Mojo UpDocs
Self-hosted AIOE

Ports and endpoints

The ports AIOE's services listen on, the addresses clients call, and the network paths a firewall must allow.

What each AIOE service listens on, which paths it serves, and which connections a firewall must allow. The full API reference is in API reference.

Listening ports

ServicePortProtocolNotes
API3001HTTPSet with PORT. Put TLS in front of it (ingress, load balancer or Container Apps).
Console8080HTTPnginx serving the static console.
Mesh relay8080HTTPaioe-relay --http. Public, behind TLS.
Overlay gateway8080HTTPaioe-gateway --http. Private: only the API calls it.
Overlay gateway51820UDPWireGuard (--listen-port).
Overlay agent on a nodeanyUDPWireGuard. --listen-port 0 reuses the last port, or picks a free one.
PostgreSQL5432TCPIn the reference layouts.
Redis6379TCPIn the local reference layout; Azure Managed Redis uses 10000 with TLS.

Paths on the API

Every path is under the API's public address (PUBLIC_URL).

PathWho calls itWhat it is
/healthzProbesLiveness, with the running version.
/readyzProbesReadiness.
/.well-known/aioe.jsonWorkbenches, the console, the mobile appThe public discovery document.
/.well-known/aioe-jwks.jsonWorkbenches, nodesThe platform's public signing keys.
/relay/v1/device/code, /relay/v1/device/token, /relay/v1/tokenWorkbenches, nodesEnrolment and token refresh.
/relay/v1/workbench/stream, /relay/v1/workbench/respond, /relay/v1/workbench/eventsWorkbenchesThe relay: the long-lived stream, answers and events.
/relay/v1/devices/…The console, the mobile appRemote control of one workbench.
/relay/v1/mesh/…Overlay agentsThe mesh relay, passed through to the relay service when AIOE_RELAY_UPSTREAM is set.
/ingest/v1Workbenches, nodesEvents, usage, audit and task snapshots.
/catalogue/v1Workbenches, nodes, the consoleThe published catalogue.
/policy/v1Workbenches, nodes, the consoleThe policy that applies, with an ETag.
/fleet/v1/…Workbenches, nodes, the consoleRegistration, heartbeats and the fleet list.
/mesh/v1/…Overlay agentsThe overlay's coordination service.
/tools/v1/…Workbenches, nodesTool servers machines start, and call counts.
/secrets/v1/…The console, workbenches, nodesSecrets for agents' tools.
/projects/v1/…, /portfolio/v1/…, /memory/v1/…, /notifications/v1/…Everyone signed in, workbenches, nodesProjects, the portfolio, memory and the inbox.
/source/v1/…The console, nodes, GitHub and Azure DevOpsSource-control connections, linked accounts and webhooks.
/people/v1/…, /platform/v1/organisationThe console, workbenchesThe signed-in person, and the organisation.
/admin/v1/…Administrators and operatorsAdministration: policy, catalogue, tools, roles, audit, nodes, budgets.

Paths on the mesh relay

PathWhat it is
/relayWebSocket transport for WireGuard packets.
/relay/stream, /relay/sendThe same packets over plain HTTPS, for proxies that refuse WebSockets.
/healthzHealth check.

Firewall rules

FromToPortWhy
Workbenches, nodes, phones, browsersAPI host443/TCPEverything: enrolment, the relay stream, ingest, policy, catalogue. The only connection a workbench must make.
BrowsersConsole host443/TCPThe console.
BrowsersYour identity provider (for Entra ID, login.microsoftonline.com)443/TCPSign-in.
Browsersgraph.microsoft.com443/TCPThe console's people pickers, when you use them.
APIYour identity provider443/TCPFetching signing keys to check tokens.
APIPostgreSQL, Redis5432, Redis portStorage.
APIOverlay gateway8080/TCPRemote control over the overlay.
APIMesh relay443/TCPPassing /relay/v1/mesh through, when AIOE_RELAY_UPSTREAM is set.
APIYour OTLP collectorthe collector's portTraces and metrics, when on.
Overlay agentsSTUN servers (stun.cloudflare.com:3478, stun.l.google.com:19302 by default)UDPFinding a node's public address. Optional.
Overlay agentsEach otherUDPDirect WireGuard paths. Optional: without them traffic goes through the mesh relay.
Overlay agentsMesh relay443/TCPRelayed WireGuard.

No rule is needed into any workbench or node.

Limits

LimitValue
Request body4 MB (a workbench backup may be up to 16 MiB).
Rate limit600 requests a minute per client address, counted by each API replica.
Remote-control answerAIOE_RPC_TIMEOUT, 30 s by default.
Enrolment codeAIOE_DEVICE_CODE_TTL, 600 s; a node's join request AIOE_NODE_CODE_TTL, 24 hours.
Polling for an enrolmentAIOE_DEVICE_POLL_INTERVAL, every 5 s at most.
Device access tokenAIOE_ACCESS_TOKEN_TTL, 3600 s.
Device refresh tokenAIOE_REFRESH_TOKEN_TTL, 30 days, replaced on every use.
A workbench shows offline afterAIOE_OFFLINE_AFTER, 90 s without a heartbeat.

On this page