Skip to main content

Addresses and ports

On the box​

PathWhatWho may open it
/The admin pagesthe local network only
/handbook/This handbookthe local network only
/api/…The box's control API (JSON, needs the admin key)the local network only
/api/health{"ok":true} when the control daemon is upthe local network only, no key
/setup/state.jsonName, address, HTTPS, certificate fingerprintthe local network only
/setup/losos-ca.crtThe box's certificatethe local network only
/setup/trust.sh, /setup/trust.ps1The one-line certificate installersthe local network only
/nextcloudLosOS cloudanyone, and through an edge
/forgejo/LosOS Gitanyone, and through an edge

"The local network only" means a source address in a private range (10.…, 172.16.… to 172.31.…, 192.168.…) that is not the box's own address and not the mesh's pod range. Anything else, including traffic arriving through an edge's tunnel, gets 403.

Ports​

PortProtocolWhat
80HTTPEverything above
443HTTPSThe same, with the box's own certificate (losos.tls.enable, on by default)
5353mDNSAnnouncing <name>.local
8082HTTPThe control API, on the box's loopback only; nginx proxies /api/ to it

Nothing else is open. The mesh and the edge are reached outwards: the box opens the tunnel and joins the cluster; no inbound port is needed at home.

Names​

NameWhat
<name>.localThe box, on its own network, over mDNS
<name>.<edge domain>The box through its edge, for LosOS cloud and LosOS Git
losos-edge.dasmat.usThe LosOS edge's control plane and the "find my box" page
proxy.losos.dasmat.usThe binary cache the box updates from
losos.dasmat.usThis handbook on the web