Foxcairn Coalhearth
Enter

Foxcairn

A cairn is a stack of stones left by travellers to mark the path for whoever comes next.

This one is private — a small node and workshop, by invitation. What is built here is meant to outlast the session it was built in.

members only · no anonymous access beyond this page

The work in hand

Coalhearth

A co-operative RPG for a group of friends who are never online at the same time. Nobody shares an instant; you share a place. Everything anyone does is still there when the next person arrives — and the world keeps moving while all of you are asleep.

That constraint removes the hardest problem in multiplayer. There is no netcode here, no prediction and no authoritative tick: every interaction is an ordinary write against shared state.

A bonfire at night ringed with set
                stones, several travellers asleep around it in different coloured cloaks
the camp at pyre — everyone logged out sleeps here, in their own dye
A finished cairn of five stacked
                stones with a lit capstone, standing in the dark
a finished waystone — five stones, five different travellers
A traveller standing at a rocky
                outcrop highlighted in gold, with a wolf approaching
a stone deposit — the only source of the game's scarcest thing

See the sprites animating → — the real atlases, running in the page at whatever speed you set.

  • The fire

    Shared, and it decays

    It burns down whether anyone is watching or not, so a group has reason to act across different evenings rather than the same one.

  • The cairns

    Built one stone at a time

    You may only ever add one to a given cairn, so a tall one is proof that several different people came the same way and each spent something scarce.

  • The walk home

    Loaded, you are slower

    Empty, you can outrun anything out there. Carrying fuel you cannot — so every further ember is a decision about what you will gamble.

The node

Built to be private first

The interesting constraint was not making it work; it was making a personal server safe to expose at all. The shape below is the answer, and everything on this page runs on it.

the guarantees
  • Nothing private is public. Every service sits behind single sign-on, enforced at the reverse proxy — not inside each application, where one missed route becomes a hole.
  • The admin plane is not on the internet. Management reaches the origin over a private mesh only; the edge closes 22 once that mesh is confirmed up, and refuses to close it before.
  • The game's API publishes no port. It trusts an identity header, which is only safe because nothing but the proxy can reach it — verified by forging it from outside and being refused at the gate.
  • No credential lives on the exposed box. Certificates are issued over HTTP, so no DNS API token is ever stored somewhere the internet can reach.
  • Deploys verify from outside. A release is checked from a different machine across the public internet, because a box asking itself whether it is up will always say yes.

Also here

The workshop

Smaller things, mostly built to solve something that was actually annoying.

  • KNR

    A single-file media renamer that turns arbitrary release names into a library a media server will actually parse.

    Python · 453 tests

  • Barrel

    A local agent and tool server running against a self-hosted model, so the parts of the network nothing else can reach still have something watching them.

    Python · no API key

  • Lodestar

    A personal operations hub — schedules, projects and notifications — with its own clients rather than a third-party push service.

    FastAPI · htmx · Android

  • This node

    Reverse proxy, SSO, forum, mail routing and the game server, deployed by one script and torn back down by another.

    Caddy · Authelia · Docker