nTSA network architecture
The installation routine creates for the nTSA service a own container bridge network, called network_ntsa. A bridge network is limited to a single host running Docker Engine.
All nTSA containers are assinged to the network_ntsa.
Only the nTSA Portal, InfluxDB and Kapacitor containers, are acceble outside of the container network on the published ports. User and agent are accessing nTSA over the hosts network interface on a single ip address.
The nTSA Portal runs an Nginx as reverse proxy, which is passing request to the Grafana, Chronograf and Documentation containers. This configuration allows the nTSA to have a single entry point for all web interfaces.