env-municipio-docker-vm

Outbound connections and external dependencies

This inventory answers which named services the deployment described in this repository contacts outside its VM, and on which destination ports. It covers installation, image pulls, updates, and the proxy’s certificate management. Host package mirrors, redirect targets, and traffic initiated by the contents of the prebuilt Municipio image or a configured WordPress site can vary.

When Initiator Destination Destination port Purpose
Installer download Operator’s VM (curl) install.getmunicipio.com TCP 443 Fetch installer.sh or uninstaller.sh using the documented HTTPS commands. The documentation site is served from the same host; plain HTTP (TCP 80) redirects to HTTPS.
Installer bootstrap VM (installer.sh) github.com (typically redirecting the archive download to codeload.github.com) TCP 443 Fetch the repository source archive. MUNICIPIO_SOURCE_URL can replace this URL.
Host package installation and removal VM (apt) The VM’s configured Ubuntu or Debian package mirrors Usually TCP 80 or 443, according to the VM’s APT sources Install prerequisites and, in cluster mode, GlusterFS and the arbitrator package; apt-get update also runs during uninstall. The repository does not choose the distribution mirror.
Docker installation on a data VM, when Docker Engine is absent VM (curl, apt) download.docker.com TCP 443 Fetch Docker’s signing key and install Docker Engine, CLI, Buildx plugin, and Compose plugin from Docker’s APT repository.
Municipio and Caddy image pulls Docker Engine on each data VM ghcr.io TCP 443 Pull the digest-pinned ghcr.io/municipio-se/municipio-deployment-docker and ghcr.io/helsingborg-stad/municipio-caddy images during install or update.
MariaDB image pull Docker Engine on each data VM Docker Hub (registry-1.docker.io, with authentication at auth.docker.io) TCP 443 Pull the digest-pinned mariadb image. Docker Hub may redirect layer downloads to changing storage/CDN hosts, so these two names alone are not a complete egress allowlist.
Automatic TLS, only when Caddy manages certificates for public hostnames Caddy container on each data VM Let’s Encrypt (acme-v02.api.letsencrypt.org); fallback ZeroSSL (acme.zerossl.com) TCP 443 ACME account, issuance, and renewal requests. The generated Caddyfile does not pin a CA; these are Caddy’s default issuers. Caddy may also use Let’s Encrypt’s staging endpoint during retries. This row does not apply when CADDY_SITE_ADDRESS=:80 and TLS is terminated upstream.
ZeroSSL fallback account setup, if used Caddy container api.zerossl.com TCP 443 Caddy can request the external account binding credentials needed for its ZeroSSL ACME fallback.
DNS-01, only when configured Caddy container Loopia API or api.name.com TCP 443 Creates and removes temporary ACME TXT records through the selected provider.
Name resolution for the above VM, Docker Engine, and containers The resolver configured on the VM or Docker network UDP/TCP 53, unless a local stub resolver is used Resolve external names. The resolver’s address is environment-specific.

The three image references are set in /etc/municipio/municipio.env; .env.example shows the current example digests. They are pulled as images, not built on the VM; the Caddy image is built in GitHub Actions (see Images). The installer does not run a plugin marketplace download, Composer, npm, or a font/CDN fetch. The Buildx and Compose plugins in the table are Docker APT packages, not WordPress plugins.

The repository does not configure a third-party application API, remote font host, analytics host, or CDN in its Compose files or generated Caddyfile. It does not inventory the internals of the prebuilt Municipio image, its bundled WordPress plugins/themes, site content, or browser-loaded assets. Those can introduce additional destinations (including WordPress update services, APIs, fonts, or CDNs) and must be checked against the deployed image and site if a complete production egress or browser-request allowlist is required. Operator-selected plugins and an external backup target are also outside this inventory.

The stack also uses non-Internet connections: Caddy reaches the local application at 127.0.0.1:${APP_BIND_PORT:-8080} (default TCP 8080), and WordPress reaches local MariaDB through a Unix socket. In cluster modes, Galera, GlusterFS, and optional Swarm communicate between the configured VM addresses; their ports are listed in Network boundaries. Public inbound HTTP/HTTPS on TCP 80/443, including ACME validation traffic, is described there separately from outbound ACME API calls.

Sources for runtime defaults: Caddy automatic HTTPS, Caddy’s ZeroSSL account setup, Let’s Encrypt ACME endpoint, ZeroSSL ACME endpoint, and Docker Registry API example.