Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
(copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once
Terminal:
- Detect and surface WebSocket connection rejections in the browser
terminal, with shared helpers in terminal-connection.js and
terminal-utils.js
Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
restores go into a temporary database and swap in only on success,
leaving the current database untouched on failure
Merge scripts/dev-instances into scripts/dev. Each branch gets its own
Compose project, container, volumes, port block, libvirt network, and
KVM VMs, so stop and start reuse the same data and worktrees do not
collide.
- Name instances after the branch; keep slots and APP_KEYs in the main
checkout's .dev-instances/ so they survive worktree removal
- Reuse existing QEMU VMs instead of recreating them; add dev:qemu --fresh
- Give each instance an isolated libvirt network (10.221.<slot>.0/24)
and VM names coolify-dev-<branch>--<profile>
- Publish per-instance browser ports and publish them with tailscale
serve when APP_URL is a tailnet host
- Add urls, exec, logs, container, destroy, and teardown commands; run
teardown from jean.json before Jean deletes a worktree
- Fix Reverb/terminal browser ports and the testing-host alias in the
instance compose file
- Keep fresh worktree instances working: pre-create laravel.log, log the
host dev:qemu call to stderr, and stop Vite from watching vendor/
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add Doppler, Infisical, and Vault integrations with per-resource secret links, autocomplete, and deploy-time resolution for applications, services, and databases without persisting remote values.
Add manual fix-release validation and stable image rebuilds, inject traceable development versions into SHA builds, and suppress invalid release links for development versions.
The pinned cloudflared 2025.7.0 is built with Go 1.24.4 and grpc
v1.72.2, which carry two CRITICAL vulnerabilities:
- CVE-2025-68121 (crypto/tls: incorrect certificate validation
during TLS session resumption), fixed in Go 1.24.13
- CVE-2026-33186 (grpc-go authz: authorization bypass due to
improper HTTP/2 path validation), fixed in grpc 1.79.3
cloudflared 2026.7.3 ships patched Go/grpc; a Trivy scan of the
official linux-amd64 binary reports zero CRITICAL findings.
Introduce V5Feature and config so V5 routes, jobs, commands, morph maps,
and model queries run only when enabled. Move V5 migrations to
migrations-v5 (loaded only when enabled), remove Flux from production
Docker/install paths, and add isolation tests.
Keep the dev container as root for s6 init so composer can create
vendor/ on root-owned mounts, then chown writable paths to www-data.
Move init-setup into a shell script and expose VITE_HOST/PORT for
remote HMR (LAN/Tailscale) with Vite listening on 0.0.0.0.
Split V5 dashboard behavior into domain controllers and policies,
add agent token rotation/revocation, status reconciliation jobs,
ingress firewall syncing, and canvas connection APIs.
Add migrations for V5 status tracking, server capabilities, resource
connection aliases, and revoked agent tokens.
Adds v5 routing, middleware, home page rendering, team context sharing,
project model/table support, and Flux health reporting. Installs Flux in
container builds with role-aware s6 services and documents runtime roles.
Run Laravel Reverb and the terminal server inside the Coolify container instead of shipping a separate coolify-realtime image. Update compose files, proxy routing, cleanup behavior, and packaging tests for the embedded realtime services.