Limits and known gaps
Falak is young. This page lists what is not supported, partly supported, or not yet covered by the end-to-end test suite. Each item links to the page that explains it.
Not supported yet
Section titled “Not supported yet”| Area | Limit |
|---|---|
| Builds | On-server builds (build_mode: on-server) fail fast. Builds run on builders only. See Build modes. |
| Builds | The built-in registry needs --tls acme for builders and servers on other hosts (with --tls internal Docker doesn’t trust its certificate). See Install. |
| Compose | Repository files shipped with a release: at most 200 files / 2 MB. include and extends read files from the repository only. Inline files and templates can’t use include/extends. See Compose apps from git. |
| Compose | A split-out Docker service needs its stack deployed first, and the stack waits for the split-out site: split services out of a stack that is already running. See Deploy order. |
| Compose | A stack’s redis/valkey service that becomes a Falak instance starts empty (the container’s data is not copied); rediss:///valkeys:// references and other services’ healthchecks naming it are not rewritten (Falak warns). Only the official redis and valkey/valkey images qualify. A service split out as a native (Laravel, Node.js) site only reaches the stack’s public services. See A Falak Redis or Valkey. |
| Compose | A failed first deployment has nothing to roll back to; containers stay as up left them. |
| Containers | Workers, daemons and cron from the Processes tab are not run for Docker and Compose sites. |
| Databases | PostgreSQL versions cannot be pinned (distribution packages). |
| Databases | Redis/Valkey: no backups or restore yet. Never reachable on a public address: other servers of the environment need a shared private network (Falak WireGuard, or a DigitalOcean/Lightsail provider private network with the same credential and region), and clients outside the environment can’t connect. Network access needs agent v0.7.1; older agents serve native sites on the same server only. See Redis and Valkey. |
| Databases | Engines on app and worker servers serve that server only: their references resolve for native sites and containers (agent 0.4.5+) on that server alone. Other servers need a dedicated database server. Only app servers can add an engine after creation. See Variable references. |
| Databases | No local-disk backup storage (S3-compatible only). |
| Octane | Falak installs neither Swoole nor RoadRunner. FrankenPHP Octane binds its port on all interfaces. A verified Octane that crashes later is not un-routed automatically. See Laravel Octane. |
| Load balancers | Active health checks send the backend IP as Host; weights are emulated by repeating backends. |
| Providers | AWS is Lightsail only (no EC2). Deleting an organization revokes agents but does not destroy provider machines. |
| Source control | No Bitbucket Server/Data Center. OAuth for only one self-managed GitLab. One GitHub App per Falak organization. No commit statuses and no preview deployments. |
| TLS | DNS-01 needs a Caddy/FrankenPHP build with the Cloudflare module on servers. |
| Identity | 2FA cannot be enforced per organization. |
| Alerting | The webhook SSRF guard does not resolve DNS (rebinding not blocked). |
| Grafana | Dashboards are copied per organization but not filtered by organization inside Grafana. |
| API | Databases, processes, firewall, domains management, alerts, template management and the terminal are UI-only. The server resource lacks the SSH user. |
| Canvas | Sites have no “crashed” canvas status yet. Duplicated environments get sites without servers. |
| Laravel | The Dockerfile Falak generates builds assets before composer install (projects importing CSS from vendor/ need their own Dockerfile). |
Not yet covered by the end-to-end suite
Section titled “Not yet covered by the end-to-end suite”These have unit and feature tests but have not been exercised on real infrastructure by Falak’s automated end-to-end run:
- Docker and Compose runtimes, and Docker builds on a real BuildKit
- Database backups and restores against real S3
- WireGuard private networks
- The web terminal and recipes
- Cloud provider APIs (Hetzner, DigitalOcean, Vultr, Linode, Lightsail)
- Load balancers
- DNS-01 wildcard certificates
- Alert delivery to real Slack, Discord and Telegram
- The Grafana provisioning API
- The Deno runtime at run time
- Access logs on the PHP-FPM + standalone Caddy path and on Caddy older than 2.9
- Release directory permissions on a PHP-FPM server with a standalone Caddy edge
Verified end to end
Section titled “Verified end to end”For contrast, the simulation’s end-to-end run covers: real provisioning on Ubuntu 24.04 (FrankenPHP, PHP 8.4, Node, PostgreSQL, nftables, SSH hardening), multi-server Laravel deployments with migrations on the leader, zero-downtime redeploys, manual and automatic rollbacks, Octane with zero failed requests, a Bun + Hono TypeScript site, APM traces, Insights issues, and deployment events in Loki. See Try Falak locally.
On real cloud servers (Ubuntu 24.04 on AWS, Falak 0.2.x), verified by hand: the one-line installer with Let’s Encrypt, agent provisioning, the GitHub App against real GitHub, multi-server Laravel with a remote PostgreSQL server, zero-downtime redeploys and rollbacks under load, static sites with SPA fallback, templates with generated sslip.io domains, upgrades from 0.2.0 through 0.2.6 with falak-ctl update, “Upgrade all agents”, and network logs.