- Servers with caddy-docker-proxy older than 2.9 show a warning on the
Proxy page and the traffic analytics settings, with the fix.
- Caddy 2.9+ images get the basic_auth label; older ones keep the
deprecated basicauth, which Caddy 2.7 still needs.
- Caddy mounts StartSentinel::trafficLogDirectory() as /traffic, so
Caddy and Sentinel use the same access log, also in development.
- The development data volume is configurable (DEV_COOLIFY_DATA_VOLUME,
same default as before) and shared by Traefik, Caddy, and Sentinel.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Traffic analytics now covers every resource on both proxies:
- Caddy: Compose applications and services get access-log labels. The
log_append key is {uuid}-{service}, the same key Sentinel reads from
Traefik router names.
- A resource owns the Sentinel key {uuid} and every key that starts
with {uuid}-. Application pages and the traffic card now merge all
keys, so Compose applications and previews show data on Traefik too.
- Global analytics: the leaderboard groups the keys of one resource
into one row, lists services, and never names keys of other teams.
- New service analytics page (project.service.analytics) with the same
view and authorization as the application page.
- Switching the proxy type restarts Sentinel when analytics is on, so
it reads the new log path. Sentinel gets no traffic mount when the
proxy has no analytics support.
- Caddy servers show a note that resources log only after a redeploy.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Centralize scp-style Git URL parsing so user@host:path (including custom
usernames and embedded ports) is accepted and converted to HTTPS for
public clones, API create, webhooks, validation, and commit/branch links.
Use resolveStoredTeam() instead of teams()->first() when picking the
next active team after a team deletion or when an admin switches into
a user's account, so a valid stored preference wins over an arbitrary
first team. DeleteTeam now returns null when the deletion leaves the
owner with multiple teams, deferring to the selection screen instead
of guessing. refreshSession also stops persisting current_team_id
while impersonating, so viewing another user's account no longer
overwrites their real last-active team.
Make clearStoredTeamIfMatches perform an atomic conditional UPDATE
so a concurrent team switch isn't clobbered, and call it for the
deleting owner in DeleteTeam so their stored team id doesn't point
at a deleted team. refreshSession now falls back to
resolveStoredTeam() instead of an arbitrary first team. Add a
return type to SelectTeam::render() and tests covering owner
deletion and concurrent-selection preservation.
Reset the user's persisted current_team_id when they are removed from
a team, when their team is deleted, or when refreshSession finds no
team left, so a dangling reference is never restored on next login.
Add current_team_id to users so the last active team is restored on
login instead of always defaulting to the personal team. When a user
belongs to multiple teams and has no valid stored choice, redirect
them to a new team.select screen (SelectTeam Livewire component) to
pick one, rather than silently choosing the first team. Update
Fortify and OAuth login flows to use the new resolveStoredTeam()
logic.
Add a persisted instance setting for S3 image CDN URLs and use it when building image links. Cache profile avatars and project icons with immutable one-year headers.
- Only send GEOIP_MAXMIND_LICENSE_KEY to Sentinel when GeoIP is enabled
- Skip restarting Sentinel when disabling analytics unless it was already running
- Validate Sentinel API responses are JSON objects before reading them
- Restore "live" toggle state from localStorage instead of only disabling it
- Use content-based wire:key for breakdown/path rows instead of loop index
- Add missing Kosovo country code and require update permission for geoip listbox
Sentinel stores container used memory in bytes while application and
database charts label the series as megabytes. Convert those samples
before they reach the frontend so the graph is not inflated by ~1024x.
Extend TrafficSeriesBucketData with requests, bytesIn, bytesOut,
uniqueVisitors, and p95 fields, and aggregate them per bucket in the
global, dashboard, and application analytics Livewire components.
Add bandwidthSpark() and uniquesSpark() to BuildsTrafficChartPayload
and wire them into the chart payloads and blade views.
Also add a compactNumber() helper for dense metric columns, a
--chart-spark-bandwidth CSS variable, and improve the traffic globe
with focus/resume controls, shortest-path angle interpolation, and
brighter base/marker theme colors.
Replace the server-scoped Analytics Livewire component with an
app-wide one that filters by server/application and supports live
refresh. Add a per-bucket status-class time series endpoint/data
class for a stacked-area chart, falling back to the donut when the
Sentinel build doesn't support it. Decorate top-path rows with their
owning domain, expand breakdown dimensions to agent/ip/useragent, and
raise path/breakdown result limits. Capture X-Forwarded-For,
User-Agent, and Referer headers in traefik access logs (now enabled
in dev too) so IP, browser, and referrer breakdowns work. Add
flag-image and referer-host helpers for geo/referrer rendering.
- Add live 24h polling toggle to server/application analytics views
- Add geo visualization (world map, country flags/names) for traffic
- Add dashboard nudge for servers eligible but not yet analytics-enabled
- Add lazy-loaded TrafficOverview widget to application General page
- Default-enable traffic analytics on new eligible server settings
- Rotate Caddy access logs via lumberjack roll options
- Add Traefik logrotate sidecar for copytruncate access-log rotation
Improve project resource UIs: sort domains by DNS failure, stop re-adding www pairs on refresh, lazy-load storage tabs with counts, tighten env-var tables, keep application tabs active across Livewire polls, unify database type labels, and update related CSS/JS and tests.
Flagged domains are served with X-Robots-Tag: noindex, nofollow via
Traefik and Caddy routing labels, so an auto-generated technical domain
can be excluded from indexing while the production domain on the same
resource stays indexable.