Grafana on a VPS is the dashboard that reads the metrics Prometheus collects on that server: CPU, memory, disk, and network. Without that history, the team finds out the disk is full only after the application is already down.
This guide installs Node Exporter, Prometheus, and Grafana on Ubuntu 22.04 or 24.04. The pinned versions are Prometheus 2.53.0 and Node Exporter 1.8.2. Before you copy the commands, check that they are still the stable releases at github.com/prometheus/prometheus/releases.
The stack concept is in monitoring with Prometheus and Grafana. The server itself can be a managed KVM VPS.
1. Create the service users
The binaries should not run as root.
sudo useradd --no-create-home --shell /usr/sbin/nologin prometheus
sudo useradd --no-create-home --shell /usr/sbin/nologin node_exporter
2. Install Node Exporter
Node Exporter publishes operating system metrics on port 9100.
cd /tmp
NODE_VERSION=1.8.2
wget https://github.com/prometheus/node_exporter/releases/download/v${NODE_VERSION}/node_exporter-${NODE_VERSION}.linux-amd64.tar.gz
tar xzf node_exporter-${NODE_VERSION}.linux-amd64.tar.gz
sudo mv node_exporter-${NODE_VERSION}.linux-amd64/node_exporter /usr/local/bin/
sudo chown node_exporter:node_exporter /usr/local/bin/node_exporter
Create /etc/systemd/system/node_exporter.service:
[Unit]
Description=Node Exporter
After=network.target
[Service]
User=node_exporter
Group=node_exporter
Type=simple
ExecStart=/usr/local/bin/node_exporter
[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable --now node_exporter
curl -s localhost:9100/metrics | head
The last command must print metrics (node_cpu_seconds_total or similar). If curl fails, run systemctl status node_exporter.
3. Install Prometheus
cd /tmp
PROM_VERSION=2.53.0
wget https://github.com/prometheus/prometheus/releases/download/v${PROM_VERSION}/prometheus-${PROM_VERSION}.linux-amd64.tar.gz
tar xzf prometheus-${PROM_VERSION}.linux-amd64.tar.gz
sudo mv prometheus-${PROM_VERSION}.linux-amd64/prometheus prometheus-${PROM_VERSION}.linux-amd64/promtool /usr/local/bin/
sudo mkdir -p /etc/prometheus /var/lib/prometheus
sudo chown -R prometheus:prometheus /etc/prometheus /var/lib/prometheus
Write /etc/prometheus/prometheus.yml:
global:
scrape_interval: 15s
scrape_configs:
- job_name: prometheus
static_configs:
- targets: ["localhost:9090"]
- job_name: node
static_configs:
- targets: ["localhost:9100"]
sudo chown prometheus:prometheus /etc/prometheus/prometheus.yml
Create /etc/systemd/system/prometheus.service:
[Unit]
Description=Prometheus
After=network.target
[Service]
User=prometheus
Group=prometheus
Type=simple
ExecStart=/usr/local/bin/prometheus \
--config.file=/etc/prometheus/prometheus.yml \
--storage.tsdb.path=/var/lib/prometheus
[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable --now prometheus
curl -s localhost:9090/-/ready
The expected response is Prometheus Server is Ready.
4. Install Grafana and import the dashboard
sudo apt-get install -y apt-transport-https wget
sudo mkdir -p /etc/apt/keyrings/
wget -q -O - https://apt.grafana.com/gpg.key | gpg --dearmor | sudo tee /etc/apt/keyrings/grafana.gpg > /dev/null
echo "deb [signed-by=/etc/apt/keyrings/grafana.gpg] https://apt.grafana.com stable main" | sudo tee /etc/apt/sources.list.d/grafana.list
sudo apt-get update
sudo apt-get install -y grafana
Keep the panel on the local interface. In /etc/grafana/grafana.ini, under [server]:
http_addr = 127.0.0.1
http_port = 3000
sudo systemctl enable --now grafana-server
From your laptop, open a tunnel and browse to http://127.0.0.1:3000:
ssh -L 3000:127.0.0.1:3000 deploy@VPS_IP
Initial login: admin / admin. Change the password on first access. Under Connections, Data sources, add Prometheus with URL http://127.0.0.1:9090. Under Dashboards, New, Import, use ID 1860 (Node Exporter Full) and select that data source.
5. Firewall
Prometheus (9090) and Node Exporter (9100) stay on localhost in this guide. Do not publish those ports on the internet. If SSH is not allowed yet, allow it before you enable the firewall:
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status
Conclusion
With dashboard 1860 open through the SSH tunnel, the VPS has a history of CPU, memory, disk, and network. The next operational step is an alert: disk above 80 percent and load above the vCPU count. If you would rather not run this stack, monitoring is part of a managed VPS, where engineering watches the same signals.