A port is a numbered door into the machine. The address beside it decides who can knock: 0.0.0.0 is the whole internet, 127.0.0.1 is the box itself.
A port is a numbered door into your machine, and something has to stand behind it or nothing answers. The part nobody explains is the address next to the port: one value means "anyone on the internet", the other means "only me". Same app, same port, different exposure.
ss -tulpn is the guest list: every row is one program holding one door open. Ignore Netid and State, they are plumbing. The Local Address column is the only one that decides who gets to knock. 0.0.0.0 means every network this box is on, including the public internet. 127.0.0.1 means the box talking to itself and nobody else, no firewall required.
This is the single most common way a self-hosted database ends up on the public internet. Nobody decided to expose it. A config file said 0.0.0.0 , the port was open, and that was enough. Your app reaching a database on 127.0.0.1 works exactly the same and nobody outside can touch it.
And only one program can hold a given port at a time. That is all "address already in use" means: something already answered that door. Usually it is the copy of your app you forgot was still running, which is exactly what block 02 taught you to find.
You have been installing and running software this whole time. Next: where all of it actually came from.