Commit Graph
17283 Commits
Author SHA1 Message Date
Andras BacsaiandClaude Opus 5.5 dc20ffd92b fix(proxy): warn about old Caddy images and share the Caddy traffic log path
- Servers with caddy-docker-proxy older than 2.9 show a warning on the
  Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
  deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
  Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
  same default as before) and shared by Traefik, Caddy, and Sentinel.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 21:19:14 +02:00
Andras BacsaiandClaude Opus 5.5 fbfe342f89 fix(databases): reserve start and restart atomically
Two parallel start requests both passed the in-progress check and got
200, because the start activity is created later by the queued action.
A per-database reservation (Cache::add, 600 s) is now taken before the
check, so the second request gets 409. The action releases it when it
creates its activity, skips, or fails. Restart, import, the deploy
API, MCP, and Livewire use the same reservation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 21:19:14 +02:00
Andras BacsaiandClaude Opus 5.5 e31c9b3926 fix(deployments): explain skipped ARG injection for Compose build contexts
When a Compose service uses a remote Git context, variables, or an
inline Dockerfile, Coolify cannot add ARG lines, and Docker ignores
build-time variables that the Dockerfile does not declare. The log
line now gives the reason and lists the variable names (never values,
at most 10) that need an ARG line in the Dockerfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 20:27:28 +02:00
Andras BacsaiandClaude Opus 5.5 0d20a14c5c fix(terminal): show an error instead of an endless connecting spinner
When the terminal started automatically, the session timeout started
only after a token arrived. If the server returned no token (container
not running, no shell, access denied, terminal disabled), the spinner
stayed on "connecting…" until the page was reloaded.

- Every early return now sends terminal-session-failed with a short
  message; denied and unknown servers get the same text.
- Auto-start starts the session timeout in init(), so a missing token
  always ends in a visible error with "Reload page".
- With more than one container, auto-start is cancelled, so the
  container picker shows no false timeout error.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 20:27:28 +02:00
Andras BacsaiandClaude Opus 5.5 a8117f9114 fix(databases): unblock interrupted imports and prevent double starts
- A Coolify restart now fails queued or running database imports, so
  they no longer block all later imports with 409.
- An import without progress for the SSH command timeout plus 30
  minutes (at least 2 hours) is stale and no longer blocks.
- The import sets its operation property when the activity is created,
  so a worker cannot save the activity without it.
- Start and restart refuse a second operation while a start, restart,
  or import is in progress, in the UI, the API (409), and actions.
- DatabaseStartJob runs only while its activity is still queued and
  the newest one, and holds a lock per database during the commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras BacsaiandClaude Opus 5.5 bbee57a81a fix(webhooks): scope manual webhook lockouts to repository and branch
Failed manual webhook deliveries were counted per provider and source
IP. On Coolify Cloud many customers share the Git provider IP, so one
repository with a wrong secret locked out valid deliveries of all
other repositories for 60 seconds.

The failure key now also contains the repository and branch. Guessing
the secret of one application stays limited to 30 tries per minute,
and a lockout rejects all deliveries in that scope, also correct ones.
A GitLab request without a token no longer counts as a failure.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras BacsaiandClaude Opus 5.5 1e207292b6 fix(deployments): keep secrets out of failed command logs
- A failed command marked skip_command_log (for example the .env,
  build-time env, and SSH key writes) no longer puts its text into the
  exception, which was shown as the visible "Deployment failed" line
  with all secrets as base64. Its error output is also cleaned.
- Mark more secret-carrying commands as sensitive: the helper container
  with build secrets, railpack prepare, the Nixpacks plan, and Compose
  file writes.
- Dev debug lines list only variable names, not values.
- Invalid build-time variable names such as my-var stop a deployment
  only when it builds an image. Docker image deployments log a warning
  with a suggested name instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras BacsaiandClaude Opus 5.5 510a2d838b feat(analytics): log Compose resources on Caddy and add service analytics
Traffic analytics now covers every resource on both proxies:

- Caddy: Compose applications and services get access-log labels. The
  log_append key is {uuid}-{service}, the same key Sentinel reads from
  Traefik router names.
- A resource owns the Sentinel key {uuid} and every key that starts
  with {uuid}-. Application pages and the traffic card now merge all
  keys, so Compose applications and previews show data on Traefik too.
- Global analytics: the leaderboard groups the keys of one resource
  into one row, lists services, and never names keys of other teams.
- New service analytics page (project.service.analytics) with the same
  view and authorization as the application page.
- Switching the proxy type restarts Sentinel when analytics is on, so
  it reads the new log path. Sentinel gets no traffic mount when the
  proxy has no analytics support.
- Caddy servers show a note that resources log only after a redeploy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 01:00:55 +02:00
Andras Bacsai 0db2eae8de feat(proxy): show sidebar warning icon when proxy is not running
Add a proxyNotRunning flag to the server sidebar state. The Proxy menu
item's warning icon now also appears when a proxy is configured but its
status is not "running". The navbar sends the flag in the
proxy-configuration-state-changed event, so the icon updates live.

Add tests for the dispatched flag and the sidebar bindings.
2026-09-26 00:17:55 +02:00
Andras Bacsai 6daea93df4 style(ui): render danger zone as red card with Permanent badge
Wrap the danger-zone component in a bordered red-tinted card with
padding and dark-mode variants, align content to the top, switch the
title and description to neutral text colors, and add a "Permanent"
pill next to the title. Update the layout test to match.
2026-09-25 23:56:01 +02:00
Andras BacsaiandClaude Opus 5.5 f4fbcaacff fix(tests): repair tests that failed on main
- ServerSetting: default is_traffic_analytics_enabled to false on the
  model, so a new instance does not show null before a refresh.
- Update navbar, mobile menu, and proxy button tests to the current
  redesigned UI (split action menus, settings rail, neutral icons).
- Traffic nudge test: set server_role to mark a build server, the same
  as the product code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:52:01 +02:00
Andras BacsaiandClaude Opus 5.5 e17b15f5f1 fix(sources): allow private networks for self-hosted Git sources
Since GitHub App and GitLab API calls use the outbound URL guard,
GitHub Enterprise or GitLab on a private network failed with "Webhook
URL resolved to an unsafe IP address" unless an admin allow-listed it.

On self-hosted instances, Git source URLs and requests now allow
private (RFC 1918), CGNAT (100.64/10, Tailscale), and IPv6 unique local
addresses, plus internal hostnames such as .internal, .local, and
container names. Loopback, localhost, link-local (cloud metadata),
0.0.0.0, and other reserved targets stay blocked. Redirects stay off
and DNS stays pinned. Coolify Cloud and all other outbound URLs keep
the strict rules.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:52:01 +02:00
Andras BacsaiandClaude Opus 5.5 b2b8177982 fix(proxy): run legacy Traefik label migration outside a transaction
In Postgres one failed server update aborts a shared transaction, so
all later queries fail and the upgrade stops. Save each server on its
own so that one failure affects only that server.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:25:39 +02:00
Andras BacsaiandClaude Opus 5.5 f92ee342a1 fix(proxy): remove legacy Traefik dashboard labels from saved configs
Older Coolify versions saved Traefik configs with a router that sends
requests with the proxy container name as Host header (for example
traefik-coolify-proxy) on port 80 to api@internal. New installs no
longer get these labels, but saved configs keep them after an upgrade.

- Replace only the unchanged legacy labels with traefik.enable=false,
  keep comments and formatting, and skip routers the user customized.
- A migration and GetProxyConfiguration fix the saved config in the
  database only. The proxy is not restarted; the UI asks for a restart.
- Change the pending notice to "Your configuration changed, please
  restart the proxy."
- Resolve conflict markers committed in the Server Proxy component,
  which broke the proxy page.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:18:34 +02:00
Andras Bacsai 165d2f3dc8 fix: harden traffic analytics, terminal errors and Postgres restores
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
  Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
  both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
  config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
  when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
  (copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once

Terminal:
- Detect and surface WebSocket connection rejections in the browser
  terminal, with shared helpers in terminal-connection.js and
  terminal-utils.js

Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
  restores go into a temporary database and swap in only on success,
  leaving the current database untouched on failure
2026-09-25 22:58:07 +02:00
Andras Bacsai 37bd776f70 feat(services): allow variables in compose network names
Accept a top-level network `name:` that is a single Compose variable
(`${VAR}`, `${VAR:-default}`, `${VAR-default}`), e.g. for external
networks that differ per server. The default must still be a valid
network name; surrounding text, nested variables, and shell syntax
are still rejected.

When parsing services, such variables are created as service
environment variables (seeded with the default) so users can view and
change them, while the compose file keeps the variable for Compose to
resolve from .env at deployment. Existing values are preserved on
re-parse.
2026-09-25 21:43:35 +02:00
Andras Bacsai a39f3f29b6 fix(deployments): allow legacy runtime-only env var names to deploy
Runtime-only environment variables whose names new variables can no longer
use (e.g. my-var) no longer fail the deployment. They are still passed to
the container through the .env file, and the deployment log now shows a
warning with a suggested valid name.

Build-time variables, and names that would break a .env line (empty or
containing =, newline, carriage return or NUL), are still rejected.
2026-09-25 21:09:35 +02:00
Andras Bacsai 064682c210 Merge remote-tracking branch 'origin/main' 2026-09-25 20:38:07 +02:00
Andras Bacsai 554b79e8dd feat: add Traefik ACME cert UI and shared managed DNS record ownership
- Proxy: list and delete Traefik ACME certificates from the server proxy
  page via new TraefikAcmeService and Get/DeleteTraefikCertificate actions
- DNS: track ownership and cross-resource references for managed DNS
  records so records are only deleted when no longer referenced; release
  records asynchronously on resource deletion via ReleaseManagedDnsRecordsJob
  and ManagedDnsRecordCleanup; harden Cloudflare provider deletion results
- Databases: fail closed on start when prerequisites or the CA certificate
  are missing (DatabaseStartException, Server::ensureCaCertificate) and
  clean up stale start activities via ResourceStartActivity
- Webhooks: throttle repeated manual webhook signature failures for
  GitHub, GitLab, Gitea and Bitbucket
- Deployments: improve compose build-context handling and compose file
  load error reporting
- Install scripts: rework terminal UI output in install.sh (stable and
  nightly)
- Misc: settings sidebar accordion fixes, log drain toggle rollback,
  add Serverside to README sponsors
- Add migrations and tests covering the above
2026-09-25 19:00:00 +02:00
Andras Bacsai a5bcf99fa8 fix(domains): allow a new dns check to replace a stored result (#11951) 2026-09-25 14:12:51 +02:00
Andras Bacsai f276f9573f fix(previews): allow re-checking DNS over a stored completed result
Starting a DNS check for a preview domain used to leave the stored
completed status in place. That blocked the new 'checking' state from
being saved. persistDnsStatuses now takes the status keys whose checks
are being started and lets those keys overwrite what is stored.

Add tests for re-checking DNS on application domains and preview
domains that already have a completed result.
2026-09-25 14:12:27 +02:00
Andras Bacsai 84b596f7ca fix(proxy): only emit Caddy log_append on caddy-docker-proxy 2.9+
Caddy 2.7.6, shipped in the caddy-docker-proxy 2.8 image, rejects the
whole Caddyfile when it contains log_append. Add
Server::caddySupportsLogAppend(), which reads the image from the applied
proxy configuration. Traffic analytics labels now add log_append only
when the server runs 2.9 or newer and has no pending proxy change.

- Change the default Caddy proxy image from 2.8-alpine to 2.13-alpine
- ProxyPortParser now validates Docker Compose port ranges and random
  host ports. It returns only fixed host ports for the availability
  check and has a clearer validation message
- After mkdir, chown only root-owned files and remove other-user access
  from the top directory only. Files owned by container users and the
  modes of mounted files no longer change
- Add tests for log_append support and the new parser/sudo behaviour
- Note in the lessons file that tests must flush the Server identity map
  between dataset cases
2026-09-25 13:59:30 +02:00
Andras Bacsai 44b28fa6b3 Merge remote-tracking branch 'origin/main' into fix/dns-recheck-blocked-by-stored-result 2026-09-25 13:51:01 +02:00
Andras Bacsai 82bb574760 fix(servers): stop double sudo on chown/chmod after mkdir
The mkdir ownership rule prepended `sudo` to chown/chmod, and the &&
rule then added another, producing `sudo sudo`. That fails on hosts
like Alpine, where root is not in sudoers. Both parseCommandsByLineForSudo
and parseLineForSudo now leave the prefix to the && rule.

Also:
- Fix the `App\Helpers\SSLHelper` reference in RegenerateSslCertJob to
  `SslHelper`, so it autoloads on case-sensitive filesystems.
- Stop StartPostgresql and StartMongodb from overriding the configuration
  dir with a hardcoded Docker volume path in development.
- Add tests for nested sudo behaviour, the class reference letter case
  and database configuration dirs in development.
2026-09-25 13:15:57 +02:00
Andras Bacsai 3879d82b08 fix(storage): confine remote paths on BusyBox and non-root servers
Replace the `realpath -m` confinement check with a POSIX sh script that
uses `readlink -f`, which BusyBox (Alpine) also provides. The script
walks up to the deepest existing path, resolves it, and appends the
missing rest. It fails closed on dangling symlinks and on `.`/`..` in
the missing part.

Send the script as a single `sh -c '<script>' sh <base> <path>` line so
the non-root sudo parser only adds sudo in front of it and does not
rewrite `$(...)`, `&&` or case statements.

Add unit tests that run the command with GNU and BusyBox tools, as root
and through the sudo parser, against a real symlink tree. Update the
feature test fakes to match the new command.
2026-09-25 12:50:08 +02:00
Andras BacsaiandClaude Opus 5.5 338f1f837f feat(dev): run one isolated dev instance per git branch
Merge scripts/dev-instances into scripts/dev. Each branch gets its own
Compose project, container, volumes, port block, libvirt network, and
KVM VMs, so stop and start reuse the same data and worktrees do not
collide.

- Name instances after the branch; keep slots and APP_KEYs in the main
  checkout's .dev-instances/ so they survive worktree removal
- Reuse existing QEMU VMs instead of recreating them; add dev:qemu --fresh
- Give each instance an isolated libvirt network (10.221.<slot>.0/24)
  and VM names coolify-dev-<branch>--<profile>
- Publish per-instance browser ports and publish them with tailscale
  serve when APP_URL is a tailnet host
- Add urls, exec, logs, container, destroy, and teardown commands; run
  teardown from jean.json before Jean deletes a worktree
- Fix Reverb/terminal browser ports and the testing-host alias in the
  instance compose file
- Keep fresh worktree instances working: pre-create laravel.log, log the
  host dev:qemu call to stderr, and stop Vite from watching vendor/

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:55:49 +02:00
Andras BacsaiandClaude Opus 5.5 60bac941ea fix(servers): build only on dedicated build servers
The server role migration gives every normal server the combined role, and
the build server queries counted combined servers as build servers.
"Use a build server" then built on a random production server, the resource
picker listed each server twice, and "Deployments only" did not stop builds.

- Build server selection and the picker use only "Builds only" servers.
  A null role falls back to the legacy is_build_server flag.
- Without a dedicated build server, builds fall back to the deployment
  server, never to another combined server.
- A "Deployments only" server always builds on a build server and needs a
  Docker image name. It never builds itself, except for restarts. Docker
  image and Compose applications are not affected.
- Setting "Deployments only" requires a dedicated build server.
- The API keeps is_build_server in sync with the role for downgrades.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:54:00 +02:00
Andras BacsaiandClaude Opus 5.5 9e999a2782 fix(database): restore every supported backup format safely
- Detect the backup format before any database is changed. "All databases"
  imports no longer drop everything when the file cannot be restored.
- PostgreSQL: restore custom and tar archives with pg_restore and SQL with
  psql in both modes, including gzip; restore the #11481 custom-archive fix.
  Replacing existing data recreates the database for SQL backups.
- MySQL/MariaDB: accept a tar with one dump; reject dumps with more than one
  database in single mode instead of restoring them partially.
- MongoDB: restore plain and gzip archives and dump directories packed as
  tar; "Replace collections" maps to --drop.
- Prepare bz2, xz, and zip backups in the helper image, because database
  images do not ship those tools; stream S3 backups from the S3 helper.
- Show the exact restore script in the import form.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:32:04 +02:00
Andras Bacsai df692e6278 fix(auth): honor instance registration for non-OIDC OAuth providers 2026-09-25 09:11:55 +02:00
Andras Bacsai 0f41b8e6d9 fix(realtime): preserve proxy routing and browser port settings
Keep the coolify-realtime network alias for existing proxy upstreams, stop overriding PUSHER_PORT, and bind the terminal to port 6002 across production and Windows Compose files. Add regression coverage for these settings.
2026-09-25 08:24:35 +02:00
Andras Bacsai a86188f391 fix(deployment): skip missing Compose Dockerfiles with portable realpath 2026-09-25 08:00:19 +02:00
Andras Bacsai 65365752d7 fix(deployment): skip secret lookup for plain build variables 2026-09-25 07:53:04 +02:00
Andras Bacsai 19744f9c26 fix(env): prevent copying unauthorized and shown-once values
Lock compose variable lookup fields against client changes, check resource update permission before resolving references, and exclude shown-once variables from reference lookup.
2026-09-25 07:30:17 +02:00
Andras Bacsai 9b59acdb55 feat(dev): reuse prepared QEMU images for faster VM startup
Provision Docker once in a prepared image and use a seed ISO for new VMs. Switch development examples to the main branch and refresh service template timestamps.
2026-09-25 07:05:03 +02:00
Andras Bacsai 0935bf141e Improve volume path handling (#11993) 2026-09-24 23:22:35 +02:00
Andras Bacsai 50f49f093e Maintenance updates for 4.4 (#11989) 2026-09-24 23:06:03 +02:00
Andras Bacsai 5721266010 fix(server-transfer): allow local peer targets in development
Route localhost targets through host.docker.internal in containers while continuing to reject other private targets.
2026-09-24 21:28:52 +02:00
Andras Bacsai 24123c0ceb fix(mcp): decouple access from REST API settings 2026-09-24 21:18:31 +02:00
Andras Bacsai f7a05da446 fix(auth): remove email verification notice route 2026-09-24 21:07:47 +02:00
Andras Bacsai d93d90e3b0 Merge remote-tracking branch 'origin/main' into maintenance/control-plane-updates 2026-09-24 19:05:07 +02:00
Andras Bacsai c8dea4badc chore: align account lifecycle 2026-09-24 16:56:38 +02:00
Andras Bacsai 70631d2a11 fix(storage): preserve and display legacy bind mount source paths
Show existing source paths as read-only fields and label bind mounts in deployment configuration. Remove the action that could convert them to named volumes.
2026-09-24 16:49:04 +02:00
Andras Bacsai 2e928d86d8 fix: show Traefik version warnings before detection completes 2026-09-24 16:37:28 +02:00
Andras Bacsai 87685d1e09 chore: align control-plane behavior 2026-09-24 15:46:04 +02:00
Andras Bacsai 2fb8c411e9 fix(analytics): keep setup prompt dismissed after refresh
Give the traffic analytics prompt a stable Livewire key and label the server link “Set up on”. Add a browser test for the link and persistent dismissal.
2026-09-24 15:26:08 +02:00
Andras Bacsai 33eb1dab79 fix(deployments): prevent deployment queue admission races (#11987) 2026-09-24 14:07:21 +02:00
Andras Bacsai c7838c7800 ci(testing-host): publish image only to Docker Hub 2026-09-24 13:48:32 +02:00
Andras Bacsai 3f47bae0b6 fix(service): save switches without saving pending Compose edits (#11985) 2026-09-24 13:43:37 +02:00
Andras Bacsai 803cea718b fix(proxy): name Traefik logrotate sidecar container 2026-09-24 13:15:09 +02:00
Andras Bacsai f35de6b3b2 feat(dev): support KVM-backed localhost development servers 2026-09-24 13:04:44 +02:00