Skip to main content

Known Limits

FRP Auto Deploy is intentionally focused on lightweight remote-access management for a small number to a few dozen systems.

Current boundaries

  • TCP services only
  • Stable client scope is Linux/systemd
  • Windows and macOS client automation are not stable-supported in the current release line
  • Published-service NAT is designed around keeping the same FRP service port on the public and internal sides
  • External cloud firewalls, security groups, host firewalls, and NAT rules are not configured automatically
  • SSH accounts, passwords, SSH keys, and sshd configuration are not managed automatically
  • HTTPS application publishing is TCP passthrough; the application owns its TLS certificate
  • Some SELinux, ARM64 systemd, and older OpenSSL environments have separate validation classifications
  • Project bootstrap scripts are checksummed but are not currently cryptographically signed by the project
  • This is not a 100+ endpoint fleet-orchestration platform

Design target

The product is aimed at operators who need to make remote systems behind NAT/firewalls reachable without building a full VPN or enterprise remote-management stack. When requirements grow into large-scale policy orchestration, endpoint compliance, inventory CMDB, or hundreds/thousands of agents, use tooling designed for that scope rather than stretching FRP Auto Deploy beyond its intended operating model.
Last modified on September 7, 2026