Chunkforge v1.0.0 — Stable Self-hosted

Forge Your World.

A self-hostable Minecraft platform that builds servers from a wizard, runs them on any machine you already own, and hands every one of them a public subdomain — while the machine doing the work never opens a single inbound port.

No port forwarding No public IP on your nodes Your hardware, your data
0
Inbound ports opened on the machine hosting your servers
7
Server platforms, from Vanilla to NeoForge, with Java handled for you
4
Add-on marketplaces searched at once and merged into one result list
1
WebSocket per node carries console, files, players and traffic
Chunk by chunk
Platforms, loaders and services Chunkforge speaks to
The model

A single triangle.

A control plane you click in. A Portal with a public address. Nodes that do the work. Nothing else to reason about — and only one of the three ever accepts an inbound connection.

TCP / UDP OUTBOUND WSS ONE SOCKET PER NODE LOGICAL — NEVER DIRECT Players survival.play.example.com ANY VANILLA CLIENT · NO MODS Chunkforge Portal Public address · owns your domain TLS 80/443 · ACME VIA CADDY SUBDOMAIN ALLOCATION · TCP + UDP RELAY RUNS NO GAME SERVERS — IT ONLY ROUTES Control plane Desktop app or Web panel WHERE YOU CLICK OUTBOUND ONLY · PIN PAIRED Nodes Homelab · spare PC · VM · cloud ZERO INBOUND PORTS RUNS THE MINECRAFT PROCESS

Hover a component — or trace a connection

Four moving parts, three wires, and only one of them ever accepts an inbound connection. Press Trace a player connection to watch a packet make the trip.

Live traffic over an established socket Connection direction Logical relationship only
player survival.play.example.com Portal (existing WebSocket) node server
01

Nodes dial out. Always.

A node opens one outbound WebSocket to the Portal and holds it. It never listens, never accepts, and never needs a firewall rule. Behind CGNAT, on hotel wifi, on a dynamic IP — the connection model does not change.

02

Portal is the only public thing.

It owns the domain, terminates TLS for the control surface, allocates a subdomain per server, and relays player packets down the socket that is already open. It runs no game servers of its own, so it stays small and cheap.

03

Remote feels local.

The control plane talks to the Portal, not to your nodes. A server three countries away has the same console, the same file browser, the same one-click restart as one running on the machine in front of you.

Capabilities

Everything a server
actually needs.

Not a thin wrapper around a start script. Chunkforge handles the whole lifecycle — creation, runtimes, add-ons, players, files, backups and routing — and it handles them the same way whether the server is local or on the other side of the planet.

Zero inbound ports, by design

This is not a convenience feature bolted on later — it is the architecture. Nodes never bind a public listener, so there is no port to forward, no NAT rule to maintain, and no attack surface exposed on the machine that holds your worlds. Every byte a player sends arrives through a socket your node opened first.

outbound-onlyCGNAT friendlyno static IP

An eight-step wizard that finishes the job

Pick a platform, a version, a memory budget and a node. Chunkforge resolves the correct build from upstream, works out which Java major it needs, fetches that runtime, writes the configuration, accepts the EULA on your say-so and allocates a subdomain. What lands is a server that is genuinely ready to join.

version resolutionmemory presetsnode placement

Live console, parsed

Full stdout streamed in real time with command input, plus chat and join/leave events lifted out of the log so you can read the room without reading raw output.

Four marketplaces, one search

Modrinth, Hangar, SpigotMC and CurseForge queried together, results merged and de-duplicated, filtered by your server's version and loader. Install without leaving the panel.

Java, handled

Requirements are read from the upstream project rather than guessed. The matching JDK is downloaded and pinned per instance, so a modern Paper build and an old Forge pack coexist without a fight.

Modpacks in one action

Install a complete pack from Modrinth or CurseForge and the loader, the Minecraft version and every mod are configured together — no manual matching of versions to loaders.

Backups you can move

Snapshot a world on demand, keep it locally, or push it to a self-hosted FileHub instance with resumable chunked uploads that survive a dropped connection.

Real file access

Browse, edit, upload and download inside the instance directory — on a remote node exactly as on a local one, over the same single connection.

Roles that mean something

Viewer, member, admin and owner, with per-project permissions and hashed API tokens. Hand a friend the console without handing them the file system.

Typed, single-use pins

Pairing pins are scoped to what they pair. A node pin cannot adopt a control plane and a control-plane pin cannot enrol a node — cross-redemption is refused outright.

DNS on autopilot

Give Portal a scoped Cloudflare token and it publishes the wildcard and every per-server record itself. Prefer to do it by hand? Leave the token out and it just tells you what to create.

One renderer, three surfaces

Desktop, Web and Node are built from a single TypeScript monorepo around a domain-agnostic core. The same renderer that draws the Electron window draws the browser panel, so a feature does not exist "on desktop first" — it exists, and then it is everywhere. Fewer surprises, identical muscle memory, and one place for a fix to land.

TypeScriptReactFluent UI v9FastifyElectronVite
Product tour

Where you'll
spend your time.

Six surfaces cover the entire day-to-day. Pick one — the panel on the right is the interface you get for every server, on every node, local or remote.

Basement Box / survival
RunningPaper 1.21.4
>
Platforms

Seven ways to
build a world.

Every supported platform is a first-class citizen — not a generic "custom jar" slot. Java requirements come from the upstream project itself, so the right runtime is fetched before the server ever tries to start.

PlatformAdd-onsJavaNotes
PPaper Recommended PluginsAuto The default for most people — fast, well-supported, enormous plugin ecosystem.
PuPurpur PluginsAuto A Paper fork with a deep bag of gameplay and tuning switches.
SSpigot PluginsAuto Built locally through BuildTools, handled for you start to finish.
VVanilla Auto Unmodified Mojang server, exactly as shipped.
FFabric ModsAuto The modern loader — light, quick to update, huge modern mod catalogue.
FoForge ModsAuto Installed through the official installer, with the classic pack library behind it.
NNeoForge ModsAuto Faster moving on newer versions, and the usual home for recent Forge-lineage packs.
Add-on discovery

Four catalogues.
One search box.

M
Modrinth
Mods, plugins, resource packs and full modpacks with clean version metadata.
H
Hangar
The PaperMC-hosted plugin catalogue, straight from the source.
S
SpigotMC
The long tail — the plugins that have been holding servers together for a decade.
C
CurseForge
The big modpack library, installable whole with loader and version set for you.
Companion

Your backups deserve
somewhere better.

FileHub is a self-hosted, Docker-first file hub — somewhere to keep files of any kind with real metadata, real authentication and transfers fast enough that a multi-gigabyte world is not an event. Chunkforge speaks to it directly.

Streaming uploads, hashed as they go. SHA-256 computed in flight and never buffered in memory, so size stops being the limit.
Resumable by default. Transfers survive a page reload, a dropped link, a laptop lid — they pick up where they stopped.
Grid, list and poster views over nested folders, with metadata pulled in automatically for the things that have it.
Share a link, not an account. Optional password, optional expiry, optional download limit.
FileHub / Chunkforge / Backups
2FA onStreaming
S
survival
3.1 GB
C
creative
840 MB
N
nether
1.2 GB
M
modpack
6.4 GB
survival — world snapshot
streaming · sha256 verified in flight · chunk 184 / 302
3.1 GB
Live
weekly-2026-08-01.tar.zst
shared link · expires in 6 days · 3 downloads left
2.7 GB
Link

Verified in flight

Every upload is hashed with SHA-256 as it streams. Nothing is held in memory waiting to be checked.

Locked down properly

Argon2id hashing, HttpOnly sessions, optional TOTP two-factor, login rate limiting and account lockout.

Sharing with limits

Public links with an optional password, an expiry date and a download cap. Registration is invite-only by default.

Twelve themes

Dark, Light, Midnight, Graphite, Ocean, Nord, Forest, Ember, Synthwave, Latte, Rosé and Mint — plus custom accents.

Downloads

Get Chunkforge.

Pick the pieces your deployment needs. Desktop alone is enough to run servers on your own machine; add a Portal the moment you want them reachable from the outside.

Standalone works with nothing else. Chunkforge Desktop runs servers on your own machine offline, with no Portal, no account and no network involvement. The Portal is what you add when you want a subdomain other people can join.
Container images

Pull, run, done.

Published on every tagged release. Ready-made Compose stacks for each of these are in the next section — copy one and it works.

Pin a release tag in production rather than :latest. A node and its Portal should move versions together — they speak one protocol, and it is easier to reason about when both ends are the same build.
Installation

Real files.
Real commands.

These are the stacks themselves, not an abridged version of them. Choose your mode, copy each file, and bring it up. The order of operations is below the code.

Order of operations

Six steps, once.

1

Point the domain, then start the Portal

Give CHUNKFORGE_PORTAL_DOMAIN — say portal.example.com — an A record at your VPS, then bring the stack up. Portal refuses to start without that variable on purpose, and Caddy needs the DNS live to complete the ACME challenge and get you a certificate.

$ docker compose -f portal.example.yml up -d
2

Create the operator account

Open https://your-domain, make the first account, then set the domain zone and port range under Settings. The public base URL is already filled in from the environment and is deliberately read-only — it is the one value everything else is derived from.

3

Publish the wildcard

One CNAME covering the whole zone, pointing at the Portal's domain. Every server you ever create lands underneath it without another DNS edit. Hand Portal a scoped Cloudflare token and it will publish this for you instead.

*.play.example.com  CNAME  portal.example.com
4

Pair the control plane

Generate a control plane pin in Portal and redeem it in Desktop under Settings → Chunkforge Portal, or in the Web panel's matching screen. Pins are typed and single-use: this one cannot enrol a node, and a node pin cannot claim a control plane.

5

Adopt each node

Generate a node pin per machine and put it in that node's CHUNKFORGE_PAIRING_PIN. It is needed only for the very first start — the node keeps the token Portal issues and reconnects by itself from then on, including after reboots and network changes.

$ docker compose -f node.example.yml up -d
6

Create a server and pick a node

That is the whole setup. From here it is the wizard: platform, version, memory, node. The subdomain is allocated automatically, players connect to it, and nothing on the hosting machine ever listened for them.

DNS

Three records.
Two of them once.

Portal allocates a public port per server and reports exactly what to publish. Set the base and the wildcard a single time; the per-server record is the only one that ever repeats — and Cloudflare automation removes even that.

RecordTypeValueHow often
portal.example.com A <your VPS IP> Once
*.play.example.com CNAME portal.example.com Once
_minecraft._tcp.<name>.play.example.com SRV 0 0 <allocated port> <portal host> Per server — or automatic

Let Portal do it

Give Portal a Cloudflare API token scoped to Zone → DNS → Edit on your zone and it publishes the wildcard and every per-server record itself. Set it in the environment up front, or later from Portal → Settings → Cloudflare DNS.

  • Records appear the moment a server is created
  • Nothing to remember when you delete one
  • The token never leaves your Portal

Or keep it manual

Leave the token unset and Portal simply reports what it needs under Subdomains. Copy the record into whatever DNS provider you already use — nothing is hidden and no third-party API is contacted.

  • Works with any provider, no integration required
  • A bare IP with no domain works too, using an A record
  • The SRV record is what lets players type the name with no port
Appearance

Eight themes,
and this page has them too.

The same eight palettes shipped in the application. Click one — the entire site repaints instantly and remembers your choice next time.

Questions

The honest answers.

Not on the machine running your servers. The node opens an outbound WebSocket to the Portal and holds it; player traffic is relayed back down that existing connection. Nothing on the node ever binds a public listener, so there is no rule to add on your router and nothing exposed to the internet.

The Portal is the one component that does accept inbound traffic — ports 80 and 443 for the control surface and TLS certificates, plus the player port range. It sits on a VPS precisely so your home network does not have to.

Yes. Chunkforge Desktop runs standalone with no Portal at all — install it, create a server, and it runs on your own machine. No account, no network calls, no domain. That is the entire local experience and it is complete on its own.

The Portal is what you add when you want the server reachable from outside your network by a name people can type. It needs a public address and a domain, which is why it lives on a VPS.

Surface, not substance. Both are control planes, and both run the exact same renderer from the same monorepo. Desktop is a native Windows application; Web is the same interface served in a browser from a container, which makes it the natural choice on a headless homelab box or when you want to reach the panel from a phone.

Web can also embed a node in the same container, so one box both manages and hosts. Desktop pairs to nodes rather than containing one.

Add as many as you like — a node is one persistent socket and a slice of the allocated port range. The default range in the example stack is a hundred ports, which is a hundred simultaneously reachable servers across every node you own; widen it in .env and in Portal → Settings if you need more.

Because Portal only relays and never runs a game server, its resource needs stay modest even with a lot of nodes attached.

No — and that is the point of the design. The console, the file browser, the add-on installer and the backup tools all travel over the same node socket. A server on a machine in another country behaves identically to one on the desk in front of you, down to editing server.properties in place.

The node reconnects on its own. The pairing pin is only needed for the very first start; after that the node holds the token Portal issued it and re-establishes the socket whenever it drops — a Portal restart, a node reboot, an ISP blip, a laptop lid closing.

Your Minecraft servers themselves keep running on the node throughout. Only routing is interrupted while the socket is down.

None. Chunkforge reads the Java requirement from the upstream project for the exact build you picked, then downloads and pins that runtime for the instance. A current Paper server and an old Forge pack can sit side by side on one machine, each with its own JDK, without you managing either.

Yes. Roles run viewer → member → admin → owner with per-project permissions, so someone can watch a console or restart a server without touching files, settings or other projects. API tokens are hashed, and pairing pins are typed and single-use so they cannot be redeemed for the wrong kind of thing.

On your hardware. On Windows, instances, runtimes and settings sit under Documents\Chunkforge; in Docker the same structure lives in the /data volume. Portal keeps only a small portal.json tracking nodes, subdomains and routes — no worlds, no backups, no player data.

Backups stay local unless you deliberately push them to a FileHub instance you also host.

Your machines.
Your world.

Stop renting a box to run something your own hardware could handle. Chunkforge gives you the panel, the routing and the polish — and leaves the servers, the worlds and the data exactly where they belong.

Copied