Skip to content

Cockpit (Web Admin + RAID)

TL;DR / when to use this: Cockpit is the web admin panel I run on the server for the things Proxmox/Nginx UIs don't do well: mounting/unmounting disks, creating RAID arrays, and SMB file sharing. It's also where I enforce sudo 2FA via PAM. Runs on port 9090 and requires a non-root user.

Install

sudo apt update
sudo apt install cockpit cockpit-storaged -y
sudo systemctl enable --now cockpit.socket

Cockpit can't log in as root — create a user:

adduser thomas
usermod -aG sudo thomas

SMB file sharing

sudo apt install samba
sudo systemctl enable smbd
sudo systemctl start smbd
sudo apt install curl
curl -sSL https://repo.45drives.com/setup | sudo bash
sudo apt-get update
sudo apt-get install cockpit-file-sharing
sudo smbpasswd -a thomas
sudo systemctl restart smbd nmbd

RAID 1 arrays

In Cockpit's Storage tab: drives appear on the right, nothing under Devices until you create a RAID device from the menu button. Command-line equivalents:

cat /proc/mdstat                 # view RAID devices
sudo mdadm --detail --scan       # inspect an array
lsblk                            # the raid1 array shows here too
sudo mount /dev/md0 /mnt/raid
sudo umount /mnt/raid

Proxmox's UI can't mount/unmount disks cleanly, which is exactly why Cockpit stays installed — see Proxmox VE. Converting a RAID1 to a ZFS mirror is covered in Proxmox VE.

Sudo 2FA (PAM)

Two-factor authentication on sudo means a stolen password alone doesn't grant admin. Install the PAM module:

sudo apt install libpam-google-authenticator
google-authenticator
  • Answer yes to time-based tokens
  • Scan the QR with an authenticator app
  • Save the emergency backup codes somewhere safe

Then add this line at the top of /etc/pam.d/sudo (before any other auth lines):

auth required pam_google_authenticator.so

Test with sudo ls. The same trick works for Cockpit logins — add the identical line to the top of /etc/pam.d/cockpit.

See also