Running the game as a live service: how players find it, how the
community is kept safe, what a new player sees first, what we measure,
and how it reaches more people. Numbers are starting targets for beta
and are revised from data. Systems details are 03-systems.md’s; infrastructure
is 04-architecture.md’s.
| Phase | Audience | Channel | Goal |
|---|---|---|---|
| Phase 0–B | Foster only; bots and AI playtesters (D28) | None: private until launch | Feel and art sign-off, bot-measured pacing and load |
| Reveal (D29) | Everyone on web and desktop | Steam page, a playable web link anyone can open, short clips, creators | Wishlists and first-week players; retention data starts here |
| Phase C (launch) | Everyone | Steam, App Store, Google Play, web | 1–5k CCU, D30 targets below |
00-canon.md). Prices set from beta
conversion, not guessed.04-architecture.md
§3).| Surface | Launch state | Control |
|---|---|---|
| Chat | Pings, markers, raid callouts and preset phrases only (D17) | Nothing to moderate |
| Character names | Free text, 3–14 letters | Filter at creation (wordlist plus a model check), reserved list (NPC and lore names), rename on report |
| Guild names | Free text, 3–20 characters | Same filter; GM review of reported names within 24 h |
| Guild free chat (later, D17) | Verified 16+ only, opt-in | Filter, report button, 7-day log retention for review |
| Market listings, mail | Item ids and brass only, no text | Nothing to moderate |
04-architecture.md §9),
with the reported character’s last hour of actions attached.08-scale.md §10). Every action is
audited.| Phase | Moderation |
|---|---|
| Phase A | Foster and agents triage; volunteer moderators from the player council for Discord only |
| Phase B | One part-time paid community manager and moderator; GM tools v1 |
| Phase C | Two moderators covering US evenings and weekends; on-call rota for child-safety reports; agents pre-sort the queue |
The first session must teach three things only, in this order, and nothing else is required before level 10: 1. Move and fight on platforms and ropes. 2. Your lantern keeps you alive, and the dark is dangerous without it. 3. Motes go home: every Lampghost you put out banks fire that makes your town stronger.
| Step | Where | Time | Teaches |
|---|---|---|---|
| Create | Class pick in the Lodge yard: a small platform map
where any of the four can be played with its level 1–8 kit (the level-30
mobility skill arrives with branches) against dummies, switching freely,
each with its complexity label (03-systems.md §4.1); then
appearance. The base class is permanent, and players pick on how a class
moves, which a video cannot show |
≤ 4 min (yard skippable) | Class fantasy and feel |
| Prologue | Instanced: the Pilgrim’s Stair during a staged Kneeling, Fen Cobble,
the Lighting at the Vent; beat sheet in 11-prologue.md |
≤ 5 min | Move, climb; your lantern |
| First field | Mossy Field: Puddlings, motes cling to your lantern | ≤ 5 min | Fight; motes are cargo |
| First bank | Back to the foot of the Stair; the motes you banked stream up into Mossback; the Sunline gauge ticks | ≤ 3 min | Every kill matters to everyone |
| Into the live world | Step out of the instance into the live Lantern Town, crowded | — | This is an MMO |
| First party | A quest that is easier with others; party finder offered, never forced | by level 6 | Together is better |
| Lodge | Induction at 10 | ~45–60 min | Your class’s place in the world |
The Create step as built: New character opens the yard (map 20) in the client’s own sim, as the Warden; the class buttons switch on the spot, Choose goes on to naming, and Begin makes the character as the chosen class on worldd and plays it. Choosing straight away skips the yard. Appearance is not built yet and comes later.
Rules: - One new UI element per step; the HUD starts with health, the
lantern gauge and the class resource bar only. - No text box over three
lines; no screen that cannot be skipped after the first time. - The
first death happens near light and costs nothing but motes, so the
scatter rule is learned cheaply. - The bot suite plays the whole first
session on every merge (06-roadmap.md Phase 1).
Events go to Postgres events (later ClickHouse, 04-architecture.md §3),
named domain.action, each with account id, character id,
level, platform, channel, map and world time.
| Domain | Events |
|---|---|
session |
start, end, transfer,
disconnect (with reason) |
ftue |
create, step_complete (step id),
skip, first_death, first_bank,
first_party, lodge |
progress |
level_up, quest_accept,
quest_complete, quest_abandon,
branch_choose |
light |
lantern_out, relight,
motes_banked (count, where), motes_scattered,
motes_recovered |
world |
sunline_contribution, stride_change,
act_event_join, world_boss_join,
dawnmark_seen |
social |
party_join, party_leave,
guild_join, friend_add, ping,
report |
economy |
brass_in, brass_out (source or sink),
market_list, market_buy,
trade |
store |
view, purchase, subscribe,
cancel |
tech |
fps_bucket, rtt_bucket,
load_time, crash |
| Metric | Target | Why |
|---|---|---|
| First-session completion to Lodge (level 10) | 60% | The FTUE works |
| D1 | 40% | Genre norm for a good free MMO on PC |
| D7 | 20% | |
| D30 | 10% | |
| Players in a party by level 20 | 50% | Pillar 4 |
| Weekly actives banking motes to the Sunline | 60% | 08-scale.md §12 |
| Median session length | 45–75 min | Fits the 3 h cycle without demanding it |
| Payer conversion (30 days) | 3–5% | Cosmetics and subscription only |
A drop of more than 10% at any FTUE step is a release blocker for the next content push.
tr() from day one (04-architecture.md §8.4);
no text in textures; UI layouts tested at +40% string length.09-glossary.md terms translated
once and frozen per language) and native-speaker review of every quest
line before release.| Area | Requirement |
|---|---|
| Color | Hostile Lampghosts read by the coloured coldlight body plus the
stolen ember, never by cyan alone (05-art-audio.md); colorblind
presets for UI accents and raid markers |
| Light and dark | Brightness and gamma sliders; a “readable dark” option raises the floor of darkness without removing light gameplay; Glare intensity slider |
| Motion | Screen shake and footfall tremor toggles; reduce flashes option for Lampghost pops and the Second Noon |
| Text | UI scale 80–150%; Atkinson Hyperlegible as a dyslexia-friendly font option (D20); subtitles for every voiced or sung line |
| Input | Full key and button remapping; hold-to-toggle options; one-handed touch layout; auto-pickup; gamepad on desktop |
| Audio | Separate volume for music, effects, ambience and UI; visual cues for every gameplay-relevant sound (Bells, the Charge warning, Lampghosts nearby) |
| Timing | No quick-time events; every timed mechanic in solo content has a slower assist mode; raid callouts also shown as markers |
| Cognitive | Quest tracker with the next step always visible; the three FTUE lessons repeatable from the Lodge |
Accessibility options are tested by the bot suite where possible (UI scale, remapping) and by at least two disabled players in each beta phase.
Until pgBackRest lands (04-architecture.md §7.5,
D30), the game host takes nightly logical dumps. Nothing else on the
host is backed up, and nothing leaves it yet.
| Item | Setting |
|---|---|
| What | pg_dump -Fc of delve_world (worldd) and
delve_nakama (accounts), as postgres; other
databases on the host are not ours and are not touched |
| When | delve-backup.timer, 03:30 UTC nightly,
Persistent=true (a run missed while the host was down
happens at boot) |
| Where | /var/backups/delve/<db>-<UTC stamp>.dump,
root-owned dir 0700, files 0600; each dump is checked with
pg_restore --list before it is kept |
| Retention | 14 days, pruned only after a night where every dump succeeded |
| Failure | The service exits non-zero and logs to the journal
(journalctl -u delve-backup); a failed dump leaves no
partial file |
| Install | deploy/host.sh install-backups, run by every
deploy/deploy.sh; the script is installed as
/usr/local/sbin/delve-pg-backup |
| Roles | Not in the dumps: host.sh ensure-db recreates them from
/opt/delve/env |
Restore drill:
ssh fdhproperty sudo /opt/delve/app/deploy/restore-drill.sh
restores the newest delve_world dump into a scratch
database, delve_world_drill, compares count(*)
of characters with the live database, and drops the scratch
database. It only reads the live database. A mismatch fails the drill;
characters made since the dump also cause one. Run it after the first
nightly dump and after any change to the backup path.
Restoring for real: stop delve-worldd,
delve-server and delve-nakama, then
pg_restore --clean --if-exists -d <db> <dump>
as postgres, and start them again.