- Servers with caddy-docker-proxy older than 2.9 show a warning on the
Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
same default as before) and shared by Traefik, Caddy, and Sentinel.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Older Coolify versions saved Traefik configs with a router that sends
requests with the proxy container name as Host header (for example
traefik-coolify-proxy) on port 80 to api@internal. New installs no
longer get these labels, but saved configs keep them after an upgrade.
- Replace only the unchanged legacy labels with traefik.enable=false,
keep comments and formatting, and skip routers the user customized.
- A migration and GetProxyConfiguration fix the saved config in the
database only. The proxy is not restarted; the UI asks for a restart.
- Change the pending notice to "Your configuration changed, please
restart the proxy."
- Resolve conflict markers committed in the Server Proxy component,
which broke the proxy page.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
(copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once
Terminal:
- Detect and surface WebSocket connection rejections in the browser
terminal, with shared helpers in terminal-connection.js and
terminal-utils.js
Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
restores go into a temporary database and swap in only on success,
leaving the current database untouched on failure
Caddy 2.7.6, shipped in the caddy-docker-proxy 2.8 image, rejects the
whole Caddyfile when it contains log_append. Add
Server::caddySupportsLogAppend(), which reads the image from the applied
proxy configuration. Traffic analytics labels now add log_append only
when the server runs 2.9 or newer and has no pending proxy change.
- Change the default Caddy proxy image from 2.8-alpine to 2.13-alpine
- ProxyPortParser now validates Docker Compose port ranges and random
host ports. It returns only fixed host ports for the availability
check and has a clearer validation message
- After mkdir, chown only root-owned files and remove other-user access
from the top directory only. Files owned by container users and the
modes of mounted files no longer change
- Add tests for log_append support and the new parser/sudo behaviour
- Note in the lessons file that tests must flush the Server identity map
between dataset cases
Apply analytics settings to existing proxy configurations while retaining custom options, including managed Traefik log rotation and Caddy traffic volumes. Upgrade new Traefik configurations to v3.7.
Use searchable repository and branch selectors, select each repository's default branch when available, and discover running container networks during proxy reconciliation.
Replace the server-scoped Analytics Livewire component with an
app-wide one that filters by server/application and supports live
refresh. Add a per-bucket status-class time series endpoint/data
class for a stacked-area chart, falling back to the donut when the
Sentinel build doesn't support it. Decorate top-path rows with their
owning domain, expand breakdown dimensions to agent/ip/useragent, and
raise path/breakdown result limits. Capture X-Forwarded-For,
User-Agent, and Referer headers in traefik access logs (now enabled
in dev too) so IP, browser, and referrer breakdowns work. Add
flag-image and referer-host helpers for geo/referrer rendering.
- Add live 24h polling toggle to server/application analytics views
- Add geo visualization (world map, country flags/names) for traffic
- Add dashboard nudge for servers eligible but not yet analytics-enabled
- Add lazy-loaded TrafficOverview widget to application General page
- Default-enable traffic analytics on new eligible server settings
- Rotate Caddy access logs via lumberjack roll options
- Add Traefik logrotate sidecar for copytruncate access-log rotation
Add strict validation for Docker network names using a regex pattern
that matches Docker's naming rules (alphanumeric start, followed by
alphanumeric, dots, hyphens, underscores).
Changes:
- Add DOCKER_NETWORK_PATTERN to ValidationPatterns with helper methods
- Validate network field in Destination creation and update Livewire components
- Add setNetworkAttribute mutator on StandaloneDocker and SwarmDocker models
- Apply escapeshellarg() to all network field usages in shell commands across
ApplicationDeploymentJob, DatabaseBackupJob, StartService, Init command,
proxy helpers, and Destination/Show
- Add comprehensive tests for pattern validation and model mutator
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Store proxy configuration in database as primary source for faster access
- Implement automatic timestamped backups when configuration changes
- Add backfill migration logic to recover configs from disk for legacy servers
- Simplify UI by removing loading states (config now readily available)
- Add comprehensive logging for debugging configuration generation and recovery
- Include unit tests for config recovery scenarios
stop explicitly re-creating networks while ensuring them since the previous IPv6 CIDR gateway workaround is no longer needed and was duplicating effort.
Fixes two critical issues preventing Traefik proxy startup:
1. TypeError when restarting proxy: Handle null return from get_traefik_versions()
- Add null check before dispatching CheckTraefikVersionForServerJob
- Log warning when version data is unavailable
- Prevents: "Argument #2 must be of type array, null given"
2. Docker network error: Filter out predefined Docker networks
- Add isDockerPredefinedNetwork() helper to centralize network filtering
- Apply filtering in collectDockerNetworksByServer() before operations
- Apply filtering in generateDefaultProxyConfiguration()
- Prevents: "operation is not permitted on predefined default network"
Also: Move $cachedVersionsFile assignment after null check in Proxy.php
Tests: Added 7 new unit tests for network filtering function
All existing tests pass with no regressions
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Fix sudo prefix bug: Use word boundary matching to prevent 'do' keyword from matching 'docker' commands
- Add ensureProxyNetworksExist() helper to create networks before docker compose up
- Ensure networks exist synchronously before dispatching async proxy startup to prevent race conditions
- Update comprehensive unit tests for sudo parsing (50 tests passing)
This resolves issues where Docker commands failed to execute with sudo on non-root servers and where proxy networks were not created before the proxy container started.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
- Add automated Traefik version checking job running weekly on Sundays
- Implement version detection from running containers and comparison with versions.json
- Add notifications across all channels (Email, Discord, Slack, Telegram, Pushover, Webhook) for outdated versions
- Create dismissible callout component with localStorage persistence
- Display cross-branch upgrade warnings (e.g., v3.5 -> v3.6) with changelog links
- Show patch update notifications within same branch
- Add warning icon that appears when callouts are dismissed
- Prevent duplicate notifications during proxy restart by adding restarting parameter
- Fix notification spam with transition-based logic for status changes
- Enable system email settings by default in development mode
- Track last saved/applied proxy settings to detect configuration drift
Upgrade default Traefik proxy configuration from v3.5 to v3.6, with Coolify version bump to beta.444.
🤖 Generated with Claude Code
Co-Authored-By: Claude <noreply@anthropic.com>
- Added a new function to extract custom proxy commands from existing Traefik configurations before regenerating the proxy configuration.
- Updated the proxy configuration generation logic to include these custom commands, ensuring they are preserved during regeneration.
- Introduced unit tests to validate the extraction of custom commands and handle various scenarios, including invalid YAML and different proxy types.
- Removed unnecessary volume mapping for production environment.
- Added insecure API access and debug logging for development environment.
- Ensured consistent handling of Docker provider exposure settings.
- Updated certificate resolver storage path for clarity.