Edit history

Self-hosting Fluxer: findings, bugs, and patches from a real deployment has not been edited, so there are no earlier versions.

Current version | Original by Rex
Show

Self-hosting Fluxer: findings, bugs, and patches from a real deployment

I've been running a self-hosted Fluxer instance for about a week now, built from the refactor branch. (Commit https://github.com/fluxerapp/fluxer/commit/848269a4d4df7349acfc861ff926b17fe4c4a548 at the time I post this, edits will likely follow.) The self-hosting docs are still TBD, so I wanted to share what I found in case others go down this path. This covers build issues, runtime bugs (some of which likely affect the upstream instance too), and SSO integration. >[!NOTE] >The root causes I describe in these posts are my assumptions, they are more pointers for maintainers than well thought out fixes that could be submitted as PRs. I don't feel like I know enough of the architecture for that. Think of these as: "I had an issue, this is what I changed to fix it." Setup: Source build from refactor, behind Traefik reverse proxy, with Valkey, NATS, Meilisearch, and LiveKit. SQLite for the database. I'll post each issue as a separate reply below so they have their own threads. Here's the summary:

Build/Dockerfile issues

  1. Dockerfile missing 16+ workspace package.json COPYs — pnpm install fails
  2. .dockerignore excludes files needed at build time — **/build glob and emojis.json
  3. No wasm32 target for Rust — apt-installed rustc doesn't include it, wasm-pack fails
  4. ENTRYPOINT points to root workspace — no start script there
  5. rspack.config.mjs hardcodes CDN publicPath — self-hosted builds must serve bundles from origin
  6. CSP directives missing static_cdn_domain — emoji/fonts/icons blocked
  7. Admin CSS not built — missing build step in Dockerfile
  8. tsgo --noEmit fails — locale modules don't exist until lingui:compile runs

Runtime bugs (likely upstream too)

  1. Voice states missing from READY payload — guild_data.erl reads from guild process (always empty) instead of voice server process
  2. LiveKit webhooks not configured in livekit.example.yaml — join/leave events never reach the server
  3. VoiceReconciliationWorker is dead code — never instantiated

SSO/OIDC issues

  1. URLSearchParams body serialized as '{}' — token exchange sends empty body
  2. client_secret missing from token exchange — getSsoConfig() omits it by default
  3. Basic auth incompatible with some IdPs — Pocket ID ignores it when client_id is in body
  4. SSO users treated as "unclaimed" — no password = unclaimed in upstream logic
  5. SSO callback route not in auth guard allowlist — redirects to /login before processing