Skip to content

Ports and roles

Port Service Reachability Notes
80, 443 Caddy Public in public mode Serves the web interface, reverse-proxies /api/* to api, terminates TLS (automatic Let’s Encrypt for RESTOW_APP_DOMAIN). Also proxies /agent/* and /install/* to api (see Agent endpoints).
3000 (RESTOW_API_PORT) api Loopback only, by default Health checks and the REST API; only reached directly on the host, or through Caddy publicly.
5432 (POSTGRES_PORT) postgres Loopback only in the source stack; not published in the release stack PostgreSQL.
5173 (RESTOW_WEB_PORT) Vite dev server Development only docker compose --profile dev up -d; not part of a normal deployment.
1025 / 8025 (MAILPIT_SMTP_PORT / MAILPIT_UI_PORT) Mailpit Development only docker compose --profile mail up -d; a local SMTP sink for testing notification mail.
25 (JOURNAL_SMTP_PORT) Archive journal receiver Closed until JOURNAL_SMTP_PORT is set; TCP 25 inbound from the internet for Exchange Online journaling Receives Exchange Online journal reports over SMTP with mandatory STARTTLS; part of the archive, Business and Service Provider. Exchange Online delivers to port 25 only and must reach the receiver directly, not through Caddy; if the receiver listens on another port, forward port 25 to it. It starts only with a TLS certificate of your own. In the release stack JOURNAL_SMTP_BIND sets the address it is published on (default loopback). See Exchange journaling.
8090 updater Internal Docker network only, no published port Runs only with docker compose --profile updater up -d (opt-in). The api reaches it at RESTOW_UPDATER_URL (default http://updater:8090). It mounts the Docker socket, which is root on the host; see Updates. Caddy forwards only one read-only status document (/_maintenance/status) to it, for the maintenance page.

worker and scheduler expose no ports of their own.

Both Compose stacks mount a host folder read-only into the api and worker containers: the folder RESTOW_IMPORT_DIR (default ./import next to the Compose file) appears at /var/lib/restow/import. Each tenant uses its own subfolder. Restow never writes to it. See Mail file import and export.

Machines backed up with the Restow agent reach your instance over HTTPS on its public address, through Caddy, and need no other port. Caddy proxies these paths to api:

Path Purpose
/agent/v1/... The agent API: enrollment, configuration, heartbeat, runs, agent update.
/agent/restic/<endpoint id>/... The restic repository of one endpoint, append-only for the agent.
/install/... The install scripts (linux.sh, macos.sh) and the agent and restic binaries with their SHA256SUMS.

The agent only connects out; nothing on the machine listens. See Endpoint backup.

Role Scope Can do
Provider admin Whole installation Manages tenants, invites tenant admins, has access to every tenant. Meaningful mainly once you manage more than one tenant (Service Provider edition).
Tenant admin One tenant Manages that tenant’s sources, protection rules, schedules, storage, members and restores, including restoring on behalf of another user (impersonation, always audited).
Tenant user Own data only Signs in, restores and downloads only their own mailbox/OneDrive/IMAP account.

See Multi-tenancy for how tenants and roles relate to editions.

Role .env variable Privileges
Owner DATABASE_MIGRATION_URL Owns every table; runs migrations only.
Application DATABASE_URL NOSUPERUSER, NOBYPASSRLS, owns no table. All tenant-scoped work at runtime.
Installation DATABASE_PROVIDER_URL BYPASSRLS. Cross-tenant lookups, installation-wide settings, the scheduler, webhook delivery, pg-boss’s schema.

Full explanation: Get started → The three database roles.