168 lines
14 KiB
Markdown
168 lines
14 KiB
Markdown
# Ports Registry — NAS Synology DS920+
|
|
# Derniere mise a jour : 12/07/2026 (resync etat REEL, 41 containers)
|
|
# LIRE CE FICHIER AVANT TOUT NOUVEAU DEPLOIEMENT
|
|
# Mettre a jour apres chaque ajout/suppression de service
|
|
|
|
---
|
|
|
|
## Regle absolue
|
|
Aucun nouveau service ne doit utiliser un port deja occupe.
|
|
Choisir un port libre et l'inscrire ici avant de deployer.
|
|
|
|
---
|
|
|
|
## SERVICES ACTIFS — Etat REEL au 12/07/2026
|
|
|
|
Source de verite = `docker ps` reel (via socket), pas le declaratif.
|
|
Colonne Exposition = binding reel constate. Restart/Health signales quand a risque.
|
|
|
|
| Service | Port | Domaine | Reseau | Exposition | Restart | Health | Notes |
|
|
|---------|------|---------|--------|------------|---------|--------|-------|
|
|
| n8n | 5678->5678 | n8n.bolbol.tn | n8n,n8n_default | 0.0.0.0 | **on-failure** | healthy | Orchestration centrale ; restart on-failure (voir alerte) |
|
|
| n8n-DB | interne | - | n8n_default | interne Docker | **on-failure** | **none** | Postgres n8n ; reseau n8n_default ; restart on-failure |
|
|
| Baserow | 3888->80 | baserow.bolbol.tn | baserow_baserow_network,n8n | 0.0.0.0 | unless-stopped | healthy | Base metier ; depends db+redis healthy |
|
|
| Baserow-DB | interne | - | baserow_baserow_network | interne Docker | unless-stopped | healthy | Postgres Baserow |
|
|
| Baserow-REDIS | interne | - | baserow_baserow_network | interne Docker | unless-stopped | healthy | Redis Baserow |
|
|
| baserow-oauth-proxy | 3887->80 | baserow.bolbol.tn (a repointer : reverse-proxy DSM 3888->3887, manuel) | n8n | 0.0.0.0 | unless-stopped | - | nginx : intercepte /.well-known/oauth-*, /register, /authorize, /token pour connecteur Claude.ai (404 natif sur Baserow) ; proxy transparent WS+SSE vers Baserow sinon ; ajoute 28/07/2026 |
|
|
| baserow-oauth-app | interne (8080) | - | n8n | interne Docker | unless-stopped | - | Stub OAuth Starlette (register/authorize/token, PKCE) pour baserow-oauth-proxy ; ajoute 28/07/2026 |
|
|
| baserow-schema-mcp | interne (8000) | - | n8n | interne Docker | unless-stopped | - | Serveur MCP compagnon : create_table/delete_table/create_field/delete_field (proxy JWT vers API REST Baserow, Database token insuffisant sur ces routes) ; ajoute 17/08/2026 |
|
|
| baserow-schema-mcp-oauth-app | interne (8080) | - | n8n | interne Docker | unless-stopped | - | Stub OAuth (meme pattern que baserow-oauth-app) pour baserow-schema-mcp-proxy ; ajoute 17/08/2026 |
|
|
| baserow-schema-mcp-proxy | 3101->80 | baserow-schema.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | - | nginx : OAuth discovery + proxy SSE vers baserow-schema-mcp ; ajoute 17/08/2026 |
|
|
| gitea | 2222->22, 3232->3232 | gitea.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Versioning (bolbol) ; SSH 2222 + 3232 |
|
|
| portainer | 9000->9000, 9443->9443 | portainer.bolbol.tn | bridge | 0.0.0.0 | unless-stopped | **none** | Gestion containers ; reseau bridge |
|
|
| nyora-notes | 8787->8787 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Memoire inter-sessions Hermes (8787) |
|
|
| linux-mcp-nas | 127.0.0.1:3042->8000 | mcp-nas.nd.i234.me | n8n | 127.0.0.1 | always | healthy | MCP shell NAS ; bind 127.0.0.1 (via reverse-proxy) |
|
|
| bifrost | 3085->8080 | - (retire du WAN 03/07) | n8n | 0.0.0.0 | unless-stopped | healthy | Gateway LLM ; piege allow_all_keys DB |
|
|
| bifrost-proxy | 3086->80 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Auth rewrite + cap 16384 tokens ; PAS de healthcheck |
|
|
| hermes-workspace-tt | 3010->3000 | hermes-tt.bolbol.tn | hermes-tt-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace TT (agent=8650 interne) |
|
|
| hermes-workspace-nyora | 3020->3000 | hermes-nyora.bolbol.tn | hermes-nyora-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Nyora (agent=8660 interne) |
|
|
| hermes-workspace-perso | 3031->3000 | hermes-perso.bolbol.tn | hermes-perso-net,n8n | 0.0.0.0 | unless-stopped | healthy | Workspace Perso -- TEMP remap 3030->3031 (12/08/2026) : port 3030 orphelin cote host, docker-proxy sans PID visible, non liberable sans sudo -- restaurer 3030 au prochain reboot NAS |
|
|
| hermes-agent-tt | interne | interne | hermes-tt-net,n8n | interne Docker | unless-stopped | healthy | Agent TT ; DeepSeek V4 Flash |
|
|
| hermes-agent-nyora | interne | interne | hermes-nyora-net,n8n | interne Docker | unless-stopped | healthy | Agent Nyora ; DeepSeek V4 Flash |
|
|
| hermes-agent-perso | interne | interne | hermes-perso-net,n8n | interne Docker | unless-stopped | healthy | Agent Perso ; DeepSeek V4 Flash |
|
|
| hermes-mail-proxy | 3060->8000 | - | n8n | 0.0.0.0 | unless-stopped | **none** | Proxy mail Hermes (3060) |
|
|
| nyora-doc-api | 3050->8000 | - | n8n | 0.0.0.0 | unless-stopped | healthy | Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora | MCP ajoute sur /mcp/ (04/08/2026, tool generate_document) |
|
|
| nyora-convert-api | 3096->8000 | - | n8n | 0.0.0.0 | unless-stopped | (pas de healthcheck) | Conversion universelle document->MD (Mimo V2.5/Bifrost, texte+vision) 04/08/2026 |
|
|
| redaction-pro | 3092->80 | llm.bolbol.tn | n8n | 0.0.0.0 | always | **none** | Assistant redaction LLM (proxy Bifrost) |
|
|
| context-hub | 3093->8000 | context.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | Contexte agents 5 scopes ; MCP SSE |
|
|
| family-help | 3041->8000 | help.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | IA familiale FastAPI+SQLite ; PAS de healthcheck |
|
|
| gsparc-mezzouna-api | 3040->8000 | gsparc-mezzouna.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | healthy | OCR carburant kimi-k2.6 |
|
|
| rla-api | 3005->3005 | rla.bolbol.tn | bridge | 0.0.0.0 | unless-stopped | **none** | RLA contrats TT ; reseau BRIDGE (voir alerte couplage) |
|
|
| reglement-definitif-api | 5099->5055 | - | n8n | 0.0.0.0 | **no** | **none** | Reglement definitif TT ; restart NO (voir alerte) |
|
|
| veille-frontend | 3055->3000 | veille.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Veille IA ; depends veille-backend |
|
|
| veille-backend | interne | interne | n8n | interne Docker | unless-stopped | **none** | Backend veille FastAPI |
|
|
| dashboard-terrain | 8085->8080 | dashboard-terrain.bolbol.tn | n8n | 0.0.0.0 | unless-stopped | **none** | Dashboard terrain |
|
|
| panda-dashboard | 3021->80 | panda.bolbol.tn | n8n_default | 0.0.0.0 | always | **none** | Dashboard Fiat Panda ; reseau n8n_default |
|
|
| Trilium | 4292->8080 | trilium.bolbol.tn | n8n,trilium_default | 0.0.0.0 | **no** | healthy | Notes ; restart NO (voir alerte) |
|
|
| Pingvin-Share | 6090->3000 | share.bolbol.tn / pv.bolbol.tn | n8n,pingvin_default | 0.0.0.0 | always | healthy | Partage fichiers |
|
|
| pihole | 3001->80, 192.168.100.33:53->53, 192.168.100.33:53->53/udp | - (admin 3001) | n8n | 0.0.0.0 | always | healthy | DNS LAN (53) + admin 3001 bind 0.0.0.0 |
|
|
| crowdsec | 127.0.0.1:9090->8080 | - | n8n | 127.0.0.1 | always | **none** | IDS ; bind 127.0.0.1:9090 ; parse auth.log+nginx error.log |
|
|
| crowdsec-firewall-bouncer | interne | - | host | interne Docker | always | **none** | Bouncer ipset ; network host ; NET_ADMIN |
|
|
| vaultwarden | 3095->80 | vault.nd.i234.me | vaultwarden_default | 0.0.0.0 | unless-stopped | healthy | Password manager ; signups fermes |
|
|
| wg-admin-client | interne (51820/udp non bind) | - | wg-admin-client_default | interne Docker | unless-stopped | **none** | Client WireGuard admin (tunnel VPS KeepSolid) |
|
|
| watchtower-nas | interne | - | bridge | interne Docker | unless-stopped | healthy | Auto-update images (attention rollout :latest) |
|
|
| ovh-ddns | interne | - | ovh-ddns_default | interne Docker | unless-stopped | **none** | Mise a jour DNS dynamique OVH |
|
|
| qbittorrent-vue | 6881->6881, 6881->6881/udp, 9866->9866 | qb.bolbol.tn | media-stack_default,qbittorrent-vue_default | 0.0.0.0 | unless-stopped | **none** | Torrent (6881) + UI 9866 |
|
|
| cin-search-tt | 3094->3000 | cin.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | **none** | Recherche CIN sous-traitants RLA ; migre depuis /volume1/web hors-Docker le 10/07/2026 ; SMTP OVH->Infomaniak, Baserow alias corrige |
|
|
| formation-consultant | 8801->80 | formation.bolbol.tn (reverse-proxy DSM a creer manuellement) | n8n | 0.0.0.0 | unless-stopped | none | Formation autodidacte perso (nginx+basic auth) ; ajoute 25/07/2026 |
|
|
|
|
---
|
|
|
|
## Bases de donnees (internes)
|
|
| Port | Service | Exposition |
|
|
|------|---------|------------|
|
|
| 5432 | postgres (n8n-DB, Baserow-DB) | interne / n8n_default |
|
|
| 6379 | redis (Baserow-REDIS) | interne |
|
|
|
|
---
|
|
|
|
## DSM Systeme (exposition WAN reelle : seuls 80/222/443/8080 forwardes par la box)
|
|
| Port | Service | Exposition |
|
|
|------|---------|------------|
|
|
| 80 | DSM HTTP / reverse-proxy | 0.0.0.0 |
|
|
| 222 | DSM SSH (OpenSSH 8.2) | 0.0.0.0 WAN — a fermer |
|
|
| 443 | DSM HTTPS / reverse-proxy | 0.0.0.0 |
|
|
| 2222 | Gitea SSH | 0.0.0.0 |
|
|
| 6690 | DSM Cloud Sync | 0.0.0.0 |
|
|
| 8080 | DSM / watchtower | 0.0.0.0 |
|
|
| 22222 | NAS SSH principal | 0.0.0.0 |
|
|
|
|
---
|
|
|
|
## SERVICES RETIRES (ne pas reinstaller, ne pas reutiliser le vhost)
|
|
| Service | Port libere | Retire | Remplace par |
|
|
|---------|-------------|--------|--------------|
|
|
| gotenberg | 3001 (repris par pihole) | 21/06 | nyora-doc-api |
|
|
| pandoc | 3002 | 21/06 | nyora-doc-api |
|
|
| document-factory | 3015 | 21/06 | nyora-doc-api |
|
|
| carbone | 4000 | 21/06 | nyora-doc-api |
|
|
| document-factory-api | 8002 | 21/06 | nyora-doc-api |
|
|
| pptx-tt-api | 8015 | 29/06 | nyora-doc-api (vhost pptx.bolbol.tn fantome a purger) |
|
|
| open-webui | 3091 | 29/06 | redaction-pro |
|
|
| tika | 9998 | 21/06 | nyora-convert-api (3096) / Mimo V2.5 |
|
|
| paperless | 8021 | — | — |
|
|
| rayhan-frontend | 3013 | 29/06 | projet clos |
|
|
| rayhan-mysql | 3306 | 29/06 | projet clos |
|
|
| Plex | 32400 | — | absent du stack actuel |
|
|
| prowlarr | 9696 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) |
|
|
| radarr | 7878 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) |
|
|
| sonarr | 8989 | 04/07 | suppression volontaire (data conservee /volume1/docker/media-stack/) |
|
|
| wg-easy | 51820/udp, 51821 | ~07/07 | Tailscale (WireGuard ne subsiste que sur le VPS KeepSolid) |
|
|
| flaresolverr | 8191 | 12/07 | orphelin purge (ex-client prowlarr) |
|
|
|
|
---
|
|
|
|
## Plages libres recommandees
|
|
| Plage | Usage |
|
|
|-------|-------|
|
|
| 3013 | LIBRE (rayhan-frontend) |
|
|
| 3091 | LIBRE (open-webui) |
|
|
| 3015 | LIBRE (document-factory) |
|
|
| 3002 | LIBRE (pandoc) |
|
|
| 4000 | LIBRE (carbone) |
|
|
| 8002 | LIBRE (document-factory-api) |
|
|
| 8015 | LIBRE (pptx-tt-api) |
|
|
| 9998 | LIBRE (tika) |
|
|
| 8021 | LIBRE (paperless) |
|
|
| 3100-3199 | APIs internes (3101 pris : baserow-schema-mcp-proxy) |
|
|
| 8800-8899 | UIs web (8801 pris : formation-consultant) |
|
|
| 8900-8999 | Experimental |
|
|
| 3887 | pris : baserow-oauth-proxy |
|
|
| 3120 | reserve : nyora-notes-tt (RAG personnel mail O365, port API interne) |
|
|
|
|
---
|
|
|
|
## Ports a ne JAMAIS utiliser
|
|
- 3001 : pihole admin (repris depuis gotenberg)
|
|
- 8787 : nyora-notes
|
|
- 3000 : port interne Docker (ne pas exposer)
|
|
- 5432 : postgres interne
|
|
- 53 : pihole DNS
|
|
- 22 : SSH DSM interne (utiliser 22222)
|
|
|
|
---
|
|
|
|
## Historique des modifications (recentes)
|
|
| Date | Action | Port | Service |
|
|
|------|--------|------|---------|
|
|
| 2026-08-17 | Ajout baserow-schema-mcp (serveur MCP compagnon : create_table/delete_table/create_field/delete_field, proxy JWT vers API REST Baserow -- l'image officielle Baserow n'est pas patchable et son MCP natif ne couvre que les lignes). Reste a faire : reverse-proxy DSM baserow-schema.bolbol.tn -> 3101 (manuel) puis ajout du connecteur cote Claude.ai | 3101 | baserow-schema-mcp, baserow-schema-mcp-oauth-app, baserow-schema-mcp-proxy |
|
|
| 2026-08-15 | Retrait dsh-test + dsh-filebrowser (test isole NAS termine, migration definitive vers dsh-vps sur VPS hermes-nabil, valide en itinerance) | 8900,8901 | dsh-test, dsh-filebrowser |
|
|
| 2026-08-14 | Ajout dsh-filebrowser (Filebrowser sur port 8901 pour upload/gestion fichiers workspace dsh-test) | 8901 | dsh-filebrowser |
|
|
| 2026-08-14 | Ajout dsh-test (DeepSeek Harness test isolé, connecté à DeepSeek V4 Flash via Bifrost) | 8900 | dsh-test |
|
|
| 2026-08-04 | Ajout SearXNG (recherche meta self-hosted, API JSON active, alternative Firecrawl quota epuise) | 8888 | searxng |
|
|
| 2026-07-30 | Reservation port + dossier scope cree pour Gemini (acces restreint, pas de scope tt context-hub, pas de credentials O365) | 3120 | nyora-notes-tt |
|
|
| 2026-07-28 | Fix connecteur Claude.ai sur Baserow MCP : sidecar OAuth stub devant Baserow (meme pattern que mcp-vps). Reste a faire : repointer reverse-proxy DSM baserow.bolbol.tn de 3888 vers 3887 (manuel) | 3887 | baserow-oauth-proxy, baserow-oauth-app |
|
|
| 2026-07-25 | Ajout formation-consultant (nginx+basic auth, formation.bolbol.tn a creer manuellement en reverse-proxy DSM) | 8801 | formation-consultant |
|
|
| 2026-07-12 | RESYNC v4 : -prowlarr/radarr/sonarr/wg-easy, +vaultwarden/wg-admin-client, flaresolverr marque orphelin | — | ports-registry.md v4 |
|
|
| 2026-07-12 | hermes-agent-perso mem_limit 600m->768m APPLIQUE (recreate fait, healthy, data 1026:100) | — | hermes-agent-perso |
|
|
| 2026-07-12 | flaresolverr purge (orphelin) — 41 containers actifs | 8191 | flaresolverr |
|
|
| 2026-07-03 | RESYNC complet etat reel (43 containers) + audit securite | — | ports-registry.md v3 |
|
|
| 2026-07-03 | Bifrost retire du reverse-proxy WAN (securite) | 3085 | bifrost |
|
|
| 2026-07-03 | MDP UI wg-easy renforce 8->28 car | 51821 | wg-easy |
|
|
| 2026-06-29 | Resync partiel v2 (voir git history) | — | — |
|
|
|
|
> Note v3 : ce registre reflete l etat REEL constate via socket Docker le 03/07/2026.
|
|
> Services ajoutes vs v2 : pihole, prompt-studio, hermes-mail-proxy, context-hub, nyora-doc-api,
|
|
> gsparc-mezzouna-api, reglement-definitif-api, watchtower-nas, ovh-ddns, flaresolverr, crowdsec x2.
|
|
> MAJ 20/07/2026 : prompt-studio desinstalle (container+image supprimes) - port 8090 libere.
|