Skip to content

Limits and known gaps

Falak is young. This page lists what is not supported, partly supported, or not yet covered by the end-to-end test suite. Each item links to the page that explains it.

Area Limit
Builds On-server builds (build_mode: on-server) fail fast. Builds run on builders only. See Build modes.
Builds The built-in registry needs --tls acme for builders and servers on other hosts (with --tls internal Docker doesn’t trust its certificate). See Install.
Compose Repository files shipped with a release: at most 200 files / 2 MB. include and extends read files from the repository only. Inline files and templates can’t use include/extends. See Compose apps from git.
Compose A split-out Docker service needs its stack deployed first, and the stack waits for the split-out site: split services out of a stack that is already running. See Deploy order.
Compose A stack’s redis/valkey service that becomes a Falak instance starts empty (the container’s data is not copied); rediss:///valkeys:// references and other services’ healthchecks naming it are not rewritten (Falak warns). Only the official redis and valkey/valkey images qualify. A service split out as a native (Laravel, Node.js) site only reaches the stack’s public services. See A Falak Redis or Valkey.
Compose A failed first deployment has nothing to roll back to; containers stay as up left them.
Containers Workers, daemons and cron from the Processes tab are not run for Docker and Compose sites.
Databases PostgreSQL versions cannot be pinned (distribution packages).
Databases Redis/Valkey: no backups or restore yet. Never reachable on a public address: other servers of the environment need a shared private network (Falak WireGuard, or a DigitalOcean/Lightsail provider private network with the same credential and region), and clients outside the environment can’t connect. Network access needs agent v0.7.1; older agents serve native sites on the same server only. See Redis and Valkey.
Databases Engines on app and worker servers serve that server only: their references resolve for native sites and containers (agent 0.4.5+) on that server alone. Other servers need a dedicated database server. Only app servers can add an engine after creation. See Variable references.
Databases No local-disk backup storage (S3-compatible only).
Octane Falak installs neither Swoole nor RoadRunner. FrankenPHP Octane binds its port on all interfaces. A verified Octane that crashes later is not un-routed automatically. See Laravel Octane.
Load balancers Active health checks send the backend IP as Host; weights are emulated by repeating backends.
Providers AWS is Lightsail only (no EC2). Deleting an organization revokes agents but does not destroy provider machines.
Source control No Bitbucket Server/Data Center. OAuth for only one self-managed GitLab. One GitHub App per Falak organization. No commit statuses and no preview deployments.
TLS DNS-01 needs a Caddy/FrankenPHP build with the Cloudflare module on servers.
Identity 2FA cannot be enforced per organization.
Alerting The webhook SSRF guard does not resolve DNS (rebinding not blocked).
Grafana Dashboards are copied per organization but not filtered by organization inside Grafana.
API Databases, processes, firewall, domains management, alerts, template management and the terminal are UI-only. The server resource lacks the SSH user.
Canvas Sites have no “crashed” canvas status yet. Duplicated environments get sites without servers.
Laravel The Dockerfile Falak generates builds assets before composer install (projects importing CSS from vendor/ need their own Dockerfile).

These have unit and feature tests but have not been exercised on real infrastructure by Falak’s automated end-to-end run:

  • Docker and Compose runtimes, and Docker builds on a real BuildKit
  • Database backups and restores against real S3
  • WireGuard private networks
  • The web terminal and recipes
  • Cloud provider APIs (Hetzner, DigitalOcean, Vultr, Linode, Lightsail)
  • Load balancers
  • DNS-01 wildcard certificates
  • Alert delivery to real Slack, Discord and Telegram
  • The Grafana provisioning API
  • The Deno runtime at run time
  • Access logs on the PHP-FPM + standalone Caddy path and on Caddy older than 2.9
  • Release directory permissions on a PHP-FPM server with a standalone Caddy edge

For contrast, the simulation’s end-to-end run covers: real provisioning on Ubuntu 24.04 (FrankenPHP, PHP 8.4, Node, PostgreSQL, nftables, SSH hardening), multi-server Laravel deployments with migrations on the leader, zero-downtime redeploys, manual and automatic rollbacks, Octane with zero failed requests, a Bun + Hono TypeScript site, APM traces, Insights issues, and deployment events in Loki. See Try Falak locally.

On real cloud servers (Ubuntu 24.04 on AWS, Falak 0.2.x), verified by hand: the one-line installer with Let’s Encrypt, agent provisioning, the GitHub App against real GitHub, multi-server Laravel with a remote PostgreSQL server, zero-downtime redeploys and rollbacks under load, static sites with SPA fallback, templates with generated sslip.io domains, upgrades from 0.2.0 through 0.2.6 with falak-ctl update, “Upgrade all agents”, and network logs.