Floodgate is a fault-isolated Fluid server on the BEAM.
Use Floodgate as the self-hosted collaboration backend for a Fluid Framework app. Each document runs in its own supervised BEAM process, while one server speaks the official Fluid protocol and Phoenix Channels.
One document restarts. Every other session stays untouched.
what a crash looks like
illustrative recovery trace- doc:a3f9 ops sequenced, clients attached
- sup doc:a3f9 exited: badarg
- sup doc:a3f9 restarted, state reloaded from storage
- doc:a3f9 client resumed at the same sequence number
- ok every other document session: untouched
Illustrative supervisor output, not a benchmark — one_for_one is the restart strategy Floodgate configures, and reloading from storage is what a restarted session does.
one server, two protocols
- [boot] loading spillway protocol engine…
- [boot] loading beryl socket runtime…
- [net] binding localhost:3000
- [socket.io] listening — official Fluid/Routerlicious drivers
- [phx] listening — Phoenix Channels (levee-driver, levee-client)
- [ready] floodgate is up. two protocols, one process.
why the BEAM
- [sup] restart_strategy: one_for_one
- [sup] each document session is its own isolated process
- [sup] a crashed session does not take the node down
- [gleam] protocol logic is compiled and type-checked before it ever runs
Gleam compiles to the same virtual machine that has run telecom switches for decades. Every document gets its own supervised process: one session crashing and restarting is normal operation, not an incident, and the sequencing logic that decides what happened next is checked by the compiler before it ships.
capabilities
- [proto] dual-mode wire protocols: Socket.IO + Phoenix Channels, from one process
- [presence] presence_v1: server-backed roster, both endpoints, no client heartbeat needed
- [storage] git-like storage: blobs, trees, commits, refs — per tenant
- [tenancy] multi-tenancy: dynamic tenants, two rotating JWT secret slots each
- [deploy] self-hosted: single binary or `docker compose up`
Run it
From the Floodgate repository root, with Docker Compose installed:
docker compose up -d --waitstarts on http://localhost:3000. The included Compose file uses known development credentials and permissive browser origins; replace both before deploying. Full steps in getting started.
Floodgate is checked against Levee's unmodified integration suites for levee-driver, levee-client, and levee-example. The suites are repointed only by environment variable, so a failure reveals a real behavioral difference between the servers. Review the conformance test setup.
Performance benchmarks are not published yet.
Get Floodgate running