Skip to content

Fledge v0.1.0 — Pre-release ​

Fledge is a self-hosted panel for managing game servers across Linux Docker nodes. This pre-release brings the web panel, API, node agent, templates, console, file operations, and backup workflows into one evaluation build.

Included ​

  • Multi-node registration, one-time Linux agent enrollment, node heartbeats, capacity-aware placement, and durable operations.
  • Server lifecycle controls, template-based configuration, collaborator permissions, audit history, and a live console with resource samples.
  • SFTP with short-lived per-server credentials and server-directory path confinement. Nodes must explicitly enable the SFTP listener and firewall its port.
  • Browser file streaming through object storage up to 1 GiB, with a 1 MiB text editor limit.
  • S3-compatible backups with retention policies, clean Docker stop/restart around archive creation, staged restore, archive integrity checks, and scheduled archive verification.
  • Portable Pterodactyl egg conversion, first-admin setup, mandatory administrator two-factor authentication, recovery codes, shared API request throttles, and administrator metrics.
  • Fresh-host install scripts and a release updater with application health checks and application-code rollback.

Verification in this checkout ​

  • API TypeScript check, CORS tests, updater tests, and template-converter tests passed.
  • Disposable PostgreSQL API smoke suite passed 216 assertions, including simulated two-node agent traffic, multi-replica console routing, recovery-code invalidation, shared request throttling, and metrics authorization/output.
  • With S3 integration enabled, the same suite passed 226 assertions against the local SeaweedFS S3-compatible service, including streamed object upload/download and retention deletion while preserving the latest backup. This is not an AWS S3 validation.
  • Web TypeScript check and production build passed.
  • Linux agent go test ./..., go vet ./..., and go build ./... passed under Ubuntu 24.04 on WSL2.
  • The agent's optional real Docker stdin integration passed against a disposable postgres:16-alpine container.
  • Windows installer and updater smoke checks passed; Linux install, update, node-connector, and amd64/arm64 release-artifact checks passed under WSL2.
  • A real Minecraft Java server booted on Docker Desktop through the enrolled WSL2 agent. Console input, file listing, a Docker resource sample, a 108 MiB S3-compatible backup download, and restore all succeeded. The disposable game and customer were removed afterward; the panel and enrolled node agent remain running for local evaluation.

These checks do not constitute a production security review or a separate-host recovery drill. They do not boot Minecraft or Valheim, contact real AWS S3, or validate Windows-native services and Windows containers.

Known limitations ​

  • Disk allowances are logical guards on panel-managed and SFTP writes. They are not hard filesystem quotas, so game processes can exceed them.
  • Automatic stateful failover and live migration are not available. Cross-node recovery is a manual provision, restore, verify, and network-update procedure.
  • Backups are non-atomic archives, not filesystem snapshots. Stopping a game before archive creation narrows the consistency window, but game behavior and filesystem state still matter. Scheduled verification checks archive readability and safe extraction; it does not boot the game.
  • Local test coverage does not validate AWS S3 retention, a second physical node, sustained multi-replica load, or complete game-image startup and recovery.
  • Docker Desktop on Windows supports local Linux containers and a WSL2 Linux-agent evaluation only. Native Windows agents/services and Windows containers are unsupported.
  • The node agent controls Docker and therefore has root-equivalent authority. Rootless operation and Docker privilege-boundary hardening are not validated.
  • The API includes shared rate limits, recovery codes, metrics, and updater application-code rollback. These do not replace an independent security review. Recovery requires previously saved codes, and application rollback cannot reverse database migrations.
  • External monitoring, load testing, and operational credential rotation still need deployment-specific setup and validation.

Fledge v0.1.0 is an evaluation pre-release. Keep independent backups and validate restore and network behavior on the target infrastructure before relying on it.

Released under the AGPL-3.0-only license.