Commit Graph
903 Commits
Author SHA1 Message Date
Andras BacsaiandClaude Opus 5.5 ebfee2ec3f fix(webhooks): handle pushes without commits and count only distinct failures
- GitLab, GitHub, and Gitea crashed with a 500 on push payloads without
  a commit list, and other malformed payloads (missing repository,
  project, ref, Bitbucket changes, non-string values, unsupported
  Gitea events) also returned 500. They now get a clean response; a
  push with an unknown file list still deploys, and a branch deletion
  does not deploy.
- The manual webhook lockout counts only distinct failed attempts: the
  same wrong GitLab token, or an identical HMAC redelivery, counts
  once, so a misconfigured hook no longer locks out a valid one. Every
  new guess still counts (30 per scope and minute). Attempts are
  stored only as HMAC hashes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 13:47:01 +02:00
Andras BacsaiandClaude Opus 5.5 5b2724621a fix(compose): validate Git-based Docker Compose applications
Git-based Docker Compose applications skipped the Compose injection
validation that services use. It now runs when the file is loaded or
reloaded, when the raw Compose is saved (UI and API create), and at
deployment before any command uses the file; an unsafe file is not
saved, and a deployment stops with a clear log line.

- All 371 service templates and realistic Compose files still pass.
- Network names may now mix text with $VAR, ${VAR}, ${VAR:-default},
  or ${VAR-default} (for example ${COMPOSE_PROJECT_NAME}_default), so
  such existing applications keep deploying; command substitution and
  unsafe defaults stay rejected.
- Quote the preserved-repository path in a stat command.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 13:47:01 +02:00
peaklabs-dev a52cafb2db Merge branch 'main' into feat/add-sqlite-database 2026-09-26 23:22:49 +02:00
Andras BacsaiandClaude Opus 5.5 8246492bb9 fix(databases): stop and clean up interrupted or stale imports
- Imports store their cleanup data (names and paths, no credentials)
  on the activity. When Coolify fails an import after a restart or as
  stale, it queues a stop of the restore inside the database container
  (only processes of that operation and their children, bottom-up so
  the database server is not affected) and the normal cleanup.
- The cleanup runs once per import, and a stopped CoolifyTask does
  not run again when the queue retries it.
- The stop message stays on the activity: RunRemoteProcess saves the
  process id at start from the stored properties and keeps a stop
  status at the end, and CoolifyTask::failed() keeps the message.
- Regenerate the OpenAPI spec (409 for database start, restart, and
  import, plus earlier API changes that were missing).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 22:18:17 +02:00
🏔️ Peak edcb884266 Merge branch 'main' into feat/add-sqlite-database 2026-09-26 21:32:43 +02:00
Andras BacsaiandClaude Opus 5.5 fbfe342f89 fix(databases): reserve start and restart atomically
Two parallel start requests both passed the in-progress check and got
200, because the start activity is created later by the queued action.
A per-database reservation (Cache::add, 600 s) is now taken before the
check, so the second request gets 409. The action releases it when it
creates its activity, skips, or fails. Restart, import, the deploy
API, MCP, and Livewire use the same reservation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 21:19:14 +02:00
peaklabs-dev 0687d1f55f feat(database): unlink applications from sqlite and protect connected volumes 2026-09-26 20:39:07 +02:00
Andras BacsaiandClaude Opus 5.5 a8117f9114 fix(databases): unblock interrupted imports and prevent double starts
- A Coolify restart now fails queued or running database imports, so
  they no longer block all later imports with 409.
- An import without progress for the SSH command timeout plus 30
  minutes (at least 2 hours) is stale and no longer blocks.
- The import sets its operation property when the activity is created,
  so a worker cannot save the activity without it.
- Start and restart refuse a second operation while a start, restart,
  or import is in progress, in the UI, the API (409), and actions.
- DatabaseStartJob runs only while its activity is still queued and
  the newest one, and holds a lock per database during the commands.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras BacsaiandClaude Opus 5.5 bbee57a81a fix(webhooks): scope manual webhook lockouts to repository and branch
Failed manual webhook deliveries were counted per provider and source
IP. On Coolify Cloud many customers share the Git provider IP, so one
repository with a wrong secret locked out valid deliveries of all
other repositories for 60 seconds.

The failure key now also contains the repository and branch. Guessing
the secret of one application stays limited to 30 tries per minute,
and a lockout rejects all deliveries in that scope, also correct ones.
A GitLab request without a token no longer counts as a failure.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 10:40:53 +02:00
Andras BacsaiandClaude Opus 5.5 e17b15f5f1 fix(sources): allow private networks for self-hosted Git sources
Since GitHub App and GitLab API calls use the outbound URL guard,
GitHub Enterprise or GitLab on a private network failed with "Webhook
URL resolved to an unsafe IP address" unless an admin allow-listed it.

On self-hosted instances, Git source URLs and requests now allow
private (RFC 1918), CGNAT (100.64/10, Tailscale), and IPv6 unique local
addresses, plus internal hostnames such as .internal, .local, and
container names. Loopback, localhost, link-local (cloud metadata),
0.0.0.0, and other reserved targets stay blocked. Redirects stay off
and DNS stays pinned. Coolify Cloud and all other outbound URLs keep
the strict rules.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:52:01 +02:00
peaklabs-dev 5261785c69 Merge remote-tracking branch 'origin/next' into feat/add-sqlite-database 2026-09-25 22:47:29 +02:00
Andras Bacsai 554b79e8dd feat: add Traefik ACME cert UI and shared managed DNS record ownership
- Proxy: list and delete Traefik ACME certificates from the server proxy
  page via new TraefikAcmeService and Get/DeleteTraefikCertificate actions
- DNS: track ownership and cross-resource references for managed DNS
  records so records are only deleted when no longer referenced; release
  records asynchronously on resource deletion via ReleaseManagedDnsRecordsJob
  and ManagedDnsRecordCleanup; harden Cloudflare provider deletion results
- Databases: fail closed on start when prerequisites or the CA certificate
  are missing (DatabaseStartException, Server::ensureCaCertificate) and
  clean up stale start activities via ResourceStartActivity
- Webhooks: throttle repeated manual webhook signature failures for
  GitHub, GitLab, Gitea and Bitbucket
- Deployments: improve compose build-context handling and compose file
  load error reporting
- Install scripts: rework terminal UI output in install.sh (stable and
  nightly)
- Misc: settings sidebar accordion fixes, log drain toggle rollback,
  add Serverside to README sponsors
- Add migrations and tests covering the above
2026-09-25 19:00:00 +02:00
Andras BacsaiandClaude Opus 5.5 60bac941ea fix(servers): build only on dedicated build servers
The server role migration gives every normal server the combined role, and
the build server queries counted combined servers as build servers.
"Use a build server" then built on a random production server, the resource
picker listed each server twice, and "Deployments only" did not stop builds.

- Build server selection and the picker use only "Builds only" servers.
  A null role falls back to the legacy is_build_server flag.
- Without a dedicated build server, builds fall back to the deployment
  server, never to another combined server.
- A "Deployments only" server always builds on a build server and needs a
  Docker image name. It never builds itself, except for restarts. Docker
  image and Compose applications are not affected.
- Setting "Deployments only" requires a dedicated build server.
- The API keeps is_build_server in sync with the role for downgrades.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 11:54:00 +02:00
peaklabs-dev 032ea6498c feat(api): support sqlite databases in the databases API 2026-09-24 22:15:08 +02:00
Andras Bacsai 87685d1e09 chore: align control-plane behavior 2026-09-24 15:46:04 +02:00
Andras Bacsai 3f47bae0b6 fix(service): save switches without saving pending Compose edits (#11985) 2026-09-24 13:43:37 +02:00
Andras Bacsai 74cc617a4c Keep API deployment behavior consistent (#11969) 2026-09-24 08:22:51 +02:00
Andras Bacsai 40b31b4a57 Align API deployment permissions 2026-09-24 08:19:02 +02:00
Andras Bacsai 2a3061adf5 Keep server creation consistent across entry points 2026-09-24 08:06:25 +02:00
Andras Bacsai d071a5df81 Improve Git source HTTP handling 2026-09-23 23:09:04 +02:00
Andras Bacsai 4b7ccfe9cd fix: align application image validation 2026-09-23 21:45:06 +02:00
Andras Bacsai 7c86e53422 fix(service): support metadata-only deletion on unreachable servers
Add a Coolify-only deletion path, improve Docker cleanup handling, and notify teams when service deletion fails.
2026-09-23 10:50:31 +02:00
Andras Bacsai 99dd634ba3 Improve file storage handling 2026-09-22 21:13:39 +02:00
Andras Bacsai bfb732bbe8 fix(webhooks): validate preview repository metadata 2026-09-21 16:53:50 +02:00
Andras Bacsai 19f0ae9a7d fix(webhooks): reject incomplete Stripe configuration (#11915) 2026-09-21 15:36:20 +02:00
Andras Bacsai 735187868c fix(webhooks): reject incomplete Stripe configuration 2026-09-21 15:35:31 +02:00
Andras Bacsai 865ebe0bdd fix(auth): improve OAuth sign-in handling 2026-09-21 14:00:14 +02:00
Andras Bacsai 1c408fb408 feat(audit): expand event tracking and remove scheduled job monitoring
Add audit levels and record user, OAuth, DNS, notification, and settings changes while removing the obsolete scheduled job monitoring UI and services.
2026-09-21 12:23:42 +02:00
Andras Bacsai a29f02fbb1 Merge remote-tracking branch 'origin/main' into pr-11443-next
# Conflicts:
#	openapi.json
#	openapi.yaml
#	resources/views/livewire/project/application/heading.blade.php
#	resources/views/livewire/project/service/heading.blade.php
2026-09-19 17:44:44 +02:00
Andras Bacsai 383a5a742f feat(servers): add configurable deployment and build roles
Introduce deployment, build, and dual-purpose server roles, with API and UI support, build-server fallback controls, and role-aware resource hosting.
2026-09-19 17:22:13 +02:00
Andras Bacsai 23f24f8425 feat(api): expose runtime logs for preview deployments (#11884) 2026-09-18 14:41:55 +02:00
Andras Bacsai ebfd4d0c1c Merge remote-tracking branch 'origin/main' into pr-11443-next
# Conflicts:
#	app/Actions/Server/StartSentinel.php
#	app/Livewire/Server/Sentinel.php
#	resources/views/livewire/project/shared/storages/all.blade.php
#	resources/views/livewire/project/shared/storages/show.blade.php
2026-09-18 12:00:04 +02:00
Andras Bacsai 128939b062 fix(storages): remove host path from storage configuration 2026-09-16 14:24:52 +02:00
Andras Bacsai 16b092336e feat(sentinel): track synchronization state and refresh status UI
Add sentinel waiting-state tracking, synchronization broadcasts, and restore
status handling across server and application interfaces.
2026-09-16 12:51:27 +02:00
Andras Bacsai 2c1744fbd2 Merge remote-tracking branch 'origin/next' into pr-11784-automation/sync-main-to-next 2026-09-14 13:30:17 +02:00
Andras Bacsai 6a8cee4630 Merge remote-tracking branch 'origin/next' into automation/sync-main-to-next 2026-09-14 13:26:19 +02:00
Andras Bacsai 7d11bc92f7 feat(logs): accept all for log lines and keep -1
API log endpoints and the GetLogs UI now treat `all` as unbounded
output, with `-1` remaining as a compatibility alias. MCP still
falls back to a positive default. Traefik version checks run from
CheckForUpdatesJob instead of a weekly schedule.
2026-09-13 15:25:20 +02:00
Andras Bacsai fc9e61b7b4 feat(services): open resource settings in a modal with restart limits
Move service application and database settings into an embedded modal with a footer, subtitle helper, and Docker restart-count control. Accept max_restart_count on the service applications API, cap compose YAML collection aliases, and tighten status, backup, and database sidebar layouts.
2026-09-10 17:39:56 +02:00
peaklabs-dev 9faa4f4b7c Merge branch 'main' into next 2026-09-09 15:32:27 +02:00
peaklabs-dev 0d8ef9411f feat(api): allow setting the container name prefix 2026-09-09 15:01:57 +02:00
Andras Bacsai 7109a11826 fix: queue import cleanup and scope DNS record updates
Move database import temp/container cleanup into a queued listener with retries, and clear the import running state on failed restore starts. Tighten Cloudflare replace/delete to the current server IP and owning resource, notify when DNS jobs fail, and pass domain-removal confirmation through remove-by-key. Document import request oneOf schemas without extra properties.
2026-09-09 13:43:56 +02:00
Andras Bacsai b5ca99c69d fix(api): return invalid token for database import endpoints
Import upload/create/show now return invalidTokenResponse() when the
access token has no team, matching the rest of the database API.
2026-09-09 13:09:31 +02:00
Andras Bacsai 25e61deefd fix(api): reject unknown fields on database import
Run validator fails() before adding extra-field errors so Laravel does not replace the message bag and accept undocumented properties.
2026-09-09 13:06:18 +02:00
Andras Bacsai 4accae95b5 feat(database): add replace-existing option for PostgreSQL restores
Allow single-database PostgreSQL imports to drop matching objects before restore. The API and import form accept replace_existing, which adds --clean --if-exists to pg_restore, and pg_restore now uses --exit-on-error.
2026-09-09 11:48:17 +02:00
Andras Bacsai ab3b3926aa feat: add database import API and Cloudflare DNS management
Queue database imports from upload, S3, or server paths via REST, and
manage Cloudflare DNS records from integration tokens and domain UIs.
2026-09-09 11:14:22 +02:00
Andras Bacsai 424dbd36ff feat(sentinel): make sentinel mandatory on regular servers
Remove the enable/disable toggle from the server UI, logs page, and
Sentinel API so is_sentinel_enabled is derived and read-only. Enable
existing regular servers via migration, start Sentinel after validate-
and-install, and drop the daily ServerManagerJob restart.
2026-09-09 06:30:32 +02:00
Andras Bacsai 83714ea395 fix(git): parse generic scp-style SSH URLs with custom users
Centralize scp-style Git URL parsing so user@host:path (including custom
usernames and embedded ports) is accepted and converted to HTTPS for
public clones, API create, webhooks, validation, and commit/branch links.
2026-09-08 20:33:45 +02:00
Florian Pfitzer e9bf2551ed fix: support generic SSH Git usernames 2026-09-08 16:11:56 +02:00
Aditya Tripathi 12498b4b86 feat(teams): persist active team and add team selection screen
Add current_team_id to users so the last active team is restored on
login instead of always defaulting to the personal team. When a user
belongs to multiple teams and has no valid stored choice, redirect
them to a new team.select screen (SelectTeam Livewire component) to
pick one, rather than silently choosing the first team. Update
Fortify and OAuth login flows to use the new resolveStoredTeam()
logic.
2026-09-08 14:44:39 +02:00
Andras Bacsai f359778115 Merge remote-tracking branch 'origin/next' into coolify-analytics-traefik-caddy
# Conflicts:
#	resources/views/components/forms/listbox.blade.php
2026-09-08 11:55:49 +02:00