Changelog

What’s new in Falak

Every release, summarised. Tags and full commit history live on GitHub.

  1. v0.8.0

    Falak

    The product has a new name — Falak (falak.sh) — renamed from its working title with no automatic migration from earlier installs, which simply reinstall.

    • NewRenamed from its working title to Falak (falak.sh): binaries falak, falak-agent, falak-ctl, FALAK_* env vars, /opt/falak, images ghcr.io/othmanhaba/falak-*.
    • NewFalak Cloud, a hosted control plane, at https://cloud.falak.sh.
    • NewOperator-owned extra sites on the control-plane host from /opt/falak/edge, mounted read-only and imported after the generated sites.
    • ImprovedThe installer moves to https://falak.sh/install.sh.
    • UpgradeAPM for Laravel supports Laravel 12 and 13; Laravel 11 is dropped (out of security support).
  2. v0.7.1

    Redis, reachable

    A Redis or Valkey instance is now reachable from containers on its own server and from other servers over a private network, and a Compose stack’s `redis` or `valkey` service can become a managed instance.

    • NewNetwork access for Redis and Valkey: containers over the Docker bridge, other servers of the environment over a private network (WireGuard, then the provider’s), never public.
    • NewA Compose stack’s redis or valkey service can run as a managed Redis/Valkey instance, with its references rewritten automatically.
    • ImprovedThe Redis panel shows who can connect and from where, with the reason when a site can’t.
    • FixedInstances come back up on their Docker or WireGuard address after a reboot instead of racing those services at boot.
  3. v0.7.0

    Redis and Valkey

    Create isolated Redis or Valkey instances next to your PostgreSQL, MySQL and MariaDB databases, connect with `REDIS_*` variables, and tune memory, eviction and persistence from the panel.

    • NewRedis and Valkey as database engines: one instance per service, with its own port, password, memory limit, eviction policy and persistence.
    • NewRotate an instance’s password and switch its persistence mode without losing data.
    • ImprovedA stock Redis the server already runs is left untouched — Falak’s instances can’t read or overwrite it, and it can’t touch theirs.
  4. v0.6.0

    Machine check

    Before provisioning a server, Falak now checks what’s already installed — Docker, nginx, a vendor PostgreSQL — and reuses, completes or stops with a fix instead of overwriting it.

    • NewMachine check runs after the agent enrolls and on every Re-provision; it only reads the machine until provisioning starts.
    • NewNeeds attention status and a Machine check panel on the server page, with Re-check and Provision actions.
    • ImprovedFalak never replaces or removes software it didn’t install.
  5. v0.5.2

    Smoother reinstalls

    Reinstalling a server replaces its agent identity cleanly, the installer runs preflight checks first, and provisioning recovers from a broken apt/PPA or a missing PHP package.

    • NewInstaller preflight: checks the OS, that the panel and agent API are reachable, and the clock, before replacing an earlier install.
    • FixedReinstalling a server replaces its agent identity instead of keeping the deleted server’s.
    • FixedProvisioning recovers from a PPA without a release and falls back to the distribution’s PHP.
    • FixedPrivate IPv4 is read from real interfaces only (the default route’s first).
  6. v0.5.1

    Compose services, in order

    Split a Compose service out into its own site at creation time, and Falak deploys everything in the order it needs.

    • NewSplit a Compose service out into its own site at creation, not just after the fact.
    • ImprovedAutomatic deploy order: split-out sites bootstrap before the stack that depends on them.
    • FixedSplit-out sites inherit their env file’s keys, and database names are freed once they’re no longer used.
  7. v0.5.0

    Compose apps from a repository

    Deploy a Compose stack straight from your repository — several files, profiles, per-service choices — with edge routing for every public service and a built-in image registry.

    • NewDocker Compose apps from a git repository: several files, profiles, include/extends, and Falak-specific adjustments.
    • NewRun a Compose service as its own Falak site or as a Falak database, with its own domains and health checks.
    • NewBuilt-in image registry for production installs, with weekly garbage collection.
    • NewEdge routing — domains, Cloudflare rules, health checks — for every public Compose service.
    • ImprovedContainers can reach database engines on the same server over the Docker bridge.
  8. v0.4.4

    Go, multi-file functions, and cleanup

    Functions can span several files and run on Go, telemetry never leaks secrets in URLs, and a batch of housekeeping fixes landed alongside.

    • NewGo runtime for functions (net/http Handler, Scheduled, static builds) with 10 starters.
    • NewMulti-file functions: a file tree and per-file diffs.
    • ImprovedFunction telemetry never includes secrets in URLs, across every runtime.
    • NewFALAK_REGISTRATION=open|invite|closed restricts sign-up; invite-only requires the invitation link.
    • Fixedfalak-ctl removes old images after a successful update (prune-images command).
  9. v0.4.3

    Lock down and test your functions

    Restrict who can call a function, mount it at a path on another site, send it a test request, and manage it all from the `falak fn` CLI.

    • NewAccess control for functions: API keys and IP allowlists.
    • NewMount a function at a path on another site (edge mounts).
    • NewTest request panel, and observability charts.
    • Newfalak fn CLI: list, pull, deploy, versions, rollback, run, logs, invoke.
  10. v0.4.2

    More languages for Functions

    Write functions in Node.js, Deno or Python, not just Bun, each with 10 ready-to-use starters.

    • NewNode.js 24, Deno 2 and Python (ASGI, uv) runtimes for functions.
    • New10 starters per language; the TypeScript ones are shared across Bun, Node and Deno.
    • ImprovedA shared tracer, entry loader and scheduled runner behind every JavaScript runtime.
  11. v0.4.1

    Functions on a schedule

    Give a function a cron schedule, trigger a run on demand, and see its run history — including the runs it missed.

    • NewSchedules (cron) for functions, with Run now and run history.
    • NewMissed-run detection, and an Insights issue that names the schedule when a run fails.
    • ImprovedA run that hits its timeout exits cleanly and keeps its logs.
  12. v0.4.0

    Cloud Functions

    Write a function in Falak’s own editor and deploy it in seconds — Bun + Hono to start, scaling to zero between requests with built-in observability.

    • NewFunctions: write code in the browser, deploy in seconds, no repository or Dockerfile.
    • NewBun + Hono runtime with scale to zero, versions and rollback.
    • NewBuilt-in observability: request spans, exceptions, outgoing fetches, cold starts, live status.
  13. v0.3.2

    Cache, purge, lock down

    Set cache behavior per domain, purge automatically after each deploy, flip on Under Attack mode, and lock your origin down to Cloudflare or a tunnel.

    • NewCache modes per domain, with an automatic purge after every deploy.
    • NewUnder Attack mode and origin lock-down (Cloudflare-only, or closed behind a tunnel) from the panel.
    • ImprovedLock-down holds against all-port firewall rules and port ranges; a lost tunnel is detected.
  14. v0.3.1

    No open ports, just a tunnel

    Route a server’s traffic through Cloudflare Tunnel instead of opening inbound ports — Falak installs and runs `cloudflared` for you.

    • NewCloudflare Tunnel as a server’s ingress: cloudflared installed and managed by Falak.
    • NewDomains route through the tunnel once it’s up; no open inbound ports needed.
    • ImprovedDNS only moves to the tunnel after cloudflared is confirmed running.
  15. v0.3.0

    Cloudflare, connected

    Connect a Cloudflare token and Falak keeps DNS in sync with your services automatically, issues certificates through the proxy, and sees visitors’ real IPs.

    • NewConnect a Cloudflare API token; Falak finds your managed zones.
    • NewDNS records created, updated and removed automatically for Falak’s own services, with names generated under your zone.
    • NewHTTP-01 certificates behind Cloudflare’s proxy (orange cloud) — no DNS plugin needed on servers.
    • ImprovedReal visitor IPs are trusted only from Cloudflare’s published ranges.
  16. v0.2.8

    Update your fleet, one click

    Update agents across selected servers or the whole fleet from the Servers list, and pick from 14 more one-click templates.

    • NewUpdate one agent, a selection, or every server’s agent from the Servers list.
    • New14 new templates: Ollama + Open WebUI, Langflow, Qdrant, changedetection.io, ntfy, Nextcloud, Paperless-ngx, BookStack, Wiki.js, Forgejo, code-server, Excalidraw, Adminer, Matomo.
    • ImprovedSelecting every updatable server sends one request instead of one per server.
    • ImprovedUpdate buttons show a loading state and ignore double clicks.
  17. v0.2.7

    Ports of their own

    Each site gets its own container port independent of the host port, so several sites can share a server, and the `falak` CLI installs in one line.

    • NewContainer port decoupled from the host port: several sites can use the same port internally on one server.
    • NewOne-line install for the falak CLI on developer machines.
    • ImprovedA changed host port redeploys the site instead of leaving the old port live.
    • FixedDeleting a site stops its containers (and Compose project) instead of leaving them running.
  18. v0.2.6

    Domains that just work

    Every new service gets a working HTTPS address instantly, and custom domains tell you exactly which DNS records to add.

    • NewGenerated domains: <name>.<server-ip>.sslip.io with a Let’s Encrypt certificate and no DNS setup. nip.io or off per organization.
    • NewCustom domains show the A/AAAA records to add and check DNS live until the name points at your server. Cloudflare proxying is detected.
    • NewNetworking → Check DNS & TLS: records, a live check and the certificate actually served.
    • ImprovedCommands in flight survive agent restarts: desired-state commands are redelivered, one-shot steps fail with a clear message.
    • Fixedfalak-ctl detects changed config files through the container’s mount namespace and recreates exactly those services.
  19. v0.2.5

    Network logs and fleet upgrades

    Access logs per deployment, one-click agent upgrades across the fleet, and tighter release permissions.

    • NewNetwork Logs: every request your edge served, per release, with status and path filters.
    • NewUpgrade one agent or all of them from the panel, in batches, verified by checksum, with automatic stop on the first failure.
    • ImprovedLaravel web logs reach Loki with site attribution (multi-line stack traces merged).
    • ImprovedBuilders send run ids and heartbeats, so a restarted builder never leaves a deploy hanging.
    • FixedRelease directories are closed to other local users (0750 plus an ACL for the web server).
  20. v0.2.4

    A calmer, faster canvas

    Stacked floating panels with motion, deployment cards with logs, and groups, volumes and references on the canvas.

    • NewCanvas groups: frame related services, collapse them, move them as one.
    • NewVolume strips under services with persistent storage, and dashed edges for variable references and depends_on.
    • NewDeployment cards with the live release, failures and history; a stacked logs panel with build, deploy and network logs.
    • ImprovedProjects dashboard with starred projects, previews and health per environment.
  21. v0.2.3

    Hardened on real servers

    Fixes from deploying real apps on AWS: static sites, remote databases, multi-server health checks and more.

    • NewStatic sites get a 404 page or an SPA fallback instead of bare 404s, served from the release root.
    • NewRemote database access over the private network.
    • Improvedpnpm and yarn builds, build-time variables and custom build commands.
    • FixedMulti-server health checks and cloud public IP detection.
  22. v0.2.2

    Fast panel under load

    The panel now runs in FrankenPHP worker mode and agents long-poll their own service, so pages stay fast however many servers you add.

    • ImprovedPanel pages answer in 2.7–23 ms (median TTFB) with 50 agents connected (previously they queued for seconds behind long-polls).
    • NewA separate agent-api service for agents, installer and builders, with its own thread pool.
    • Newfalak-ctl status and doctor show PHP thread usage and flag saturated pools.
    • FixedGitHub App manifest conversion error handling.
  23. v0.2.1

    One-click GitHub

    Connect GitHub in one click with a private GitHub App: read-only access, no deploy keys, short-lived tokens per build.

    • NewGitHub App via the manifest flow, registered on your account or organization.
    • NewOne app-level webhook for push-to-deploy; installation tokens minted per build and never stored.
  24. v0.2.0

    Compose, templates and Octane

    Docker Compose deploys, a catalog of 18 one-click apps, Octane routing and smarter multi-server deploys.

    • NewDocker Compose sites from your repo or stored in Falak with history; images pinned by digest for exact rollbacks.
    • NewTemplates: n8n, Plausible, Umami, Ghost, WordPress, MinIO, Metabase and more, plus your own custom templates.
    • NewLaravel Octane (FrankenPHP, Swoole, RoadRunner) with stable per-site ports and zero failed requests on redeploy.
    • ImprovedDeploys wait for servers that are still provisioning instead of failing.
    • NewRuntime download mirrors for FrankenPHP, Node, Bun and Deno.
  25. v0.1.0

    First release

    The production installer, the Railway-style UI and everything underneath: servers, sites, deploys, databases and observability.

    • NewOne-command production install (Docker Compose, Let’s Encrypt) and falak-ctl for status, updates with rollback, backup and restore.
    • NewProject canvas with environments, services, a create picker, service panels and deploy views.
    • NewInfrastructure: server fleet, add-server flow, metrics, processes, firewall, network, terminal, SSH keys, recipes.
    • NewObservability: issues, traces, logs, heartbeats, alerts and a notification center.

Your servers are waiting.

One command installs Falak on a fresh Ubuntu or Debian host. Connect servers, push code, watch it go live.

curl -fsSL https://falak.sh/install.sh | sudo bash -s -- --domain falak.example.com --email you@example.com