STREAMIOV SERVER FIREWALL POLICY

PUBLIC:
- TCP 443: Streamiov public HTTPS router
- TCP 80: optional HTTP -> HTTPS redirect
- TCP 22: administration only when explicitly enabled

INTERNAL ONLY:
- TCP 8080: Streamiov backend
- TCP 8090: Streamiov gateway

NEVER PUBLIC:
- 8080
- 8090
- database ports
- internal administration ports

RULE:
Only the public router is exposed to the Internet.

BACKEND:
127.0.0.1:8080

GATEWAY:
127.0.0.1:8090

PUBLIC ROUTER:
0.0.0.0:8091 during infrastructure testing.
Production HTTPS entry must use the assigned public server IP and HTTPS.

NO THIRD-PARTY PROXY.
NO THIRD-PARTY APPLICATION GATEWAY.
