Configuration parameters: Zabbix bridge adapter

Overview

Configuration parameters allow customizing Zabbix bridge adapter behavior.

Specify parameter values in the configuration file (zabbix_bridge_adapter.conf). All parameters are optional, unless explicitly stated that the parameter is mandatory.

This page is structured as:

  • Parameter overview (to see full details of a parameter, click its name)
  • Parameter details
Parameter Description
AllowedAPIMethods Specify which Zabbix API methods can be called through Zabbix bridge adapter.
DataDir Specify the directory where the bridge adapter state file and encryption keys are created and stored.
DebugLevel Set the debug level.
Include Specify a directory or individual files to be included in the configuration file.
ListenIP Specify the bridge adapter listen IP address for incoming HTTP[S] connections from Zabbix server.
ListenHealthPort Specify the bridge adapter listen port for incoming HTTP health-check connections.
ListenPort Specify the bridge adapter listen port for incoming HTTP[S] connections from Zabbix server.
LogFile Specify the full path to the bridge adapter log file.
LogFileSize Set the maximum log file size (in MB).
LogType Specify the log output type.
PidFile Specify the PID file.
TLSConfig.AllowedCN Specify a comma-separated list of permitted client Common Names (mTLS only).
TLSConfig.CAFile Specify the full path to a file containing the top-level CA certificate(s) used to verify client certificates in mTLS mode.
TLSConfig.CertFile Specify the full path to a file containing the certificate or certificate chain.
TLSConfig.KeyFile Specify the full path to a file containing the private key.
TLSConfig.Mode Set the TLS mode for incoming connections on ListenPort.
ServerId Specify the unique identifier of Zabbix server. Mandatory.
ZabbixAPITLSCAFile Specify the full pathname of a file containing the top-level CA certificate(s) used by the bridge adapter to verify the Zabbix API certificate.
ZabbixAPITLSConnect Set the TLS mode for outbound connections to the Zabbix API.
ZabbixAPIURL Specify the URL of the Zabbix API endpoint. Mandatory.
ZabbixBridgeURL Specify Zabbix Bridge URL for Zabbix Bridge configuration retrieval (retrieved when the bridge adapter starts).

Note that:

  • The default values reflect process defaults, not the values in the shipped configuration files.
  • Values support environment variables.
  • Zabbix supports configuration files only in UTF-8 encoding without BOM;
  • Comments starting with # are only supported at the beginning of the line.

Parameter details

AllowedAPIMethods

Specify which Zabbix API methods can be called through Zabbix bridge adapter.
For several methods, repeat the parameter, one method per line.

Each parameter value must be either an exact method name (e.g., problem.get) or a wildcard pattern that replaces only the whole API name (e.g., *.get) or the whole method name (e.g., problem.*).

Any other value is invalid and prevents Zabbix bridge adapter from starting. This includes a lone wildcard (*), a partial wildcard pattern (host* or host*.*), or an empty value (AllowedAPIMethods=).

Example:

AllowedAPIMethods=apiinfo.version
AllowedAPIMethods=problem.*
AllowedAPIMethods=*.get

The minimal set of methods that Zabbix mobile app requires:

AllowedAPIMethods=apiinfo.version
AllowedAPIMethods=device.onboard
AllowedAPIMethods=device.offboard
AllowedAPIMethods=user.get
AllowedAPIMethods=role.get
AllowedAPIMethods=problem.get
AllowedAPIMethods=event.get
AllowedAPIMethods=event.acknowledge
AllowedAPIMethods=trigger.get
AllowedAPIMethods=alert.get
AllowedAPIMethods=host.get
AllowedAPIMethods=hostgroup.get

Default: not set (all Zabbix API methods are denied)

DataDir

Specify the directory where the bridge adapter state file and encryption keys are created and stored.
The directory must have 0700 permissions, and all files stored in it must have 0600 permissions.

Default: /var/lib/zabbix-bridge-adapter

DebugLevel

Set the debug level:

  • 0 - basic information about starting and stopping of Zabbix processes
  • 1 - critical information
  • 2 - error information
  • 3 - warnings
  • 4 - for debugging (produces lots of information)
  • 5 - extended debugging (produces even more information)

Default: 3
Range: 0-5

Include

Specify a directory or individual files to be included in the configuration file.
During Zabbix installation, this parameter is set to /usr/local/etc, unless you change this during compile time.

General rules for the Include parameter:

  • The path can be relative to the zabbix_bridge_adapter.conf file location.
  • You can specify multiple Include parameters in one configuration file.
  • Zabbix processes the Include parameter as soon as it reads it, so consider placing it at the end of the configuration file.

Rules for included files:

  • Each file must be readable.
  • Each file must have correct syntax. Otherwise, the component will not start.

Rules for including directories or file patterns:

  • Do not assume any order of inclusion (e.g., files are not included in alphabetical order).
  • Do not define the same parameter in more than one included file (e.g., to override a general setting with a specific one), since you cannot predict which value will be used.
  • Watch out for backup copies that some text editors create automatically (e.g., editing include/my_specific.conf may create include/my_specific.conf.BAK), since both files will be included.

To include only relevant files from a directory, use the wildcard (*) for pattern matching.

Example:

Include=/absolute/path/to/config/files/*.conf
ListenIP

Specify the bridge adapter listen IP address for incoming HTTP[S] connections from Zabbix server.
If not specified, the bridge adapter listens on all IP addresses.

ListenHealthPort

Specify the bridge adapter listen port for incoming HTTP health-check connections.
Serves the /health and /ready endpoints.
If not specified, the health service is not started.

Default: 8081
Range: 1024-32767

ListenPort

Specify the bridge adapter listen port for incoming HTTP[S] connections from Zabbix server.

Default: 10005
Range: 1024-32767

LogFile

Specify the full path to the bridge adapter log file.

Mandatory: Yes if LogType is set to file

Default: /tmp/zabbix_bridge_adapter.log

LogFileSize

Set the maximum log file size (in MB).
0 - disable automatic log rotation.

Default: 1
Range: 0-1024

LogType

Specify the log output type:

  • file - write log to file specified by LogFile parameter.
  • system - write log to syslog.
  • console - write log to standard output.

Default: file

PidFile

Specify the PID file.

Default: /tmp/zabbix_bridge_adapter.pid

ServerId

Specify the unique identifier of Zabbix server.
Available in Reports > System information in the Zabbix user interface.

Mandatory: Yes

TLSConfig.AllowedCN

Specify a comma-separated list of permitted client Common Names (mTLS only).
If not specified, the bridge adapter does not check the client Common Name.

TLSConfig.CAFile

Specify the full path to a file containing the top-level CA certificate(s) used to verify client certificates in mTLS mode.

TLSConfig.CertFile

Specify the full path to a file containing the certificate or certificate chain.

TLSConfig.KeyFile

Specify the full path to a file containing the private key.

TLSConfig.Mode

Set the TLS mode for incoming connections on ListenPort:

  • none - accept connections without encryption.
  • tls - standard TLS with v1.2 minimum.
  • mtls - extends TLS with mutual authentication.

Default: none

ZabbixAPITLSCAFile

Specify the full pathname of a file containing the top-level CA certificate(s) used by the bridge adapter to verify the Zabbix API certificate.

Mandatory: Yes if ZabbixAPITLSConnect is set to verify_ca or verify_full.

ZabbixAPITLSConnect

Set the TLS mode for outbound connections to the Zabbix API:

  • disabled (or empty) - use plain HTTP; ZabbixAPIURL must use http://.
  • required - use HTTPS without certificate verification (testing only).
  • verify_ca - use HTTPS and verify the Zabbix API certificate.
  • verify_full - use HTTPS and verify the Zabbix API certificate and hostname.
ZabbixAPIURL

Specify the URL of the Zabbix API endpoint.

Mandatory: Yes

Example:

ZabbixAPIURL=https://example.com/zabbix/api_jsonrpc.php
ZabbixBridgeURL

Specify Zabbix bridge URL for Zabbix Bridge configuration retrieval (retrieved when the bridge adapter starts).

Default: ZabbixBridgeURL=https://test.aws.zabbix-lab.win/.well-known/bridge-configuration