# Ports Registry — NAS Synology DS920+ # Derniere mise a jour : 12/07/2026 (resync etat REEL, 41 containers) # LIRE CE FICHIER AVANT TOUT NOUVEAU DEPLOIEMENT # Mettre a jour apres chaque ajout/suppression de service --- ## Regle absolue Aucun nouveau service ne doit utiliser un port deja occupe. Choisir un port libre et l'inscrire ici avant de deployer. --- ## SERVICES ACTIFS — Etat REEL au 12/07/2026 Source de verite = `docker ps` reel (via socket), pas le declaratif. Colonne Exposition = binding reel constate. Restart/Health signales quand a risque. | Service | Port | Domaine | Reseau | Exposition | Restart | Health | Notes | |---------|------|---------|--------|------------|---------|--------|-------| | n8n | 5678->5678 | n8n.bolbol.tn | n8n,n8n_default | 0.0.0.0 | **on-failure** | healthy | Orchestration centrale ; restart on-failure (voir alerte) | | n8n-DB | interne | - | n8n_default | interne Docker | **on-failure** | **none** | Postgres n8n ; reseau n8n_default ; restart on-failure | | Baserow | 3888->80 | baserow.bolbol.tn | baserow_baserow_network,n8n | 0.0.0.0 | unless-stopped | healthy | Base metier ; depends db+redis healthy | | Baserow-DB | interne | - | baserow_baserow_network | interne Docker | unless-stopped | healthy | Postgres Baserow | | Baserow-REDIS | interne | - | baserow_baserow_network | interne Docker | unless-stopped | healthy | Redis Baserow | | baserow-oauth-proxy | 3887->80 | baserow.bolbol.tn (a repointer : reverse-proxy DSM 3888->3887, manuel) | n8n | 0.0.0.0 | unless-stopped | - | nginx : intercepte /.well-known/oauth-*, /register, /authorize, /token pour connecteur Claude.ai (404 natif sur Baserow) ; proxy transparent WS+SSE vers Baserow sinon ; ajoute 28/07/2026 | | baserow-oauth-app | interne (8080) | - | n8n | interne Docker | unless-stopped | - | Stub OAuth Starlette (register/authorize/token, PKCE) pour baserow-oauth-proxy ; ajoute 28/07/2026 | | baserow-schema-mcp | interne (8000) | - | n8n | interne Docker | unless-stopped | - | Serveur MCP compagnon : create_table/delete_table/create_field/delete_field (proxy JWT vers API REST Baserow, Database token insuffisant sur ces routes) ; ajoute 17/08/2026 | | baserow-schema-mcp-oauth-app | interne (8080) | - | n8n | interne Docker | unless-stopped | - | Stub OAuth (meme pattern que baserow-oauth-app) pour baserow-schema-mcp-proxy ; ajoute 17/08/2026 | | baserow-schema-mcp-proxy | 3101->80 | baserow-schema.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | - | nginx : OAuth discovery + proxy SSE vers baserow-schema-mcp ; ajoute 17/08/2026 | | gitea | 2222->22, 3232->3232 | gitea.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Versioning (bolbol) ; SSH 2222 + 3232 | | portainer | 9000->9000, 9443->9443 | portainer.bolbol.tn | bridge | 0.0.0.0 | unless-stopped | **none** | Gestion containers ; reseau bridge | | nyora-notes | 8787->8787 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Memoire inter-sessions Hermes (8787) | | linux-mcp-nas | 127.0.0.1:3042->8000 | mcp-nas.nd.i234.me | n8n | 127.0.0.1 | always | healthy | MCP shell NAS ; bind 127.0.0.1 (via reverse-proxy) | | bifrost | 3085->8080 | - (retire du WAN 03/07) | n8n | 0.0.0.0 | unless-stopped | healthy | Gateway LLM ; piege allow_all_keys DB | | bifrost-proxy | 3086->80 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Auth rewrite + cap 16384 tokens ; PAS de healthcheck | | hermes-workspace-tt | 3010->3000 | hermes-tt.bolbol.tn | hermes-tt-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace TT (agent=8650 interne) | | hermes-workspace-nyora | 3020->3000 | hermes-nyora.bolbol.tn | hermes-nyora-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Nyora (agent=8660 interne) | | hermes-workspace-perso | 3031->3000 | hermes-perso.bolbol.tn | hermes-perso-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Perso -- TEMP remap 3030->3031 (12/08/2026) : port 3030 orphelin cote host, docker-proxy sans PID visible, non liberable sans sudo -- restaurer 3030 au prochain reboot NAS | | hermes-agent-tt | interne | interne | hermes-tt-net,n8n | interne Docker | unless-stopped | healthy | Agent TT ; DeepSeek V4 Flash | | hermes-agent-nyora | interne | interne | hermes-nyora-net,n8n | interne Docker | unless-stopped | healthy | Agent Nyora ; DeepSeek V4 Flash | | hermes-agent-perso | interne | interne | hermes-perso-net,n8n | interne Docker | unless-stopped | healthy | Agent Perso ; DeepSeek V4 Flash | | hermes-mail-proxy | 3060->8000 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Proxy mail Hermes (3060) | | nyora-doc-api | 3050->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora | MCP ajoute sur /mcp/ (04/08/2026, tool generate_document) | | nyora-convert-api | 3096->8000 | - | n8n | 0.0.0.0 | unless-stopped | (pas de healthcheck) | Conversion universelle document->MD (Mimo V2.5/Bifrost, texte+vision) 04/08/2026 | | redaction-pro | 3092->80 | llm.bolbol.tn | n8n | 0.0.0.0 | always | **none** | Assistant redaction LLM (proxy Bifrost) | | context-hub | 3093->8000 | context.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Contexte agents 5 scopes ; MCP SSE | | family-help | 3041->8000 | help.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | IA familiale FastAPI+SQLite ; PAS de healthcheck | | gsparc-mezzouna-api | 3040->8000 | gsparc-mezzouna.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | OCR carburant kimi-k2.6 | | rla-api | 3005->3005 | rla.bolbol.tn | bridge | 0.0.0.0 | unless-stopped | **none** | RLA contrats TT ; reseau BRIDGE (voir alerte couplage) | | reglement-definitif-api | 5099->5055 | - | n8n | 0.0.0.0 | **no** | **none** | Reglement definitif TT ; restart NO (voir alerte) | | veille-frontend | 3055->3000 | veille.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Veille IA ; depends veille-backend | | veille-backend | interne | interne | n8n | interne Docker | unless-stopped | **none** | Backend veille FastAPI | | dashboard-terrain | 8085->8080 | dashboard-terrain.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Dashboard terrain | | panda-dashboard | 3021->80 | panda.bolbol.tn | n8n_default | 0.0.0.0 | always | **none** | Dashboard Fiat Panda ; reseau n8n_default | | Trilium | 4292->8080 | trilium.bolbol.tn | n8n,trilium_default | 0.0.0.0 | **no** | healthy | Notes ; restart NO (voir alerte) | | Pingvin-Share | 6090->3000 | share.bolbol.tn / pv.bolbol.tn | n8n,pingvin_default | 0.0.0.0 | always | healthy | Partage fichiers | | pihole | 3001->80, 192.168.100.33:53->53, 192.168.100.33:53->53/udp | - (admin 3001) | n8n | 0.0.0.0 | always | healthy | DNS LAN (53) + admin 3001 bind 0.0.0.0 | | crowdsec | 127.0.0.1:9090->8080 | - | n8n | 127.0.0.1 | always | **none** | IDS ; bind 127.0.0.1:9090 ; parse auth.log+nginx error.log | | crowdsec-firewall-bouncer | interne | - | host | interne Docker | always | **none** | Bouncer ipset ; network host ; NET_ADMIN | | vaultwarden | 3095->80 | vault.nd.i234.me | vaultwarden_default | 0.0.0.0 | unless-stopped | healthy | Password manager ; signups fermes | | wg-admin-client | interne (51820/udp non bind) | - | wg-admin-client_default | interne Docker | unless-stopped | **none** | Client WireGuard admin (tunnel VPS KeepSolid) | | watchtower-nas | interne | - | bridge | interne Docker | unless-stopped | healthy | Auto-update images (attention rollout :latest) | | ovh-ddns | interne | - | ovh-ddns_default | interne Docker | unless-stopped | **none** | Mise a jour DNS dynamique OVH | | qbittorrent-vue | 6881->6881, 6881->6881/udp, 9866->9866 | qb.bolbol.tn | media-stack_default,qbittorrent-vue_default | 0.0.0.0 | unless-stopped | **none** | Torrent (6881) + UI 9866 | | cin-search-tt | 3094->3000 | cin.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | **none** | Recherche CIN sous-traitants RLA ; migre depuis /volume1/web hors-Docker le 10/07/2026 ; SMTP OVH->Infomaniak, Baserow alias corrige | | formation-consultant | 8801->80 | formation.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | none | Formation autodidacte perso (nginx+basic auth) ; ajoute 25/07/2026 | --- ## Bases de donnees (internes) | Port | Service | Exposition | |------|---------|------------| | 5432 | postgres (n8n-DB, Baserow-DB) | interne / n8n_default | | 6379 | redis (Baserow-REDIS) | interne | --- ## DSM Systeme (exposition WAN reelle : seuls 80/222/443/8080 forwardes par la box) | Port | Service | Exposition | |------|---------|------------| | 80 | DSM HTTP / reverse-proxy | 0.0.0.0 | | 222 | DSM SSH (OpenSSH 8.2) | 0.0.0.0 WAN — a fermer | | 443 | DSM HTTPS / reverse-proxy | 0.0.0.0 | | 2222 | Gitea SSH | 0.0.0.0 | | 6690 | DSM Cloud Sync | 0.0.0.0 | | 8080 | DSM / watchtower | 0.0.0.0 | | 22222 | NAS SSH principal | 0.0.0.0 | --- ## SERVICES RETIRES (ne pas reinstaller, ne pas reutiliser le vhost) | Service | Port libere | Retire | Remplace par | |---------|-------------|--------|--------------| | gotenberg | 3001 (repris par pihole) | 21/06 | nyora-doc-api | | pandoc | 3002 | 21/06 | nyora-doc-api | | document-factory | 3015 | 21/06 | nyora-doc-api | | carbone | 4000 | 21/06 | nyora-doc-api | | document-factory-api | 8002 | 21/06 | nyora-doc-api | | pptx-tt-api | 8015 | 29/06 | nyora-doc-api (vhost pptx.bolbol.tn fantome a purger) | | open-webui | 3091 | 29/06 | redaction-pro | | tika | 9998 | — | gemini-3-flash OCR | | paperless | 8021 | — | — | | rayhan-frontend | 3013 | 29/06 | projet clos | | rayhan-mysql | 3306 | 29/06 | projet clos | | Plex | 32400 | — | absent du stack actuel | | prowlarr | 9696 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) | | radarr | 7878 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) | | sonarr | 8989 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) | | wg-easy | 51820/udp, 51821 | ~07/07 | Tailscale (WireGuard ne subsiste que sur le VPS KeepSolid) | | flaresolverr | 8191 | 12/07 | orphelin purge (ex-client prowlarr) | --- ## Plages libres recommandees | Plage | Usage | |-------|-------| | 3013 | LIBRE (rayhan-frontend) | | 3091 | LIBRE (open-webui) | | 3015 | LIBRE (document-factory) | | 3002 | LIBRE (pandoc) | | 4000 | LIBRE (carbone) | | 8002 | LIBRE (document-factory-api) | | 8015 | LIBRE (pptx-tt-api) | | 9998 | LIBRE (tika) | | 8021 | LIBRE (paperless) | | 3100-3199 | APIs internes (3101 pris : baserow-schema-mcp-proxy) | | 8800-8899 | UIs web (8801 pris : formation-consultant) | | 8900-8999 | Experimental | | 3887 | pris : baserow-oauth-proxy | | 3120 | reserve : nyora-notes-tt (RAG personnel mail O365, port API interne) | --- ## Ports a ne JAMAIS utiliser - 3001 : pihole admin (repris depuis gotenberg) - 8787 : nyora-notes - 3000 : port interne Docker (ne pas exposer) - 5432 : postgres interne - 53 : pihole DNS - 22 : SSH DSM interne (utiliser 22222) --- ## Historique des modifications (recentes) | Date | Action | Port | Service | |------|--------|------|---------| | 2026-08-17 | Ajout baserow-schema-mcp (serveur MCP compagnon : create_table/delete_table/create_field/delete_field, proxy JWT vers API REST Baserow -- l'image officielle Baserow n'est pas patchable et son MCP natif ne couvre que les lignes). Reste a faire : reverse-proxy DSM baserow-schema.bolbol.tn -> 3101 (manuel) puis ajout du connecteur cote Claude.ai | 3101 | baserow-schema-mcp, baserow-schema-mcp-oauth-app, baserow-schema-mcp-proxy | | 2026-08-15 | Retrait dsh-test + dsh-filebrowser (test isole NAS termine, migration definitive vers dsh-vps sur VPS hermes-nabil, valide en itinerance) | 8900,8901 | dsh-test, dsh-filebrowser | | 2026-08-14 | Ajout dsh-filebrowser (Filebrowser sur port 8901 pour upload/gestion fichiers workspace dsh-test) | 8901 | dsh-filebrowser | | 2026-08-14 | Ajout dsh-test (DeepSeek Harness test isolé, connecté à DeepSeek V4 Flash via Bifrost) | 8900 | dsh-test | | 2026-08-04 | Ajout SearXNG (recherche meta self-hosted, API JSON active, alternative Firecrawl quota epuise) | 8888 | searxng | | 2026-07-30 | Reservation port + dossier scope cree pour Gemini (acces restreint, pas de scope tt context-hub, pas de credentials O365) | 3120 | nyora-notes-tt | | 2026-07-28 | Fix connecteur Claude.ai sur Baserow MCP : sidecar OAuth stub devant Baserow (meme pattern que mcp-vps). Reste a faire : repointer reverse-proxy DSM baserow.bolbol.tn de 3888 vers 3887 (manuel) | 3887 | baserow-oauth-proxy, baserow-oauth-app | | 2026-07-25 | Ajout formation-consultant (nginx+basic auth, formation.bolbol.tn a creer manuellement en reverse-proxy DSM) | 8801 | formation-consultant | | 2026-07-12 | RESYNC v4 : -prowlarr/radarr/sonarr/wg-easy, +vaultwarden/wg-admin-client, flaresolverr marque orphelin | — | ports-registry.md v4 | | 2026-07-12 | hermes-agent-perso mem_limit 600m->768m APPLIQUE (recreate fait, healthy, data 1026:100) | — | hermes-agent-perso | | 2026-07-12 | flaresolverr purge (orphelin) — 41 containers actifs | 8191 | flaresolverr | | 2026-07-03 | RESYNC complet etat reel (43 containers) + audit securite | — | ports-registry.md v3 | | 2026-07-03 | Bifrost retire du reverse-proxy WAN (securite) | 3085 | bifrost | | 2026-07-03 | MDP UI wg-easy renforce 8->28 car | 51821 | wg-easy | | 2026-06-29 | Resync partiel v2 (voir git history) | — | — | > Note v3 : ce registre reflete l etat REEL constate via socket Docker le 03/07/2026. > Services ajoutes vs v2 : pihole, prompt-studio, hermes-mail-proxy, context-hub, nyora-doc-api, > gsparc-mezzouna-api, reglement-definitif-api, watchtower-nas, ovh-ddns, flaresolverr, crowdsec x2. > MAJ 20/07/2026 : prompt-studio desinstalle (container+image supprimes) - port 8090 libere.