PostgreSQL, MySQL, MariaDB
Create databases and users on your database servers from the canvas.
Features
Falak covers the whole path from a bare Linux box to an observed, production app: provisioning, builds, releases, domains, databases, processes and telemetry.
Project canvas
Railway’s model, on your hardware: a project is a canvas of services per environment. Panels slide over the canvas and stack, so context never gets lost.
${{ service.KEY }} resolve at deploy time; unresolved references fail the deploy with a clear errorDeploys
Falak’s deploy pipeline is the same for one server or ten: BUILD once → FETCH → PREPARE → MIGRATE on the leader → ACTIVATE everywhere at once → RESTART → HEALTH CHECK. Any failure rolls every server back and alerts you.
releases/<id> with shared .env and storage, a current symlink flip, and retention you chooseRuntimes
Pick a framework preset and a runtime per service. PHP and Node apps run natively (no container overhead); Docker images, Dockerfiles and Compose stacks run as containers.
Templates
Templates are Compose stacks with inputs, versioned with Falak and validated in CI: pinned image tags, working health checks and a policy check.
Domains and TLS
Each public endpoint gets a domain when it is created. Generated names work immediately with a Let’s Encrypt certificate; custom domains come with the exact records to add and a live check.
minio-files.63-182-218-247.sslip.io (sslip.io, nip.io or off per organization)Databases
Create databases and users on your database servers from the canvas.
Scheduled backups to S3, Cloudflare R2, Backblaze B2 or local storage, with history and one-click restore.
Every database exposes DATABASE_URL, DB_HOST, DB_PORT and friends for ${{ … }} references.
Apps reach databases over the private network; revealing a password is recorded in the audit log.
Processes
Declared per site, supervised by the agent’s built-in supervisor, restarted on every release.
Cron runs through a heartbeat wrapper, so Insights shows expected vs actual runs and flags missed ones.
Any long-running command, with its own environment, started once the first release is live.
FrankenPHP worker mode, Swoole or RoadRunner on a stable per-server port; routing switches only once Octane answers.
Observability
The agent ships host metrics, logs and container logs as OTLP, and relays your apps’ telemetry to Loki, Tempo and VictoriaMetrics or Mimir. Only exceptions and threshold breaches go to the control plane, as Insights.
falak/apm-laravel: requests with timelines, queries, jobs and attempts, outgoing HTTP, mail, notifications, cache, commands, scheduled tasks, exceptions and logs@falak/apm-node: an OpenTelemetry preset for Node, Bun, Deno and TypeScript appsServers
falak-agent is a single static Go binary (about 10 MB on disk, about 17 MB of memory). It dials out to your Falak host, so servers need no inbound SSH, and it replaces a handful of tools you would otherwise install and babysit.
Security
Your Falak host runs its own Fleet CA. Agents enroll with a one-time token and pin that CA.
Environment variables, provider credentials and keys use encrypted columns and are never logged.
A private GitHub App with contents and metadata read-only; installation tokens are minted per build and never stored.
nftables rules applied by the agent, SSH hardening at provisioning, a default-drop policy.
Privileged containers, host networking, host PID, device and Docker socket mounts are rejected unless you allow them.
Release directories are 0750 with an ACL for the web server only; other local users cannot read your config cache.
Organizations, teams, roles and permissions, two-factor authentication and an audit log.
Browser terminal sessions go through the agent (no inbound SSH) and can be recorded.
Operations
Preflight checks, Docker, a generated .env, Let’s Encrypt, and the first admin, on Ubuntu or Debian, amd64 or arm64.
falak-ctl update backs up first, then restores the previous version automatically if anything fails.
Database, storage, Fleet CA and .env in one archive, optionally encrypted and copied to S3.
Checks DNS, certificates, ports, disk, containers, the agent API, PHP thread pools and backups.
No pull-request preview environments, no autoscaling, and no global edge network. Provider APIs cover Hetzner, DigitalOcean, Vultr, Linode and AWS Lightsail (not EC2). The full list of known limits lives in the repository’s integration notes.
One command installs Falak on a fresh Ubuntu or Debian host. Connect servers, push code, watch it go live.
curl -fsSL https://falak.sh/install.sh | sudo bash -s -- --domain falak.example.com --email you@example.com