- Servers with caddy-docker-proxy older than 2.9 show a warning on the
Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
same default as before) and shared by Traefik, Caddy, and Sentinel.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics now covers every resource on both proxies:
- Caddy: Compose applications and services get access-log labels. The
log_append key is {uuid}-{service}, the same key Sentinel reads from
Traefik router names.
- A resource owns the Sentinel key {uuid} and every key that starts
with {uuid}-. Application pages and the traffic card now merge all
keys, so Compose applications and previews show data on Traefik too.
- Global analytics: the leaderboard groups the keys of one resource
into one row, lists services, and never names keys of other teams.
- New service analytics page (project.service.analytics) with the same
view and authorization as the application page.
- Switching the proxy type restarts Sentinel when analytics is on, so
it reads the new log path. Sentinel gets no traffic mount when the
proxy has no analytics support.
- Caddy servers show a note that resources log only after a redeploy.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ServerSetting: default is_traffic_analytics_enabled to false on the
model, so a new instance does not show null before a refresh.
- Update navbar, mobile menu, and proxy button tests to the current
redesigned UI (split action menus, settings rail, neutral icons).
- Traffic nudge test: set server_role to mark a build server, the same
as the product code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
(copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once
Terminal:
- Detect and surface WebSocket connection rejections in the browser
terminal, with shared helpers in terminal-connection.js and
terminal-utils.js
Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
restores go into a temporary database and swap in only on success,
leaving the current database untouched on failure
- Proxy: list and delete Traefik ACME certificates from the server proxy
page via new TraefikAcmeService and Get/DeleteTraefikCertificate actions
- DNS: track ownership and cross-resource references for managed DNS
records so records are only deleted when no longer referenced; release
records asynchronously on resource deletion via ReleaseManagedDnsRecordsJob
and ManagedDnsRecordCleanup; harden Cloudflare provider deletion results
- Databases: fail closed on start when prerequisites or the CA certificate
are missing (DatabaseStartException, Server::ensureCaCertificate) and
clean up stale start activities via ResourceStartActivity
- Webhooks: throttle repeated manual webhook signature failures for
GitHub, GitLab, Gitea and Bitbucket
- Deployments: improve compose build-context handling and compose file
load error reporting
- Install scripts: rework terminal UI output in install.sh (stable and
nightly)
- Misc: settings sidebar accordion fixes, log drain toggle rollback,
add Serverside to README sponsors
- Add migrations and tests covering the above
Caddy 2.7.6, shipped in the caddy-docker-proxy 2.8 image, rejects the
whole Caddyfile when it contains log_append. Add
Server::caddySupportsLogAppend(), which reads the image from the applied
proxy configuration. Traffic analytics labels now add log_append only
when the server runs 2.9 or newer and has no pending proxy change.
- Change the default Caddy proxy image from 2.8-alpine to 2.13-alpine
- ProxyPortParser now validates Docker Compose port ranges and random
host ports. It returns only fixed host ports for the availability
check and has a clearer validation message
- After mkdir, chown only root-owned files and remove other-user access
from the top directory only. Files owned by container users and the
modes of mounted files no longer change
- Add tests for log_append support and the new parser/sudo behaviour
- Note in the lessons file that tests must flush the Server identity map
between dataset cases
Replace the `realpath -m` confinement check with a POSIX sh script that
uses `readlink -f`, which BusyBox (Alpine) also provides. The script
walks up to the deepest existing path, resolves it, and appends the
missing rest. It fails closed on dangling symlinks and on `.`/`..` in
the missing part.
Send the script as a single `sh -c '<script>' sh <base> <path>` line so
the non-root sudo parser only adds sudo in front of it and does not
rewrite `$(...)`, `&&` or case statements.
Add unit tests that run the command with GNU and BusyBox tools, as root
and through the sudo parser, against a real symlink tree. Update the
feature test fakes to match the new command.
The server role migration gives every normal server the combined role, and
the build server queries counted combined servers as build servers.
"Use a build server" then built on a random production server, the resource
picker listed each server twice, and "Deployments only" did not stop builds.
- Build server selection and the picker use only "Builds only" servers.
A null role falls back to the legacy is_build_server flag.
- Without a dedicated build server, builds fall back to the deployment
server, never to another combined server.
- A "Deployments only" server always builds on a build server and needs a
Docker image name. It never builds itself, except for restarts. Docker
image and Compose applications are not affected.
- Setting "Deployments only" requires a dedicated build server.
- The API keeps is_build_server in sync with the role for downgrades.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add database-backed schedule states and deliveries so distributed schedulers publish each occurrence once, queue jobs claim executions atomically, and stale occurrences are cleaned up.
Move service application and database settings into an embedded modal with a footer, subtitle helper, and Docker restart-count control. Accept max_restart_count on the service applications API, cap compose YAML collection aliases, and tighten status, backup, and database sidebar layouts.
Remove the enable/disable toggle from the server UI, logs page, and
Sentinel API so is_sentinel_enabled is derived and read-only. Enable
existing regular servers via migration, start Sentinel after validate-
and-install, and drop the daily ServerManagerJob restart.
Centralize scp-style Git URL parsing so user@host:path (including custom
usernames and embedded ports) is accepted and converted to HTTPS for
public clones, API create, webhooks, validation, and commit/branch links.
Make clearStoredTeamIfMatches perform an atomic conditional UPDATE
so a concurrent team switch isn't clobbered, and call it for the
deleting owner in DeleteTeam so their stored team id doesn't point
at a deleted team. refreshSession now falls back to
resolveStoredTeam() instead of an arbitrary first team. Add a
return type to SelectTeam::render() and tests covering owner
deletion and concurrent-selection preservation.
Reset the user's persisted current_team_id when they are removed from
a team, when their team is deleted, or when refreshSession finds no
team left, so a dangling reference is never restored on next login.
Add current_team_id to users so the last active team is restored on
login instead of always defaulting to the personal team. When a user
belongs to multiple teams and has no valid stored choice, redirect
them to a new team.select screen (SelectTeam Livewire component) to
pick one, rather than silently choosing the first team. Update
Fortify and OAuth login flows to use the new resolveStoredTeam()
logic.