Skip to content
slopscale
Esc
↑↓navigate↵open⌘Jpreview
On this page

Requirements

What a slopscale server needs: a public address, HTTPS on port 443, the ports the DERP relay and metrics use, and the paths these docs assume.

Slopscale should just work as long as the following requirements are met:

  • A server with a public IP address for slopscale. A dual-stack setup with a public IPv4 and a public IPv6 address is recommended.
  • Slopscale is served via HTTPS on port 4431 and may use additional ports.
  • A reasonably modern Linux or BSD based operating system. Release binaries and container images cover Linux (amd64, arm64, armv7); macOS and FreeBSD are built from source.
  • A dedicated local user account to run slopscale.
  • A little bit of command line knowledge to configure and operate slopscale.

Ports in use

The ports in use vary with the intended scenario and enabled features. Some of the listed ports may be changed via the configuration file but we recommend to stick with the default values.

  • tcp/80
    • Expose publicly: yes
    • HTTP, used by Let’s Encrypt to verify ownership via the HTTP-01 challenge.
    • Only required if the built-in Let’s Encrypt client with the HTTP-01 challenge is used. See TLS for details.
  • tcp/443
    • Expose publicly: yes
    • HTTPS, required to make Slopscale available to Tailscale clients1
    • Required for the embedded DERP server, which is on by default
  • udp/3478
  • tcp/9090

Assumptions

The slopscale documentation and the provided examples are written with a few assumptions in mind:

  • Slopscale is running as system service via a dedicated local user slopscale.
  • The configuration is loaded from /etc/slopscale/config.yaml.
  • SQLite is used as database.
  • The data directory for slopscale (used for private keys, policy, SQLite database, …) is located in /var/lib/slopscale.
  • URLs and values that need to be replaced by the user are either denoted as <VALUE_TO_CHANGE> or use placeholder values such as slopscale.example.com.

Please adjust to your local environment accordingly.

Footnotes

  1. The Tailscale client assumes HTTPS on port 443 in certain situations. Serving slopscale either via HTTP or via HTTPS on a port other than 443 is possible but sticking with HTTPS on port 443 is strongly recommended for production setups. See issue 2164 for more information. ↩ ↩2

Last updated on September 27, 2026

Was this page helpful?