1"use strict";(self.webpackChunkcaprover_docs_site=self.webpackChunkcaprover_docs_site||[]).push([["2153"],{1706(e,t,n){n.r(t),n.d(t,{metadata:()=>o,default:()=>d,frontMatter:()=>i,contentTitle:()=>a,toc:()=>p,assets:()=>c});var o=JSON.parse('{"id":"applications/public-ports","title":"Public TCP / UDP Ports","description":"Use an app port mapping when clients outside CapRover\'s Docker network need direct TCP or UDP access to a container. Internal app-to-app communication does not require a public mapping.","source":"@site/../content/en/docs-next/applications/public-ports.md","sourceDirName":"applications","slug":"/applications/public-ports","permalink":"/docs-next/applications/public-ports","draft":false,"unlisted":false,"editUrl":"https://github.com/caprover/caprover-website/edit/master/content/en/docs-next/applications/public-ports.md","tags":[],"version":"current","frontMatter":{"id":"public-ports","title":"Public TCP / UDP Ports","slug":"/applications/public-ports"},"sidebar":"preview","previous":{"title":"HTTP Settings","permalink":"/docs-next/applications/http-settings"},"next":{"title":"Tags and Descriptions","permalink":"/docs-next/applications/tags-descriptions"}}'),s=n(4848),r=n(8453);let i={id:"public-ports",title:"Public TCP / UDP Ports",slug:"/applications/public-ports"},a,c={},p=[];function l(e){let t={a:"a",code:"code",p:"p",strong:"strong",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.p,{children:"Use an app port mapping when clients outside CapRover's Docker network need direct TCP or UDP access to a container. Internal app-to-app communication does not require a public mapping."}),"\n",(0,s.jsxs)(t.p,{children:["In the app configuration, add a mapping with a ",(0,s.jsx)(t.strong,{children:"container port"}),", a ",(0,s.jsx)(t.strong,{children:"host port"}),", and a protocol (",(0,s.jsx)(t.code,{children:"tcp"})," or ",(0,s.jsx)(t.code,{children:"udp"}),"). Choose the publish mode: ",(0,s.jsx)(t.code,{children:"ingress"})," routes through Docker Swarm's routing mesh, while ",(0,s.jsx)(t.code,{children:"host"})," publishes on the node running the task. Host mode requires attention to placement and port conflicts when scaling or moving the app."]}),"\n",(0,s.jsxs)(t.p,{children:["Allow the host port through the provider firewall only for the clients that need it. Docker-published ports can bypass ordinary UFW restrictions, so use Docker-aware rules or a provider firewall to limit access. A publicly exposed database must have its own authentication and transport protection. See ",(0,s.jsx)(t.a,{href:"/docs-next/data-persistence/external-databases",children:"Connect to Databases Externally"})," and ",(0,s.jsx)(t.a,{href:"/docs-next/domains/firewall",children:"Firewall"}),"."]})]})}function d(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(l,{...e})}):l(e)}},8453(e,t,n){n.d(t,{R:()=>i,x:()=>a});var o=n(6540);let s={},r=o.createContext(s);function i(e){let t=o.useContext(r);return o.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:i(e.components),o.createElement(r.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.