Deterministic Port Registry

Audience: developers and operators wiring up local environments, hosts files, and service-discovery configuration for Stella Ops.

All Stella Ops web services are assigned deterministic HTTPS/HTTP port pairs to avoid collisions during local development and to simplify service-discovery configuration. This page focuses on deterministic slot/port allocation and may include legacy or unassigned notes; the canonical service inventory is the WebService Catalog. For the layered platform view, see Platform topology.

Port Assignment Scheme

Port Table

SlotHTTPSHTTPServiceHostnamePathEnv Var
01000010001Router Gatewayrouter.stella-ops.localsrc/Router/StellaOps.Gateway.WebServiceSTELLAOPS_ROUTER_URL
11001010011Platformplatform.stella-ops.localsrc/Platform/StellaOps.Platform.WebServiceSTELLAOPS_PLATFORM_URL
21002010021Authorityauthority.stella-ops.localsrc/Authority/StellaOps.Authority/StellaOps.AuthoritySTELLAOPS_AUTHORITY_URL
3(removed — consolidated into Router Gateway, slot 0)
41004010041Attestorattestor.stella-ops.localsrc/Attestor/StellaOps.Attestor/StellaOps.Attestor.WebServiceSTELLAOPS_ATTESTOR_URL
51005010051Attestor TileProxysrc/Attestor/StellaOps.Attestor.TileProxySTELLAOPS_ATTESTOR_TILEPROXY_URL
61006010061Evidence Lockerevidencelocker.stella-ops.localsrc/EvidenceLocker/StellaOps.EvidenceLocker/StellaOps.EvidenceLocker.WebServiceSTELLAOPS_EVIDENCELOCKER_URL
71007010071Evidence Locker Aggregatorsrc/EvidenceLocker/StellaOps.EvidenceLockerSTELLAOPS_EVIDENCELOCKER_AGGREGATOR_URL
81008010081Scannerscanner.stella-ops.localsrc/Scanner/StellaOps.Scanner.WebServiceSTELLAOPS_SCANNER_URL
91009010091Concelierconcelier.stella-ops.localsrc/Concelier/StellaOps.Concelier.WebServiceSTELLAOPS_CONCELIER_URL
101010010101Excititorexcititor.stella-ops.localsrc/Concelier/StellaOps.Excititor.WebServiceSTELLAOPS_EXCITITOR_URL
111011010111VexHubvexhub.stella-ops.localsrc/VexHub/StellaOps.VexHub.WebServiceSTELLAOPS_VEXHUB_URL
121012010121VexLensvexlens.stella-ops.localsrc/VexLens/StellaOps.VexLens.WebServiceSTELLAOPS_VEXLENS_URL
131013010131VulnExplorer (merged into Findings Ledger)vulnexplorer.stella-ops.local (alias on findings-ledger-web)src/Findings/StellaOps.Findings.Ledger.WebServiceSTELLAOPS_VULNEXPLORER_URL
141014010141Policy Enginepolicy-engine.stella-ops.localsrc/Policy/StellaOps.Policy.EngineSTELLAOPS_POLICY_ENGINE_URL
151015010151Policy Gateway (merged into Policy Engine, Slot 14)policy-gateway.stella-ops.local -> policy-engine.stella-ops.localremovedremoved
161016010161RiskEngineriskengine.stella-ops.localsrc/Findings/StellaOps.RiskEngine.WebServiceSTELLAOPS_RISKENGINE_URL
171017010171Orchestrator (JobEngine WebService) (retired; audit/first-signal moved to Release Orchestrator, Slot 47)orchestrator.stella-ops.local (legacy alias)removedremoved
181018010181TaskRunner (removed)taskrunner.stella-ops.localremovedremoved
191019010191Schedulerscheduler.stella-ops.localsrc/JobEngine/StellaOps.Scheduler.WebServiceSTELLAOPS_SCHEDULER_URL
201020010201Graph APIgraph.stella-ops.localsrc/Graph/StellaOps.Graph.ApiSTELLAOPS_GRAPH_URL
211021010211(Cartographer merged into Graph API)cartographer.stella-ops.local (alias)(see Graph API)STELLAOPS_CARTOGRAPHER_URL
221022010221ReachGraphreachgraph.stella-ops.localsrc/ReachGraph/StellaOps.ReachGraph.WebServiceSTELLAOPS_REACHGRAPH_URL
231023010231(Timeline Indexer merged into Timeline)timelineindexer.stella-ops.local (alias)(see Timeline)STELLAOPS_TIMELINEINDEXER_URL
241024010241Timelinetimeline.stella-ops.localsrc/Timeline/StellaOps.Timeline.WebServiceSTELLAOPS_TIMELINE_URL
251025010251Findings Ledgerfindings.stella-ops.localsrc/Findings/StellaOps.Findings.Ledger.WebServiceSTELLAOPS_FINDINGS_LEDGER_URL
261026010261Doctordoctor.stella-ops.localsrc/Doctor/StellaOps.Doctor.WebServiceSTELLAOPS_DOCTOR_URL
271027010271OpsMemoryopsmemory.stella-ops.localsrc/AdvisoryAI/StellaOps.OpsMemory.WebServiceSTELLAOPS_OPSMEMORY_URL
281028010281(Notifier WebService merged into Notify)notifier.stella-ops.local (alias)(see Notify)STELLAOPS_NOTIFIER_URL
291029010291Notifynotify.stella-ops.localsrc/Notify/StellaOps.Notify.WebServiceSTELLAOPS_NOTIFY_URL
301030010301Signersigner.stella-ops.localsrc/Attestor/StellaOps.Signer/StellaOps.Signer.WebServiceSTELLAOPS_SIGNER_URL
311031010311SmRemotesmremote.stella-ops.localsrc/SmRemote/StellaOps.SmRemote.ServiceSTELLAOPS_SMREMOTE_URL
321032010321AirGap Controllerairgap-controller.stella-ops.localsrc/AirGap/StellaOps.AirGap.ControllerSTELLAOPS_AIRGAP_CONTROLLER_URL
331033010331AirGap Timeairgap-time.stella-ops.localsrc/AirGap/StellaOps.AirGap.TimeSTELLAOPS_AIRGAP_TIME_URL
341034010341PacksRegistrypacksregistry.stella-ops.localsrc/JobEngine/StellaOps.PacksRegistry/StellaOps.PacksRegistry.WebServiceSTELLAOPS_PACKSREGISTRY_URL
351035010351Registry Tokenregistry-token.stella-ops.localsrc/Registry/StellaOps.Registry.TokenServiceSTELLAOPS_REGISTRY_TOKENSERVICE_URL
361036010361BinaryIndexbinaryindex.stella-ops.localsrc/BinaryIndex/StellaOps.BinaryIndex.WebServiceSTELLAOPS_BINARYINDEX_URL
371037010371IssuerDirectoryissuerdirectory.stella-ops.localsrc/Authority/StellaOps.IssuerDirectory/StellaOps.IssuerDirectory.WebServiceSTELLAOPS_ISSUERDIRECTORY_URL
381038010381Symbolssymbols.stella-ops.localsrc/BinaryIndex/StellaOps.Symbols.ServerSTELLAOPS_SYMBOLS_URL
391039010391SbomServicesbomservice.stella-ops.localsrc/SbomService/StellaOps.SbomServiceSTELLAOPS_SBOMSERVICE_URL
401040010401ExportCenterexportcenter.stella-ops.localsrc/ExportCenter/StellaOps.ExportCenter/StellaOps.ExportCenter.WebServiceSTELLAOPS_EXPORTCENTER_URL
411041010411Replayreplay.stella-ops.localsrc/Replay/StellaOps.Replay.WebServiceSTELLAOPS_REPLAY_URL
421042010421Integrationsintegrations.stella-ops.localsrc/Integrations/StellaOps.Integrations.WebServiceSTELLAOPS_INTEGRATIONS_URL
431043010431Signalssignals.stella-ops.localsrc/Signals/StellaOps.SignalsSTELLAOPS_SIGNALS_URL
441044010441AdvisoryAIadvisoryai.stella-ops.localsrc/AdvisoryAI/StellaOps.AdvisoryAI.WebServiceSTELLAOPS_ADVISORYAI_URL
451045010451Unknownsunknowns.stella-ops.localsrc/Unknowns/StellaOps.Unknowns.WebServiceSTELLAOPS_UNKNOWNS_URL
461046010461Workflow Engineworkflow.stella-ops.localsrc/Workflow/StellaOps.Workflow.WebService(none — not surfaced via Platform)
471047010471Release Orchestratorrelease-orchestrator.stella-ops.localsrc/ReleaseOrchestrator/__Apps/StellaOps.ReleaseOrchestrator.WebApiSTELLAOPS_RELEASE_ORCHESTRATOR_URL
901090010901Examples.Gatewaysrc/Router/examples/Examples.Gateway
911091010911Examples.MultiTransportsrc/Router/examples/Examples.MultiTransport.Gateway

Zastava (formerly slot 43, STELLAOPS_ZASTAVA_URL) has been removed: no project exists under src/Zastava/, no STELLAOPS_ZASTAVA_URL env var is defined anywhere, and there is no zastava.stella-ops.local hosts entry. Slot 43 is now occupied by Signals (127.1.0.43), with AdvisoryAI on slot 44 (127.1.0.44) and Unknowns on slot 45 (127.1.0.45), matching the loopback assignments in devops/compose/hosts.stellaops.local and the actual port bindings in devops/compose/docker-compose.stella-services.yml.

Slots 46/47 dev-port note: the deterministic HTTPS/HTTP columns for Workflow Engine and Release Orchestrator follow the slot formula, but in devops/compose these two services publish only port :80 on their dedicated loopback IPs (127.1.0.46, 127.1.0.47) rather than the 104xx dev ports. Release Orchestrator also exposes mTLS on :8443 for the agent-task transport.

Remediation runtime note: src/Remediation/StellaOps.Remediation.WebService is active and binds remediation.stella-ops.local, but no deterministic slot is currently published in this table because compose/router inventory does not yet expose a stable route mapping. Track status in docs/modules/router/webservices-valkey-rollout-matrix.md.

Worker Services

Worker services associated with a web service use ports offset by +2/+3 from the web service slot:

HTTPSHTTPServicePath
1006210063EvidenceLocker Workersrc/EvidenceLocker/StellaOps.EvidenceLocker/StellaOps.EvidenceLocker.Worker
1016210163RiskEngine Workersrc/Findings/StellaOps.RiskEngine.Worker
1017210173Orchestrator Worker (JobEngine Worker) (removed)removed — jobengine/jobengine-worker deleted; Scheduler worker is now embedded in scheduler-web (Scheduler:Worker:Embedded=true)
1018210183TaskRunner Worker (removed)removed
1023210233TimelineIndexer Workersrc/Timeline/StellaOps.TimelineIndexer.Worker
1028210283Notifier Workersrc/Notifier/StellaOps.Notifier/StellaOps.Notifier.Worker
1034210343PacksRegistry Workersrc/JobEngine/StellaOps.PacksRegistry/StellaOps.PacksRegistry.Worker
1040210403ExportCenter Workersrc/ExportCenter/StellaOps.ExportCenter/StellaOps.ExportCenter.Worker

Environment Variable Convention

Each web service has a corresponding STELLAOPS_{SERVICE}_URL environment variable. The Platform service reads these at startup (Layer 1 of the 3-layer configuration) and maps them into ApiBaseUrls for the Angular frontend.

Example: STELLAOPS_SCANNER_URL=https://scanner.stella-ops.local maps to ApiBaseUrls["scanner"].

See also: 3-Layer Service URL Configuration

Friendly Hostnames (.stella-ops.local)

Each service can be reached via https://{name}.stella-ops.local (port 443) and http://{name}.stella-ops.local (port 80) — no port in the URL. The HTTPS/HTTP dev ports (10000+) are bound to localhost only; the .stella-ops.local hostnames use standard ports.

Each hostname resolves to a unique loopback IP (127.1.0.x) so every service can bind ports 443/80 simultaneously without collisions. The entire 127.0.0.0/8 range is loopback on all platforms, so 127.1.0.x addresses work the same as 127.0.0.1.

The Angular UI (ng serve) binds to https://stella-ops.local (port 443 on 127.1.0.1).

At startup each service resolves its hostname to its dedicated loopback IP and binds ports 443/80 on that IP. It logs the result:

Hosts file setup

Each service gets a unique loopback IP in the 127.1.0.x range so ports 443/80 never collide.

Add the following to your hosts file (C:\Windows\System32\drivers\etc\hosts on Windows, /etc/hosts on Linux/macOS):

# Stella Ops local development hostnames
# Each service gets a unique loopback IP so all can bind :443/:80 simultaneously.
127.1.0.1  stella-ops.local
127.1.0.2  router.stella-ops.local
127.1.0.3  platform.stella-ops.local
127.1.0.4  authority.stella-ops.local
127.1.0.6  attestor.stella-ops.local
127.1.0.7  evidencelocker.stella-ops.local
127.1.0.8  scanner.stella-ops.local
127.1.0.9  concelier.stella-ops.local
127.1.0.10 excititor.stella-ops.local
127.1.0.11 vexhub.stella-ops.local
127.1.0.12 vexlens.stella-ops.local
# 127.1.0.13 vulnexplorer.stella-ops.local  # MERGED: alias on findings-ledger-web
127.1.0.14 policy-engine.stella-ops.local
127.1.0.14 policy-gateway.stella-ops.local  # alias -> policy-engine (merged)
127.1.0.16 riskengine.stella-ops.local
127.1.0.17 orchestrator.stella-ops.local  # legacy alias (JobEngine WebService retired; see Slot 17)
# 127.1.0.18 taskrunner.stella-ops.local  # REMOVED
127.1.0.19 scheduler.stella-ops.local
127.1.0.20 graph.stella-ops.local
# 127.1.0.21 cartographer.stella-ops.local  # RETIRED: merged into graph-api (alias on 127.1.0.20)
127.1.0.20 cartographer.stella-ops.local
127.1.0.22 reachgraph.stella-ops.local
127.1.0.23 timelineindexer.stella-ops.local
127.1.0.24 timeline.stella-ops.local
127.1.0.25 findings.stella-ops.local
127.1.0.26 doctor.stella-ops.local
127.1.0.27 opsmemory.stella-ops.local
127.1.0.28 notifier.stella-ops.local
127.1.0.29 notify.stella-ops.local
127.1.0.30 signer.stella-ops.local
127.1.0.31 smremote.stella-ops.local
127.1.0.32 airgap-controller.stella-ops.local
127.1.0.33 airgap-time.stella-ops.local
127.1.0.34 packsregistry.stella-ops.local
127.1.0.35 registry-token.stella-ops.local
127.1.0.36 binaryindex.stella-ops.local
127.1.0.37 issuerdirectory.stella-ops.local
127.1.0.38 symbols.stella-ops.local
127.1.0.39 sbomservice.stella-ops.local
127.1.0.40 exportcenter.stella-ops.local
127.1.0.41 replay.stella-ops.local
127.1.0.42 integrations.stella-ops.local
127.1.0.43 signals.stella-ops.local
127.1.0.44 advisoryai.stella-ops.local
127.1.0.45 unknowns.stella-ops.local
127.1.0.46 workflow.stella-ops.local
127.1.0.47 release-orchestrator.stella-ops.local

# Stella Ops infrastructure (local dev containers)
127.1.1.1  db.stella-ops.local
127.1.1.2  cache.stella-ops.local
127.1.1.3  s3.stella-ops.local
127.1.1.4  rekor.stella-ops.local
127.1.1.5  registry.stella-ops.local
127.1.1.6  harbor-fixture.stella-ops.local
127.1.1.7  github-app-fixture.stella-ops.local
127.1.1.8  advisory-fixture.stella-ops.local

# Stella Ops third-party integration services (overlay compose files)
127.1.2.1  gitea.stella-ops.local
127.1.2.2  jenkins.stella-ops.local
127.1.2.3  nexus.stella-ops.local
127.1.2.4  vault.stella-ops.local
127.1.2.5  oci-registry.stella-ops.local
127.1.2.6  minio.stella-ops.local
127.1.2.7  gitlab.stella-ops.local

Infrastructure services

Infrastructure containers (databases, caches, object storage, transparency logs) use a separate loopback range (127.1.1.x) to avoid collisions with application services.

IPHostnameServicePort
127.1.1.1db.stella-ops.localPostgreSQL 18.15432
127.1.1.2cache.stella-ops.localValkey 9.0.16379
127.1.1.3s3.stella-ops.localSeaweedFS (S3-compatible)8333 (S3 API; -volume.port=8080 internal)
127.1.1.4rekor.stella-ops.localRekor v2 (tiles)3322
127.1.1.5registry.stella-ops.localZot v2.1.3 (OCI registry)80 (→5000)
127.1.1.6harbor-fixture.stella-ops.localHarbor registry fixture (integration tests)
127.1.1.7github-app-fixture.stella-ops.localGitHub App fixture (integration tests)
127.1.1.8advisory-fixture.stella-ops.localAdvisory fixture (integration tests)

Image versions are digest-pinned via env vars in devops/compose/.env (POSTGRES_IMAGE=postgres:18.1, VALKEY_IMAGE=valkey/valkey:9.0.1, RUSTFS_IMAGE=chrislusf/seaweedfs:latest, REKOR_TILES_IMAGE=ghcr.io/sigstore/rekor-tiles:latest); override for production with audited digests. The fixture containers (127.1.1.6127.1.1.8) are defined in devops/compose/docker-compose.integration-fixtures.yml and only run during integration-test overlays.

Third-party integration services (127.1.2.x)

Optional third-party services used by integration/e2e overlay compose files (docker-compose.integrations.yml, docker-compose.e2e-analyzer-coverage.yml) use the 127.1.2.x loopback range:

IPHostnameService
127.1.2.1gitea.stella-ops.localGitea (SCM)
127.1.2.2jenkins.stella-ops.localJenkins (CI)
127.1.2.3nexus.stella-ops.localNexus (artifact repo)
127.1.2.4vault.stella-ops.localHashiCorp Vault (secrets)
127.1.2.5oci-registry.stella-ops.localOCI registry
127.1.2.6minio.stella-ops.localMinIO (S3-compatible)
127.1.2.7gitlab.stella-ops.localGitLab (SCM/CI)