================================================================================
           AUDITORÍA DEFINITIVA DE PUERTOS EN USO - VPS (vps-82b856da)
================================================================================
Fecha de auditoría : 2026-10-05
Dominio principal  : vbstechags.com.mx
Hostname           : vps-82b856da
Verificación       : ss -tulpn | grep LISTEN + Docker inspection

--------------------------------------------------------------------------------
1. SERVICIOS DEL SISTEMA HOST (UBUNTU / PROCESOS NATIVOS)
--------------------------------------------------------------------------------
PUERTO       PROTOCOLO   PROCESO / USUARIO    ALCANCE        DESCRIPCIÓN
--------------------------------------------------------------------------------
22           TCP         sshd (systemd)       0.0.0.0 / [::] Acceso remoto SSH al VPS (Ubuntu)
53           TCP/UDP     systemd-resolve      127.0.0.53/.54 DNS Stub Resolver local
80           TCP         nginx                0.0.0.0 / [::] Proxy Inverso HTTP (Redirect / ACME)
443          TCP         nginx                0.0.0.0 / [::] Proxy Inverso HTTPS (Terminación SSL)
4001         TCP         dotnet (PID 473727)  0.0.0.0 / [::] MedConnect API (.NET nativo en Host)

--------------------------------------------------------------------------------
2. CONTENEDORES DOCKER (PUERTOS EXPUESTOS AL HOST)
--------------------------------------------------------------------------------
PUERTO HOST  PROTOCOLO   CONTENEDOR           PUERTO INT.    SERVICIO / IMAGEN
--------------------------------------------------------------------------------
25           TCP         posteio_corpise      25             Poste.io SMTP (Envío de correo)
110          TCP         posteio_corpise      110            Poste.io POP3 (Correo entrante)
143          TCP         posteio_corpise      143            Poste.io IMAP (Buzón correo)
587          TCP         posteio_corpise      587            Poste.io SMTP Submission (Auth)
993          TCP         posteio_corpise      993            Poste.io IMAPS (IMAP seguro SSL/TLS)
995          TCP         posteio_corpise      995            Poste.io POP3S (POP3 seguro SSL/TLS)
1433         TCP         sqlserver            1433           Microsoft SQL Server 2022
2222         TCP         gitea_server         2222           Gitea SSH (git clone / git push)
3000 (local) TCP         gitea_server         3000           Gitea Web UI (127.0.0.1:3000 -> Nginx)
3306         TCP         mariadb_server       3306           MariaDB Database 11.4
4002         TCP         medconnectweb        80             MedConnect Web Frontend (Docker)
5000         TCP         registry             5000           Docker Registry v2
5432         TCP         gas_delivery_db      5432           PostgreSQL 16 + PostGIS 3.4
5678         TCP         n8n                  5678           n8n Automatización de Workflows
7567         TCP         gas-delivery-frontend 7567          Gas Delivery Frontend Web
7652         TCP         gas-delivery-backend 7652           Gas Delivery Backend (Java)
8080         TCP         registry-ui          80             Docker Registry Web UI
8081         TCP         posteio_corpise      80             Poste.io Webmail / Panel HTTP
8443         TCP         posteio_corpise      443            Poste.io Webmail / Panel HTTPS

--------------------------------------------------------------------------------
3. SERVICIOS DOCKER INTERNOS (SIN EXPOSICIÓN AL HOST)
--------------------------------------------------------------------------------
CONTENEDOR               RED / SOCKET         PROPÓSITO
--------------------------------------------------------------------------------
gitea_db                 gitea-net (5432)     PostgreSQL 15 exclusivo para Gitea
gas-delivery-watchtower  /var/run/docker.sock Actualización automática de imágenes
medconnect-api           bridge interno       Contenedor puente API MedConnect

--------------------------------------------------------------------------------
4. RANGOS LIBRES RECOMENDADOS PARA NUEVOS PROYECTOS
--------------------------------------------------------------------------------
- Aplicaciones Web locales (Nginx upstream) : 3001 a 3999, 8082 a 8089
- Servicios y APIs con puerto expuesto     : 7000 a 7500, 9000 a 9500
================================================================================
