Citadel
Reference

Network ports

Find the browser address and the ports needed by Agents and Docker.

In the supplied local Compose setup, open http://localhost:18000 in your browser. Port 18001 is for Edge Agent connections; it is not another web page.

Default connections

ConnectionHost port in the supplied setupContainer portDirection
Browser and API127.0.0.1:180008000Browser or reverse proxy to Core
Edge Agent gRPC127.0.0.1:180018001Edge Agent or its reverse proxy to Core
Regular AgentChosen on the Agent host, usually 90009000Core to Agent
PostgreSQLNot published5432Core to the database on its private Docker network
Docker engineNot a TCP port in the supplied setup/var/run/docker.sockLocal Core or Agent to Docker

The bind address and Core host ports are controlled by CITADEL_BIND_ADDRESS, CITADEL_HTTP_PORT, and CITADEL_EDGE_PORT. A reverse proxy may publish HTTPS on a different port, commonly 443. Direct TLS uses the configured listeners and Compose port mappings.

Connecting another machine

localhost always means the machine making the connection. A remote Agent cannot reach your Core by using Core's localhost address. Configure a hostname or IP it can reach and protect that connection with TLS or a trusted private network, as described in the TLS guide.

  • A regular Agent needs an inbound connection from Core to its Agent port.
  • An Edge Agent needs an outbound, long-lived HTTP/2 gRPC connection to Core.
  • A Swarm cluster has its own Docker networking requirements; connecting it to Citadel does not change those requirements.

Use the generated Agent or Edge Agent setup command. Keep PostgreSQL and the Docker socket private.

On this page