Sockets, bind addresses, and reachability

A listener answers only on the addresses it bound, and only callers who can route to them reach it.

A TCP server binds an address and a port. 127.0.0.1:8080 accepts connections only from the same host. 10.0.4.12:8080 accepts connections that arrive on that interface. 0.0.0.0:8080 accepts on every IPv4 address the host has, including the public one. ss -ltn (or ss -ltnp with privileges) shows exactly what is listening where.

Reading the failure tells you which layer to look at:

  • Connection refused. The packet arrived, but nothing listens on that address and port. Look at the bind address, the port, and whether the process is running.
  • Timeout. Nothing answered. Suspect routing, a firewall silently dropping packets, or a host that is down.
  • 502 from a proxy. The proxy is alive and its upstream dial failed. Read the proxy's log for the target it tried. It is often a stale port or address after a migration.

Two operational rules:

  1. Bind to the narrowest interface that serves the intended peers. Binding to all addresses to make a proxy work also exposes the service on the public uplink. A firewall may catch it, or may not after the next change.
  2. Verify from the caller's network position. A health check on loopback proves the process works. It says nothing about the proxy, the LAN, or the customer path.

Every network call in production code needs a timeout. A call without one can hang a worker forever when the peer stops answering. Timeouts are the first stability pattern for a reason.