A Docker Compose application could use ${VAR} as a network name, but
only services created the variable. With ${VAR:-default} the value was
hidden and could not be edited; with ${VAR} Compose got an empty name
and the deployment failed. Applications now get the variable (and its
preview copy) with the default from the compose file, like services.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Servers with caddy-docker-proxy older than 2.9 show a warning on the
Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
same default as before) and shared by Traefik, Caddy, and Sentinel.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- A Coolify restart now fails queued or running database imports, so
they no longer block all later imports with 409.
- An import without progress for the SSH command timeout plus 30
minutes (at least 2 hours) is stale and no longer blocks.
- The import sets its operation property when the activity is created,
so a worker cannot save the activity without it.
- Start and restart refuse a second operation while a start, restart,
or import is in progress, in the UI, the API (409), and actions.
- DatabaseStartJob runs only while its activity is still queued and
the newest one, and holds a lock per database during the commands.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics now covers every resource on both proxies:
- Caddy: Compose applications and services get access-log labels. The
log_append key is {uuid}-{service}, the same key Sentinel reads from
Traefik router names.
- A resource owns the Sentinel key {uuid} and every key that starts
with {uuid}-. Application pages and the traffic card now merge all
keys, so Compose applications and previews show data on Traefik too.
- Global analytics: the leaderboard groups the keys of one resource
into one row, lists services, and never names keys of other teams.
- New service analytics page (project.service.analytics) with the same
view and authorization as the application page.
- Switching the proxy type restarts Sentinel when analytics is on, so
it reads the new log path. Sentinel gets no traffic mount when the
proxy has no analytics support.
- Caddy servers show a note that resources log only after a redeploy.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Older Coolify versions saved Traefik configs with a router that sends
requests with the proxy container name as Host header (for example
traefik-coolify-proxy) on port 80 to api@internal. New installs no
longer get these labels, but saved configs keep them after an upgrade.
- Replace only the unchanged legacy labels with traefik.enable=false,
keep comments and formatting, and skip routers the user customized.
- A migration and GetProxyConfiguration fix the saved config in the
database only. The proxy is not restarted; the UI asks for a restart.
- Change the pending notice to "Your configuration changed, please
restart the proxy."
- Resolve conflict markers committed in the Server Proxy component,
which broke the proxy page.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
(copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once
Terminal:
- Detect and surface WebSocket connection rejections in the browser
terminal, with shared helpers in terminal-connection.js and
terminal-utils.js
Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
restores go into a temporary database and swap in only on success,
leaving the current database untouched on failure
Accept a top-level network `name:` that is a single Compose variable
(`${VAR}`, `${VAR:-default}`, `${VAR-default}`), e.g. for external
networks that differ per server. The default must still be a valid
network name; surrounding text, nested variables, and shell syntax
are still rejected.
When parsing services, such variables are created as service
environment variables (seeded with the default) so users can view and
change them, while the compose file keeps the variable for Compose to
resolve from .env at deployment. Existing values are preserved on
re-parse.
Caddy 2.7.6, shipped in the caddy-docker-proxy 2.8 image, rejects the
whole Caddyfile when it contains log_append. Add
Server::caddySupportsLogAppend(), which reads the image from the applied
proxy configuration. Traffic analytics labels now add log_append only
when the server runs 2.9 or newer and has no pending proxy change.
- Change the default Caddy proxy image from 2.8-alpine to 2.13-alpine
- ProxyPortParser now validates Docker Compose port ranges and random
host ports. It returns only fixed host ports for the availability
check and has a clearer validation message
- After mkdir, chown only root-owned files and remove other-user access
from the top directory only. Files owned by container users and the
modes of mounted files no longer change
- Add tests for log_append support and the new parser/sudo behaviour
- Note in the lessons file that tests must flush the Server identity map
between dataset cases
The mkdir ownership rule prepended `sudo` to chown/chmod, and the &&
rule then added another, producing `sudo sudo`. That fails on hosts
like Alpine, where root is not in sudoers. Both parseCommandsByLineForSudo
and parseLineForSudo now leave the prefix to the && rule.
Also:
- Fix the `App\Helpers\SSLHelper` reference in RegenerateSslCertJob to
`SslHelper`, so it autoloads on case-sensitive filesystems.
- Stop StartPostgresql and StartMongodb from overriding the configuration
dir with a hardcoded Docker volume path in development.
- Add tests for nested sudo behaviour, the class reference letter case
and database configuration dirs in development.
Reject names that are not portable identifiers before a deployment starts
and when Docker flags are built. Quote the full KEY=value assignment for
docker run -e flags, and declare generated Dockerfile ARGs as keys only.
Use the shared Docker container-name rules for custom internal names
in the API and Advanced settings form. Quote container names in
deployment inspect, log, and stop commands.
Use the existing git ref validator when a deployment is queued and
when a queued deployment starts, so only well-formed commit values
are stored and used.
Apply analytics settings to existing proxy configurations while retaining custom options, including managed Traefik log rotation and Caddy traffic volumes. Upgrade new Traefik configurations to v3.7.
API log endpoints and the GetLogs UI now treat `all` as unbounded
output, with `-1` remaining as a compatibility alias. MCP still
falls back to a positive default. Traefik version checks run from
CheckForUpdatesJob instead of a weekly schedule.
Normalize schemes when comparing routing identities and include per-service
Compose domains in conflict checks. Show the conflicting service name and
align the service domains heading layout.
Centralize scp-style Git URL parsing so user@host:path (including custom
usernames and embedded ports) is accepted and converted to HTTPS for
public clones, API create, webhooks, validation, and commit/branch links.
Use resolveStoredTeam() instead of teams()->first() when picking the
next active team after a team deletion or when an admin switches into
a user's account, so a valid stored preference wins over an arbitrary
first team. DeleteTeam now returns null when the deletion leaves the
owner with multiple teams, deferring to the selection screen instead
of guessing. refreshSession also stops persisting current_team_id
while impersonating, so viewing another user's account no longer
overwrites their real last-active team.
Make clearStoredTeamIfMatches perform an atomic conditional UPDATE
so a concurrent team switch isn't clobbered, and call it for the
deleting owner in DeleteTeam so their stored team id doesn't point
at a deleted team. refreshSession now falls back to
resolveStoredTeam() instead of an arbitrary first team. Add a
return type to SelectTeam::render() and tests covering owner
deletion and concurrent-selection preservation.
Reset the user's persisted current_team_id when they are removed from
a team, when their team is deleted, or when refreshSession finds no
team left, so a dangling reference is never restored on next login.
Add current_team_id to users so the last active team is restored on
login instead of always defaulting to the personal team. When a user
belongs to multiple teams and has no valid stored choice, redirect
them to a new team.select screen (SelectTeam Livewire component) to
pick one, rather than silently choosing the first team. Update
Fortify and OAuth login flows to use the new resolveStoredTeam()
logic.