Network
The ports 3AM listens on and the connections it makes.
Inbound
| Port | Who connects | Purpose |
|---|---|---|
8700/tcp (configurable) | People's browsers, your automation, your load balancer's health check | Console and API |
That is all. No tool needs to reach 3AM: alerts and approvals are fetched by 3AM. The installer binds the console to
127.0.0.1 unless you pass --bind; put it behind your reverse proxy for TLS and single sign-on.
The model runs on an internal network with no published port; only 3AM can reach it.
Outbound
3AM connects only to the tools you configure, on the addresses in their settings:
| Tool | Typical destination |
|---|---|
| PagerDuty | api.pagerduty.com:443 (api.eu.pagerduty.com for EU accounts) |
| Slack | slack.com:443 |
| Twilio | api.twilio.com:443, studio.twilio.com:443 |
| Kubernetes | The API server, usually :6443 or :443 |
| Prometheus / Alertmanager | Usually :9090 and :9093 |
| Databases | MySQL :3306, PostgreSQL :5432, SQL Server :1433, Oracle :1521 |
| Git hosts, Jira, ServiceNow, Splunk, Datadog | Their HTTPS address |
3am-core preflight tests a TCP connection to every configured tool, so run it after opening the firewall.
3AM never contacts 3am.si: the licence is verified offline.
Proxies
3AM honours the standard HTTPS_PROXY, HTTP_PROXY and NO_PROXY variables on its container. If you set a proxy,
list your internal tools and the model in NO_PROXY (for example NO_PROXY=model,.bank.internal,10.20.30.40; host names, domain suffixes and single addresses, not CIDR ranges) so only
SaaS traffic goes through it.