Docs
Reference

Network

The ports 3AM listens on and the connections it makes.

Inbound

PortWho connectsPurpose
8700/tcp (configurable)People's browsers, your automation, your load balancer's health checkConsole and API

That is all. No tool needs to reach 3AM: alerts and approvals are fetched by 3AM. The installer binds the console to 127.0.0.1 unless you pass --bind; put it behind your reverse proxy for TLS and single sign-on.

The model runs on an internal network with no published port; only 3AM can reach it.

Outbound

3AM connects only to the tools you configure, on the addresses in their settings:

ToolTypical destination
PagerDutyapi.pagerduty.com:443 (api.eu.pagerduty.com for EU accounts)
Slackslack.com:443
Twilioapi.twilio.com:443, studio.twilio.com:443
KubernetesThe API server, usually :6443 or :443
Prometheus / AlertmanagerUsually :9090 and :9093
DatabasesMySQL :3306, PostgreSQL :5432, SQL Server :1433, Oracle :1521
Git hosts, Jira, ServiceNow, Splunk, DatadogTheir HTTPS address

3am-core preflight tests a TCP connection to every configured tool, so run it after opening the firewall.

3AM never contacts 3am.si: the licence is verified offline.

Proxies

3AM honours the standard HTTPS_PROXY, HTTP_PROXY and NO_PROXY variables on its container. If you set a proxy, list your internal tools and the model in NO_PROXY (for example NO_PROXY=model,.bank.internal,10.20.30.40; host names, domain suffixes and single addresses, not CIDR ranges) so only SaaS traffic goes through it.

On this page