Appearance
Ports
Every well-known port in the system, in one table. The short version: nothing you run at home listens on the network. The gateway and CLI only dial out (WSS to a relay), the gateway's console binds loopback only, and the only component that opens public ports is a relay — the system relay fleet, or an edge you host yourself.
| Port | Component | Bind | Purpose |
|---|---|---|---|
443/tcp | Relay (system + edge) | public | The WSS endpoints everything dials — gateways, clients, and the relay's own links up to the console. On an edge this is the tls_listen listener, default :443, settable or off for a LAN-only edge. With the nginx front installed, nginx owns :443 and passes through. |
443/udp (QUIC) | Relay (system + edge) | public, optional | The QUIC transport on the system relay fleet. On an edge, QUIC has no default — it is off unless quic_addr is set in the edge's config (or --quic-addr), and it binds exactly the address you give; nginx does not front it. The CLI opts in per client with --relay-quic <host:port> (or --transport quic). |
16518/tcp | Gateway | 127.0.0.1 only | The local console — the gateway's web UI. Never reachable from the network on its own; change the port with console_port=<n> in the gateway config, disable with --console off. |
8448/tcp | Edge | LAN interfaces | The nginx LAN TLS front (nginx apply --listen-lan <port>, default 8448). Terminates the pinned LAN cert and proxies to the edge's loopback dial-in listener below. This is the port advertised in LAN endpoints. |
9448/tcp | Edge | 127.0.0.1 only | The edge's loopback dial-in listener (lan_listen, default 127.0.0.1:9448; burrowee edge lan-listen on|off|status) — always bound, in frontier and LAN modes alike, and clamped to loopback. A co-located gateway dials it directly; LAN clients reach it only through the nginx front on 8448. Leave it on when a gateway shares the host — off is the deliberate choice only for an edge with no co-located gateway. |
| operator-set, off by default | Edge | public (bypasses nginx) | The edge-to-edge bridging raw listener (raw_port in the edge config, or burrowee edge bridge raw-port <port>) — serves the same relay service on a dedicated port nginx never fronts, so isolated carriers between bridged edges aren't double-handled by the reverse proxy. Unset (off) keeps an edge byte-identical to one with no bridging configured. |
| ephemeral | CLI | 127.0.0.1:0 | The local forward listener connect/ssh/open opens for each tunnel (--local to pin one; default 127.0.0.1:0). ssh always uses an ephemeral loopback port. |
Unix sockets (not TCP, listed for completeness)
| Socket | Component | Purpose |
|---|---|---|
~/.burrowee/cli/sockets/transport.sock | CLI daemon | Transport IPC — stream consumers, plus every relays/gateways subcommand that mutates or needs a live answer (use, rm, pair, resync, probe, …). Not used by the list forms, routes, or relays ping, which read config.json directly — ping dials the relay itself |
~/.burrowee/gateway/sockets/register.sock | Gateway | burrowee-register registers local services (burrowee gateway register info prints the resolved path) |
/usr/local/var/burrowee/gateway/sockets/console.sock | Gateway | The separate burrowee-gateway-console process triggers key/carrier operations on the daemon over this socket |
On a pathologically long home path the transport socket overflows to $XDG_RUNTIME_DIR/burrowee/transport.sock (OS temp dir when XDG_RUNTIME_DIR is unset), and burrowee-register requires an explicit --sock. Paths and overrides: Config homes & files.
What dials what
Outbound-only summary — useful for firewall rules:
| From | To | Protocol |
|---|---|---|
| CLI | relay :443 (and QUIC if configured); LAN-published edge origins first when present | WSS / QUIC |
| Gateway | every configured relay :443 | WSS |
| Edge | the Burrowee console (compiled-in host) | WSS + HTTPS |
| Gateway → local service | e.g. 127.0.0.1:22 on the gateway host | plain TCP (the target you exposed) |