Nieuwste stabiele versie — v1.8.2

Download Fluxheim

Linux x86_64 · Linux aarch64 · Windows x86_64 · macOS Apple Silicon 2026-09-13.

Volledige variant Aanbevolen

Volledige productiebuild

Alle stabiele productiemodules: proxy, web, cache, compressie, load balancing, ruwe TCP stream proxying, TLS (rustls), PHP-FPM, ACME-client, GeoIP/Geo-Context, security hardening, metrics en OpenTelemetry.

Statische servering + reverse proxy + PHP-FPM
Cache-backends (geheugen, disk, tiered)
gzip-, zstd- en Brotli-compressie
TLS + beheerde ACME-vernieuwing
Lokale GeoIP land-/ASN-context
Geharde TCP stream proxying
Prometheus en OpenTelemetry
~10.3 MB binary
Load balancer Nieuw

Load-balancer edge

Gerichte HTTP/TCP load-balancer-build zonder cache, statische web, PHP, GeoIP, stream proxying of traffic mirroring.

Advanced pool selection
Drain, uitschakelen, force-down
Geharde LB-kern
TLS + beheerde ACME-vernieuwing
PHP Beheerde PHP-FPM

PHP-applicatiebuild

Statische web + reverse proxy + PHP-FPM FastCGI-bridge. Ideaal voor WordPress en PHP front-controllerapps. Geen cachemodule gecompileerd.

PHP-FPM FastCGI-bridge
Statische assetservering vanaf dezelfde root
TLS + beheerde ACME-vernieuwing
~8.9 MB binary
Cache-laag

Cache-edge-build

Gerichte cache edge zonder lokale statische webservering. Bevat proxy, cache, compressie, TLS en ACME. Ideaal voor CDN-achtige deployments.

Reverse proxy en cache
Cache-veilige compressiecontrols
TLS + beheerde ACME-vernieuwing
Geen statische webmodule gecompileerd
~6.8 MB binary
Proxy-laag

Proxy-edge-build

Gerichte reverse proxy zonder cache, statische web of de dedicated load-balancer-module. Ontworpen voor pure reverse-proxy-deployments met TLS, ACME, compressie en upstream-resilience.

Alleen reverse proxy
ACL's, rate limits, retries, health checks
TLS + beheerde ACME-vernieuwing
Geen cache- of webmodule gecompileerd
~5.8 MB binary
Wasm Nieuw

Wasm-productiebuild

Speciale Wasm-build op basis van het volledige productieprofiel, met begrensde beleidshooks, ACME, metrieken en OpenTelemetry.

Statische servering + reverse proxy + PHP-FPM
Cache-backends (geheugen, disk, tiered)
WASM-extensies
TLS + beheerde ACME-vernieuwing
Prometheus en OpenTelemetry

Platform Downloads

Linux x86_64 · Linux aarch64 · Windows x86_64 · macOS Apple Silicon

Ondersteunde platforms

Installatie

bash - tarball-installatie
# 1. Download de volledige Linux-buildtarball
# Gebruik aarch64-linux in plaats van x86_64-linux op ARM64-servers.
curl -fLO https://github.com/valkyoth/fluxheim/releases/download/v1.8.2/fluxheim-1.8.2-full-x86_64-linux.tar.gz

# 2. Verifieer en pak uit
echo '1a323dcd5632e25acf2e4463e549f20cdd3d568f445f9d923b1be312ec7f9839  fluxheim-1.8.2-full-x86_64-linux.tar.gz' | sha256sum -c -
tar xzf fluxheim-1.8.2-full-x86_64-linux.tar.gz

# 3. Verplaats binary en helpertools naar systeempad
cd fluxheim-1.8.2-full-x86_64-linux
sudo install -m 0755 fluxheim fluxheim-acme /usr/local/bin/

# 4. Maak configdirectory en voeg je config toe
sudo mkdir -p /etc/fluxheim /srv/fluxheim
sudo cp packaging/default/fluxheim.toml /etc/fluxheim/fluxheim.toml

# 5. Valideer config
fluxheim --check-config --config /etc/fluxheim/fluxheim.toml

# 6. Draai direct (of zie de Systemd-tab voor serviceopzet)
sudo fluxheim --config /etc/fluxheim/fluxheim.toml
PowerShell — Windows x86_64
$Version = "1.8.2"
$Archive = "fluxheim-$Version-full-x86_64-windows.zip"
$BaseUrl = "https://github.com/valkyoth/fluxheim/releases/download/v$Version"
$InstallDir = Join-Path $env:LOCALAPPDATA "Fluxheim"

Invoke-WebRequest "$BaseUrl/$Archive" -OutFile $Archive
$Expected = "a72b84720083406f318bf3fc87555eb62fd76dbd1506dbf2cd368e7364726b44"
$Actual = (Get-FileHash $Archive -Algorithm SHA256).Hash.ToLowerInvariant()
if ($Actual -cne $Expected) { throw "Archive checksum verification failed" }

New-Item -ItemType Directory -Force -Path $InstallDir | Out-Null
Expand-Archive -LiteralPath $Archive -DestinationPath $InstallDir -Force
$Bundle = Join-Path $InstallDir "fluxheim-$Version-full-x86_64-windows"

& "$Bundle\fluxheim.exe" --config "$InstallDir\fluxheim.toml" --check-config
& "$Bundle\fluxheim.exe" --config "$InstallDir\fluxheim.toml"

Niet-ondertekende preview: Dit is een niet-ondertekende draagbare preview. Laat de beveiliging van SmartScreen en PowerShell ingeschakeld; Authenticode-ondertekening en een Windows-service-installatieprogramma zijn nog niet beschikbaar. Beheerd PHP-FPM-toezicht is alleen beschikbaar op Unix; Windows ondersteunt externe TCP FastCGI-pools.

bash — macOS Apple Silicon
VERSION="1.8.2"
PROFILE="full"
ARCHIVE="fluxheim-${VERSION}-${PROFILE}-aarch64-macos.tar.gz"
BASE_URL="https://github.com/valkyoth/fluxheim/releases/download/v${VERSION}"

curl -fLO "${BASE_URL}/${ARCHIVE}"
echo "a725ebcccac259af6640da57ce12e7a3944c5bd0d9e7869d4001196a0c394031  ${ARCHIVE}" | shasum -a 256 -c -
tar -xzf "$ARCHIVE"

install -d "$HOME/.local/bin"
install -m 0755 "fluxheim-${VERSION}-${PROFILE}-aarch64-macos/fluxheim" "$HOME/.local/bin/fluxheim"
install -m 0755 "fluxheim-${VERSION}-${PROFILE}-aarch64-macos/fluxheim-acme" "$HOME/.local/bin/fluxheim-acme"

fluxheim --config "$HOME/.config/fluxheim/fluxheim.toml" --check-config
fluxheim --config "$HOME/.config/fluxheim/fluxheim.toml"

Niet-ondertekende preview: Dit is een niet-ondertekende commandoregelpreview. Laat Gatekeeper ingeschakeld; Developer ID-ondertekening, notarisatie en launchd-integratie zijn nog niet beschikbaar.

bash - rootless Podman
# Pull GHCR-images (Wasm, full, load-balancer, cache, proxy en PHP-varianten)
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2         # full variant
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-wasm
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-load-balancer # load-balancer-variant
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-cache   # cache-edge
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-proxy   # proxy-edge
podman pull ghcr.io/valkyoth/fluxheim:v1.8.2-php     # beheerde PHP-FPM

# Dezelfde buildset is beschikbaar op Quay
podman pull quay.io/valkyoth/fluxheim:v1.8.2
podman pull quay.io/valkyoth/fluxheim:v1.8.2-wasm
podman pull quay.io/valkyoth/fluxheim:v1.8.2-load-balancer
podman pull quay.io/valkyoth/fluxheim:v1.8.2-cache
podman pull quay.io/valkyoth/fluxheim:v1.8.2-proxy
podman pull quay.io/valkyoth/fluxheim:v1.8.2-php

# Draai rootless - interne poorten 8080 en 8443
podman run -d \
  --name fluxheim \
  --restart unless-stopped \
  -p 8080:8080 \
  -p 8443:8443 \
  -v /srv/sites:/srv/sites:ro \
  -v /srv/fluxheim/certs:/etc/fluxheim/certs:rw \
  -v ./fluxheim.toml:/etc/fluxheim/fluxheim.toml:ro \
  ghcr.io/valkyoth/fluxheim:v1.8.2

# Controleer logs
podman logs -f fluxheim
bash - systemd-service
# De tarball bevat een geharde systemd-unit
sudo cp packaging/systemd/fluxheim.service /etc/systemd/system/

# Maak de fluxheim-systeemgebruiker
sudo useradd -r -s /sbin/nologin -d /var/lib/fluxheim fluxheim

# Stel directories in
sudo mkdir -p /etc/fluxheim /srv/fluxheim /var/log/fluxheim
sudo chown fluxheim:fluxheim /srv/fluxheim /var/log/fluxheim

# Herlaad systemd en activeer de service
sudo systemctl daemon-reload
sudo systemctl enable --now fluxheim

# Controleer status
sudo systemctl status fluxheim
sudo journalctl -u fluxheim -f

Let op: De gepackagede systemd-unit gebruikt CAP_NET_BIND_SERVICE zodat Fluxheim aan poorten 80 en 443 kan binden zonder als root te draaien. De unit-file bevat security hardening-opties.

bash - beheerde ACME-certificaatuitgifte
# Fluxheim levert acme-init voor begeleide certificaatopzet
# Let's Encrypt (HTTP-01 challenge)
sudo fluxheim acme-init letsencrypt

# Actalis (gratis EAB-capable issuer)
sudo fluxheim acme-init actalis

# De companion-tool fluxheim-acme behandelt vernieuwing voor
# container- en externe service-manager-deployments
fluxheim-acme status
fluxheim-acme renew
fluxheim-acme reload
fluxheim.toml - ACME-config
[[vhosts]]
name = "site"
hosts = ["example.com", "www.example.com"]

[vhosts.tls]
enabled = true

[vhosts.tls.acme]
enabled = true
# issuer-keuze: issuer = "letsencrypt"
Volledige TLS- en ACME-documentatie →

Systeemvereisten

Ondersteunde platforms

  • Linux x86_64 (kernel 4.14+)
  • Linux ARM64 / aarch64
  • macOS Apple Silicon / aarch64
  • Windows x86_64

Container-images

Alle release image-builds worden gepubliceerd op GHCR en Quay.

  • Wolfi (minimaal, gehard)
  • Wasm + Imageprofielen voor full, load-balancer, cache, proxy en PHP
  • Alpine Linux
  • SUSE Micro (non-PHP profiles)
  • SUSE BCI (PHP: php-suse-bci)
  • Debian
  • Gepubliceerd op GHCR en Quay
Versie Datum Hoogtepunten Downloadbestanden
v1.8.2 Nieuwste
2026-09 Voegt niet-ondertekende native Windows x86_64-ZIP-archieven toe voor alle zeven openbare profielen, behoudt de beveiliging van het Windows-bestandssysteem en aanmeldgegevens en vervangt de PHP SUSE Micro-image door de zelfstandige php-suse-bci-runtime. Alles op GitHub
v1.8.1
2026-08 Voegt native macOS-archieven voor Apple Silicon toe voor alle zeven openbare buildprofielen, live tests voor runtimepariteit, draagbare controlesomtools en sterkere bescherming van diagnostiek en bestandssystemen. Alles op GitHub
v1.8.0
July 2026 Speciale Wasm-build op basis van het volledige productieprofiel, met begrensde beleidshooks, ACME, metrieken en OpenTelemetry. Voegt overeenkomende tar.gz- en ZIP-archieven toe, waaronder native volledige en Wasm-builds voor macOS. Versterkt de grenzen voor cachevulling, bereikcache en Wasm-toelating per virtuele host. Alles op GitHub
v1.7.0 – v1.7.12
July 2026 Fluxheim 1.7 releaseserie: op opt-in standaarden gebaseerde cache-, proxy- en respons-digest-metagegevens; geverifieerde live snapshot herladen en terugdraaien; reproduceerbaar FIPS-backend bewijsmateriaal; procesupgrades zonder downtime; onafhankelijk geteste Wasm beleidsvoorbeelden; en sterkere cache, TLS, buffering, stream- en protocolgrenzen. Alles op GitHub
v1.6.0 – v1.6.37
Juni 2026 Native-runtime-cutover en opruimlijn: Pingora-exitfundamenten, Fluxheim-eigen HTTP/1- en HTTP/2-paden, native TLS/listener-previews, route proxy/static-web-pariteit, compressie en foutpagina’s, forwarded-headerbeleid, auth-request, verkeersmirroring, rate limits, gRPC-validatie, gepoolde upstream HTTP/2, native proxy-opruiming na de cutover, finale crate-boundary-opruiming vóór Wasm, Rust 1.96.1, verharde OpenSSL stream-TLS, ACME-accountzeroisatie en kleinere gerichte runtime-modules. Alles op GitHub
v1.5.0 - v1.5.23 Juni 2026 Enterprise load-balancer- en runtime-ownership-lijn: gerichte load-balancer binaries/images, runtime member- en weight-controls, beheerde affinity cookies, stream- en HTTP-boundarywerk, actieve en protocol-aware health checks, service discovery, background-task ownership, cache crate boundaries, UDP beta-guardrails, origin-protection budgets, ARM/macOS-assets en brede security hardening. Alles op GitHub
v1.4.0 – v1.4.7 Mei 2026 Proxy operations-lijn met productieproxypariteit, rijkere routepolicy, traffic mirroring, dynamische upstream-discovery, modulaire runtime/config-splitsing, Apple Silicon- en Linux ARM64-releaseassets, GeoIP/Geo-Context, config-tester-archieven en geharde TCP stream proxying Alles op GitHub
v1.3.0 – v1.3.7 Mei 2026 PHP-FPM-productielijn, beheerde php-fpm-supervisie, config tester en ACME companion binaries, FIPS/ISO-validatiesporen, gerichte cache-/proxyprofielen en security hardening Alles op GitHub
v1.2.0 – v1.2.6 Mei 2026 Cache- en observability-baseline met route-scoped cache policy, memory/disk/tiered backends, encrypted disk cache, peer fill, range caching, Prometheus en OpenTelemetry-export Alles op GitHub
v1.1.x 2026 Certificaatoperations-lijn met TLS-policyprofielen, multi-certificate rustls SNI, beheerde ACME-uitgifte en -vernieuwing, EAB-capable issuers, file-backed TLS secrets en renewal units Alles op GitHub
v1.0.0 2026 Gateway-fundament met vhost-routing, route-level static/proxy/redirect-acties, statische bestandsservering, reverse proxying, rustls TLS, admin control-plane, secure headers, systemd-packaging en rootless containers GitHub
v0.5.0 Prerelease Eerste publieke prerelease-mijlpaal voor de stabiele 1.x gateway-lijn GitHub

See Wijzigingslog voor gedetailleerde releasenotes.

Nederlands