Network and ports
Which ports are open, what leaves the appliance, and how environments reach the outside.
On this page
The management interface#
The appliance needs one network interface: the address you sign in on. DHCP is fine; you can set a static address in Settings › Network. Environments do not use this interface for their own traffic.
| Port | State | Use |
|---|---|---|
443/tcp | Open | The web interface and consoles, over HTTPS |
80/tcp | Open | Redirects to HTTPS |
| Device console ports | Closed | Consoles go through the web interface instead |
| SSH (22/tcp) | Closed | The appliance firewall allows only the web ports |
| WireGuard (UDP) | Closed until you turn it on | The listen port is set in Settings › Remote access when you enable WireGuard |
The appliance creates its own TLS certificate on first boot, so your browser warns once. This is expected. /health and /metrics answer on the HTTPS port without a sign-in, so your own monitoring can read them.
What leaves the appliance#
ONEP sends nothing to ONEP on its own. It has no telemetry. The license is checked locally against the signed license file, and this release sends no license check-in. The appliance's operating system may fetch its own security updates from package mirrors, and needs DNS and time (NTP) on your network. ONEP itself connects out only for what you ask for:
| Reason | Goes to | When |
|---|---|---|
| Discover downloads | The vendor's own site | When you add an image |
| Container pulls | The container image's registry | When you add a container image through Discover |
| First build of a Content Hub card | The vendor sources of that card's parts | The first deploy of a card on this appliance |
| AI Generator, external AI service | The service you configured, on your own account | When you ask it to build a topology; only the text you type is sent. A model on this appliance sends nothing out |
| AI model download | The model library | Only when you choose Download recommended model in Settings › AI |
| Remote access | Cloudflare, Tailscale or your Dynamic DNS provider, on your accounts | Only while that method is on |
| Report a Problem | ONEP support | Only when you press Submit; attachments are encrypted |
| Operating system updates | The operating system's package mirrors | On the operating system's own schedule, not something ONEP asks for |
| Time (NTP) | Time servers reachable from your network | Whenever the appliance keeps its clock in step |
| Name resolution (DNS) | The DNS server on your network | Whenever the appliance looks up a name |
Environments you have already deployed do not need the internet to run.
How environments reach the outside#
Every environment starts sealed: it has no path to the ONEP host, your network or another environment, whichever switch it uses. It reaches the outside only through a door you open:
| Door | What it does | Editions |
|---|---|---|
| Cloud node, NAT | Outbound internet for the environment through the shared address space (100.64.0.0/10, RFC 6598). The environment cannot reach private address ranges, and nothing on your network can reach in. This is the same range Tailscale uses, so avoid overlap | All |
| Cloud node, bridge | The environment joins your real network, as if plugged into your switch | All |
| Container expose | Open an app from an environment in your browser (Expose Containers in the device menu) | Which devices can be exposed depends on the edition. See Limits per edition |
A cloud node in bridge mode puts the environment on your LAN by design. Environments often contain attack tools and deliberately vulnerable systems, so use bridge mode only when you mean it. The Add Device dialog starts with Bridge selected, so choose NAT or Bridge on purpose when you add a cloud node. Right-click a cloud node and choose Switch to NAT or Switch to Bridge to change its mode later.
Because environments are isolated, the addresses inside them do not clash with your own network, even when they reuse the same ranges, unless you bridge them onto it.
Remote access#
Remote access publishes the management interface only (sign-in, canvas and Settings), never anything inside an environment. See Remote access for what each method opens.