Commit Graph
115 Commits
Author SHA1 Message Date
Andras BacsaiandClaude Opus 5.5 dc20ffd92b fix(proxy): warn about old Caddy images and share the Caddy traffic log path
- Servers with caddy-docker-proxy older than 2.9 show a warning on the
  Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
  deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
  Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
  same default as before) and shared by Traefik, Caddy, and Sentinel.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 21:19:14 +02:00
Andras BacsaiandClaude Opus 5.5 f92ee342a1 fix(proxy): remove legacy Traefik dashboard labels from saved configs
Older Coolify versions saved Traefik configs with a router that sends
requests with the proxy container name as Host header (for example
traefik-coolify-proxy) on port 80 to api@internal. New installs no
longer get these labels, but saved configs keep them after an upgrade.

- Replace only the unchanged legacy labels with traefik.enable=false,
  keep comments and formatting, and skip routers the user customized.
- A migration and GetProxyConfiguration fix the saved config in the
  database only. The proxy is not restarted; the UI asks for a restart.
- Change the pending notice to "Your configuration changed, please
  restart the proxy."
- Resolve conflict markers committed in the Server Proxy component,
  which broke the proxy page.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:18:34 +02:00
Andras Bacsai 165d2f3dc8 fix: harden traffic analytics, terminal errors and Postgres restores
Traffic analytics:
- Reject enabling unless the server runs a Coolify-managed Traefik or
  Caddy proxy, and show the reason in the settings UI
- Save the proxy configuration before the setting so a failure leaves
  both unchanged; allow disabling after the proxy was removed
- Skip the proxy restart when the proxy is stopped and report that the
  config applies on next start
- Preserve the user's own Traefik --accesslog* flags and restore them
  when analytics is disabled
- Rotate the Traefik access log in the sidecar with BusyBox tools
  (copytruncate, 5 gzip rotations)
- Create the access log before starting Sentinel, which opens it once

Terminal:
- Detect and surface WebSocket connection rejections in the browser
  terminal, with shared helpers in terminal-connection.js and
  terminal-utils.js

Database import:
- Restore PostgreSQL backups in a single transaction; SQL replace
  restores go into a temporary database and swap in only on success,
  leaving the current database untouched on failure
2026-09-25 22:58:07 +02:00
Andras Bacsai 84b596f7ca fix(proxy): only emit Caddy log_append on caddy-docker-proxy 2.9+
Caddy 2.7.6, shipped in the caddy-docker-proxy 2.8 image, rejects the
whole Caddyfile when it contains log_append. Add
Server::caddySupportsLogAppend(), which reads the image from the applied
proxy configuration. Traffic analytics labels now add log_append only
when the server runs 2.9 or newer and has no pending proxy change.

- Change the default Caddy proxy image from 2.8-alpine to 2.13-alpine
- ProxyPortParser now validates Docker Compose port ranges and random
  host ports. It returns only fixed host ports for the availability
  check and has a clearer validation message
- After mkdir, chown only root-owned files and remove other-user access
  from the top directory only. Files owned by container users and the
  modes of mounted files no longer change
- Add tests for log_append support and the new parser/sudo behaviour
- Note in the lessons file that tests must flush the Server identity map
  between dataset cases
2026-09-25 13:59:30 +02:00
Andras Bacsai 803cea718b fix(proxy): name Traefik logrotate sidecar container 2026-09-24 13:15:09 +02:00
Andras Bacsai aa2b6b862b fix(compose): validate Docker network names
Require Compose network names to match Docker identifier rules.
Ensure missing proxy networks with inspect and a single escaped argument.
2026-09-21 15:30:11 +02:00
Andras Bacsai b8f630be6b fix(proxy): prevent automatic Traefik self-exposure 2026-09-21 15:06:01 +02:00
Andras Bacsai 9bae1530bf fix(proxy): preserve custom config when toggling traffic analytics
Apply analytics settings to existing proxy configurations while retaining custom options, including managed Traefik log rotation and Caddy traffic volumes. Upgrade new Traefik configurations to v3.7.
2026-09-21 13:07:29 +02:00
Andras Bacsai c68259cddf Merge remote-tracking branch 'origin/next' into coolify-analytics-traefik-caddy 2026-09-07 20:28:42 +02:00
Andras Bacsai 16352fad23 fix(proxy): restore project networks after host reboot (#11476) 2026-08-24 00:22:29 +02:00
Aditya Tripathi b2fb22934c Merge remote-tracking branch 'origin/next' into coolify-analytics-traefik-caddy
# Conflicts:
#	app/Models/ServerSetting.php
#	package-lock.json
#	package.json
#	resources/views/components/forms/listbox.blade.php
2026-08-20 09:33:47 +00:00
Andras Bacsai 0d23b29775 fix: honor GitHub default branches and reconcile proxy networks
Use searchable repository and branch selectors, select each repository's default branch when available, and discover running container networks during proxy reconciliation.
2026-08-18 09:16:29 +02:00
Aditya Tripathi a5cfa7c238 feat(traffic): add global analytics page with status time series
Replace the server-scoped Analytics Livewire component with an
app-wide one that filters by server/application and supports live
refresh. Add a per-bucket status-class time series endpoint/data
class for a stacked-area chart, falling back to the donut when the
Sentinel build doesn't support it. Decorate top-path rows with their
owning domain, expand breakdown dimensions to agent/ip/useragent, and
raise path/breakdown result limits. Capture X-Forwarded-For,
User-Agent, and Referer headers in traefik access logs (now enabled
in dev too) so IP, browser, and referrer breakdowns work. Add
flag-image and referer-host helpers for geo/referrer rendering.
2026-08-12 08:50:58 +00:00
Aditya Tripathi 872f8aafb8 feat(traffic): add live refresh, geo maps, and app overview widget
- Add live 24h polling toggle to server/application analytics views
- Add geo visualization (world map, country flags/names) for traffic
- Add dashboard nudge for servers eligible but not yet analytics-enabled
- Add lazy-loaded TrafficOverview widget to application General page
- Default-enable traffic analytics on new eligible server settings
- Rotate Caddy access logs via lumberjack roll options
- Add Traefik logrotate sidecar for copytruncate access-log rotation
2026-08-11 10:55:50 +00:00
Aditya Tripathi 0c06b5e0d1 fix(traffic): validate sentinel app keys, gate caddy log volume + swarm toggle, null-safe link 2026-08-11 03:32:16 +00:00
Aditya Tripathi bb7ad7ab12 feat(traffic): stamp coolify_app_id + JSON access log on Caddy sites 2026-08-10 19:27:57 +00:00
Aditya Tripathi e8e651bd7e feat(traffic): enable Traefik JSON access log when analytics on 2026-08-10 19:19:42 +00:00
Andras Bacsai 07f381b88c Merge remote-tracking branch 'origin/next' into jean/port-exposes-improvement 2026-06-03 10:32:57 +02:00
Andras Bacsai 7542c71dc4 Merge remote-tracking branch 'origin/next' into 2731-investigate-failed-git-clone 2026-04-03 09:05:13 +02:00
Andras BacsaiandClaude Opus 4.6 3d1b9f53a0 fix: add validation and escaping for Docker network names
Add strict validation for Docker network names using a regex pattern
that matches Docker's naming rules (alphanumeric start, followed by
alphanumeric, dots, hyphens, underscores).

Changes:
- Add DOCKER_NETWORK_PATTERN to ValidationPatterns with helper methods
- Validate network field in Destination creation and update Livewire components
- Add setNetworkAttribute mutator on StandaloneDocker and SwarmDocker models
- Apply escapeshellarg() to all network field usages in shell commands across
  ApplicationDeploymentJob, DatabaseBackupJob, StartService, Init command,
  proxy helpers, and Destination/Show
- Add comprehensive tests for pattern validation and model mutator

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-28 12:28:59 +01:00
Andras Bacsai 6488751fd2 feat(proxy): add database-backed config storage with disk backups
- Store proxy configuration in database as primary source for faster access
- Implement automatic timestamped backups when configuration changes
- Add backfill migration logic to recover configs from disk for legacy servers
- Simplify UI by removing loading states (config now readily available)
- Add comprehensive logging for debugging configuration generation and recovery
- Include unit tests for config recovery scenarios
2026-03-11 14:11:31 +01:00
Andras Bacsai 4015e03153 fix(proxy): remove ipv6 cidr network remediation
stop explicitly re-creating networks while ensuring them since the previous IPv6 CIDR gateway workaround is no longer needed and was duplicating effort.
2026-03-04 11:36:52 +01:00
Andras Bacsai 236745ede1 chore: prepare for PR 2026-03-01 18:49:40 +01:00
Andras BacsaiandClaude cb0f2301f5 Fix: Traefik proxy startup issues - handle null versions and filter predefined networks
Fixes two critical issues preventing Traefik proxy startup:

1. TypeError when restarting proxy: Handle null return from get_traefik_versions()
   - Add null check before dispatching CheckTraefikVersionForServerJob
   - Log warning when version data is unavailable
   - Prevents: "Argument #2 must be of type array, null given"

2. Docker network error: Filter out predefined Docker networks
   - Add isDockerPredefinedNetwork() helper to centralize network filtering
   - Apply filtering in collectDockerNetworksByServer() before operations
   - Apply filtering in generateDefaultProxyConfiguration()
   - Prevents: "operation is not permitted on predefined default network"

Also: Move $cachedVersionsFile assignment after null check in Proxy.php

Tests: Added 7 new unit tests for network filtering function
All existing tests pass with no regressions

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-28 17:53:26 +01:00
Andras BacsaiandClaude 246e3cd8a2 fix: resolve Docker validation race conditions and sudo prefix bug
- Fix sudo prefix bug: Use word boundary matching to prevent 'do' keyword from matching 'docker' commands
- Add ensureProxyNetworksExist() helper to create networks before docker compose up
- Ensure networks exist synchronously before dispatching async proxy startup to prevent race conditions
- Update comprehensive unit tests for sudo parsing (50 tests passing)

This resolves issues where Docker commands failed to execute with sudo on non-root servers and where proxy networks were not created before the proxy container started.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-27 09:04:42 +01:00
Andras Bacsai 29bf4d29f0 fix(proxy): remove debugging ray call from Traefik version retrieval 2025-11-17 15:03:20 +01:00
Andras Bacsai 8c77c63043 feat(proxy): add Traefik version tracking with notifications and dismissible UI warnings
- Add automated Traefik version checking job running weekly on Sundays
- Implement version detection from running containers and comparison with versions.json
- Add notifications across all channels (Email, Discord, Slack, Telegram, Pushover, Webhook) for outdated versions
- Create dismissible callout component with localStorage persistence
- Display cross-branch upgrade warnings (e.g., v3.5 -> v3.6) with changelog links
- Show patch update notifications within same branch
- Add warning icon that appears when callouts are dismissed
- Prevent duplicate notifications during proxy restart by adding restarting parameter
- Fix notification spam with transition-based logic for status changes
- Enable system email settings by default in development mode
- Track last saved/applied proxy settings to detect configuration drift
2025-11-14 11:35:22 +01:00
Andras BacsaiandClaude f731ec74e6 feat(proxy): upgrade Traefik image to v3.6
Upgrade default Traefik proxy configuration from v3.5 to v3.6, with Coolify version bump to beta.444.

🤖 Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-14 09:31:07 +01:00
Andras Bacsai 9656855cef fix(proxy): downgrade Traefik image version from v3.6 to v3.5 in default proxy configuration 2025-11-13 14:51:47 +01:00
Andras Bacsai afdc4f92fe fix(proxy): update Traefik image version to v3.6 in default proxy configuration 2025-11-12 08:18:29 +01:00
Andras Bacsai cef3d3af5d feat(proxy): enhance proxy configuration regeneration by extracting custom commands
- Added a new function to extract custom proxy commands from existing Traefik configurations before regenerating the proxy configuration.
- Updated the proxy configuration generation logic to include these custom commands, ensuring they are preserved during regeneration.
- Introduced unit tests to validate the extraction of custom commands and handle various scenarios, including invalid YAML and different proxy types.
2025-10-07 11:11:13 +02:00
Andras Bacsai 1ca94b90da fix(proxy): replace CheckConfiguration with GetProxyConfiguration and SaveConfiguration with SaveProxyConfiguration for improved clarity and consistency in proxy management 2025-09-09 12:52:19 +02:00
Aditya Tripathi 8a35295f13 fix(proxy): filter host network from default proxy (#6383) 2025-08-18 17:48:24 +02:00
Andras Bacsai ddcb14500d refactor(proxy-status): refactored how the proxy status is handled on the UI and on the backend
feat(cloudflare): improved cloudflare tunnel automated installation
2025-06-06 14:47:54 +02:00
Andras Bacsai 24b7b53973 Revert "fix(dev): mount points?!"
This reverts commit 365bf3cbf0.
2025-05-05 08:55:44 +02:00
Andras Bacsai cf7a6eccab fix(dev): proxy mount point 2025-05-03 12:44:32 +02:00
Andras Bacsai 365bf3cbf0 fix(dev): mount points?! 2025-05-03 09:59:42 +02:00
Andras Bacsai 773caf7fd5 feat(core): add name to default proxy configuration 2025-02-03 21:24:01 +01:00
Andras Bacsai 8be536d3ec fix(core): increase HTTP/2 max concurrent streams to 250 (default) 2025-02-02 14:03:18 +01:00
Hederson Boechat 071cabdc31 fix(proxy) update traefik proxy config for docker swarm 2025-01-23 11:57:34 -03:00
Andras Bacsai f82d95e908 refactor: update Traefik configuration for improved security and logging
- Removed unnecessary volume mapping for production environment.
- Added insecure API access and debug logging for development environment.
- Ensured consistent handling of Docker provider exposure settings.
- Updated certificate resolver storage path for clarity.
2024-12-06 13:07:56 +01:00
Lucas Michot 1ec224fde1 Inline many variables. 2024-10-31 18:20:11 +01:00
Lucas Michot 8e1444eaa7 Get rid of many useless blank lines 2024-10-31 17:44:01 +01:00
Andras Bacsai 52caa045c9 Merge branch 'next' into proxy-fixes 2024-10-21 15:08:13 +02:00
peaklabs-dev 3984eda4db fix: make sure caddy is not removed by cleanup 2024-10-14 21:35:20 +02:00
🏔️ Peak 2f84664996 Merge pull request #3813 from lynt-smitka/fix-caddy-quic-udp-port
Fix caddy quic udp port
2024-10-14 15:07:18 +02:00
Darren Sisson c1b996ef05 add https3 support to traefik and fix 404 redirect for traefik3 2024-10-10 18:47:01 +01:00
Vladimír Smitka a094eceb62 Expose port 443/udp with Caddy proxy 2024-10-09 18:34:17 +02:00
Andras Bacsai fe20480fdc fix: proxy 2024-09-28 11:14:14 +02:00
Andras Bacsai dedf2cf87b fix: proxy fixes 2024-09-27 15:36:51 +02:00