Ports and Endpoints
Every port an API7 Gateway control plane, data plane, and Developer Portal listens on or connects to, the configuration key that sets it, and the HTTP endpoints served on it.
Applies to:API7 Gateway 3.10.x
Roles:Platform engineerSRE
The scope of this page is a rule: a port that is not in one of these tables is not part of the product's documented surface. Where this documentation names a port, it is here; where it names a listener but not the path it answers on, the page says so rather than guessing. The tables are grouped by what runs the listener — the two control-plane services, the data plane, the Developer Portal — then by the connections a deployment dials outward, and last by the HTTP endpoints those listeners serve.
Three pages carry the material this one collects: firewall direction and the per-component minimum are in System Requirements, and the configuration files each key lives in are Control Plane and Data Plane.
Control plane ports
The control plane is two services with two configuration files. Each service has four listeners: a plain HTTP one, a TLS one, a status listener for orchestrator probes, and a profiling listener.
| Port | Protocol | Service | What it serves | Set by |
|---|---|---|---|---|
7080 | HTTP | Dashboard | The web UI. Set disable: true in production and serve the UI on the TLS listener. | server.listen.port in dashboard_conf/conf.yaml |
7443 | HTTPS | Dashboard | The web UI and the Admin API. This is the port ADC, a7, and every curl against the Admin API talk to. | server.tls.port in dashboard_conf/conf.yaml |
7081 | HTTP | Dashboard | Liveness and readiness probes. Bound to 127.0.0.1 by default, so a probe reaches it from inside the container or pod only. | server.status.port in dashboard_conf/conf.yaml |
7900 | HTTP | DP Manager | Internal traffic. | server.listen.port in dp_manager_conf/conf.yaml |
7943 | HTTPS, mTLS | DP Manager | The etcd-compatible configuration API that data planes connect to. The DP Manager presents its own certificate and validates each data plane's client certificate against the same trust chain — see Mutual TLS between Control Plane and Data Plane. | server.tls.port in dp_manager_conf/conf.yaml |
7901 | HTTP | DP Manager | Liveness and readiness probes. Bound to 127.0.0.1 by default. | server.status.port in dp_manager_conf/conf.yaml |
6060 | HTTP | Dashboard | The Go pprof profiling endpoint. Bound to 127.0.0.1, and enabled by default since 3.9.0 — reach it from inside the container, and do not publish it. | pprof.port in dashboard_conf/conf.yaml, gated by pprof.enable |
6060 | HTTP | DP Manager | The same profiling endpoint, in the DP Manager's own process and its own container. | pprof.port in dp_manager_conf/conf.yaml, gated by pprof.enable |
A data plane reaches 7943 through its own deployment.etcd.host, which holds the DP Manager address rather than an etcd address. On Docker Desktop, with the control plane in Docker Compose on the same machine, that address is https://host.docker.internal:7943 — see Deploy with Docker Compose.
pprof arrived as an opt-in switch in 3.8.11, "listens on 127.0.0.1 and is disabled by default" (3.8.11 release notes), and was enabled by default in 3.9.0 (3.9.0 release notes); the Docker Compose package ships both services with pprof.enable: true — see Deploy with Docker Compose. A profiling endpoint on by default is worth an explicit check that nothing publishes 6060 beyond the pod or container.
The status listeners serve /healthz and /metrics — see Control-plane metrics. Because they bind to 127.0.0.1, a probe has to run inside the container or pod: the Docker Compose package probes API7 Dashboard with a TCP connect to 7443 instead; from 3.10.7 the offline package's compose file starts the Dashboard binary directly and probes it with api7-ee-dashboard healthz (3.10.7 upgrade notes).
Data plane ports
| Port | Protocol | What it serves | Set by |
|---|---|---|---|
9080 | HTTP | Proxy traffic. Returns 404 until a route matches. | apisix.node_listen in the gateway's config.yaml |
9443 | HTTPS | Proxy traffic. | apisix.ssl.listen in the gateway's config.yaml |
7085 | HTTP | The status API: /status and /status/ready. Keep it off the Service that carries client traffic. Disabled by default — set status_endpoint.enabled: true (Helm) or uncomment the status block in config.yaml (Docker/binary) to turn it on. | apisix.status.port in the gateway's config.yaml, gated by api7ee.status_endpoint.enabled (Helm) |
9090 | HTTP | The APISIX Control API (health-check status, plugin metadata, and other runtime introspection endpoints). Bound to 127.0.0.1 by default, so a probe reaches it from inside the container or pod only — this is separate from the outbound 9090 a control plane dials to reach Prometheus, below. | apisix.control.port in the gateway's config.yaml, gated by apisix.enable_control |
9091 | HTTP | Prometheus metrics at /apisix/prometheus/metrics, once the prometheus (opens in Plugin Hub docs) plugin is enabled as a global rule. Bound to 127.0.0.1 by default, so a scraper outside the container or pod cannot reach it until you change export_addr.ip. | plugin_attr.prometheus.export_addr.port in the gateway's config.yaml, with plugin_attr.prometheus.enable_export_server as the switch and export_uri as the path — see Configuration Files and Monitor Metrics |
Additional proxy ports are added as further entries under apisix.node_listen and apisix.ssl.listen; TCP and UDP stream ports are separate lists again. Configuration Files carries the shape of each.
The data plane's config-default.yaml also carries deployment.admin.admin_listen on port 9180, the separate Admin API listener Apache APISIX serves its own Admin API on, and defaults it to enabled (enable_admin: true). In an API7 Gateway deployment the Admin API is the Dashboard's 7443, and the deployment artifacts (Helm chart and Docker images) explicitly override the data plane's config.yaml to set enable_admin: false, so 9180 does not listen on a stock API7 Gateway data plane. If you set enable_admin: true yourself, firewall 9180 the same way you would any Admin API listener — this documentation otherwise assumes it stays off.
Developer Portal ports
The Developer Portal is a backend that shares the control plane's database and one or more frontends. Both are separate from the Dashboard.
| Port | Protocol | Component | What it serves | Set by |
|---|---|---|---|---|
4321 | HTTPS | Portal API backend | The portal definitions, API products, developers, applications, subscriptions, and credentials. It shares the control plane's api7ee database. | server.listen.port, with server.listen.tls.enabled: true, in backend_conf/conf.yaml |
4322 | HTTP | Portal API backend | Liveness and readiness probes. Bound to 127.0.0.1 by default. | server.status.port in backend_conf/conf.yaml |
6060 | HTTP | Portal API backend | The Go pprof profiling endpoint, enabled by default. Bound to 127.0.0.1 — reach it from inside the container, and do not publish it. | pprof.port in backend_conf/conf.yaml, gated by pprof.enable |
3001 | HTTP | Developer Portal frontend | The site developers sign in to. One backend serves the organization; one frontend is deployed per portal, and each keeps its own PostgreSQL for user sessions. | The container's own port — published as 3001:3001 under Docker Compose and reached through a Service on Kubernetes; see Deploy the Developer Portal |
Outbound connections
These are ports the deployment dials, not ports it listens on. A cluster that allows no egress blocks the first three.
| Port | Protocol | Direction | What connects | Set by |
|---|---|---|---|---|
5432 | TCP | Dashboard, DP Manager, Portal API → PostgreSQL | Configuration storage. Both control-plane services must point at the same database. | database.dsn in each service's configuration file |
9090 | HTTP | Dashboard, DP Manager → Prometheus | The Dashboard queries Prometheus for the metrics it renders; the DP Manager pushes data-plane telemetry to it. | prometheus.addr in each service's configuration file |
4318 | HTTP | Data plane → OTLP collector | Spans, when the opentelemetry (opens in Plugin Hub docs) plugin is configured. The plugin's own default is 127.0.0.1:4318, which is rarely the right address — see Configure Distributed Tracing. | The plugin metadata's collector.address |
MySQL and Microsoft SQL Server are supported as configuration storage as well, on their own ports; the supported versions are in Supported Versions and Interoperability.
Endpoints
The paths this documentation publishes, with the port each is served on.
| Endpoint | Port | Served by | Notes |
|---|---|---|---|
/api/… | 7443 | Dashboard | The Admin API. Authenticated with a Dashboard token in X-API-KEY — see Obtain a Token from the Dashboard and the Admin API reference. |
/apisix/admin/… | 7443 | Dashboard | The APISIX-compatible half of the Admin API — routes, services, consumers, ssls, global_rules, and the rest — with the gateway group in gateway_group_id. This is the prefix the how-to guides and the Admin API reference use. |
/ | 7443 | Dashboard | The web UI. The initial credentials are admin / admin, and the Dashboard asks for a new password on first sign-in. |
/status | 7085 | Data plane | 200 once the gateway process is up. Use it for liveness. |
/status/ready | 7085 | Data plane | 503 while the gateway can reach none of its configured DP Manager endpoints. Use it for readiness, so a node that has lost the control plane stops receiving traffic — see Configure Readiness and Liveness Probes. |
/apisix/prometheus/metrics | 9091 | Data plane | Prometheus exposition format, one scrape target per data-plane node. |
Related
- System Requirements — which of these ports a firewall has to allow, per component, and in which direction.
- Configuration Reference for API7 Gateway Control Plane — the two control-plane configuration files these keys live in.
- Configuration Files — the data plane's
config.yamlandconfig-default.yaml, including every listener key. - Configure Readiness and Liveness Probes — the status endpoints wired into Kubernetes probes, a load balancer, and a Compose health check.
- Shared Memory Sizing — the other deployment-sizing reference a platform engineer reads beside this one.