| Port |
Protocol |
Exposed |
Used by |
| 80 |
TCP |
yes |
HTTP → HTTPS, ACME HTTP-01 |
| 443 |
TCP + UDP (HTTP/3) |
yes |
Panel, API, webhooks, installer, agent API (agents. host, mTLS), Grafana, OTLP ingest (/otlp) |
Other ports stay inside the Compose network (Postgres 5432, Valkey 6379, Reverb 8080, Grafana 3000, Loki 3100, Tempo 3200, gateway 9090). Change the public ports only for testing (--http-port/--https-port with --tls internal).
| Path |
Contents |
/opt/falak/.env |
Settings and secrets (mode 600) |
/opt/falak/custom.env |
Optional extra settings |
/opt/falak/deploy/ |
compose.yml, falak-ctl, support files (previous version kept as deploy.prev) |
/opt/falak/observability/ |
Loki, Tempo, gateway and Grafana configuration |
/opt/falak/backups/ |
falak-ctl backup output (mode 700) |
/usr/local/bin/falak-ctl |
The operations tool |
/etc/cron.d/falak-backup |
Your backup schedule (if you create it) |
pg-data, valkey-data, app-storage (artifacts, app files), falak-ca (Fleet CA certificate), edge-pki, caddy-data (ACME certificates), caddy-config, builder-data, builder-cache, and with observability loki-data, tempo-data, vm-data, grafana-data.
| Port |
Listens on |
Opened by default |
Purpose |
| 22 |
all |
yes (always accepted) |
SSH |
| 80, 443 |
all |
app, web, lb servers |
Caddy / FrankenPHP |
| 2019 |
127.0.0.1 |
no |
Caddy admin API (agent only) |
| 4318 |
127.0.0.1 |
no |
OTLP/HTTP receiver of the agent |
| 3000–3999 |
127.0.0.1 |
no |
App ports of Node, Bun, Deno and Docker sites (blue/green: +1000) |
| 8000–8999 |
127.0.0.1 (FrankenPHP Octane: all interfaces) |
no |
Laravel Octane ports; auxiliary port = +10000 |
| 5432 / 3306 |
localhost; all interfaces on db servers with remote users |
no |
PostgreSQL / MySQL / MariaDB |
| 51820/udp |
all |
on private network members |
WireGuard (default) |
Compose public services are published on 127.0.0.1:<allocated port>.
| Path |
Contents |
/usr/local/bin/falak-agent |
Agent binary (.prev: previous version after an upgrade) |
/etc/systemd/system/falak-agent.service |
Agent unit |
/etc/falak/ |
agent.key, agent.crt, ca.crt, agent.json, telemetry.json, certs/, optional agent.env |
/var/lib/falak/ |
Process and cron state, OTLP disk buffer |
/run/falak/otlp.sock |
OTLP socket for apps |
/var/log/falak/ |
Supervised program logs |
/var/log/falak/access/<site>.log |
Caddy access logs (JSON, 10 MB × 3) |
/srv/falak/sites/<site>/releases/<RELEASE_ID>/ |
Releases |
/srv/falak/sites/<site>/shared/ |
.env, storage/, shared paths |
/srv/falak/sites/<site>/current |
Symlink to the live release |
/home/falak |
The falak user’s home |
/etc/postgresql/<version>/main/conf.d/90-falak-network.conf |
Network listening for db servers |