Reference
Ports
Every port a server and a node use, and who needs to reach it.
Servers
| Port | Flag | What | Who reaches it |
|---|---|---|---|
| 7233 | --edge-temporal-port | The edge's Temporal proxy (mTLS) | Nodes |
| 7443 | --edge-api-port | The edge's HTTPS API: join, renewals, the control stream, artifacts, the LLM gateway and the runtime API | Nodes and apps |
| 8443 | --management-port | Management: the web UI and the admin API | Operators (the CLI) and people (a browser) |
| 7234 | --temporal-frontend-port | Temporal frontend gRPC | Other servers, and the local edge |
| 7235 | --temporal-history-port | Temporal history gRPC | Other servers |
| 7236 | --temporal-matching-port | Temporal matching gRPC | Other servers |
| 7239 | --temporal-worker-port | Temporal worker gRPC | Other servers |
| 6933 | --temporal-frontend-membership-port | Temporal frontend membership | Other servers |
| 6934 | --temporal-history-membership-port | Temporal history membership | Other servers |
| 6935 | --temporal-matching-membership-port | Temporal matching membership | Other servers |
| 6939 | --temporal-worker-membership-port | Temporal worker membership | Other servers |
| 8233 | --temporal-ui-port | The Temporal web UI, in dev mode only (0 turns it off) | Developers |
| none | --metrics-listen | /metrics for Prometheus over plain HTTP, only when you set an address such as 127.0.0.1:9464 | Your Prometheus, on a private network |
Every Temporal port must be 32767 or lower; the server refuses anything higher. --ip sets the address listeners bind to: 127.0.0.1 in dev mode, 0.0.0.0 otherwise.
Nodes
Nodes listen on nothing reachable from outside. They dial out to the edge on 7233 and 7443, and run their local Temporal and LLM proxies on 127.0.0.1 with random ports.