Data collected by live audit on 2026-07-11. Regenerate rather than hand-edit resource numbers.
LAN-exposed listeners by host (excluding :22 SSH which is open on every guest/node, and Tailscale's UDP 41641).
| Host | Port | Service |
|---|---|---|
| .2 | 1883 | Mosquitto MQTT (auth required) |
| .6 | 8096 | Jellyfin HTTP |
| .6 | 7359, 111 | Jellyfin discovery, rpcbind |
| .100β.102, .13 | 8006 | Proxmox web UI |
| .100β.102, .13 | 3300/6789/68xx | Ceph mon/OSD (cluster internal) |
| .200 | 5678 | n8n |
| .201 | 80 / 443 | NPM reverse proxy (public entry) |
| .201 | 81 | NPM admin UI |
| .203 | 2283 | Immich |
| .204 | 3000 | Homepage |
| .204 | 8765 | Speedtest Tracker |
| .207 | 8080 | qBittorrent (via gluetun) |
| .207 | 8191 | FlareSolverr (via gluetun) |
| .207 | 6881 | BitTorrent (via gluetun) |
| .207 | 8989 / 7878 / 9696 | Sonarr / Radarr / Prowlarr |
| .207 | 8945 | Pinchflat |
| .208 | 7000 | Odysseus web UI |
| .208 | 11434 | Ollama API (no auth!) |
| .209 | 3000 | Karakeep |
| .209 | 9000 | Mealie |
| .209 | 9283 | Grocy |
| .210 | 2368 | Ghost |
| .211 | 14002 | Storj dashboard |
| .211 | 28967 tcp+udp | Storj node (needs WAN reachability) |
| .212 | 8971 | Frigate UI (https, authenticated) |
| .212 | 8554 / 8555 | go2rtc RTSP / WebRTC |
| .212 | 1984 | go2rtc API |
| .213 | 9000 / 9443 | Authentik http/https |
| .214 | 8080 | OpenProject |
| .215 | 3001 | Uptime Kuma |
| .215 | 9090 | Prometheus |
| .216 | 3000 | Wiki.js |
Loopback-only (not LAN-exposed): Odysseus SearXNG :8080, ChromaDB :8100, ntfy :8091.
Port assignment policy (observed): container-native default ports are kept and exposed 1:1 on the LXC IP; collisions are avoided because every service has its own IP. Two hosts use :3000 (Homepage, Karakeep, Wiki.js) and two use :8080-style admin ports β fine under IP-per-service, but always check this table before adding a port on an existing host.