Applications Networking
Choose between the Applications bridge and a LAN attachment for an application in FreeCORE 15.1.
FreeCORE 15.1 reaches an application in one of two ways, chosen per application under Network in the install and Edit forms of a catalog application. Applications bridge is the default. Attach to LAN is available from 15.1-RC6. Imported and converted applications use the Applications bridge.
| Applications bridge | Attach to LAN | |
|---|---|---|
| Address | An address on the managed bridge, inside the Managed Container Subnet (10.88.0.0/16 by default). |
A static IPv4 address you choose on the network of a host interface. |
| Reached through | The host's addresses and the host ports you publish. | Its own address. |
| Ports | Only the published ports, each from a host port you choose. | Every port the application listens on. Nothing is published through the host. |
| Broadcast and multicast | Do not reach the application. | Work on the attached network. |
| Outbound traffic | Leaves through the host's address. | Leaves through the gateway you set. |
A LAN-attached application is exposed like a virtual machine's network interface: every listener it opens is reachable from that network. Use the Applications bridge unless the application needs one of the following.
| Need | Examples |
|---|---|
| Discovery by broadcast or multicast | Plex's GDM discovery, Jellyfin's client discovery, DLNA and mDNS announcements. |
| An address of its own that other devices use | A DNS server for the network, such as AdGuard Home. |
| Ports the catalog entry does not declare | Listeners the application opens beyond the ports the entry lists, which the bridge cannot publish. |
Attach an Application to the LAN
In the install or Edit form, set Network to Attach to LAN and fill in:
- Interface: the host network interface whose network the application joins.
- IPv4 address: a static address with its prefix, for example
192.0.2.201/24. Choose an address outside the DHCP pool of that network: FreeCORE cannot see the pool, and keeping the two apart is the administrator's part. - Gateway: the IPv4 gateway of that network. It must lie inside the attached network and differ from the address.
- Also reach the Applications bridge (optional): see below.
The ports section then reads Ports and lists the container ports without host ports. The attachment is IPv4 only, and its address is static; there is no DHCP option.
The address is refused when it lies inside the managed container subnet, when another application already attaches it, when it is configured on the host, or when a defined jail uses it. The refusal appears on the field it concerns.
After installation, the application's Network detail on the Installed tab reads LAN with its address and interface. Open Portal opens the application's own address at its container port, and the startup check reaches the application there as well.
The Bridge on the Interface
The application joins the bridge that carries the chosen interface, the same
bridge that iocage jails and virtual machines attached to that interface use.
When no bridge carries the interface yet, FreeCORE puts it into bridge0, or
into bridge1 for a second interface, and jails started later share it. A
start that finds neither free, or finds the interface in a bridge with another
host interface, is refused, so two networks are never bridged together.
The bridge is checked at every start of the application. If the interface no longer exists, the application is not started at boot, and starting it reports an error that names the interface.
Reach the Applications Bridge from the LAN
Also reach the Applications bridge gives a LAN-attached application a second address on the Applications bridge, assigned automatically and shown in its Network detail beside the LAN address. Its default route stays on the LAN. Use it for an application that answers on the LAN and talks to applications on the bridge, such as a reverse proxy that forwards to them at their bridge addresses.
Every application on the Applications bridge keeps a fixed bridge address, shown in its Network detail, so such routes stay valid across restarts, updates, reboots and a pool export and import. Applications installed before 15.1-RC6 receive one with their next Update or Edit. The managed container subnet cannot be changed while installed applications keep fixed bridge addresses; the refusal names them.
Host Networking
Host networking is never granted to an application. A compose file that asks
for network_mode: host is refused for conversion and ignored when it fills
the import form; attach the application to the LAN instead.
Export for Linux does not carry a LAN attachment: the bundle publishes the
application's ports.
See Installing and Managing Applications and the Applications Screen.