Fledge v0.1.0 — Pre-release
Fledge is a self-hosted panel for managing game servers across Linux Docker nodes. This pre-release brings the web panel, API, node agent, templates, console, file operations, and backup workflows into one evaluation build.
Included
- Multi-node registration, one-time Linux agent enrollment, node heartbeats, capacity-aware placement, and durable operations.
- Server lifecycle controls, template-based configuration, collaborator permissions, audit history, and a live console with resource samples.
- SFTP with short-lived per-server credentials and server-directory path confinement. Nodes must explicitly enable the SFTP listener and firewall its port.
- Browser file streaming through object storage up to 1 GiB, with a 1 MiB text editor limit.
- S3-compatible backups with retention policies, clean Docker stop/restart around archive creation, staged restore, archive integrity checks, and scheduled archive verification.
- Portable Pterodactyl egg conversion, first-admin setup, mandatory administrator two-factor authentication, recovery codes, shared API request throttles, and administrator metrics.
- Fresh-host install scripts and a release updater with application health checks and application-code rollback.
Verification in this checkout
- API TypeScript check, CORS tests, updater tests, and template-converter tests passed.
- Disposable PostgreSQL API smoke suite passed 216 assertions, including simulated two-node agent traffic, multi-replica console routing, recovery-code invalidation, shared request throttling, and metrics authorization/output.
- With S3 integration enabled, the same suite passed 226 assertions against the local SeaweedFS S3-compatible service, including streamed object upload/download and retention deletion while preserving the latest backup. This is not an AWS S3 validation.
- Web TypeScript check and production build passed.
- Linux agent
go test ./...,go vet ./..., andgo build ./...passed under Ubuntu 24.04 on WSL2. - The agent's optional real Docker stdin integration passed against a disposable
postgres:16-alpinecontainer. - Windows installer and updater smoke checks passed; Linux install, update, node-connector, and amd64/arm64 release-artifact checks passed under WSL2.
- A real Minecraft Java server booted on Docker Desktop through the enrolled WSL2 agent. Console input, file listing, a Docker resource sample, a 108 MiB S3-compatible backup download, and restore all succeeded. The disposable game and customer were removed afterward; the panel and enrolled node agent remain running for local evaluation.
These checks do not constitute a production security review or a separate-host recovery drill. They do not boot Minecraft or Valheim, contact real AWS S3, or validate Windows-native services and Windows containers.
Known limitations
- Disk allowances are logical guards on panel-managed and SFTP writes. They are not hard filesystem quotas, so game processes can exceed them.
- Automatic stateful failover and live migration are not available. Cross-node recovery is a manual provision, restore, verify, and network-update procedure.
- Backups are non-atomic archives, not filesystem snapshots. Stopping a game before archive creation narrows the consistency window, but game behavior and filesystem state still matter. Scheduled verification checks archive readability and safe extraction; it does not boot the game.
- Local test coverage does not validate AWS S3 retention, a second physical node, sustained multi-replica load, or complete game-image startup and recovery.
- Docker Desktop on Windows supports local Linux containers and a WSL2 Linux-agent evaluation only. Native Windows agents/services and Windows containers are unsupported.
- The node agent controls Docker and therefore has root-equivalent authority. Rootless operation and Docker privilege-boundary hardening are not validated.
- The API includes shared rate limits, recovery codes, metrics, and updater application-code rollback. These do not replace an independent security review. Recovery requires previously saved codes, and application rollback cannot reverse database migrations.
- External monitoring, load testing, and operational credential rotation still need deployment-specific setup and validation.
Fledge v0.1.0 is an evaluation pre-release. Keep independent backups and validate restore and network behavior on the target infrastructure before relying on it.
