# Ports and file paths

> Every network port and file path Falak uses on the control plane host and on managed servers — for firewalls, audits and debugging.

Source: https://falak.sh/docs/reference/ports-and-paths/

## Control plane host

### Ports

| Port | Protocol | Exposed | Used by |
|---|---|---|---|
| 80 | TCP | yes | HTTP → HTTPS, ACME HTTP-01 |
| 443 | TCP + UDP (HTTP/3) | yes | Panel, API, webhooks, installer, agent API (`agents.` host, mTLS), Grafana, OTLP ingest (`/otlp`) |

Other ports stay inside the Compose network (Postgres 5432, Valkey 6379, Reverb 8080, Grafana 3000, Loki 3100, Tempo 3200, gateway 9090). Change the public ports only for testing (`--http-port`/`--https-port` with `--tls internal`).

### Paths

| Path | Contents |
|---|---|
| `/opt/falak/.env` | Settings and secrets (mode 600) |
| `/opt/falak/custom.env` | Optional extra settings |
| `/opt/falak/deploy/` | `compose.yml`, `falak-ctl`, support files (previous version kept as `deploy.prev`) |
| `/opt/falak/observability/` | Loki, Tempo, gateway and Grafana configuration |
| `/opt/falak/backups/` | `falak-ctl backup` output (mode 700) |
| `/usr/local/bin/falak-ctl` | The operations tool |
| `/etc/cron.d/falak-backup` | Your backup schedule (if you create it) |

### Docker volumes (project `falak`)

`pg-data`, `valkey-data`, `app-storage` (artifacts, app files), `falak-ca` (Fleet CA certificate), `edge-pki`, `caddy-data` (ACME certificates), `caddy-config`, `builder-data`, `builder-cache`, and with observability `loki-data`, `tempo-data`, `vm-data`, `grafana-data`.

## Managed servers

### Ports

| Port | Listens on | Opened by default | Purpose |
|---|---|---|---|
| 22 | all | yes (always accepted) | SSH |
| 80, 443 | all | app, web, lb servers | Caddy / FrankenPHP |
| 2019 | 127.0.0.1 | no | Caddy admin API (agent only) |
| 4318 | 127.0.0.1 | no | OTLP/HTTP receiver of the agent |
| 3000–3999 | 127.0.0.1 | no | App ports of Node, Bun, Deno and Docker sites (blue/green: +1000) |
| 8000–8999 | 127.0.0.1 (FrankenPHP Octane: all interfaces) | no | Laravel Octane ports; auxiliary port = +10000 |
| 5432 / 3306 | localhost; all interfaces on `db` servers with remote users | no | PostgreSQL / MySQL / MariaDB |
| 51820/udp | all | on private network members | WireGuard (default) |

Compose public services are published on `127.0.0.1:<allocated port>`.

### Paths

| Path | Contents |
|---|---|
| `/usr/local/bin/falak-agent` | Agent binary (`.prev`: previous version after an upgrade) |
| `/etc/systemd/system/falak-agent.service` | Agent unit |
| `/etc/falak/` | `agent.key`, `agent.crt`, `ca.crt`, `agent.json`, `telemetry.json`, `certs/`, optional `agent.env` |
| `/var/lib/falak/` | Process and cron state, OTLP disk buffer |
| `/run/falak/otlp.sock` | OTLP socket for apps |
| `/var/log/falak/` | Supervised program logs |
| `/var/log/falak/access/<site>.log` | Caddy access logs (JSON, 10 MB × 3) |
| `/srv/falak/sites/<site>/releases//` | Releases |
| `/srv/falak/sites/<site>/shared/` | `.env`, `storage/`, shared paths |
| `/srv/falak/sites/<site>/current` | Symlink to the live release |
| `/home/falak` | The `falak` user's home |
| `/etc/postgresql/<version>/main/conf.d/90-falak-network.conf` | Network listening for `db` servers |
