Commit Graph
17 Commits
Author SHA1 Message Date
Andras BacsaiandClaude Opus 5.5 129cc97047 fix(previews): remove only the preview's own networks and volumes
- Deleting a Docker Compose preview removed every top-level network
  and volume named in the compose file, so it could disconnect
  coolify-proxy from the coolify network or a shared proxy network and
  delete a shared named volume. It now removes only the network and
  volumes that Coolify generated for that preview, and a network only
  when no other container uses it.
- A deployment that stops with an explained error (unsafe compose,
  missing secret keys, invalid build variable names) shows the
  explanation once, followed by "Deployment failed.".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 14:37:21 +02:00
Andras BacsaiandClaude Opus 5.5 1e207292b6 fix(deployments): keep secrets out of failed command logs
- A failed command marked skip_command_log (for example the .env,
  build-time env, and SSH key writes) no longer puts its text into the
  exception, which was shown as the visible "Deployment failed" line
  with all secrets as base64. Its error output is also cleaned.
- Mark more secret-carrying commands as sensitive: the helper container
  with build secrets, railpack prepare, the Nixpacks plan, and Compose
  file writes.
- Dev debug lines list only variable names, not values.
- Invalid build-time variable names such as my-var stop a deployment
  only when it builds an image. Docker image deployments log a warning
  with a suggested name instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras Bacsai a39f3f29b6 fix(deployments): allow legacy runtime-only env var names to deploy
Runtime-only environment variables whose names new variables can no longer
use (e.g. my-var) no longer fail the deployment. They are still passed to
the container through the .env file, and the deployment log now shows a
warning with a suggested valid name.

Build-time variables, and names that would break a .env line (empty or
containing =, newline, carriage return or NUL), are still rejected.
2026-09-25 21:09:35 +02:00
Andras Bacsai 554b79e8dd feat: add Traefik ACME cert UI and shared managed DNS record ownership
- Proxy: list and delete Traefik ACME certificates from the server proxy
  page via new TraefikAcmeService and Get/DeleteTraefikCertificate actions
- DNS: track ownership and cross-resource references for managed DNS
  records so records are only deleted when no longer referenced; release
  records asynchronously on resource deletion via ReleaseManagedDnsRecordsJob
  and ManagedDnsRecordCleanup; harden Cloudflare provider deletion results
- Databases: fail closed on start when prerequisites or the CA certificate
  are missing (DatabaseStartException, Server::ensureCaCertificate) and
  clean up stale start activities via ResourceStartActivity
- Webhooks: throttle repeated manual webhook signature failures for
  GitHub, GitLab, Gitea and Bitbucket
- Deployments: improve compose build-context handling and compose file
  load error reporting
- Install scripts: rework terminal UI output in install.sh (stable and
  nightly)
- Misc: settings sidebar accordion fixes, log drain toggle rollback,
  add Serverside to README sponsors
- Add migrations and tests covering the above
2026-09-25 19:00:00 +02:00
Andras Bacsai a86188f391 fix(deployment): skip missing Compose Dockerfiles with portable realpath 2026-09-25 08:00:19 +02:00
Andras Bacsai 65365752d7 fix(deployment): skip secret lookup for plain build variables 2026-09-25 07:53:04 +02:00
Andras Bacsai 50643a44f8 Keep deployment logging available on formatting errors 2026-09-24 09:36:59 +02:00
Andras Bacsai b37d24d258 Improve deployment log value handling 2026-09-24 09:29:23 +02:00
Andras Bacsai 17ca63ff4c fix(deployments): validate environment variable names used in Docker commands
Reject names that are not portable identifiers before a deployment starts
and when Docker flags are built. Quote the full KEY=value assignment for
docker run -e flags, and declare generated Dockerfile ARGs as keys only.
2026-09-21 15:42:12 +02:00
Andras Bacsai 9ef1ab7649 Merge remote-tracking branch 'origin/next' into automation/sync-main-to-next
# Conflicts:
#	app/Actions/Database/StartDatabase.php
#	app/Jobs/ApplicationDeploymentJob.php
#	app/Livewire/Project/Shared/EnvironmentVariable/Show.php
#	app/Models/Application.php
#	app/Models/Service.php
#	app/Models/StandaloneClickhouse.php
#	app/Models/StandaloneDragonfly.php
#	app/Models/StandaloneKeydb.php
#	app/Models/StandaloneMariadb.php
#	app/Models/StandaloneMongodb.php
#	app/Models/StandaloneMysql.php
#	app/Models/StandalonePostgresql.php
#	app/Models/StandaloneRedis.php
#	resources/views/livewire/project/application/heading.blade.php
#	resources/views/livewire/project/service/heading.blade.php
#	tests/Feature/PersistentStorageVolumesLayoutTest.php
2026-09-02 21:19:57 +02:00
Andras BacsaiandClaude Opus 4.8 2018e7f329 Validate build-time environment variable names before writing the build .env file (#11575)
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-01 11:14:24 +02:00
Andras Bacsai 91d4467322 feat(secrets): resolve integrations across deployments and databases
Add secret manager integration links and API support, resolve referenced credentials in database startup commands, and improve environment variable handling and filtering.
2026-08-23 21:33:00 +02:00
Andras Bacsai ba179d50ac feat(secrets): add integration token and application manager APIs
Add API endpoints for creating validated secret manager tokens and configuring application secret manager settings. Suppress secret-bearing deployment command logs and redact resolved remote secrets.
2026-08-23 20:42:20 +02:00
Andras Bacsai 51461456f6 feat(secrets): resolve remote secret references at deployment
Add Doppler, Infisical, and Vault integrations with per-resource secret links, autocomplete, and deploy-time resolution for applications, services, and databases without persisting remote values.
2026-08-23 20:09:31 +02:00
Andras Bacsai d1126c02a9 fix(deployments): filter generated compose service env vars
Exclude generated Docker Compose SERVICE_FQDN, SERVICE_URL, and SERVICE_NAME variables from runtime, build-time, and build arg environments so stale stored values cannot override generated service names for preview deployments.
2026-05-13 11:59:45 +02:00
Andras Bacsai d5946dcfca fix(railpack): include scoped env vars in builds
Build Railpack variables from generic build-time vars plus Railpack-specific vars, filter unrelated buildpack control vars, and ensure curl/wget deploy apt packages are present. Add coverage for standard and preview deployments.
2026-05-11 13:29:21 +02:00
Andras Bacsai b3339d1034 feat(railpack): add buildpack control var filtering and dev seeder
Extract NIXPACKS_/RAILPACK_ prefix filtering into a reusable
`scopeWithoutBuildpackControlVariables` query scope on EnvironmentVariable.
Apply scope consistently to runtime vars, runtime preview vars, and
buildtime var generation in ApplicationDeploymentJob.

Refactor `generate_railpack_env_variables` to return a Collection.
Add `RAILPACK_FRONTEND_IMAGE` constant and bake it into the
coolify-helper Dockerfile as a build arg.

Add DevelopmentRailpackExamplesSeeder (dev/local env only) for
seeding example Railpack apps, wired into DatabaseSeeder.

Add tests:
- ApplicationDeploymentControlVarFilteringTest: verifies control vars
  are excluded from runtime and buildtime envs
- DevelopmentRailpackExamplesSeederTest: verifies seeder behavior
- ApplicationDeploymentRailpackEnvParityTest: parity checks for env
  handling across build/runtime paths
2026-04-28 14:37:31 +02:00