Skip to main content

Ports and network flows

Every listening port and every outbound connection, so a firewall rule set can be written from one table.

Listening (inbound)​

PortProcessConfig keyWho connects
17000n9e (Center)[HTTP] PortBrowsers, API clients, MCP clients, Categraf
19000n9e-edge[HTTP] Port in etc/edge/edge.tomlBrowsers and collectors at that site
20090ibex, in n9e / n9e-edge[Ibex] RPCListenCategraf's self-healing agent

What is on 17000​

Write endpoints and the admin UI share the port, which is the single most important fact when locking down the network:

PathPurposeWho should reach it
/Web UIPeople
/api/n9e/*The API the frontend runs onPeople, automation
/prometheus/v1/writePrometheus Remote Write ingestCollectors
/opentsdb/putOpenTSDB protocol ingestCollectors
/openfalcon/pushOpen-Falcon protocol ingestCollectors
/datadog/api/v1/seriesDatadog Agent ingestCollectors
/v1/n9e/heartbeatCollector heartbeatCollectors
/prometheusQuery endpoint of the embedded TSDBNightingale itself (localhost only by default)
/mcp, /a2aMCP / A2A endpointsAI clients
/metricsIts own metricsYour monitoring

So "just expose 17000" is not an answer. Either put the whole thing behind a gateway that splits by path, or separate the collector network from the user network. See Network and TLS hardening.

Outbound​

TargetAddress fromWhen needed
MySQL / PostgreSQL[DB] DSNProduction (not needed while on SQLite)
Redis[Redis] AddressProduction (not needed while on miniredis)
Data sourcesThe data source's own configEvery evaluation, every query
External TSDB[[Pushgw.Writers]] UrlWith the embedded TSDB off, or during a dual write
Notification mediaThe media type's URL / SMTP serverEvery notification
LLM providerThe LLM config's API URLWhen using Nightingale AI

Edge mode​

n9e-edge needs to reach the centre's 17000 to pull rule configuration, and the centre needs [HTTP.APIForService] Enable = true. The rest of the edge flows are in Edge data centers.