I've been running a self-hosted Fluxer instance for about a week now, built from the
refactor branch. (Commit https://github.com/fluxerapp/fluxer/commit/848269a4d4df7349acfc861ff926b17fe4c4a548 at the time I post this, edits will likely follow.) The self-hosting docs are still TBD, so I wanted to share what I found in case others go down this path. This covers build issues, runtime bugs (some of which likely affect the upstream instance too), and SSO integration.
>[!NOTE]
>The root causes I describe in these posts are my assumptions, they are more pointers for maintainers than well thought out fixes that could be submitted as PRs. I don't feel like I know enough of the architecture for that. Think of these as: "I had an issue, this is what I changed to fix it."
Setup: Source build from refactor, behind Traefik reverse proxy, with Valkey, NATS, Meilisearch, and LiveKit. SQLite for the database.
I'll post each issue as a separate reply below so they have their own threads. Here's the summary:
Build/Dockerfile issues
- Dockerfile missing 16+ workspace
package.jsonCOPYs —pnpm installfails .dockerignoreexcludes files needed at build time —**/buildglob andemojis.json- No wasm32 target for Rust — apt-installed rustc doesn't include it,
wasm-packfails - ENTRYPOINT points to root workspace — no
startscript there rspack.config.mjshardcodes CDNpublicPath— self-hosted builds must serve bundles from origin- CSP directives missing
static_cdn_domain— emoji/fonts/icons blocked - Admin CSS not built — missing build step in Dockerfile
tsgo --noEmitfails — locale modules don't exist untillingui:compileruns
Runtime bugs (likely upstream too)
- Voice states missing from READY payload —
guild_data.erlreads from guild process (always empty) instead of voice server process - LiveKit webhooks not configured in
livekit.example.yaml— join/leave events never reach the server VoiceReconciliationWorkeris dead code — never instantiated
SSO/OIDC issues
URLSearchParamsbody serialized as'{}'— token exchange sends empty bodyclient_secretmissing from token exchange —getSsoConfig()omits it by default- Basic auth incompatible with some IdPs — Pocket ID ignores it when
client_idis in body - SSO users treated as "unclaimed" — no password = unclaimed in upstream logic
- SSO callback route not in auth guard allowlist — redirects to
/loginbefore processing