Download Fluxheim
Linux x86_64 · Linux aarch64 · Windows x86_64 · macOS Apple Silicon 2026-09-13.
Full Production Build
All stable production modules: proxy, web, cache, compression, load balancing, raw TCP stream proxying, TLS (rustls), PHP-FPM, ACME client, GeoIP/Geo-Context, security hardening, metrics, and OpenTelemetry.
Load Balancer Edge
Focused HTTP/TCP load-balancer build without cache, static web, PHP, GeoIP, stream proxying, or traffic mirroring.
PHP Application Build
Static web + reverse proxy + PHP-FPM FastCGI bridge. Ideal for WordPress and PHP front-controller apps. No cache module compiled.
Cache Edge Build
Focused cache edge without local static web serving. Includes proxy, cache, compression, TLS, and ACME. Ideal for CDN-style deployments.
Proxy Edge Build
Focused reverse proxy without cache, static web, or the dedicated load-balancer module. Designed for pure reverse-proxy deployments with TLS, ACME, compression, and upstream resilience.
Wasm Production Build
Dedicated Wasm build based on the full production profile, with bounded policy hooks, ACME, metrics, and OpenTelemetry.
Platform Downloads
Linux x86_64 · Linux aarch64 · Windows x86_64 · macOS Apple Silicon
| Build | Linux x86_64 | Linux aarch64 | Windows x86_64 | macOS Apple Silicon |
|---|---|---|---|---|
| Full | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| Wasm | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| PHP | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| Load Balancer | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| Cache | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| Proxy | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
| Config tester | x86_64-linux | aarch64-linux | x86_64-windows | aarch64-macos |
Installation
# 1. Download the full Linux build tarball
# Use aarch64-linux instead of x86_64-linux on ARM64 servers.
curl -fLO https://github.com/valkyoth/fluxheim/releases/download/v1.8.2/fluxheim-1.8.2-full-x86_64-linux.tar.gz
# 2. Verify and extract
echo '1a323dcd5632e25acf2e4463e549f20cdd3d568f445f9d923b1be312ec7f9839 fluxheim-1.8.2-full-x86_64-linux.tar.gz' | sha256sum -c -
tar xzf fluxheim-1.8.2-full-x86_64-linux.tar.gz
# 3. Move binary and helper tools to system path
cd fluxheim-1.8.2-full-x86_64-linux
sudo install -m 0755 fluxheim fluxheim-acme /usr/local/bin/
# 4. Create config directory and add your config
sudo mkdir -p /etc/fluxheim /srv/fluxheim
sudo cp packaging/default/fluxheim.toml /etc/fluxheim/fluxheim.toml
# 5. Validate config
fluxheim --check-config --config /etc/fluxheim/fluxheim.toml
# 6. Run directly (or see Systemd tab for service setup)
sudo fluxheim --config /etc/fluxheim/fluxheim.toml
$Version = "1.8.2"
$Archive = "fluxheim-$Version-full-x86_64-windows.zip"
$BaseUrl = "https://github.com/valkyoth/fluxheim/releases/download/v$Version"
$InstallDir = Join-Path $env:LOCALAPPDATA "Fluxheim"
Invoke-WebRequest "$BaseUrl/$Archive" -OutFile $Archive
$Expected = "a72b84720083406f318bf3fc87555eb62fd76dbd1506dbf2cd368e7364726b44"
$Actual = (Get-FileHash $Archive -Algorithm SHA256).Hash.ToLowerInvariant()
if ($Actual -cne $Expected) { throw "Archive checksum verification failed" }
New-Item -ItemType Directory -Force -Path $InstallDir | Out-Null
Expand-Archive -LiteralPath $Archive -DestinationPath $InstallDir -Force
$Bundle = Join-Path $InstallDir "fluxheim-$Version-full-x86_64-windows"
& "$Bundle\fluxheim.exe" --config "$InstallDir\fluxheim.toml" --check-config
& "$Bundle\fluxheim.exe" --config "$InstallDir\fluxheim.toml"
Unsigned preview: This is an unsigned portable preview. Keep SmartScreen and PowerShell security enabled; Authenticode signing and a Windows service installer are not yet provided. Managed PHP-FPM supervision is Unix-only; Windows supports external TCP FastCGI pools.
VERSION="1.8.2"
PROFILE="full"
ARCHIVE="fluxheim-${VERSION}-${PROFILE}-aarch64-macos.tar.gz"
BASE_URL="https://github.com/valkyoth/fluxheim/releases/download/v${VERSION}"
curl -fLO "${BASE_URL}/${ARCHIVE}"
echo "a725ebcccac259af6640da57ce12e7a3944c5bd0d9e7869d4001196a0c394031 ${ARCHIVE}" | shasum -a 256 -c -
tar -xzf "$ARCHIVE"
install -d "$HOME/.local/bin"
install -m 0755 "fluxheim-${VERSION}-${PROFILE}-aarch64-macos/fluxheim" "$HOME/.local/bin/fluxheim"
install -m 0755 "fluxheim-${VERSION}-${PROFILE}-aarch64-macos/fluxheim-acme" "$HOME/.local/bin/fluxheim-acme"
fluxheim --config "$HOME/.config/fluxheim/fluxheim.toml" --check-config
fluxheim --config "$HOME/.config/fluxheim/fluxheim.toml"
Unsigned preview: This is an unsigned command-line preview. Keep Gatekeeper enabled; Developer ID signing, notarisation, and launchd integration are not yet provided.
# Pull GHCR images (Wasm, full, load-balancer, cache, proxy, and PHP variants)
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2 # full
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-wasm
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer # load balancer
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-cache # cache edge
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-proxy # proxy edge
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-php # managed PHP-FPM
# Same build set is available on Quay
podman pull quay.io/valkyoth/fluxheim:v1.8.2
podman pull quay.io/valkyoth/fluxheim:v1.8.2-wasm
podman pull quay.io/valkyoth/fluxheim:v1.8.2-load-balancer
podman pull quay.io/valkyoth/fluxheim:v1.8.2-cache
podman pull quay.io/valkyoth/fluxheim:v1.8.2-proxy
podman pull quay.io/valkyoth/fluxheim:v1.8.2-php
# Run rootless — internal ports 8080 and 8443
podman run -d \
--name fluxheim \
--restart unless-stopped \
-p 8080:8080 \
-p 8443:8443 \
-v /srv/sites:/srv/sites:ro \
-v /srv/fluxheim/certs:/etc/fluxheim/certs:rw \
-v ./fluxheim.toml:/etc/fluxheim/fluxheim.toml:ro \
ghcr.io/valkyoth/fluxheim:v1.8.2
# Check logs
podman logs -f fluxheim
# The tarball includes a hardened systemd unit
sudo cp packaging/systemd/fluxheim.service /etc/systemd/system/
# Create the fluxheim system user
sudo useradd -r -s /sbin/nologin -d /var/lib/fluxheim fluxheim
# Set up directories
sudo mkdir -p /etc/fluxheim /srv/fluxheim /var/log/fluxheim
sudo chown fluxheim:fluxheim /srv/fluxheim /var/log/fluxheim
# Reload systemd and enable the service
sudo systemctl daemon-reload
sudo systemctl enable --now fluxheim
# Check status
sudo systemctl status fluxheim
sudo journalctl -u fluxheim -f
Note: The packaged systemd unit uses CAP_NET_BIND_SERVICE so Fluxheim can bind to ports 80 and 443 without running as root. The unit file includes security hardening options.
# Fluxheim ships with acme-init for guided certificate setup
# Let's Encrypt (HTTP-01)
sudo fluxheim acme-init letsencrypt
# Actalis (free EAB-capable issuer)
sudo fluxheim acme-init actalis
# The companion tool fluxheim-acme handles renewal for
# container and external service-manager deployments
fluxheim-acme status
fluxheim-acme renew
fluxheim-acme reload
[[vhosts]]
name = "site"
hosts = ["example.com", "www.example.com"]
[vhosts.tls]
enabled = true
[vhosts.tls.acme]
enabled = true
# issuer = "letsencrypt"
System Requirements
Supported Platforms
- Linux x86_64 (kernel 4.14+)
- Linux ARM64 / aarch64
- macOS Apple Silicon / aarch64
- Windows x86_64
Container Images
All release image builds are published on GHCR and Quay.
- Wolfi (minimal, hardened)
- Wasm + Full, load-balancer, cache, proxy, and PHP image profiles
- Alpine Linux
- SUSE Micro (non-PHP profiles)
- SUSE BCI (PHP:
php-suse-bci) - Debian
- Published on GHCR and Quay
All Releases
View all on GitHub →| Version | Date | Highlights | Downloads |
|---|---|---|---|
|
v1.8.2
Latest
|
2026-09 | Adds unsigned native Windows x86_64 ZIP archives for all seven public profiles, preserves Windows filesystem and credential protections, and replaces the PHP SUSE Micro image with the self-contained php-suse-bci runtime. | All on GitHub |
|
v1.8.1
|
2026-08 | Adds native Apple Silicon macOS archives for all seven public build profiles, live runtime parity tests, portable checksum tooling, and stronger diagnostic and filesystem protections. | All on GitHub |
|
v1.8.0
|
July 2026 | Dedicated Wasm build based on the full production profile, with bounded policy hooks, ACME, metrics, and OpenTelemetry. Adds matching tar.gz and ZIP archives, including native macOS full and Wasm builds. Strengthens cache-fill, range-cache, and per-vhost Wasm admission boundaries. | All on GitHub |
|
v1.7.0 – v1.7.12
|
July 2026 | Fluxheim 1.7 release series: opt-in standards-based cache, proxy, and response-digest metadata; authenticated live snapshot reload and rollback; reproducible FIPS-backend evidence; zero-downtime process upgrades; independently tested Wasm policy examples; and stronger cache, TLS, buffering, stream, and protocol boundaries. | All on GitHub |
|
v1.6.0 – v1.6.37
|
June 2026 | Native-runtime cutover and cleanup line: Pingora-exit foundations, Fluxheim-owned HTTP/1 and HTTP/2 paths, native TLS/listener previews, route proxy/static-web parity, compression and error pages, forwarded-header policy, auth-request, traffic mirroring, rate limits, gRPC validation, pooled upstream HTTP/2, post-cutover native proxy cleanup, final pre-Wasm crate-boundary cleanup, Rust 1.96.1, hardened OpenSSL stream TLS, ACME account zeroisation, and smaller focused runtime modules. | All on GitHub |
| v1.5.0 - v1.5.23 | June 2026 | Enterprise load-balancer and runtime-ownership line: focused load-balancer binaries/images, runtime member and weight controls, managed affinity cookies, stream and HTTP boundary work, active and protocol-aware health checks, service discovery, background task ownership, cache crate boundaries, UDP beta guardrails, origin-protection budgets, ARM/macOS assets, and broad security hardening. | All on GitHub |
| v1.4.0 – v1.4.7 | May 2026 | Proxy operations line with production proxy parity, richer route policy, traffic mirroring, dynamic upstream discovery, modular runtime/config split, Apple Silicon and Linux ARM64 release assets, GeoIP/Geo-Context, config-tester archives, and hardened TCP stream proxying | All on GitHub |
| v1.3.0 – v1.3.7 | May 2026 | PHP-FPM production line, managed php-fpm supervision, config tester and ACME companion binaries, FIPS/ISO validation tracks, focused cache/proxy profiles, and security hardening | All on GitHub |
| v1.2.0 – v1.2.6 | May 2026 | Cache and observability baseline with route-scoped cache policy, memory/disk/tiered backends, encrypted disk cache, peer fill, range caching, Prometheus, and OpenTelemetry export | All on GitHub |
| v1.1.x | 2026 | Certificate operations line with TLS policy profiles, multi-certificate rustls SNI, managed ACME issuance and renewal, EAB-capable issuers, file-backed TLS secrets, and renewal units | All on GitHub |
| v1.0.0 | 2026 | Gateway foundation with vhost routing, route-level static/proxy/redirect actions, static file serving, reverse proxying, rustls TLS, admin control-plane, secure headers, systemd packaging, and rootless containers | GitHub |
| v0.5.0 | Pre-release | First public pre-release milestone before the stable 1.x gateway line | GitHub |
See Changelog for detailed release notes.