and response, each tune.bufsize). Under memory pressure, connections stall waiting for buffers, which produces latency spikes with no CPU or network explanation. The PoolFailed counter in show info is the confirmation signal; it should always be zero.

Connection pools. Idle backend connections kept alive for reuse via http-reuse. The connect vs reuse counters show the ratio of new to reused backend connections, and idle_conn_cur shows the pool depth. When reuse silently breaks (backend starts sending Connection: close, HTTP version change, config drift), you pay full TCP and possibly TLS cost per request, and ctime and backend handshake rates spike.

Stick tables. In-memory key-value stores for session persistence, rate limiting, and tracking. Fixed size. When full, the default is to purge expired entries; with nopurge, new entries are rejected outright. Either way, the functionality the table backs (rate limiting, persistence) silently stops working for affected clients. There is no eviction counter. show table is the only way to see utilization. Tables can be replicated between instances via the peers subsystem.

Health check engine. Runs independently of traffic, periodically probing servers over TCP, HTTP, agent-check, or external scripts. The resulting state (UP, DOWN, MAINT, DRAIN, plus transition states like UP 1/3) is the routing table. Two things to internalize: rise/fall thresholds mean there is a deliberate delay between a real failure and a status change, and a passing health check proves only that the check passes. A server can return 200 on /health while 500ing every real request. That gap is its own failure pattern.

DNS resolver. Used for dynamic server resolution (server-template, SRV records). Resolution failures do not immediately change routing: HAProxy keeps using cached results until TTL expiry, then it is stuck. In service-discovery deployments this means traffic can silently flow to stale IPs while every health-visible signal looks acceptable. show resolvers exposes sent queries, answers, timeouts, and errors.

Peers subsystem. Replicates stick-table state between HAProxy instances. Broken peer sync causes state divergence: rate limiting works on one node and not the other, session affinity breaks across failover. show peers shows connection state and replication activity per peer.

SSL engine. Handles TLS termination. Session cache, OCSP stapling, and certificate storage all consume memory, and handshake CPU cost dominates under high new-connection rates. The session cache is invalidated on every reload, which is why SslFrontendKeyRate spikes after each reload even with constant traffic.

Where it shows up in production

The failure archetypes below are not random; each maps to one mechanism above. Recognizing the mapping is most of diagnosis.

ArchetypeMechanismDistinguishing signature
Connection saturationmaxconn hierarchyscur flat at slim, queuing or 503s, CPU often fine
Backend collapse cascadehealth check engine + redistributionServers go DOWN sequentially, survivors overload, more go DOWN
TLS CPU exhaustionSSL engineSslFrontendKeyRate high, Idle_pct collapsing, backends healthy
Buffer starvationbuffer poolsLatency spikes with no CPU/network cause, PoolFailed nonzero
Reload stormsprocess lifecycleMultiple haproxy PIDs, Stopping: 1 lingering, FD and memory growth
Stick-table overflowstick tablesRate limiting or persistence silently degrades, table at capacity
Backend timeout cascadequeue + slow serversServers UP, rtime and qcur climbing, 504s
Ephemeral port exhaustionbackend-side socketsecon spikes with no backend failure
Kernel accept queue overflowOS accept queueListenOverflows rising, clients time out, HAProxy sees nothing
DNS resolver failureresolverStale IPs, show resolvers errors, servers UP until they are not

Deployment variants change which of these you can even see. TCP mode loses every HTTP-level signal (response codes, request rates). Multi-threaded mode (nbthread > 1) spreads load but makes some counters per-thread, so show activity per-thread counters become necessary to spot a single hot thread that the averaged Idle_pct hides. With busy-polling enabled, Idle_pct sits near zero by design and you must use show activity run-queue depth or system CPU instead. Active-passive pairs have a standby with no traffic signals at all, so failover detection replaces traffic monitoring there. Master-worker mode means the master is always alive while workers restart; monitor the worker, not the master. Reloads reset every cumulative counter, so rate math must handle resets and Uptime_sec is your reload detector.

Signals to watch in production

You do not need all of these on day one, but you should know which subsystem each one belongs to.

SignalWhy it mattersWarning sign
Stats socket responsiveness (show info)Proves the event loop is processing, not just that a PID existsNo response while process exists
Backend/server statusThe routing tableAny server DOWN; backend row DOWN is an outage
scur/slim at all four levelsThe binding maxconn constraint can be anywhereRatio sustained above 80%
qcur, qtimeEarliest saturation indicator, before errorsAny sustained nonzero value
rtime per serverBackend application health as HAProxy sees it> 2x baseline, or dropping while 5xx rises (failing fast)
wretr/wredisHAProxy masking backend instability from usersSustained nonzero; the canary most teams miss
Frontend minus backend hrsp_5xx deltaIsolates HAProxy-generated errors from backend errorsDelta rising
Idle_pctEvent loop headroom (meaningless with busy-polling)Sustained below 20%
PoolFailedInternal memory allocation failuresAny nonzero value
connect vs reuseConnection pool healthReuse ratio dropping
show table utilizationSilent rate-limit/persistence failureTable above 80% of size
show resolvers, show peersDynamic routing and state replication integrityTimeouts, errors, disconnected peers
ListenOverflows/ListenDropsPre-accept losses invisible to HAProxyCounters incrementing
SslFrontendKeyRate, cache hit ratioTLS CPU costHigh key rate with low cache effectiveness

How Netdata helps

  • Netdata collects HAProxy stats continuously, so scur/slim, qcur, hrsp_5xx, econ/eresp, and wretr/wredis are available as time series at every level (frontend, backend, server) without hand-rolled socat cron jobs.
  • The latency decomposition (qtime, ctime, rtime, ttime) is charted together, which turns “latency is up” into “the queue stage is up” in one glance.
  • Correlating server status transitions with per-server scur and rtime on the same dashboard makes the backend-collapse cascade visible as it develops, rather than after the last server goes DOWN.
  • Idle_pct alongside SslFrontendKeyRate separates TLS-driven CPU exhaustion from general traffic load, which is the difference between “scale TLS” and “scale everything.”
  • Because Netdata also collects host metrics, kernel-level signals like ListenOverflows/ListenDrops and file descriptor headroom sit next to HAProxy’s own counters, closing the “HAProxy saw nothing” blind spot.
  • Counter resets on reload appear as such in the time series, so reload storms do not read as phantom rate spikes when you correlate with uptime.
The Netdata solution

HAProxy load balancer monitoring with Netdata

Netdata monitors HAProxy with per-second frontend, backend, and queue metrics plus ML-powered anomaly detection. Correlate maxconn saturation, queue buildup, health-check cascades, 5xx attribution, and file-descriptor exhaustion against the backend and host signals behind them, so you catch the incidents in these runbooks before they page anyone.