Deterministic Port Registry

Audience: developers and operators wiring up local environments, hosts files, and service-discovery configuration for Stella Ops.

All Stella Ops web services are assigned deterministic HTTPS/HTTP port pairs to avoid collisions during local development and to simplify service-discovery configuration. This page focuses on deterministic slot/port allocation and may include legacy or unassigned notes; the canonical service inventory is the WebService Catalog. For the layered platform view, see Platform topology.

Port Assignment Scheme

Port Table

SlotHTTPSHTTPServiceHostnamePathEnv Var
01000010001Router Gatewayrouter.stella-ops.localsrc/Router/StellaOps.Gateway.WebServiceSTELLAOPS_ROUTER_URL
11001010011Platformplatform.stella-ops.localsrc/Platform/StellaOps.Platform.WebServiceSTELLAOPS_PLATFORM_URL
21002010021Authorityauthority.stella-ops.localsrc/Authority/StellaOps.Authority/StellaOps.AuthoritySTELLAOPS_AUTHORITY_URL
3——(removed — consolidated into Router Gateway, slot 0)———
41004010041Attestorattestor.stella-ops.localsrc/Attestor/StellaOps.Attestor/StellaOps.Attestor.WebServiceSTELLAOPS_ATTESTOR_URL
51005010051Attestor TileProxy—src/Attestor/StellaOps.Attestor.TileProxySTELLAOPS_ATTESTOR_TILEPROXY_URL
61006010061Evidence Lockerevidencelocker.stella-ops.localsrc/EvidenceLocker/StellaOps.EvidenceLocker/StellaOps.EvidenceLocker.WebServiceSTELLAOPS_EVIDENCELOCKER_URL
71007010071Evidence Locker Aggregator—src/EvidenceLocker/StellaOps.EvidenceLockerSTELLAOPS_EVIDENCELOCKER_AGGREGATOR_URL
81008010081Scannerscanner.stella-ops.localsrc/Scanner/StellaOps.Scanner.WebServiceSTELLAOPS_SCANNER_URL
9——Concelier host retired 2026-09-11 (VULN-G6)—src/__Obsoleted/Concelier/StellaOps.Concelier.WebService—
101010010101Excititorexcititor.stella-ops.localsrc/Concelier/StellaOps.Excititor.WebServiceSTELLAOPS_EXCITITOR_URL
111011010111VexHubvexhub.stella-ops.localsrc/VexHub/StellaOps.VexHub.WebServiceSTELLAOPS_VEXHUB_URL
121012010121VexLensvexlens.stella-ops.localsrc/VexLens/StellaOps.VexLens.WebServiceSTELLAOPS_VEXLENS_URL
131013010131VulnExplorer (merged into Findings Ledger)vulnexplorer.stella-ops.local (alias on findings-ledger-web)src/Findings/StellaOps.Findings.Ledger.WebServiceSTELLAOPS_VULNEXPLORER_URL
141014010141Policy Enginepolicy-engine.stella-ops.localsrc/Policy/StellaOps.Policy.EngineSTELLAOPS_POLICY_ENGINE_URL
151015010151Policy Gateway (merged into Policy Engine, Slot 14)policy-gateway.stella-ops.local -> policy-engine.stella-ops.localremovedremoved
161016010161RiskEngine (retired 2026-08-27, SPRINT_20260722_010 FND-10; scoring folds into the consolidated Findings family)riskengine.stella-ops.localremovedremoved
171017010171Orchestrator (JobEngine WebService) (retired; audit/first-signal moved to Release Orchestrator, Slot 47)orchestrator.stella-ops.local (legacy alias)removedremoved
181018010181TaskRunner (removed)taskrunner.stella-ops.localremovedremoved
191019010191JobEngine (consolidated: Scheduler + PacksRegistry, JOB-9 2026-09-12)jobengine.stella-ops.local, jobengine-web.stella-ops.local (the JOB-9 soak aliases scheduler.stella-ops.local, scheduler-worker.stella-ops.local and packsregistry.stella-ops.local were RETIRED at JOB-10)src/JobEngine/StellaOps.JobEngine.WebServiceSTELLAOPS_SCHEDULER_URL, STELLAOPS_PACKSREGISTRY_URL
201020010201Graph APIgraph.stella-ops.localsrc/Graph/StellaOps.Graph.ApiSTELLAOPS_GRAPH_URL
211021010211(Cartographer merged into Graph API)cartographer.stella-ops.local (alias)(see Graph API)STELLAOPS_CARTOGRAPHER_URL
221022010221(ReachGraph merged into Graph API, 023 GRA-10 2026-09-08)reachgraph.stella-ops.local (alias on graph-api)(see Graph API)STELLAOPS_REACHGRAPH_URL
231023010231(Timeline Indexer merged into Timeline)timelineindexer.stella-ops.local (alias)(see Timeline)STELLAOPS_TIMELINEINDEXER_URL
241024010241Timelinetimeline.stella-ops.localsrc/Timeline/StellaOps.Timeline.WebServiceSTELLAOPS_TIMELINE_URL
251025010251Findings Ledgerfindings.stella-ops.localsrc/Findings/StellaOps.Findings.Ledger.WebServiceSTELLAOPS_FINDINGS_LEDGER_URL
261026010261Doctordoctor.stella-ops.localsrc/Doctor/StellaOps.Doctor.WebServiceSTELLAOPS_DOCTOR_URL
271027010271OpsMemory — RETIRED 2026-09-07 (AAI-10); slot held, not reassigned(none: served by advisoryai.stella-ops.local)src/AdvisoryAI/__Libraries/StellaOps.OpsMemory.ApplicationSTELLAOPS_OPSMEMORY_URL now points at advisoryai.stella-ops.local
281028010281(retired 2026-09-08, NTF-10 — Notifier merged into Notify)notifier.stella-ops.local (alias on notify-web)(see Notify)STELLAOPS_NOTIFIER_URL (still read by Platform; resolves to notify.stella-ops.local)
291029010291Notifynotify.stella-ops.localsrc/Notify/StellaOps.Notify.WebServiceSTELLAOPS_NOTIFY_URL
301030010301Signersigner.stella-ops.localsrc/Attestor/StellaOps.Signer/StellaOps.Signer.WebServiceSTELLAOPS_SIGNER_URL
311031010311SmRemotesmremote.stella-ops.localsrc/SmRemote/StellaOps.SmRemote.ServiceSTELLAOPS_SMREMOTE_URL
321032010321AirGap Controller — RETIRED 2026-09-11 (SPRINT_20260722_025 OK-5, ADR-039 Rev-8/EVL-3). Sealed posture moved to Platform’s generic environment_state custodian; exchange (Importer/Bundle/Sync) moved to OfflineKit, Slot 40. Slot held, not reassignedairgap-controller.stella-ops.local (dead — resolves to nothing; still listed in devops/compose/hosts.stellaops.local)src/__Obsoleted/AirGap/StellaOps.AirGap.Controller (frozen)STELLAOPS_AIRGAP_CONTROLLER_URL — no longer set by any compose file
331033010331AirGap Time — RETIRED 2026-09-11 (SPRINT_20260722_025 OK-5, ADR-039 Rev-8/EVL-3). The time-anchor face is a Platform posture concern; the AirGap.Time.Verification contract survives as a domain-neutral library under src/OfflineKit/__Libraries/. Slot held, not reassignedairgap-time.stella-ops.local (dead)src/__Obsoleted/AirGap/StellaOps.AirGap.Time (frozen)STELLAOPS_AIRGAP_TIME_URL — no longer set by any compose file
341034010341PacksRegistry — RETIRED 2026-09-12 (SPRINT_20260722_012 JOB-9, ADR-039 D14; folded into jobengine-web, Slot 19). Loopback 127.1.0.34 was published alongside 127.1.0.19 on jobengine-web through the soak and RETIRED at JOB-10; slot still held, not reassignedpacksregistry.stella-ops.local (alias on jobengine-web)src/__Obsoleted/JobEngine/StellaOps.PacksRegistry/StellaOps.PacksRegistry.WebService (frozen)STELLAOPS_PACKSREGISTRY_URL now points at jobengine.stella-ops.local
351035010351Registry Tokenregistry-token.stella-ops.localsrc/Registry/StellaOps.Registry.TokenServiceSTELLAOPS_REGISTRY_TOKENSERVICE_URL
361036010361BinaryIndexbinaryindex.stella-ops.localsrc/BinaryIndex/StellaOps.BinaryIndex.WebServiceSTELLAOPS_BINARYINDEX_URL
37——IssuerDirectory — RETIRED 2026-09-11 (SPRINT_20260722_016 AUTH-10; folded into authority, Slot 2); slot held, not reassigned(none: served by authority.stella-ops.local)src/__Obsoleted/Authority/StellaOps.IssuerDirectory.WebService (frozen)STELLAOPS_ISSUERDIRECTORY_URL now points at authority.stella-ops.local
381038010381Symbolssymbols.stella-ops.localsrc/BinaryIndex/StellaOps.Symbols.ServerSTELLAOPS_SYMBOLS_URL
391039010391SbomServicesbomservice.stella-ops.localsrc/SbomService/StellaOps.SbomServiceSTELLAOPS_SBOMSERVICE_URL
401040010401OfflineKit (succeeded ExportCenter 2026-09-13, SPRINT_20260722_025 OK-10)offlinekit.stella-ops.local, offlinekit-web.stella-ops.localsrc/OfflineKit/StellaOps.OfflineKit.WebServiceSTELLAOPS_OFFLINEKIT_URL
411041010411Replayreplay.stella-ops.localsrc/Replay/StellaOps.Replay.WebServiceSTELLAOPS_REPLAY_URL
421042010421Integrationsintegrations.stella-ops.localsrc/Integrations/StellaOps.Integrations.WebServiceSTELLAOPS_INTEGRATIONS_URL
431043010431Signalssignals.stella-ops.localsrc/Signals/StellaOps.SignalsSTELLAOPS_SIGNALS_URL
441044010441AdvisoryAIadvisoryai.stella-ops.localsrc/AdvisoryAI/StellaOps.AdvisoryAI.WebServiceSTELLAOPS_ADVISORYAI_URL
451045010451Unknownsunknowns.stella-ops.localsrc/Unknowns/StellaOps.Unknowns.WebServiceSTELLAOPS_UNKNOWNS_URL
461046010461Workflow Engineworkflow.stella-ops.localsrc/Workflow/StellaOps.Workflow.WebService(none — not surfaced via Platform)
471047010471Release Orchestratorrelease-orchestrator.stella-ops.localsrc/ReleaseOrchestrator/__Apps/StellaOps.ReleaseOrchestrator.WebApiSTELLAOPS_RELEASE_ORCHESTRATOR_URL
901090010901Examples.Gateway—src/Router/examples/Examples.Gateway—
911091010911Examples.MultiTransport—src/Router/examples/Examples.MultiTransport.Gateway—

Zastava (formerly slot 43, STELLAOPS_ZASTAVA_URL) has been removed: no project exists under src/Zastava/, no STELLAOPS_ZASTAVA_URL env var is defined anywhere, and there is no zastava.stella-ops.local hosts entry. Slot 43 is now occupied by Signals (127.1.0.43), with AdvisoryAI on slot 44 (127.1.0.44) and Unknowns on slot 45 (127.1.0.45), matching the loopback assignments in devops/compose/hosts.stellaops.local and the actual port bindings in devops/compose/docker-compose.stella-services.yml.

Slots 46/47 dev-port note: the deterministic HTTPS/HTTP columns for Workflow Engine and Release Orchestrator follow the slot formula, but in devops/compose these two services publish only port :80 on their dedicated loopback IPs (127.1.0.46, 127.1.0.47) rather than the 104xx dev ports. Release Orchestrator also exposes mTLS on :8443 for the agent-task transport.

Remediation runtime note: src/Remediation/StellaOps.Remediation.WebService is active and binds remediation.stella-ops.local, but no deterministic slot is currently published in this table because compose/router inventory does not yet expose a stable route mapping. Track status in docs/modules/router/webservices-valkey-rollout-matrix.md.

Worker Services

Worker services associated with a web service use ports offset by +2/+3 from the web service slot:

HTTPSHTTPServicePath
1006210063EvidenceLocker Workersrc/EvidenceLocker/StellaOps.EvidenceLocker/StellaOps.EvidenceLocker.Worker
1016210163RiskEngine Worker (retired 2026-08-27, SPRINT_20260722_010 FND-10)removed — the scoring role is a role of findings-worker
1017210173Orchestrator Worker (removed 2026-07; the Slot 17 host, unrelated to the family below)removed — audit/first-signal moved to Release Orchestrator, Slot 47. The name jobengine-worker was REUSED on 2026-09-12 for the consolidated family’s worker role (Slot 19); the scheduler worker itself stays embedded in the web role (Scheduler:Worker:Embedded=true)
1018210183TaskRunner Worker (removed)removed
1023210233TimelineIndexer Worker (archived)archived 2026-08-10 to src/__Obsoleted/Timeline/StellaOps.TimelineIndexer.Worker; ingestion runs in-process inside timeline-web
1028210283Notify Workersrc/Notify/StellaOps.Notify.Worker
1034210343PacksRegistry Worker — RETIRED 2026-09-12 (JOB-9)removed — succeeded by jobengine-worker, the worker ROLE of the consolidated family (src/JobEngine/StellaOps.JobEngine.Worker), sharing stellaops_jobengine with the web role
1040210403OfflineKit Worker (succeeded ExportCenter Worker 2026-09-13, OK-10)src/OfflineKit/StellaOps.OfflineKit.Worker

Environment Variable Convention

Each web service has a corresponding STELLAOPS_{SERVICE}_URL environment variable. The Platform service reads these at startup (Layer 1 of the 3-layer configuration) and maps them into ApiBaseUrls for the Angular frontend.

Example: STELLAOPS_SCANNER_URL=https://scanner.stella-ops.local maps to ApiBaseUrls["scanner"].

See also: 3-Layer Service URL Configuration

Friendly Hostnames (.stella-ops.local)

Each service can be reached via https://{name}.stella-ops.local (port 443) and http://{name}.stella-ops.local (port 80) — no port in the URL. The HTTPS/HTTP dev ports (10000+) are bound to localhost only; the .stella-ops.local hostnames use standard ports.

Each hostname resolves to a unique loopback IP (127.1.0.x) so every service can bind ports 443/80 simultaneously without collisions. The entire 127.0.0.0/8 range is loopback on all platforms, so 127.1.0.x addresses work the same as 127.0.0.1.

The Angular UI (ng serve) binds to https://stella-ops.local (port 443 on 127.1.0.1).

At startup each service resolves its hostname to its dedicated loopback IP and binds ports 443/80 on that IP. It logs the result:

Hosts file setup

Each service gets a unique loopback IP in the 127.1.0.x range so ports 443/80 never collide.

Add the following to your hosts file (C:\Windows\System32\drivers\etc\hosts on Windows, /etc/hosts on Linux/macOS):

# Stella Ops local development hostnames
# Each service gets a unique loopback IP so all can bind :443/:80 simultaneously.
127.1.0.1  stella-ops.local
127.1.0.2  router.stella-ops.local
127.1.0.3  platform.stella-ops.local
127.1.0.4  authority.stella-ops.local
127.1.0.6  attestor.stella-ops.local
127.1.0.7  evidencelocker.stella-ops.local
127.1.0.8  scanner.stella-ops.local
127.1.0.9  concelier.stella-ops.local
127.1.0.10 excititor.stella-ops.local
127.1.0.11 vexhub.stella-ops.local
127.1.0.12 vexlens.stella-ops.local
# 127.1.0.13 vulnexplorer.stella-ops.local  # MERGED: alias on findings-ledger-web
127.1.0.14 policy-engine.stella-ops.local
127.1.0.14 policy-gateway.stella-ops.local  # alias -> policy-engine (merged)
# 127.1.0.16 riskengine.stella-ops.local  # RETIRED 2026-08-27 (FND-10): no service claims this name
127.1.0.17 orchestrator.stella-ops.local  # legacy alias (JobEngine WebService retired; see Slot 17)
# 127.1.0.18 taskrunner.stella-ops.local  # REMOVED
127.1.0.19 jobengine.stella-ops.local
127.1.0.19 jobengine-web.stella-ops.local
127.1.0.20 graph.stella-ops.local
# 127.1.0.21 cartographer.stella-ops.local  # RETIRED: merged into graph-api (alias on 127.1.0.20)
127.1.0.20 cartographer.stella-ops.local
127.1.0.22 reachgraph.stella-ops.local
127.1.0.23 timelineindexer.stella-ops.local
127.1.0.24 timeline.stella-ops.local
127.1.0.25 findings.stella-ops.local
127.1.0.26 doctor.stella-ops.local
127.1.0.27 opsmemory.stella-ops.local
127.1.0.28 notifier.stella-ops.local
127.1.0.29 notify.stella-ops.local
127.1.0.30 signer.stella-ops.local
127.1.0.31 smremote.stella-ops.local
127.1.0.35 registry-token.stella-ops.local
127.1.0.36 binaryindex.stella-ops.local
127.1.0.38 symbols.stella-ops.local
127.1.0.39 sbomservice.stella-ops.local
127.1.0.40 offlinekit.stella-ops.local
127.1.0.41 replay.stella-ops.local
127.1.0.42 integrations.stella-ops.local
127.1.0.43 signals.stella-ops.local
127.1.0.44 advisoryai.stella-ops.local
127.1.0.45 unknowns.stella-ops.local
127.1.0.46 workflow.stella-ops.local
127.1.0.47 release-orchestrator.stella-ops.local

# Stella Ops infrastructure (local dev containers)
127.1.1.1  db.stella-ops.local
127.1.1.2  cache.stella-ops.local
127.1.1.3  s3.stella-ops.local
127.1.1.4  rekor.stella-ops.local
127.1.1.5  registry.stella-ops.local
127.1.1.6  harbor-fixture.stella-ops.local
127.1.1.7  github-app-fixture.stella-ops.local
127.1.1.8  advisory-fixture.stella-ops.local

# Stella Ops third-party integration services (overlay compose files)
127.1.2.1  gitea.stella-ops.local
127.1.2.2  jenkins.stella-ops.local
127.1.2.3  nexus.stella-ops.local
127.1.2.4  vault.stella-ops.local
127.1.2.5  oci-registry.stella-ops.local
127.1.2.6  minio.stella-ops.local
127.1.2.7  gitlab.stella-ops.local

Retired loopbacks 127.1.0.32 / .33 / .34. Slots 32 (AirGap Controller) and 33 (AirGap Time) retired 2026-09-11 and slot 34 (PacksRegistry) 2026-09-12; none of the three names resolves to a running service, and all three are absent from the block above. devops/compose/hosts.stellaops.local is the file a developer actually installs and it still carries airgap-controller, airgap-time and exportcenter and has no offlinekit entry. A stale entry there is harmless — nothing listens — but it is misleading, and it is recorded against SPRINT_20260722_025 rather than changed here: this page documents the allocation, it does not deploy it.

Slot 40 is a reuse, not a rename. exportcenter.stella-ops.local was the name the gateway resolved for the bare /v1/exports routes. Those routes are gone — live probe 2026-09-14: GET https://127.1.0.1/v1/exports → 404 — and the export plane now answers under /api/offlinekit/v1/exports/* on offlinekit-web (same probe: /api/offlinekit/v1/exports/profiles → 401, served and auth-gated). Note the bare collection path /api/offlinekit/v1/exports also returns 404 and that is correct: the group maps only /profiles and /runs beneath it, never a collection root. STELLAOPS_EXPORTCENTER_URL is still set in devops/compose/docker-compose.stella-services.yml and still points at the dead name — a live-config residue, also tracked in SPRINT_20260722_025.

Infrastructure services

Infrastructure containers (databases, caches, object storage, transparency logs) use a separate loopback range (127.1.1.x) to avoid collisions with application services.

IPHostnameServicePort
127.1.1.1db.stella-ops.localPostgreSQL 18.15432
127.1.1.2cache.stella-ops.localValkey 9.0.16379
127.1.1.3s3.stella-ops.localSeaweedFS (S3-compatible)8333 (S3 API; -volume.port=8080 internal)
127.1.1.4rekor.stella-ops.localRekor v2 (tiles)3322
127.1.1.5registry.stella-ops.localZot v2.1.3 (OCI registry)80 (→5000)
127.1.1.6harbor-fixture.stella-ops.localHarbor registry fixture (integration tests)—
127.1.1.7github-app-fixture.stella-ops.localGitHub App fixture (integration tests)—
127.1.1.8advisory-fixture.stella-ops.localAdvisory fixture (integration tests)—

Image versions are digest-pinned via env vars in devops/compose/.env (POSTGRES_IMAGE=postgres:18.1, VALKEY_IMAGE=valkey/valkey:9.0.1, RUSTFS_IMAGE=chrislusf/seaweedfs:latest, REKOR_TILES_IMAGE=ghcr.io/sigstore/rekor-tiles:latest); override for production with audited digests. The fixture containers (127.1.1.6–127.1.1.8) are defined in devops/compose/docker-compose.integration-fixtures.yml and only run during integration-test overlays.

Third-party integration services (127.1.2.x)

Optional third-party services used by integration/e2e overlay compose files (docker-compose.integrations.yml, docker-compose.e2e-analyzer-coverage.yml) use the 127.1.2.x loopback range:

IPHostnameService
127.1.2.1gitea.stella-ops.localGitea (SCM)
127.1.2.2jenkins.stella-ops.localJenkins (CI)
127.1.2.3nexus.stella-ops.localNexus (artifact repo)
127.1.2.4vault.stella-ops.localHashiCorp Vault (secrets)
127.1.2.5oci-registry.stella-ops.localOCI registry
127.1.2.6minio.stella-ops.localMinIO (S3-compatible)
127.1.2.7gitlab.stella-ops.localGitLab (SCM/CI)