Commit Graph
4008 Commits
Author SHA1 Message Date
Andras BacsaiandClaude Opus 5.5 dc20ffd92b fix(proxy): warn about old Caddy images and share the Caddy traffic log path
- Servers with caddy-docker-proxy older than 2.9 show a warning on the
  Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
  deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
  Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
  same default as before) and shared by Traefik, Caddy, and Sentinel.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 21:19:14 +02:00
Andras BacsaiandClaude Opus 5.5 0d20a14c5c fix(terminal): show an error instead of an endless connecting spinner
When the terminal started automatically, the session timeout started
only after a token arrived. If the server returned no token (container
not running, no shell, access denied, terminal disabled), the spinner
stayed on "connecting…" until the page was reloaded.

- Every early return now sends terminal-session-failed with a short
  message; denied and unknown servers get the same text.
- Auto-start starts the session timeout in init(), so a missing token
  always ends in a visible error with "Reload page".
- With more than one container, auto-start is cancelled, so the
  container picker shows no false timeout error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 20:27:28 +02:00
Andras BacsaiandClaude Opus 5.5 510a2d838b feat(analytics): log Compose resources on Caddy and add service analytics
Traffic analytics now covers every resource on both proxies:

- Caddy: Compose applications and services get access-log labels. The
  log_append key is {uuid}-{service}, the same key Sentinel reads from
  Traefik router names.
- A resource owns the Sentinel key {uuid} and every key that starts
  with {uuid}-. Application pages and the traffic card now merge all
  keys, so Compose applications and previews show data on Traefik too.
- Global analytics: the leaderboard groups the keys of one resource
  into one row, lists services, and never names keys of other teams.
- New service analytics page (project.service.analytics) with the same
  view and authorization as the application page.
- Switching the proxy type restarts Sentinel when analytics is on, so
  it reads the new log path. Sentinel gets no traffic mount when the
  proxy has no analytics support.
- Caddy servers show a note that resources log only after a redeploy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 01:00:55 +02:00
Andras Bacsai 0db2eae8de feat(proxy): show sidebar warning icon when proxy is not running
Add a proxyNotRunning flag to the server sidebar state. The Proxy menu
item's warning icon now also appears when a proxy is configured but its
status is not "running". The navbar sends the flag in the
proxy-configuration-state-changed event, so the icon updates live.

Add tests for the dispatched flag and the sidebar bindings.
2026-09-26 00:17:55 +02:00
Andras Bacsai 6daea93df4 style(ui): render danger zone as red card with Permanent badge
Wrap the danger-zone component in a bordered red-tinted card with
padding and dark-mode variants, align content to the top, switch the
title and description to neutral text colors, and add a "Permanent"
pill next to the title. Update the layout test to match.
2026-09-25 23:56:01 +02:00
Andras BacsaiandClaude Opus 5.5 f92ee342a1 fix(proxy): remove legacy Traefik dashboard labels from saved configs
Older Coolify versions saved Traefik configs with a router that sends
requests with the proxy container name as Host header (for example
traefik-coolify-proxy) on port 80 to api@internal. New installs no
longer get these labels, but saved configs keep them after an upgrade.

- Replace only the unchanged legacy labels with traefik.enable=false,
  keep comments and formatting, and skip routers the user customized.
- A migration and GetProxyConfiguration fix the saved config in the
  database only. The proxy is not restarted; the UI asks for a restart.
- Change the pending notice to "Your configuration changed, please
  restart the proxy."
- Resolve conflict markers committed in the Server Proxy component,
  which broke the proxy page.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:18:34 +02:00
Andras Bacsai 165d2f3dc8 fix: harden traffic analytics, terminal errors and Postgres restores
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
  Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
  both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
  config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
  when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
  (copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once

Terminal:
- Detect and surface WebSocket connection rejections in the browser
  terminal, with shared helpers in terminal-connection.js and
  terminal-utils.js

Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
  restores go into a temporary database and swap in only on success,
  leaving the current database untouched on failure
2026-09-25 22:58:07 +02:00
Andras Bacsai 554b79e8dd feat: add Traefik ACME cert UI and shared managed DNS record ownership
- Proxy: list and delete Traefik ACME certificates from the server proxy
  page via new TraefikAcmeService and Get/DeleteTraefikCertificate actions
- DNS: track ownership and cross-resource references for managed DNS
  records so records are only deleted when no longer referenced; release
  records asynchronously on resource deletion via ReleaseManagedDnsRecordsJob
  and ManagedDnsRecordCleanup; harden Cloudflare provider deletion results
- Databases: fail closed on start when prerequisites or the CA certificate
  are missing (DatabaseStartException, Server::ensureCaCertificate) and
  clean up stale start activities via ResourceStartActivity
- Webhooks: throttle repeated manual webhook signature failures for
  GitHub, GitLab, Gitea and Bitbucket
- Deployments: improve compose build-context handling and compose file
  load error reporting
- Install scripts: rework terminal UI output in install.sh (stable and
  nightly)
- Misc: settings sidebar accordion fixes, log drain toggle rollback,
  add Serverside to README sponsors
- Add migrations and tests covering the above
2026-09-25 19:00:00 +02:00
Andras BacsaiandClaude Opus 5.5 60bac941ea fix(servers): build only on dedicated build servers
The server role migration gives every normal server the combined role, and
the build server queries counted combined servers as build servers.
"Use a build server" then built on a random production server, the resource
picker listed each server twice, and "Deployments only" did not stop builds.

- Build server selection and the picker use only "Builds only" servers.
  A null role falls back to the legacy is_build_server flag.
- Without a dedicated build server, builds fall back to the deployment
  server, never to another combined server.
- A "Deployments only" server always builds on a build server and needs a
  Docker image name. It never builds itself, except for restarts. Docker
  image and Compose applications are not affected.
- Setting "Deployments only" requires a dedicated build server.
- The API keeps is_build_server in sync with the role for downgrades.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:54:00 +02:00
Andras BacsaiandClaude Opus 5.5 9e999a2782 fix(database): restore every supported backup format safely
- Detect the backup format before any database is changed. "All databases"
  imports no longer drop everything when the file cannot be restored.
- PostgreSQL: restore custom and tar archives with pg_restore and SQL with
  psql in both modes, including gzip; restore the #11481 custom-archive fix.
  Replacing existing data recreates the database for SQL backups.
- MySQL/MariaDB: accept a tar with one dump; reject dumps with more than one
  database in single mode instead of restoring them partially.
- MongoDB: restore plain and gzip archives and dump directories packed as
  tar; "Replace collections" maps to --drop.
- Prepare bz2, xz, and zip backups in the helper image, because database
  images do not ship those tools; stream S3 backups from the S3 helper.
- Show the exact restore script in the import form.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:32:04 +02:00
Andras Bacsai 70631d2a11 fix(storage): preserve and display legacy bind mount source paths
Show existing source paths as read-only fields and label bind mounts in deployment configuration. Remove the action that could convert them to named volumes.
2026-09-24 16:49:04 +02:00
Andras Bacsai 2e928d86d8 fix: show Traefik version warnings before detection completes 2026-09-24 16:37:28 +02:00
Andras Bacsai 2fb8c411e9 fix(analytics): keep setup prompt dismissed after refresh
Give the traffic analytics prompt a stable Livewire key and label the server link “Set up on”. Add a browser test for the link and persistent dismissal.
2026-09-24 15:26:08 +02:00
Andras BacsaiandClaude Opus 5.5 d1b30ce704 fix(tags): pass only the tag id when quick adding a tag
The available tags list now sends only the tag id to the Livewire
action. The component resolves the tag from the current team, so
tag names with special characters, such as apostrophes, work.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 08:26:45 +02:00
Andras Bacsai 7c86e53422 fix(service): support metadata-only deletion on unreachable servers
Add a Coolify-only deletion path, improve Docker cleanup handling, and notify teams when service deletion fails.
2026-09-23 10:50:31 +02:00
Andras Bacsai a5564320ab fix: improve terminal and realtime session handling
Commit creation was blocked because the shared Git metadata is read-only in this session. All 14 changes remain staged and ready to commit.
2026-09-22 20:17:14 +02:00
Andras Bacsai 67dd34bce7 Merge remote-tracking branch 'origin/next' into reverb-realtime-migration 2026-09-21 21:32:19 +02:00
Andras Bacsai 20a72f0f80 feat: deprecate new Docker Swarm usage and group referrers 2026-09-21 16:45:21 +02:00
Andras Bacsai 766aea933c fix(server): distinguish pending Sentinel reports from out-of-sync state 2026-09-21 12:45:28 +02:00
Andras Bacsai 1c408fb408 feat(audit): expand event tracking and remove scheduled job monitoring
Add audit levels and record user, OAuth, DNS, notification, and settings changes while removing the obsolete scheduled job monitoring UI and services.
2026-09-21 12:23:42 +02:00
Andras Bacsai a29f02fbb1 Merge remote-tracking branch 'origin/main' into pr-11443-next
# Conflicts:
#	openapi.json
#	openapi.yaml
#	resources/views/livewire/project/application/heading.blade.php
#	resources/views/livewire/project/service/heading.blade.php
2026-09-19 17:44:44 +02:00
Andras Bacsai 383a5a742f feat(servers): add configurable deployment and build roles
Introduce deployment, build, and dual-purpose server roles, with API and UI support, build-server fallback controls, and role-aware resource hosting.
2026-09-19 17:22:13 +02:00
Andras Bacsai af75492c83 feat(deployments): add team policy for build server fallback
Allow teams to choose whether deployments fall back to the deployment server when no usable dedicated build server is available.
2026-09-19 14:16:30 +02:00
Andras Bacsai 7b84e8722c fix(ui): clarify resource deployment and restart action labels
Update application and service action menus with consistent, explicit labels and align feature coverage for desktop and mobile navigation.
2026-09-18 18:57:42 +02:00
Andras Bacsai 1b0af6464f docs: clarify restart cause (#11774) 2026-09-18 14:24:48 +02:00
Andras Bacsai ce9347386d feat(ui): dashboard & resource UI refinements + reopen deployment log (#11783) 2026-09-18 12:31:07 +02:00
Andras Bacsai 9346f5f4af fix(ui): keep active settings group expanded
Ensure the group for the current page remains open despite persisted collapse state, with regression coverage.
2026-09-18 12:24:32 +02:00
Andras Bacsai ebfd4d0c1c Merge remote-tracking branch 'origin/main' into pr-11443-next
# Conflicts:
#	app/Actions/Server/StartSentinel.php
#	app/Livewire/Server/Sentinel.php
#	resources/views/livewire/project/shared/storages/all.blade.php
#	resources/views/livewire/project/shared/storages/show.blade.php
2026-09-18 12:00:04 +02:00
Aditya Tripathi ccc2a3fd57 refactor(ui): make settings filter subordinate to the global search
Two full-width, equally weighted search boxes (global ⌘K search + settings
search) sat side by side and read as duplicates. Restyle the settings one as a
quiet inline filter: borderless recessed fill instead of a bordered box, 28px
instead of 32px, 'Filter settings' instead of 'Search settings', and a subtle
focus tint. It now reads clearly as a list filter, not a second search bar.
2026-09-18 09:25:40 +00:00
Aditya Tripathi df83ea2b17 feat(ui): search results show category/parent + include sub-pages
Build a flat search index for the application settings sidebar: every page plus
its in-page sub-sections. Each result now renders with a breadcrumb (its
category, and the parent page for a sub-section), and the query matches
sub-pages too (e.g. searching 'proxy' finds Advanced > Proxy). While searching,
the accordion is replaced by this flat result list; clearing restores it.
2026-09-18 09:18:05 +00:00
Aditya Tripathi d645ce1644 feat(ui): search box on the application settings sidebar
The application settings sidebar is long, so add a client-side search that
filters the nav items as you type. While searching it flattens the list (hides
group headers/dividers and in-page sub-sections) and shows a 'no results' hint;
clearing it restores the accordion. Extends the shared settingsSidebarAccordion
Alpine helper (search/matches/hasResults) so other sidebars can opt in later.
2026-09-18 09:13:38 +00:00
Aditya Tripathi 1151449221 fix(ui): collapse non-active sub-sections + accordion on inline service nav
Follow-up to the settings-sidebar accordion. Two gaps:

- Application sidebar rendered every item's in-page sub-sections, so Advanced's
  Build/Container/Deployment/… showed while you were on General. Gate the
  nav-children on the active item so only the current page's sub-sections expand
  (database/service/server already did this).
- The service *main* configuration page renders its nav inline (the component is
  only used by service sub-pages), so it missed the accordion. Wire it up there
  too.

Extends the regression test to cover both.
2026-09-18 08:59:38 +00:00
Andras Bacsai 8a2457da93 feat(storages): support selective archive deletion for backup schedules
Allow local and S3 archives to be deleted independently when removing a
volume backup schedule, and consolidate destructive-action layouts with a
shared danger-zone component.
2026-09-17 21:20:06 +02:00
Andras Bacsai 84e80142bc fix(storages): make volume backup executions responsive on mobile
Stack execution details into labeled mobile rows and keep archive paths visible with copy actions.
2026-09-17 19:27:18 +02:00
Aditya Tripathi 7585480670 feat(ui): collapse resource settings sidebar groups into an accordion
Discussion #11833: since v4.3.19 the resource settings sidebar expands every
group by default, so reaching Backups etc. means scrolling past every section.

Restore the v4.3.18 behaviour across all grouped resource sidebars (application,
database, service, server): each group header is now a collapsible toggle, and
only the group containing the active page is open by default. Manual expand/
collapse is remembered per resource type in localStorage; an explicit collapse
sticks even for the active group. Desktop (xl) only — the mobile grid is
unchanged (display:contents wrapper + xl-scoped collapse).

- new shared Alpine provider settingsSidebarAccordion (resources/js) + app.js
- nav-section-toggle utility (chevron header)
- wired into the four grouped sidebars
- static regression test
2026-09-16 12:39:14 +00:00
Andras Bacsai 128939b062 fix(storages): remove host path from storage configuration 2026-09-16 14:24:52 +02:00
Andras Bacsai 011d8bdb2a fix(storages): keep volume actions on one line 2026-09-16 14:13:44 +02:00
Andras Bacsai 34b3318639 fix(deployments): preserve and display pull request filters
Include configured previews in pull request options and show the active filter.
2026-09-16 14:02:31 +02:00
Andras Bacsai 63f26aefd9 feat(previews): move pull request settings into a modal
Add pull request loading, refreshing, and deployment controls to the preview settings modal, simplify modal subtitles, and update sponsor listings.
2026-09-16 13:51:18 +02:00
Aditya Tripathi 2f5b03aee0 Merge remote-tracking branch 'origin/next' into coolify-dashboard-ui-refinements 2026-09-16 11:17:04 +00:00
Andras Bacsai 16b092336e feat(sentinel): track synchronization state and refresh status UI
Add sentinel waiting-state tracking, synchronization broadcasts, and restore
status handling across server and application interfaces.
2026-09-16 12:51:27 +02:00
Andras Bacsai d3a6cb2343 fix(teams): redirect team switches to the dashboard 2026-09-16 11:20:32 +02:00
github-actions[bot] 69d1e89ac2 Merge remote-tracking branch 'origin/main' into next 2026-09-16 03:14:20 +00:00
Andras Bacsai 8ab54da2ac style(ui): remove description placeholders and normalize control heights 2026-09-15 12:28:16 +02:00
Aditya Tripathi d152db3dd2 Merge remote-tracking branch 'origin/next' into coolify-dashboard-ui-refinements 2026-09-14 11:37:30 +00:00
Andras Bacsai 2c1744fbd2 Merge remote-tracking branch 'origin/next' into pr-11784-automation/sync-main-to-next 2026-09-14 13:30:17 +02:00
Andras Bacsai 6a8cee4630 Merge remote-tracking branch 'origin/next' into automation/sync-main-to-next 2026-09-14 13:26:19 +02:00
Aditya Tripathi f39fa67cf0 fix(notifications): add canGate/canResource authorization to channel buttons
Per the repo's form-authorization guideline (flagged in review), the enable/
disable and send-test buttons now pass canGate/canResource so they gate on the
policy server-side, not just the browser :disabled. The 5 channel pages pass
their $settings resource; the toggle/test Livewire methods already authorize.
2026-09-14 10:11:17 +00:00
Aditya Tripathi 28de75af32 fix: address review — minio mc build stage + settings sidebar sticky
- docker/development/Dockerfile: the minio-client build stage pulled
  minio/mc:${MINIO_VERSION} from Docker Hub (now 404), which fails a clean image
  build; repoint to quay.io/minio/mc with the same pinned tag
- shared-variables layout: drop inline xl:sticky/xl:top-26 (SettingsSidebarStickyTest
  forbids them); sticky positioning comes from the shared .application-settings-navigation
  CSS rule
2026-09-14 10:05:47 +00:00
Aditya Tripathi 7a96f0900d fix(ui): follow-up polish + extend deploy-log reopen to apps
- Fix DB URL copy button: a Blade @if inside the <x-copy-button> tag silently
  broke the component; compute the resolve expression in PHP and pass one attr
- Sidebar: show section dividers between groups in the collapsed rail
- Project cards/list + dashboard: use the app's styled tooltip (data-tooltip) on
  the env/resource icon stats, and lift them above the card link overlay so they
  actually receive hover
- Applications: show the persistent 'Deploying… View log' indicator (links to the
  running deployment's log page) in the heading, extending the reopen feature to
  all resource types
- Shared variables: use the canonical application-settings-workspace stacked,
  sticky sidebar to match other settings pages
- Environment page: add a 'Shared variables' shortcut to the dedicated page
2026-09-14 07:12:11 +00:00