Features

Everything you need to ship, on servers you own

Falak covers the whole path from a bare Linux box to an observed, production app: provisioning, builds, releases, domains, databases, processes and telemetry.

Project canvas

Projects, environments and services on one canvas

Railway’s model, on your hardware: a project is a canvas of services per environment. Panels slide over the canvas and stack, so context never gets lost.

  • Environments such as production and staging, created empty or duplicated from another (configs and variables, not servers)
  • Variable references ${{ service.KEY }} resolve at deploy time; unresolved references fail the deploy with a clear error
  • Groups you can collapse, compose stacks as groups of their services, volume strips for persistent storage
  • Deep links restore the exact panel and tab; ⌘K and keyboard shortcuts everywhere

Deploys

Build once, release everywhere, roll back instantly

Falak’s deploy pipeline is the same for one server or ten: BUILD once → FETCH → PREPARE → MIGRATE on the leader → ACTIVATE everywhere at once → RESTART → HEALTH CHECK. Any failure rolls every server back and alerts you.

  • Push-to-deploy through a one-click GitHub App, GitLab, Bitbucket or any git server; a deploy hook URL for CI
  • Releases in releases/<id> with shared .env and storage, a current symlink flip, and retention you choose
  • Builds run on a builder (the Falak host by default, or a dedicated server); managed servers never build
  • Deploy scripts with macros, variables such as FALAK_COMMIT and FALAK_RELEASE_DIR, and live logs per server and phase
  • Deploys wait for servers that are still provisioning instead of failing

Runtimes

Native where it matters, containers when you want them

Pick a framework preset and a runtime per service. PHP and Node apps run natively (no container overhead); Docker images, Dockerfiles and Compose stacks run as containers.

Templates

A curated catalog of 18 self-hostable apps

Templates are Compose stacks with inputs, versioned with Falak and validated in CI: pinned image tags, working health checks and a policy check.

  • Secrets generated once and kept stable across redeploys; inputs become encrypted service variables
  • A domain for each public service: generated sslip.io, your test domain, or your own with DNS instructions
  • A warning when a stateful template is deployed to more than one server
  • Custom templates per organization: import YAML or save a running compose site as a template
Browse all 32 templates: Templates

Domains and TLS

Domains that work before you touch DNS

Each public endpoint gets a domain when it is created. Generated names work immediately with a Let’s Encrypt certificate; custom domains come with the exact records to add and a live check.

  • Generated names like minio-files.63-182-218-247.sslip.io (sslip.io, nip.io or off per organization)
  • A/AAAA records per server for DNS round-robin, or a single load balancer record
  • Cloudflare proxying detected: keep “DNS only” until the certificate is issued
  • Redirects, basic auth and security rules, custom certificates and DNS-01 wildcard certificates

Databases

Databases next to your app, with backups

PostgreSQL, MySQL, MariaDB

Create databases and users on your database servers from the canvas.

Backups and restore

Scheduled backups to S3, Cloudflare R2, Backblaze B2 or local storage, with history and one-click restore.

Connection variables

Every database exposes DATABASE_URL, DB_HOST, DB_PORT and friends for ${{ … }} references.

Private network access

Apps reach databases over the private network; revealing a password is recorded in the audit log.

Processes

Workers, schedulers and daemons, supervised

Queue workers and Horizon

Declared per site, supervised by the agent’s built-in supervisor, restarted on every release.

Scheduler with heartbeats

Cron runs through a heartbeat wrapper, so Insights shows expected vs actual runs and flags missed ones.

Daemons

Any long-running command, with its own environment, started once the first release is live.

Octane

FrankenPHP worker mode, Swoole or RoadRunner on a stable per-server port; routing switches only once Octane answers.

Observability

Logs, metrics, traces and APM on your own LGTM stack

The agent ships host metrics, logs and container logs as OTLP, and relays your apps’ telemetry to Loki, Tempo and VictoriaMetrics or Mimir. Only exceptions and threshold breaches go to the control plane, as Insights.

  • falak/apm-laravel: requests with timelines, queries, jobs and attempts, outgoing HTTP, mail, notifications, cache, commands, scheduled tasks, exceptions and logs
  • @falak/apm-node: an OpenTelemetry preset for Node, Bun, Deno and TypeScript apps
  • Issues grouped by fingerprint with affected users; route, job and query thresholds; heartbeats for scheduled tasks
  • Grafana dashboards per organization (servers, Laravel sites, Node apps, deployments, containers, queues), with every deploy as an annotation
  • Network Logs: the requests your edge served, per release; alerts to email, Slack, Discord, Telegram or webhooks

Servers

One small agent per server

falak-agent is a single static Go binary (about 10 MB on disk, about 17 MB of memory). It dials out to your Falak host, so servers need no inbound SSH, and it replaces a handful of tools you would otherwise install and babysit.

  • Provisions servers declaratively for their role: app, web, database, cache, worker, load balancer or builder
  • Built-in process supervisor, cron with heartbeats, /proc metrics and log tailing (no supervisord, node_exporter or promtail)
  • Every command is idempotent; desired-state commands survive agent restarts and are redelivered
  • Create servers on Hetzner, DigitalOcean, Vultr, Linode or AWS Lightsail, or run the one-liner on any Ubuntu box
  • Fleet upgrades from the panel: SHA-256 verified, previous binary kept, rolled out in batches

Security

Secure defaults, not a checklist

mTLS to every agent

Your Falak host runs its own Fleet CA. Agents enroll with a one-time token and pin that CA.

Secrets encrypted at rest

Environment variables, provider credentials and keys use encrypted columns and are never logged.

Read-only GitHub access

A private GitHub App with contents and metadata read-only; installation tokens are minted per build and never stored.

Firewall by default

nftables rules applied by the agent, SSH hardening at provisioning, a default-drop policy.

Compose policy

Privileged containers, host networking, host PID, device and Docker socket mounts are rejected unless you allow them.

Closed releases

Release directories are 0750 with an ACL for the web server only; other local users cannot read your config cache.

Teams and roles

Organizations, teams, roles and permissions, two-factor authentication and an audit log.

Recorded terminal

Browser terminal sessions go through the agent (no inbound SSH) and can be recorded.

Operations

Easy to install, easy to keep running

One-command install

Preflight checks, Docker, a generated .env, Let’s Encrypt, and the first admin, on Ubuntu or Debian, amd64 or arm64.

Updates with rollback

falak-ctl update backs up first, then restores the previous version automatically if anything fails.

Backups of Falak itself

Database, storage, Fleet CA and .env in one archive, optionally encrypted and copied to S3.

falak-ctl doctor

Checks DNS, certificates, ports, disk, containers, the agent API, PHP thread pools and backups.

What Falak doesn’t do (yet)

No pull-request preview environments, no autoscaling, and no global edge network. Provider APIs cover Hetzner, DigitalOcean, Vultr, Linode and AWS Lightsail (not EC2). The full list of known limits lives in the repository’s integration notes.

Your servers are waiting.

One command installs Falak on a fresh Ubuntu or Debian host. Connect servers, push code, watch it go live.

curl -fsSL https://falak.sh/install.sh | sudo bash -s -- --domain falak.example.com --email you@example.com