Ports and roles
| Port | Service | Reachability | Notes |
|---|---|---|---|
| 80, 443 | Caddy | Public in public mode | Serves the web interface, reverse-proxies /api/* to api, terminates TLS (automatic Let’s Encrypt for RESTOW_APP_DOMAIN). Also proxies /agent/* and /install/* to api (see Agent endpoints). |
3000 (RESTOW_API_PORT) |
api |
Loopback only, by default | Health checks and the REST API; only reached directly on the host, or through Caddy publicly. |
5432 (POSTGRES_PORT) |
postgres |
Loopback only in the source stack; not published in the release stack | PostgreSQL. |
5173 (RESTOW_WEB_PORT) |
Vite dev server | Development only | docker compose --profile dev up -d; not part of a normal deployment. |
1025 / 8025 (MAILPIT_SMTP_PORT / MAILPIT_UI_PORT) |
Mailpit | Development only | docker compose --profile mail up -d; a local SMTP sink for testing notification mail. |
25 (JOURNAL_SMTP_PORT) |
Archive journal receiver | Closed until JOURNAL_SMTP_PORT is set; TCP 25 inbound from the internet for Exchange Online journaling |
Receives Exchange Online journal reports over SMTP with mandatory STARTTLS; part of the archive, Business and Service Provider. Exchange Online delivers to port 25 only and must reach the receiver directly, not through Caddy; if the receiver listens on another port, forward port 25 to it. It starts only with a TLS certificate of your own. In the release stack JOURNAL_SMTP_BIND sets the address it is published on (default loopback). See Exchange journaling. |
| 8090 | updater |
Internal Docker network only, no published port | Runs only with docker compose --profile updater up -d (opt-in). The api reaches it at RESTOW_UPDATER_URL (default http://updater:8090). It mounts the Docker socket, which is root on the host; see Updates. Caddy forwards only one read-only status document (/_maintenance/status) to it, for the maintenance page. |
worker and scheduler expose no ports of their own.
Import folder
Section titled “Import folder”Both Compose stacks mount a host folder read-only into the api and worker containers: the folder RESTOW_IMPORT_DIR (default ./import next to the Compose file) appears at /var/lib/restow/import. Each tenant uses its own subfolder. Restow never writes to it. See Mail file import and export.
Agent endpoints
Section titled “Agent endpoints”Machines backed up with the Restow agent reach your instance over HTTPS on its public address, through Caddy, and need no other port. Caddy proxies these paths to api:
| Path | Purpose |
|---|---|
/agent/v1/... |
The agent API: enrollment, configuration, heartbeat, runs, agent update. |
/agent/restic/<endpoint id>/... |
The restic repository of one endpoint, append-only for the agent. |
/install/... |
The install scripts (linux.sh, macos.sh) and the agent and restic binaries with their SHA256SUMS. |
The agent only connects out; nothing on the machine listens. See Endpoint backup.
Application roles
Section titled “Application roles”| Role | Scope | Can do |
|---|---|---|
| Provider admin | Whole installation | Manages tenants, invites tenant admins, has access to every tenant. Meaningful mainly once you manage more than one tenant (Service Provider edition). |
| Tenant admin | One tenant | Manages that tenant’s sources, protection rules, schedules, storage, members and restores, including restoring on behalf of another user (impersonation, always audited). |
| Tenant user | Own data only | Signs in, restores and downloads only their own mailbox/OneDrive/IMAP account. |
See Multi-tenancy for how tenants and roles relate to editions.
Database roles
Section titled “Database roles”| Role | .env variable |
Privileges |
|---|---|---|
| Owner | DATABASE_MIGRATION_URL |
Owns every table; runs migrations only. |
| Application | DATABASE_URL |
NOSUPERUSER, NOBYPASSRLS, owns no table. All tenant-scoped work at runtime. |
| Installation | DATABASE_PROVIDER_URL |
BYPASSRLS. Cross-tenant lookups, installation-wide settings, the scheduler, webhook delivery, pg-boss’s schema. |
Full explanation: Get started → The three database roles.