Reference / Network and ports

Network and ports

Which ports are open, what leaves the appliance, and how environments reach the outside.

On this page
  1. The management interface
  2. What leaves the appliance
  3. How environments reach the outside
  4. Remote access

The management interface#

The appliance needs one network interface: the address you sign in on. DHCP is fine; you can set a static address in Settings › Network. Environments do not use this interface for their own traffic.

PortStateUse
443/tcpOpenThe web interface and consoles, over HTTPS
80/tcpOpenRedirects to HTTPS
Device console portsClosedConsoles go through the web interface instead
SSH (22/tcp)ClosedThe appliance firewall allows only the web ports
WireGuard (UDP)Closed until you turn it onThe listen port is set in Settings › Remote access when you enable WireGuard

The appliance creates its own TLS certificate on first boot, so your browser warns once. This is expected. /health and /metrics answer on the HTTPS port without a sign-in, so your own monitoring can read them.

What leaves the appliance#

ONEP sends nothing to ONEP on its own. It has no telemetry. The license is checked locally against the signed license file, and this release sends no license check-in. The appliance's operating system may fetch its own security updates from package mirrors, and needs DNS and time (NTP) on your network. ONEP itself connects out only for what you ask for:

ReasonGoes toWhen
Discover downloadsThe vendor's own siteWhen you add an image
Container pullsThe container image's registryWhen you add a container image through Discover
First build of a Content Hub cardThe vendor sources of that card's partsThe first deploy of a card on this appliance
AI Generator, external AI serviceThe service you configured, on your own accountWhen you ask it to build a topology; only the text you type is sent. A model on this appliance sends nothing out
AI model downloadThe model libraryOnly when you choose Download recommended model in Settings › AI
Remote accessCloudflare, Tailscale or your Dynamic DNS provider, on your accountsOnly while that method is on
Report a ProblemONEP supportOnly when you press Submit; attachments are encrypted
Operating system updatesThe operating system's package mirrorsOn the operating system's own schedule, not something ONEP asks for
Time (NTP)Time servers reachable from your networkWhenever the appliance keeps its clock in step
Name resolution (DNS)The DNS server on your networkWhenever the appliance looks up a name

Environments you have already deployed do not need the internet to run.

How environments reach the outside#

Every environment starts sealed: it has no path to the ONEP host, your network or another environment, whichever switch it uses. It reaches the outside only through a door you open:

DoorWhat it doesEditions
Cloud node, NATOutbound internet for the environment through the shared address space (100.64.0.0/10, RFC 6598). The environment cannot reach private address ranges, and nothing on your network can reach in. This is the same range Tailscale uses, so avoid overlapAll
Cloud node, bridgeThe environment joins your real network, as if plugged into your switchAll
Container exposeOpen an app from an environment in your browser (Expose Containers in the device menu)Which devices can be exposed depends on the edition. See Limits per edition
Bridge is a real door

A cloud node in bridge mode puts the environment on your LAN by design. Environments often contain attack tools and deliberately vulnerable systems, so use bridge mode only when you mean it. The Add Device dialog starts with Bridge selected, so choose NAT or Bridge on purpose when you add a cloud node. Right-click a cloud node and choose Switch to NAT or Switch to Bridge to change its mode later.

Because environments are isolated, the addresses inside them do not clash with your own network, even when they reuse the same ranges, unless you bridge them onto it.

Remote access#

Remote access publishes the management interface only (sign-in, canvas and Settings), never anything inside an environment. See Remote access for what each method opens.

Something wrong or missing on this page? Write to hello@onep.io.