export declare function getFreePort(basePort: number, host?: string, timeoutMs?: number): Promise; /** * Loopback port handed out by the OS for a listener that must not collide with ports the * embedding process plans for other services. * * Probing next to the ports this runtime already owns is not safe: a host that allocates * `gateway + 10`/`gateway + 11` (the full integration matrix does) has already reserved * the neighbour of our own `api` port for another runtime, and binding it steals that * runtime's service. */ export declare function getEphemeralLoopbackPort(): Promise; /** * The ingress port this deployment should keep using. * * Remote tunnels forward to a port the operator typed into a provider console, so an * OS-assigned port would invalidate that copy on every restart. The port is remembered in * the runtime state directory; if something else took it meanwhile, a new one is chosen and * persisted — the caller reports the change so the stale console value can be corrected. */ export declare function resolveStableLoopbackPort(stateFile: string): Promise<{ port: number; changed: boolean; }>; export declare function readPortFile(stateFile: string): number | undefined; /** * Allocates a port for child services that bind wildcard addresses. * CSS may bind `::` while the API binds `0.0.0.0`, so probing only localhost * can miss an occupied port on the other address family. */ /** * Takes exactly this port or fails. * * A port that a tunnel console forwards to cannot be substituted: `getFreePortForWildcard` * scans upward, which would leave the runtime listening somewhere the tunnel never reaches. */ export declare function requireFreePortForWildcard(port: number, timeoutMs?: number): Promise; export declare function getFreePortForWildcard(basePort: number, timeoutMs?: number): Promise;