Docs

Ports and Endpoints

Every port an API7 Gateway control plane, data plane, and Developer Portal listens on or connects to, the configuration key that sets it, and the HTTP endpoints served on it.

Applies to:API7 Gateway 3.10.x

Roles:Platform engineerSRE

The scope of this page is a rule: a port that is not in one of these tables is not part of the product's documented surface. Where this documentation names a port, it is here; where it names a listener but not the path it answers on, the page says so rather than guessing. The tables are grouped by what runs the listener — the two control-plane services, the data plane, the Developer Portal — then by the connections a deployment dials outward, and last by the HTTP endpoints those listeners serve.

Three pages carry the material this one collects: firewall direction and the per-component minimum are in System Requirements, and the configuration files each key lives in are Control Plane and Data Plane.

Control plane ports

The control plane is two services with two configuration files. Each service has four listeners: a plain HTTP one, a TLS one, a status listener for orchestrator probes, and a profiling listener.

PortProtocolServiceWhat it servesSet by
7080HTTPDashboardThe web UI. Set disable: true in production and serve the UI on the TLS listener.server.listen.port in dashboard_conf/conf.yaml
7443HTTPSDashboardThe web UI and the Admin API. This is the port ADC, a7, and every curl against the Admin API talk to.server.tls.port in dashboard_conf/conf.yaml
7081HTTPDashboardLiveness and readiness probes. Bound to 127.0.0.1 by default, so a probe reaches it from inside the container or pod only.server.status.port in dashboard_conf/conf.yaml
7900HTTPDP ManagerInternal traffic.server.listen.port in dp_manager_conf/conf.yaml
7943HTTPS, mTLSDP ManagerThe etcd-compatible configuration API that data planes connect to. The DP Manager presents its own certificate and validates each data plane's client certificate against the same trust chain — see Mutual TLS between Control Plane and Data Plane.server.tls.port in dp_manager_conf/conf.yaml
7901HTTPDP ManagerLiveness and readiness probes. Bound to 127.0.0.1 by default.server.status.port in dp_manager_conf/conf.yaml
6060HTTPDashboardThe Go pprof profiling endpoint. Bound to 127.0.0.1, and enabled by default since 3.9.0 — reach it from inside the container, and do not publish it.pprof.port in dashboard_conf/conf.yaml, gated by pprof.enable
6060HTTPDP ManagerThe same profiling endpoint, in the DP Manager's own process and its own container.pprof.port in dp_manager_conf/conf.yaml, gated by pprof.enable

A data plane reaches 7943 through its own deployment.etcd.host, which holds the DP Manager address rather than an etcd address. On Docker Desktop, with the control plane in Docker Compose on the same machine, that address is https://host.docker.internal:7943 — see Deploy with Docker Compose.

pprof arrived as an opt-in switch in 3.8.11, "listens on 127.0.0.1 and is disabled by default" (3.8.11 release notes), and was enabled by default in 3.9.0 (3.9.0 release notes); the Docker Compose package ships both services with pprof.enable: true — see Deploy with Docker Compose. A profiling endpoint on by default is worth an explicit check that nothing publishes 6060 beyond the pod or container.

The status listeners serve /healthz and /metrics — see Control-plane metrics. Because they bind to 127.0.0.1, a probe has to run inside the container or pod: the Docker Compose package probes API7 Dashboard with a TCP connect to 7443 instead; from 3.10.7 the offline package's compose file starts the Dashboard binary directly and probes it with api7-ee-dashboard healthz (3.10.7 upgrade notes).

Data plane ports

PortProtocolWhat it servesSet by
9080HTTPProxy traffic. Returns 404 until a route matches.apisix.node_listen in the gateway's config.yaml
9443HTTPSProxy traffic.apisix.ssl.listen in the gateway's config.yaml
7085HTTPThe status API: /status and /status/ready. Keep it off the Service that carries client traffic. Disabled by default — set status_endpoint.enabled: true (Helm) or uncomment the status block in config.yaml (Docker/binary) to turn it on.apisix.status.port in the gateway's config.yaml, gated by api7ee.status_endpoint.enabled (Helm)
9090HTTPThe APISIX Control API (health-check status, plugin metadata, and other runtime introspection endpoints). Bound to 127.0.0.1 by default, so a probe reaches it from inside the container or pod only — this is separate from the outbound 9090 a control plane dials to reach Prometheus, below.apisix.control.port in the gateway's config.yaml, gated by apisix.enable_control
9091HTTPPrometheus metrics at /apisix/prometheus/metrics, once the prometheus (opens in Plugin Hub docs) plugin is enabled as a global rule. Bound to 127.0.0.1 by default, so a scraper outside the container or pod cannot reach it until you change export_addr.ip.plugin_attr.prometheus.export_addr.port in the gateway's config.yaml, with plugin_attr.prometheus.enable_export_server as the switch and export_uri as the path — see Configuration Files and Monitor Metrics

Additional proxy ports are added as further entries under apisix.node_listen and apisix.ssl.listen; TCP and UDP stream ports are separate lists again. Configuration Files carries the shape of each.

The data plane's config-default.yaml also carries deployment.admin.admin_listen on port 9180, the separate Admin API listener Apache APISIX serves its own Admin API on, and defaults it to enabled (enable_admin: true). In an API7 Gateway deployment the Admin API is the Dashboard's 7443, and the deployment artifacts (Helm chart and Docker images) explicitly override the data plane's config.yaml to set enable_admin: false, so 9180 does not listen on a stock API7 Gateway data plane. If you set enable_admin: true yourself, firewall 9180 the same way you would any Admin API listener — this documentation otherwise assumes it stays off.

Developer Portal ports

The Developer Portal is a backend that shares the control plane's database and one or more frontends. Both are separate from the Dashboard.

PortProtocolComponentWhat it servesSet by
4321HTTPSPortal API backendThe portal definitions, API products, developers, applications, subscriptions, and credentials. It shares the control plane's api7ee database.server.listen.port, with server.listen.tls.enabled: true, in backend_conf/conf.yaml
4322HTTPPortal API backendLiveness and readiness probes. Bound to 127.0.0.1 by default.server.status.port in backend_conf/conf.yaml
6060HTTPPortal API backendThe Go pprof profiling endpoint, enabled by default. Bound to 127.0.0.1 — reach it from inside the container, and do not publish it.pprof.port in backend_conf/conf.yaml, gated by pprof.enable
3001HTTPDeveloper Portal frontendThe site developers sign in to. One backend serves the organization; one frontend is deployed per portal, and each keeps its own PostgreSQL for user sessions.The container's own port — published as 3001:3001 under Docker Compose and reached through a Service on Kubernetes; see Deploy the Developer Portal

Outbound connections

These are ports the deployment dials, not ports it listens on. A cluster that allows no egress blocks the first three.

PortProtocolDirectionWhat connectsSet by
5432TCPDashboard, DP Manager, Portal API → PostgreSQLConfiguration storage. Both control-plane services must point at the same database.database.dsn in each service's configuration file
9090HTTPDashboard, DP Manager → PrometheusThe Dashboard queries Prometheus for the metrics it renders; the DP Manager pushes data-plane telemetry to it.prometheus.addr in each service's configuration file
4318HTTPData plane → OTLP collectorSpans, when the opentelemetry (opens in Plugin Hub docs) plugin is configured. The plugin's own default is 127.0.0.1:4318, which is rarely the right address — see Configure Distributed Tracing.The plugin metadata's collector.address

MySQL and Microsoft SQL Server are supported as configuration storage as well, on their own ports; the supported versions are in Supported Versions and Interoperability.

Endpoints

The paths this documentation publishes, with the port each is served on.

EndpointPortServed byNotes
/api/…7443DashboardThe Admin API. Authenticated with a Dashboard token in X-API-KEY — see Obtain a Token from the Dashboard and the Admin API reference.
/apisix/admin/…7443DashboardThe APISIX-compatible half of the Admin API — routes, services, consumers, ssls, global_rules, and the rest — with the gateway group in gateway_group_id. This is the prefix the how-to guides and the Admin API reference use.
/7443DashboardThe web UI. The initial credentials are admin / admin, and the Dashboard asks for a new password on first sign-in.
/status7085Data plane200 once the gateway process is up. Use it for liveness.
/status/ready7085Data plane503 while the gateway can reach none of its configured DP Manager endpoints. Use it for readiness, so a node that has lost the control plane stops receiving traffic — see Configure Readiness and Liveness Probes.
/apisix/prometheus/metrics9091Data planePrometheus exposition format, one scrape target per data-plane node.