Self-hosting Fluxer: findings, bugs, and patches from a real deployment

(#1037) Feature Shipped self-hosting

Thread

Comment by @mgabor3141
RexSystem 1 vote originally by @mgabor3141 on GitHub OP

6: Config architecture and gotchas for self-hosters

Erlang gateway can't use env overrides. The Node.js server supports FLUXER_CONFIG__ prefixed env vars for config overrides (double-underscore separated path). The Erlang gateway reads config.json directly with no env substitution. Any config value the gateway needs must be in the JSON file — env overrides won't reach it. Practical consequence: if you set a NATS auth token via env vars, the Node.js server authenticates fine but the gateway silently fails to connect. Easiest workaround is to run NATS without auth — it's only on the internal Docker network anyway. Git LFS will break your clone. The repo uses LFS for static assets (fluxer_static/). If you run git lfs install (even accidentally), it enables the smudge filter globally and every subsequent git operation tries to download from a private LFS store and hangs indefinitely. Clone with:
GIT_LFS_SKIP_SMUDGE=1 git clone --depth 1 --branch refactor https://github.com/fluxerapp/fluxer.git
Or pass -c filter.lfs.smudge= -c filter.lfs.required=false to every git command. Related: the upstream Dockerfile has a COPY fluxer_static/ ... line that copies LFS pointer files (not actual assets). Remove it — static assets (emoji SVGs, fonts, icons) are served from fluxerstatic.com CDN and aren't instance-specific. SQLite path must be absolute. pnpm changes the working directory, so a relative sqlite_path resolves to the wrong location and you get a silent empty database. Use the full container path:
"sqlite_path": "/usr/src/app/data/fluxer.db"
First registered user gets admin. The first account created automatically receives wildcard admin ACLs (*). The admin panel is at /admin. Once SSO is configured and ready, the LocalAuthMiddleware blocks the /auth/register endpoint entirely (SSO_REQUIRED), so new users can only be provisioned via your IdP. LiveKit needs special handling. See Reply 7 for details, but the short version: don't use Docker port mappings for the UDP range (it can crash your system), use host networking instead, and plan for dynamic IP if you're on a residential connection.