# Limits and known gaps

> Everything Falak does not support yet or has not verified end to end, in one place — deployments, Compose, Octane, databases, providers and source control.

Source: https://falak.sh/docs/reference/limits/

Falak is young. This page lists what is **not supported**, **partly supported**, or **not yet covered by the end-to-end test suite**. Each item links to the page that explains it.

## Not supported yet

| Area | Limit |
|---|---|
| Builds | **On-server builds** (`build_mode: on-server`) fail fast. Builds run on builders only. See [Build modes](/docs/guides/build-modes/). |
| Builds | The built-in registry needs `--tls acme` for builders and servers on other hosts (with `--tls internal` Docker doesn't trust its certificate). See [Install](/docs/operations/install/#the-built-in-image-registry). |
| Compose | Repository files shipped with a release: at most 200 files / 2 MB. `include` and `extends` read files from the repository only. Inline files and templates can't use `include`/`extends`. See [Compose apps from git](/docs/guides/compose-apps/#limits). |
| Compose | A split-out Docker service needs its stack deployed first, and the stack waits for the split-out site: split services out of a stack that is already running. See [Deploy order](/docs/guides/compose-apps/#deploy-order-for-split-out-services). |
| Compose | A stack's `redis`/`valkey` service that becomes a Falak instance starts empty (the container's data is not copied); `rediss://`/`valkeys://` references and other services' healthchecks naming it are not rewritten (Falak warns). Only the official `redis` and `valkey/valkey` images qualify. A service split out as a native (Laravel, Node.js) site only reaches the stack's public services. See [A Falak Redis or Valkey](/docs/guides/compose-apps/#a-falak-redis-or-valkey). |
| Compose | A failed **first** deployment has nothing to roll back to; containers stay as `up` left them. |
| Containers | Workers, daemons and cron from the Processes tab are not run for Docker and Compose sites. |
| Databases | PostgreSQL versions cannot be pinned (distribution packages). |
| Databases | Redis/Valkey: no backups or restore yet. Never reachable on a public address: other servers of the environment need a shared private network (Falak WireGuard, or a DigitalOcean/Lightsail provider private network with the same credential and region), and clients outside the environment can't connect. Network access needs agent v0.7.1; older agents serve native sites on the same server only. See [Redis and Valkey](/docs/databases/redis-and-valkey/#limits). |
| Databases | Engines on **app** and **worker** servers serve that server only: their references resolve for native sites and containers (agent 0.4.5+) on that server alone. Other servers need a dedicated database server. Only app servers can add an engine after creation. See [Variable references](/docs/guides/variable-references/#what-a-service-exposes). |
| Databases | No local-disk backup storage (S3-compatible only). |
| Octane | Falak installs neither Swoole nor RoadRunner. FrankenPHP Octane binds its port on all interfaces. A verified Octane that crashes later is not un-routed automatically. See [Laravel Octane](/docs/deploy/laravel-octane/#limits). |
| Load balancers | Active health checks send the backend IP as `Host`; weights are emulated by repeating backends. |
| Providers | AWS is **Lightsail only** (no EC2). Deleting an organization revokes agents but does not destroy provider machines. |
| Source control | No Bitbucket Server/Data Center. OAuth for only one self-managed GitLab. One GitHub App per Falak organization. No commit statuses and no preview deployments. |
| TLS | DNS-01 needs a Caddy/FrankenPHP build with the Cloudflare module on servers. |
| Identity | 2FA cannot be enforced per organization. |
| Alerting | The webhook SSRF guard does not resolve DNS (rebinding not blocked). |
| Grafana | Dashboards are copied per organization but not filtered by organization inside Grafana. |
| API | Databases, processes, firewall, domains management, alerts, template management and the terminal are UI-only. The server resource lacks the SSH user. |
| Canvas | Sites have no "crashed" canvas status yet. Duplicated environments get sites without servers. |
| Laravel | The Dockerfile Falak generates builds assets before `composer install` (projects importing CSS from `vendor/` need their own Dockerfile). |

## Not yet covered by the end-to-end suite

These have unit and feature tests but have not been exercised on real infrastructure by Falak's automated end-to-end run:

- Docker and Compose runtimes, and Docker builds on a real BuildKit
- Database backups and restores against real S3
- WireGuard private networks
- The web terminal and recipes
- Cloud provider APIs (Hetzner, DigitalOcean, Vultr, Linode, Lightsail)
- Load balancers
- DNS-01 wildcard certificates
- Alert delivery to real Slack, Discord and Telegram
- The Grafana provisioning API
- The Deno runtime at run time
- Access logs on the PHP-FPM + standalone Caddy path and on Caddy older than 2.9
- Release directory permissions on a PHP-FPM server with a standalone Caddy edge

## Verified end to end

For contrast, the simulation's end-to-end run covers: real provisioning on Ubuntu 24.04 (FrankenPHP, PHP 8.4, Node, PostgreSQL, nftables, SSH hardening), multi-server Laravel deployments with migrations on the leader, zero-downtime redeploys, manual and automatic rollbacks, Octane with zero failed requests, a Bun + Hono TypeScript site, APM traces, Insights issues, and deployment events in Loki. See [Try Falak locally](/docs/getting-started/local-simulation/).

On real cloud servers (Ubuntu 24.04 on AWS, Falak 0.2.x), verified by hand: the one-line installer with Let's Encrypt, agent provisioning, the GitHub App against real GitHub, multi-server Laravel with a remote PostgreSQL server, zero-downtime redeploys and rollbacks under load, static sites with SPA fallback, templates with generated sslip.io domains, upgrades from 0.2.0 through 0.2.6 with `falak-ctl update`, "Upgrade all agents", and network logs.
