Files
nas-runbooks/common/ports-registry.md
T

19 KiB

Ports Registry — NAS Synology DS920+

Derniere mise a jour : 06/09/2026 (openclaw-perso documenté sur le port 8910 pour le ticket perso-2026-09-022)

LIRE CE FICHIER AVANT TOUT NOUVEAU DEPLOIEMENT

Mettre a jour apres chaque ajout/suppression de service


Regle absolue

Aucun nouveau service ne doit utiliser un port deja occupe. Choisir un port libre et l'inscrire ici avant de deployer.


SERVICES ACTIFS — Etat REEL au 12/07/2026

Source de verite = docker ps reel (via socket), pas le declaratif. Colonne Exposition = binding reel constate. Restart/Health signales quand a risque.

Service Port Domaine Reseau Exposition Restart Health Notes
n8n 5678->5678 n8n.bolbol.tn n8n,n8n_default 0.0.0.0 on-failure healthy Orchestration centrale ; restart on-failure (voir alerte)
n8n-DB interne - n8n_default interne Docker on-failure none Postgres n8n ; reseau n8n_default ; restart on-failure
Baserow 3888->80 baserow.bolbol.tn baserow_baserow_network,n8n 0.0.0.0 unless-stopped healthy Base metier ; depends db+redis healthy
Baserow-DB interne - baserow_baserow_network interne Docker unless-stopped healthy Postgres Baserow
Baserow-REDIS interne - baserow_baserow_network interne Docker unless-stopped healthy Redis Baserow
baserow-oauth-proxy 3887->80 baserow.bolbol.tn (a repointer : reverse-proxy DSM 3888->3887, manuel) n8n 0.0.0.0 unless-stopped - nginx : intercepte /.well-known/oauth-*, /register, /authorize, /token pour connecteur Claude.ai (404 natif sur Baserow) ; proxy transparent WS+SSE vers Baserow sinon ; ajoute 28/07/2026
baserow-oauth-app interne (8080) - n8n interne Docker unless-stopped - Stub OAuth Starlette (register/authorize/token, PKCE) pour baserow-oauth-proxy ; ajoute 28/07/2026
baserow-schema-mcp interne (8000) - n8n interne Docker unless-stopped - Serveur MCP compagnon : create_table/delete_table/create_field/delete_field (proxy JWT vers API REST Baserow, Database token insuffisant sur ces routes) ; ajoute 17/08/2026
baserow-schema-mcp-oauth-app interne (8080) - n8n interne Docker unless-stopped - Stub OAuth (meme pattern que baserow-oauth-app) pour baserow-schema-mcp-proxy ; ajoute 17/08/2026
baserow-schema-mcp-proxy 3101->80 baserow-schema.bolbol.tn (reverse-proxy DSM a creer manuellement) n8n 0.0.0.0 unless-stopped - nginx : OAuth discovery + proxy SSE vers baserow-schema-mcp ; ajoute 17/08/2026
gitea 2222->22, 3232->3232 gitea.bolbol.tn n8n 0.0.0.0 unless-stopped healthy Versioning (bolbol) ; SSH 2222 + 3232
portainer 9000->9000, 9443->9443 portainer.bolbol.tn bridge 0.0.0.0 unless-stopped none Gestion containers ; reseau bridge
nyora-notes 8787->8787 - n8n 0.0.0.0 unless-stopped healthy Memoire inter-sessions Hermes (8787)
linux-mcp-nas 127.0.0.1:3042->8000 mcp-nas.nd.i234.me n8n 127.0.0.1 always healthy MCP shell NAS ; bind 127.0.0.1 (via reverse-proxy)
bifrost 3085 (décommissionné) - - - - decommissioned Ancien stub forwarder socat 3085 retiré (Ticket infra-2026-09-031). Port libéré.
bifrost-proxy 3086->80 - n8n 0.0.0.0 unless-stopped - Relais socat SOCKS5 vers bifrost-proxy VPS (100.94.90.119:3086). bifrost-proxy OpenResty migré sur VPS (Ticket infra-2026-09-030)
hermes-workspace-tt 3010->3000 hermes-tt.bolbol.tn hermes-tt-net,n8n 0.0.0.0 unless-stopped healthy Workspace TT (agent=8650 interne)
hermes-workspace-nyora 3020->3000 hermes-nyora.bolbol.tn hermes-nyora-net,n8n 0.0.0.0 unless-stopped healthy Workspace Nyora (agent=8660 interne)
hermes-workspace-perso 3031->3000 hermes-perso.bolbol.tn hermes-perso-net,n8n 0.0.0.0 unless-stopped healthy Workspace Perso -- Port 3031 fixe definitivement (19/08/2026) suite a validation Hermes Hub ; 3030 orphelin/abandonne
hermes-agent-tt interne interne hermes-tt-net,n8n interne Docker unless-stopped healthy Agent TT ; Mimo V2.5
hermes-agent-nyora interne interne hermes-nyora-net,n8n interne Docker unless-stopped healthy Agent Nyora ; Mimo V2.5
hermes-agent-perso interne interne hermes-perso-net,n8n interne Docker unless-stopped healthy Agent Perso ; Mimo V2.5
hermes-mail-browser 192.168.100.33:3110->8000, 192.168.100.33:8810->6080 - n8n LAN uniquement unless-stopped healthy Navigateur automatise pour sync SharePoint/OneDrive->archive (voir hermes-tt/sharepoint-delta-sync.md) ; remplace hermes-mail-proxy ; ajoute 11/08/2026
nyora-doc-api 3050->8000 - n8n 0.0.0.0 unless-stopped healthy Moteur doc unique (docx/xlsx/pptx/pdf) charte Nyora
nyora-convert-api 3096->8000 - n8n 0.0.0.0 unless-stopped healthy Actif sur NAS pour corpus pack-mp1 ; miroir deploye et valide sur VPS (100.94.90.119:3096) (04/09/2026)
redaction-pro 3092->80 llm.bolbol.tn n8n 0.0.0.0 always none Assistant redaction LLM (proxy Bifrost)
context-hub 3093->8000 context.bolbol.tn n8n 0.0.0.0 unless-stopped healthy Contexte agents 5 scopes ; MCP SSE
family-help 3041->8000 help.bolbol.tn n8n 0.0.0.0 unless-stopped none IA familiale FastAPI+SQLite ; PAS de healthcheck
yesmine-mp1-rag 3097->8000 - n8n 0.0.0.0 unless-stopped healthy RAG semantique corpus MP1 Yesmine (FastMCP + REST) ; dependance family-help ; ajoute 18/08/2026
nyora-notes-mcp 3098->8000 - n8n 0.0.0.0 unless-stopped healthy Passerelle MCP dediee pour NyoraNotes (StreamableHTTP, scoping strict par token/agent, mapping vault/dsh/) ; ajoute 26/08/2026
gsparc-mezzouna-api 3040->8000 gsparc-mezzouna.bolbol.tn n8n 0.0.0.0 unless-stopped healthy OCR carburant kimi-k2.6
rla-api 3005->3005 rla.bolbol.tn n8n 0.0.0.0 unless-stopped healthy RLA contrats TT (build context: /volume1/docker/rla-api-src)
reglement-definitif-api 5099->5055 - n8n 0.0.0.0 no none Reglement definitif TT ; restart NO (voir alerte)
dashboard-terrain 8085->8080 dashboard-terrain.bolbol.tn n8n 0.0.0.0 unless-stopped none Dashboard terrain
panda-dashboard 3021->80 panda.bolbol.tn n8n_default 0.0.0.0 always none Dashboard Fiat Panda ; reseau n8n_default
Trilium 4292->8080 trilium.bolbol.tn n8n,trilium_default 0.0.0.0 no healthy Notes ; restart NO (voir alerte)
Pingvin-Share 6090->3000 share.bolbol.tn / pv.bolbol.tn n8n,pingvin_default 0.0.0.0 always healthy Partage fichiers
pihole 3001->80, 192.168.100.33:53->53, 192.168.100.33:53->53/udp - (admin 3001) n8n 0.0.0.0 always healthy DNS LAN (53) + admin 3001 bind 0.0.0.0
crowdsec 127.0.0.1:9090->8080 - n8n 127.0.0.1 always none IDS ; bind 127.0.0.1:9090 ; parse auth.log+nginx error.log
crowdsec-firewall-bouncer interne - host interne Docker always none Bouncer ipset ; network host ; NET_ADMIN
vaultwarden 3095->80 vault.nd.i234.me vaultwarden_default 0.0.0.0 unless-stopped healthy Password manager ; signups fermes
wg-admin-client interne (51820/udp non bind) - wg-admin-client_default interne Docker unless-stopped none Client WireGuard admin (tunnel VPS KeepSolid)
watchtower-nas interne - bridge interne Docker unless-stopped healthy Auto-update images (attention rollout :latest)
ovh-ddns interne - ovh-ddns_default interne Docker unless-stopped none Mise a jour DNS dynamique OVH
qbittorrent-vue 6881->6881, 6881->6881/udp, 9866->9866 qb.bolbol.tn media-stack_default,qbittorrent-vue_default 0.0.0.0 unless-stopped none Torrent (6881) + UI 9866
cin-search-tt 3094->3000 cin.bolbol.tn (reverse-proxy DSM a creer manuellement) n8n 0.0.0.0 unless-stopped none Recherche CIN sous-traitants RLA ; migre depuis /volume1/web hors-Docker le 10/07/2026 ; SMTP OVH->Infomaniak, Baserow alias corrige
formation-consultant 8801->80 formation.bolbol.tn (reverse-proxy DSM a creer manuellement) n8n 0.0.0.0 unless-stopped none Formation autodidacte perso (nginx+basic auth) ; ajoute 25/07/2026
hermes-hub (VPS) 127.0.0.1:8088->8080 hub.yesminedor.tn (410), dsh-hub / files-hub .yesminedor.tn dsh_vps_net, mcp-vps 127.0.0.1 (Cloudflare Access) unless-stopped healthy Dispatcher minimal Cloudflare Origin (proxy Host-based dsh-hub:3080 et files-hub:8080 uniquement ; UI switcher et DB chat supprimes le 26/08/2026)
reglement-mcp 5098->8000 - n8n 0.0.0.0 unless-stopped healthy Serveur MCP pour reglement-definitif-api (Google credentials.json) ; ajoute 23/08/2026, absent du registre jusqu au 30/08
gotenberg (gsparc) interne, pas de port host - n8n interne Docker unless-stopped - Sidecar Chromium/PDF dedie a gsparc-mezzouna-api (export fiches vehicules + tableaux consommation en arabe) ; distinct de l ancien gotenberg 3001 retire le 21/06 ; cable dans gsparc-mezzouna/docker-compose.yml commit 85faef3 (21/06/2026), deploye 25/07/2026 ; jamais documente ici avant le 30/08
hermes-watchdog-telegram interne - bridge interne Docker unless-stopped - Boucle python (relance toutes les 10 min) surveillant les containers via docker.sock, alerte Telegram ; image docker:cli generique (apk install python3 a chaque restart, pas d image dediee -- fragile) ; cree 27/07/2026, jamais documente ici avant le 30/08
openclaw-perso 127.0.0.1:8910->18789 - n8n 127.0.0.1 unless-stopped healthy Agent OpenClaw autonome perso en test parallèle (ticket perso-2026-09-022) ; Control UI bind loopback 127.0.0.1 (accès via tunnel SSH local pour fonction Talk/Microphone WebCrypto) ; bot Telegram @Perso_OC_bot configuré et actif ; ajouté 06/09/2026

Bases de donnees (internes)

Port Service Exposition
5432 postgres (n8n-DB, Baserow-DB) interne / n8n_default
6379 redis (Baserow-REDIS) interne

DSM Systeme (exposition WAN reelle : seuls 80/222/443/8080 forwardes par la box)

Port Service Exposition
80 DSM HTTP / reverse-proxy 0.0.0.0
222 DSM SSH (OpenSSH 8.2) 0.0.0.0 WAN — a fermer
443 DSM HTTPS / reverse-proxy 0.0.0.0
2222 Gitea SSH 0.0.0.0
6690 DSM Cloud Sync 0.0.0.0
8080 DSM / watchtower 0.0.0.0
22222 NAS SSH principal 0.0.0.0

SERVICES RETIRES (ne pas reinstaller, ne pas reutiliser le vhost)

Service Port libere Retire Remplace par
hermes-mail-proxy 3060 ~11/08 (constate le 30/08) hermes-mail-browser
gotenberg 3001 (repris par pihole) 21/06 nyora-doc-api
pandoc 3002 21/06 nyora-doc-api
document-factory 3015 21/06 nyora-doc-api
carbone 4000 21/06 nyora-doc-api
document-factory-api 8002 21/06 nyora-doc-api
pptx-tt-api 8015 29/06 nyora-doc-api (vhost pptx.bolbol.tn fantome a purger)
open-webui 3091 29/06 redaction-pro
tika 9998 gemini-3-flash OCR
paperless 8021
rayhan-frontend 3013 29/06 projet clos
rayhan-mysql 3306 29/06 projet clos
Plex 32400 absent du stack actuel
prowlarr 9696 04/07 suppression volontaire (data conservee /volume1/docker/media-stack/)
radarr 7878 04/07 suppression volontaire (data conservee /volume1/docker/media-stack/)
sonarr 8989 04/07 suppression volontaire (data conservee /volume1/docker/media-stack/)
wg-easy 51820/udp, 51821 ~07/07 Tailscale (WireGuard ne subsiste que sur le VPS KeepSolid)
flaresolverr 8191 12/07 orphelin purge (ex-client prowlarr)

Plages libres recommandees

Plage Usage
3013 LIBRE (rayhan-frontend)
3091 LIBRE (open-webui)
3015 LIBRE (document-factory)
3002 LIBRE (pandoc)
4000 LIBRE (carbone)
8002 LIBRE (document-factory-api)
8015 LIBRE (pptx-tt-api)
9998 LIBRE (tika)
8021 LIBRE (paperless)
3100-3199 APIs internes (3101 pris : baserow-schema-mcp-proxy)
8800-8899 UIs web (8801 pris : formation-consultant)
8900-8999 Experimental
3887 pris : baserow-oauth-proxy
3120 reserve : nyora-notes-tt (RAG personnel mail O365, port API interne)

Ports a ne JAMAIS utiliser

  • 3001 : pihole admin (repris depuis gotenberg)
  • 8787 : nyora-notes
  • 3000 : port interne Docker (ne pas exposer)
  • 5432 : postgres interne
  • 53 : pihole DNS
  • 22 : SSH DSM interne (utiliser 22222)

Historique des modifications (recentes)

Date Action Port Service
2026-09-09 Décommissionnement stub bifrost NAS 3085 (Ticket infra-2026-09-031) : stub socat retiré (docker-compose down), port 3085 libéré sur NAS. Relocalisation bifrost-proxy VPS 100% finalisée. 3085 bifrost
2026-09-08 Relocalisation bifrost-proxy vers VPS (Ticket infra-2026-09-030) : bifrost-proxy OpenResty déployé sur VPS (port 3086, bifrost-net). hermes-nabil et dsh-vps repointés localement sur VPS (découplage total Sfax). bifrost-proxy NAS converti en relais socat SOCKS5 vers VPS 3086. 3086 bifrost-proxy
2026-09-04 Migration VPS (Tickets infra-2026-09-010 et infra-2026-09-008) : Bifrost (3085) et nyora-doc-api (3050) migres sur VPS Contabo (100.94.90.119), nyora-convert-api (3096) deploye en miroir sur VPS (tests 13/13 OK, conteneur NAS non touche pour pack-mp1). Côté NAS : conteneur bifrost renomme bifrost-nas-backup (arrete, secours immediat), stub forwarder socat SOCKS5 deploye sur 3085 vers VPS. bifrost-proxy (3086) patche pour injection x-bf-eh-x-opencode-session=$resolved_vk. Inferences reelles Gemini et OpenCode Go testees et validees avec succes. 3085, 3086, 3050, 3096 bifrost, bifrost-proxy, nyora-doc-api, nyora-convert-api
2026-09-04 Decommission veille-backend (FastAPI) et veille-frontend, remplaces par page HTML statique (localStorage, tags, recherche, filtre lu/non lu) servie sur bolbol.tn/veille. Containers et images supprimes, code archive dans _archived/nyora-veille-DECOM-20260904, entree reverse proxy veille.bolbol.tn retiree par Nabil, workflow n8n Ingest Opportunites desactive (backend cible supprime). - decom-veille-04-09
2026-08-30 Audit total via Claude : 55 containers reels confirmes (registre en comptait 43/vs derniere resync). Clarifie gotenberg gsparc (sidecar interne distinct de l ancien gotenberg 3001, jamais documente). Corrige hermes-mail-proxy -> retire, remplace par hermes-mail-browser (actif depuis 11/08, jamais documente). Ajoute reglement-mcp (actif depuis 23/08, jamais documente) et hermes-watchdog-telegram (actif depuis 27/07, jamais documente, image fragile a corriger). RAM 41% mais swap 4.1Gi/13Gi utilise -- a surveiller. Disque /volume1 73% (7.6T/11T). linux-mcp-nas signale unhealthy depuis 2j (fonctionnel, healthcheck a verifier). - audit-30-08
2026-08-26 Ajout nyora-notes-mcp (Passerelle MCP dediee NyoraNotes, StreamableHTTP port 3098, scoping strict par token/dossier, connecteur DSH dsh/ valide) 3098 nyora-notes-mcp
2026-08-26 Reduction hermes-hub (suppression UI switcher et DB chat, conservation dispatcher pur dsh-hub / files-hub, fix timeout WS /api/events.mux et .host) 8088 hermes-hub
2026-08-25 Ajout yesmine-mp1-rag (RAG semantique corpus MP1 Yesmine, REST+FastMCP port 3097, reseau n8n, dependance de family-help) 3097 yesmine-mp1-rag
2026-08-21 MAJ Stack : Portainer 2.39.6, n8n 2.36.5 (custom docx/exceljs), Bifrost v1.6.11 (pin image), Gitea 1.27.2-rootless (migration DB OK), Vaultwarden 1.37.1, Tailscale bridge 1.102.3 portainer, n8n, bifrost, gitea, vaultwarden, tailscale
2026-08-19 Deploiement reel Hermes Hub sur VPS Contabo (port 8088 loopback, Cloudflare Access, integration dsh-vps-filebrowser sans auth interne) 8088 hermes-hub
2026-08-19 Fixation definitive de hermes-workspace-perso sur le port 3031 (validation Hermes Hub). Port 3030 marque orphelin/abandonne 3031 hermes-workspace-perso
2026-08-17 Ajout baserow-schema-mcp (serveur MCP compagnon : create_table/delete_table/create_field/delete_field, proxy JWT vers API REST Baserow -- l'image officielle Baserow n'est pas patchable et son MCP natif ne couvre que les lignes). Reste a faire : reverse-proxy DSM baserow-schema.bolbol.tn -> 3101 (manuel) puis ajout du connecteur cote Claude.ai 3101 baserow-schema-mcp, baserow-schema-mcp-oauth-app, baserow-schema-mcp-proxy
2026-08-15 Retrait dsh-test + dsh-filebrowser (test isole NAS termine, migration definitive vers dsh-vps sur VPS hermes-nabil, valide en itinerance) 8900,8901 dsh-test, dsh-filebrowser
2026-08-14 Ajout dsh-filebrowser (Filebrowser sur port 8901 pour upload/gestion fichiers workspace dsh-test) 8901 dsh-filebrowser
2026-08-14 Ajout dsh-test (DeepSeek Harness test isolé, connecté à DeepSeek V4 Flash via Bifrost) 8900 dsh-test
2026-08-04 Ajout SearXNG (recherche meta self-hosted, API JSON active, alternative Firecrawl quota epuise) 8888 searxng
2026-07-30 Reservation port + dossier scope cree pour Gemini (acces restreint, pas de scope tt context-hub, pas de credentials O365) 3120 nyora-notes-tt
2026-07-28 Fix connecteur Claude.ai sur Baserow MCP : sidecar OAuth stub devant Baserow (meme pattern que mcp-vps). Reste a faire : repointer reverse-proxy DSM baserow.bolbol.tn de 3888 vers 3887 (manuel) 3887 baserow-oauth-proxy, baserow-oauth-app
2026-07-25 Ajout formation-consultant (nginx+basic auth, formation.bolbol.tn a creer manuellement en reverse-proxy DSM) 8801 formation-consultant
2026-07-12 RESYNC v4 : -prowlarr/radarr/sonarr/wg-easy, +vaultwarden/wg-admin-client, flaresolverr marque orphelin ports-registry.md v4
2026-07-12 hermes-agent-perso mem_limit 600m->768m APPLIQUE (recreate fait, healthy, data 1026:100) hermes-agent-perso
2026-07-12 flaresolverr purge (orphelin) — 41 containers actifs 8191 flaresolverr
2026-07-03 RESYNC complet etat reel (43 containers) + audit securite ports-registry.md v3
2026-07-03 Bifrost retire du reverse-proxy WAN (securite) 3085 bifrost
2026-07-03 MDP UI wg-easy renforce 8->28 car 51821 wg-easy
2026-06-29 Resync partiel v2 (voir git history)

Note v3 : ce registre reflete l etat REEL constate via socket Docker le 03/07/2026. Services ajoutes vs v2 : pihole, prompt-studio, hermes-mail-proxy, context-hub, nyora-doc-api, gsparc-mezzouna-api, reglement-definitif-api, watchtower-nas, ovh-ddns, flaresolverr, crowdsec x2. MAJ 20/07/2026 : prompt-studio desinstalle (container+image supprimes) - port 8090 libere.