Publish a container port on the node's public IP (TCP or UDP).
This is how inbound UDP reaches a container. There is no other way: the
container's own address is private, and the IP allow/deny rules of
add_firewall_rule cannot route anything.
PORT PRESERVATION MATTERS. Leave external_port at 0 and a port is allocated
from 10000-19999 — your service becomes reachable, but on a DIFFERENT
number. That is fine for HTTP or ssh and broken for every protocol that
carries its own port inside the payload: STUN, TURN, RTP/WebRTC, SIP,
WireGuard, QUIC. For those, pass external_port equal to internal_port.
A media server needs a contiguous span, not one port — pass
internal_port_end. A span is always published unchanged and counts as ONE
rule against your limit.
Some ports are refused because the host or its neighbours already answer on
them: 22, 80, 443, 2222, 9201, 51820, and the bands 9210-9250, 9310-9350
and 20000-20099. The last one is why the "forward UDP 20000-20999 for
Janus" recipe printed in most Nextcloud Talk guides will not work here —
pick a span above it, e.g. 20100-20599.
Requires: API key with write scope.
Args:
slug: Site identifier
internal_port: Port your service listens on inside the container
protocol: "tcp" or "udp". Default: "tcp"
label: Free-text note shown in the panel
external_port: Publish on this exact port; 0 allocates one from the pool
internal_port_end: End of a contiguous range (inclusive); 0 means one port
Returns:
{"id": "...", "external_port": 3478, "internal_port": 3478,
"protocol": "udp", "status": "active",
"public_address": "203.0.113.5:3478", "port_preserved": true}
ConnectorNo auth