Andras Bacsai
95a3c453d8
Merge remote-tracking branch 'origin/next' into 9249-pr-investigation
2026-07-07 14:45:48 +02:00
Andras Bacsai
a8000ac2ad
fix(hetzner): require at least one public IP protocol
2026-07-07 14:41:17 +02:00
Andras Bacsai
c9ffa0db96
Merge remote-tracking branch 'origin/next' into feat/hetzner-firewalls-and-internal-networks
2026-07-07 14:37:54 +02:00
Andras Bacsai
b939e09f12
refactor(hetzner): move advanced options into dropdown
2026-07-07 14:36:11 +02:00
Andras Bacsai
d723a52d9c
fix(hetzner): secure token-backed option fetches
...
Authorize stored Hetzner cloud provider tokens before fetching
firewalls or networks, hide provider error details, and keep server
creation intact if backup activation fails.
Collapse advanced Hetzner server options by default while preserving
visibility when advanced values are selected.
2026-07-07 14:24:15 +02:00
Andras Bacsai
aded45acbe
Merge remote-tracking branch 'origin/next' into feat/api/tag-management
2026-07-07 14:02:45 +02:00
Andras Bacsai
11b35ba3c1
feat(api): add tags to resource creation
...
Normalize tag names before attaching them, reject names that are too short
after sanitization, and return 404 when removing tags not attached to the
resource.
Adds a per-team unique tag-name index and migrates duplicate tags onto the
kept record before creating the constraint.
2026-07-07 13:56:33 +02:00
Andras Bacsai
2ad11fdd9a
Merge remote-tracking branch 'origin/next' into feat/hetzner-firewalls-and-internal-networks
2026-07-07 13:47:51 +02:00
Andras Bacsai
c58b4fd69c
Merge remote-tracking branch 'origin/next' into feature/vultr-cloud-provider
2026-07-07 13:44:37 +02:00
Andras Bacsai
ff976a134f
Merge remote-tracking branch 'origin/next' into api-sensitive-data-scrubber
2026-07-07 12:56:19 +02:00
Andras Bacsai
9a2c432c79
fix(api): expose sensitive fields for privileged tokens
...
Privileged API tokens can read hidden resource fields in environment and
resource responses, including instance-admin team tokens with team_id 0.
Configuration hashes now include hidden environment variable values so
secret edits trigger restart detection.
2026-07-07 12:53:34 +02:00
Andras Bacsai
f617e58401
Merge remote-tracking branch 'origin/next' into feat/api/tag-management
...
# Conflicts:
# app/Http/Controllers/Api/ApplicationsController.php
2026-07-07 12:49:19 +02:00
Andras Bacsai
00a3738ec7
Merge remote-tracking branch 'origin/next' into api-application-preview-deployments
2026-07-07 12:38:37 +02:00
Andras Bacsai
e9bef8443b
fix(api): hide nested server secrets in database responses
...
Prevent database detail responses from exposing log drain and Sentinel
settings when callers lack sensitive read access.
2026-07-07 12:34:09 +02:00
Andras Bacsai
2caa5e67ff
fix(github): derive API URLs from GitHub HTML hosts ( #10610 )
2026-07-07 12:29:15 +02:00
Andras Bacsai
b50839d451
Merge remote-tracking branch 'origin/next' into fix/url-validator-underscore-hostnames
2026-07-07 12:24:32 +02:00
Andras Bacsai
d01e3a9730
fix(parsers): populate docker_compose_domains for API-created Docker Compose apps ( #9300 )
2026-07-07 12:17:52 +02:00
Andras Bacsai
d657c10df3
fix(api): allow source commit build setting ( #10551 )
2026-07-07 12:12:32 +02:00
Andras Bacsai
59b158381c
fix(api): preserve source commit flag until cleanup
2026-07-07 12:12:20 +02:00
Andras Bacsai
6c42ca82cb
fix: only strip git_host from repository_url when git_host is github.com ( #10274 )
2026-07-07 12:11:45 +02:00
Andras Bacsai
76a4c1484d
fix(deploy): cast force param as boolean to prevent cache bust on every deploy ( #9909 )
2026-07-07 12:08:29 +02:00
Andras Bacsai
6baabf9eda
fix(api): document source commit build option
2026-07-07 12:08:07 +02:00
Andras Bacsai
ff5cfd4253
fix(api): normalize log endpoint query handling
...
Clamp log line counts, parse timestamp flags consistently, and filter
service subcontainers by Coolify labels. Document log endpoint timestamp
parameters and database/service log routes in OpenAPI.
2026-07-06 23:58:12 +02:00
Andras Bacsai
adc4b3091f
Merge remote-tracking branch 'origin/next' into feat/database-service-logs-endpoint
2026-07-06 23:29:54 +02:00
Andras Bacsai
b6a4c7383a
fix(env): preserve empty service variable values ( #10850 )
2026-07-03 20:47:18 +02:00
Andras Bacsai
1adeed2a48
fix(github): preserve custom app API URLs
2026-07-03 12:01:16 +02:00
Andras Bacsai
9b060958aa
fix(ray): remove Ray debug hooks from runtime ( #10847 )
2026-07-03 11:40:20 +02:00
Andras Bacsai
e551f9c176
Merge remote-tracking branch 'origin/next' into fix/docker-compose-domains-api-9211
2026-07-03 11:32:41 +02:00
Andras Bacsai
29c122b31a
fix(api): return deployment UUID strings directly
2026-07-03 11:31:49 +02:00
Andras Bacsai
a7dddccd2e
Merge remote-tracking branch 'origin/next' into ghe-support-helpers
2026-07-03 10:26:58 +02:00
Andras Bacsai
b5ba40b049
Merge remote-tracking branch 'origin/next' into fix/docker-compose-domains-api-9211
2026-07-03 10:26:19 +02:00
Andras Bacsai
b90380f542
Merge remote-tracking branch 'origin/next' into ghe-support-helpers
2026-07-03 10:15:29 +02:00
Andras Bacsai
d73649ca15
Merge remote-tracking branch 'origin/next' into fix-ghe-app-install-url
2026-07-03 10:10:39 +02:00
Andras Bacsai
58f6f9e05b
feat(dev): add Lima testing server fixtures ( #10844 )
2026-07-03 10:07:55 +02:00
Andras Bacsai
c0866d4cb3
fix(auth): preserve invite login with database sessions
2026-07-03 09:38:05 +02:00
Andras Bacsai
eb56287b57
Merge remote-tracking branch 'origin/next' into 10633-invitation-link-redirect
2026-07-02 18:55:25 +02:00
Andras Bacsai
bb2f70ac3b
fix(railpack): isolate buildx from Docker client env ( #10840 )
2026-07-02 18:53:00 +02:00
Andras Bacsai
cf6f5a2678
feat(registry): add configurable docker registry url ( #9017 )
2026-07-02 18:52:46 +02:00
Andras Bacsai
99f60228ad
fix(api): avoid lazy loading nested server secrets
2026-07-02 17:47:22 +02:00
Andras Bacsai
c6c7ec1c31
fix(security): validate application domains safely
...
Use shared domain validation and normalization for application, service, and
preview domains so unsafe host input is rejected consistently.
Cover command-substitution payloads in application domain tests.
2026-07-02 17:47:04 +02:00
Andras Bacsai
cc4f666ba2
Merge remote-tracking branch 'origin/next' into improve-application-url-handling
2026-07-02 17:40:31 +02:00
Andras Bacsai
954c1e369c
fix(env-vars): avoid service preview variable lookups ( #10837 )
2026-07-02 17:39:16 +02:00
Andras Bacsai
d5395f0500
fix(services): preserve template keys for selection
2026-07-02 17:16:40 +02:00
Andras Bacsai
ed6352682e
Merge remote-tracking branch 'origin/next' into improve-application-url-handling
2026-07-02 16:57:14 +02:00
Andras Bacsai
bbff70c8d0
fix: improve application URL handling
2026-07-02 16:52:07 +02:00
Andras Bacsai
3988ad6921
fix(webhooks): resolve hostnames using custom DNS servers
...
Keep webhook SSRF DNS checks active when general DNS validation is disabled, and include localhost loopback resolution in safe URL validation.
2026-07-02 16:47:55 +02:00
Andras Bacsai
0bf97df9af
feat: add internal endpoint controls
2026-07-02 16:35:39 +02:00
Andras Bacsai
7a853efa79
chore: inspect PR context ( #10834 )
2026-07-02 16:27:06 +02:00
Andras Bacsai
13172849e1
Merge remote-tracking branch 'origin/next' into api-sensitive-data-scrubber
2026-07-02 15:57:43 +02:00
Andras Bacsai
6871160623
fix(api): gate sensitive storage and GitHub fields
...
Expose GitHub app secrets and file storage content only when the request has sensitive read access. Hide LocalFileVolume content by default and resolve application UUIDs from route parameters.
2026-07-02 15:50:43 +02:00
Andras Bacsai
438eeefa73
feat(api): add REST endpoints for destinations ( #10405 )
2026-07-02 15:34:30 +02:00
Andras Bacsai
70021c8d5e
fix(api): handle destination create races as conflicts
2026-07-02 15:33:01 +02:00
Andras Bacsai
88d5aff018
Merge remote-tracking branch 'origin/next' into team-level-mcp-enablement
2026-07-02 15:15:11 +02:00
Andras Bacsai
4ef884e1ac
Merge remote-tracking branch 'origin/next' into feat/api-destinations
2026-07-02 15:14:13 +02:00
Andras Bacsai
20b5b90cf9
Merge remote-tracking branch 'origin/next' into improve-s3-storage-handling
2026-07-02 15:06:11 +02:00
Andras Bacsai
78d9244caa
fix: improve s3 storage handling
2026-07-02 15:05:05 +02:00
Andras Bacsai
bed058b826
Improve outbound URL validation ( #10833 )
2026-07-02 15:02:37 +02:00
Andras Bacsai
a06c1a7bf5
Improve storage mount path handling
2026-07-02 14:54:38 +02:00
Andras Bacsai
c7f014017b
Improve outbound URL validation
2026-07-02 14:46:46 +02:00
Andras Bacsai
a121386ab4
Merge branch 'next' into improve-resource-route-handling
2026-07-02 13:25:47 +02:00
Andras Bacsai
fb2d477e48
fix: improve team resource route handling
2026-07-02 13:05:27 +02:00
Andras Bacsai
74f4d04f53
fix(backups): default S3 storage for backup schedules
...
Show the S3 storage selector even when S3 backups are disabled, save
storage changes immediately, and improve responsive confirmation buttons.
2026-07-02 12:47:54 +02:00
Julien Bouquillon
77086e28af
Merge branch 'v4.x' into api-application-preview-deployments
2026-07-01 19:11:16 +02:00
Andras Bacsai
22b31f5671
fix(backups): require valid S3 storage selection
...
Preserve S3 backups when a single valid storage is available, require
explicit selection when multiple storages exist, and disable S3 when none
are available.
Make backup action controls responsive on narrow screens.
2026-07-01 11:14:20 +02:00
Andras Bacsai
78374b566a
fix members smtp pw update
2026-06-30 15:29:19 +02:00
Andras Bacsai
63d6d835a9
Align resource creation permissions ( #10799 )
2026-06-29 15:59:46 +02:00
Andras Bacsai
29445bf177
fix: align resource creation permissions
2026-06-29 15:57:17 +02:00
Andras Bacsai
f2d11d9300
fix(railpack): interpolate build-time env variables by sourcing build… ( #10768 )
2026-06-29 11:08:19 +02:00
Andras Bacsai
7d65a4b496
Merge remote-tracking branch 'origin/next' into harden-database-import-files
2026-06-29 10:35:35 +02:00
Andras Bacsai
2d63d51237
fix: harden database backup imports
2026-06-29 10:27:01 +02:00
Andras Bacsai
9a64b2ea0a
Merge remote-tracking branch 'origin/next' into fix/railpack-buildtime-env-interpolation
2026-06-29 10:20:07 +02:00
Andras Bacsai
2dc34f61ff
fix(railpack): create empty build-time env file
2026-06-29 10:19:22 +02:00
Andras Bacsai
a630532308
fix(deploy): preserve deploy key command metadata
2026-06-29 10:17:09 +02:00
Andras Bacsai
3729b5c074
improve github webhook
2026-06-28 15:25:58 +02:00
Andras Bacsai
1a5b8d3612
fix(deploy): skip logging deploy key commands
2026-06-28 13:15:18 +02:00
Andras Bacsai
87d4744390
Validate environment variable keys
2026-06-25 18:19:58 +02:00
Andras Bacsai
bef94a9ce2
feat(mcp): add per-team server toggle
2026-06-25 11:42:19 +02:00
Aditya Tripathi
623bf89543
fix(railpack): interpolate build-time env variables by sourcing build-time .env
...
Railpack builds forwarded build-time variables inline as `env 'KEY=VALUE'`,
which single-quotes each value and prevents shell interpolation. References
like BETTER_AUTH_URL=$COOLIFY_URL reached the build as the literal string
"$COOLIFY_URL" instead of the resolved URL, breaking builds that validate
their env (e.g. SvelteKit/better-auth).
Wrap the railpack `docker buildx build` invocation with the same
wrap_build_command_with_env_export() helper used by the Dockerfile and
Nixpacks build paths, sourcing the build-time .env file (which writes
COOLIFY_* first and double-quotes normal vars to allow $VAR expansion).
Only buildpack control variables (NIXPACKS_/RAILPACK_), excluded from that
file and never needing interpolation, remain inline. Secret flags are
unchanged and read the interpolated values from the exported environment.
Fixes #10736
2026-06-24 20:11:46 +00:00
Andras Bacsai
00c5a630cf
fix(subscription): clamp dynamic quantity to MIN_SERVER_LIMIT on update
2026-06-19 08:27:41 +02:00
Andras Bacsai
9e021c4037
fix(api): enforce destination access and cleanup networks
...
Require admin team membership for destination mutations, return invalid-token
responses for tokenless requests, and remove standalone Docker networks when
deleting destinations.
2026-06-15 17:15:56 +02:00
Andras Bacsai
9665aa292c
fix(api): block invalid destination types and service deletions
2026-06-15 17:03:01 +02:00
Andras Bacsai
506643603c
Merge remote-tracking branch 'origin/next' into feat/api-destinations
2026-06-15 17:02:24 +02:00
Andras Bacsai
f5ecdfa4ce
Merge remote-tracking branch 'origin/next' into api-sensitive-data-scrubber
2026-06-15 13:29:25 +02:00
Andras Bacsai
22d05c78aa
Merge remote-tracking branch 'origin/next' into ghe-support-helpers
2026-06-15 12:55:34 +02:00
Andras Bacsai
507a8afa20
fix(github): sync app slug before generating installation path
2026-06-15 12:55:29 +02:00
Andras Bacsai
b9bda7301a
Merge remote-tracking branch 'origin/next' into fix-ghe-app-install-url
2026-06-15 12:55:08 +02:00
Andras Bacsai
d2deaa8363
fix(auth): restrict Sentinel access and register S3 policy
2026-06-15 12:31:30 +02:00
Andras Bacsai
2ebe2e8dbb
Merge remote-tracking branch 'origin/next' into api-sensitive-data-scrubber
2026-06-15 12:30:15 +02:00
Andras Bacsai
78d8afa602
Merge remote-tracking branch 'origin/next' into audit-policies
2026-06-15 12:05:19 +02:00
Andras Bacsai
9302a49bbf
Merge remote-tracking branch 'origin/next' into 10633-invitation-link-redirect
2026-06-15 11:58:03 +02:00
Osamaali313
74b1077010
fix: accept underscores in domain hostnames for API URL validation
...
PHP's FILTER_VALIDATE_URL rejects underscores in the host, so domains
like https://myapp_service.example.com were rejected by the API and
never got a Let's Encrypt certificate. Add an isValidDomainUrl() helper
that validates a copy with underscores replaced by hyphens, and route
domain validation in the Applications and Services API controllers
through it.
Fixes #10597
2026-06-13 22:46:04 +03:00
Andras Bacsai
52739141ee
fix(previews): clean up closed PR previews after update failures ( #10180 )
2026-06-12 20:08:34 +02:00
Andras Bacsai
403f8abcb4
Merge remote-tracking branch 'origin/next' into fix-ghe-app-install-url
2026-06-12 20:02:23 +02:00
Andras Bacsai
78d7291929
fix(github): keep provided api_url on GitHub app updates
2026-06-12 19:56:13 +02:00
Andras Bacsai
4f509c02be
fix(auth): validate invitation magic link tokens
...
Accept invitation links across configured public origins while still
rejecting stored invitations whose token no longer matches.
2026-06-12 16:17:45 +02:00
Andras Bacsai
61d2d17f52
feat(subscription): add Stripe action controls
...
Add subscription action handling and tests for cancel, resume, and refund flows while resolving StripeClient through the container.
2026-06-12 15:54:21 +02:00
Andras Bacsai
0d9a39ea23
fix(github): sync pending app credentials before slug lookup
2026-06-09 18:32:05 +02:00
Andras Bacsai
281184c040
fix(github): derive app API URLs from HTML hosts
...
Normalize GitHub organization values and derive API URLs for GitHub.com,
GHE.com, and enterprise hosts when creating or updating GitHub Apps.
2026-06-09 18:31:06 +02:00
Andras Bacsai
bc2c6068ea
fix(github): sync app slug before building install URL
...
Move GitHub App JWT generation and slug synchronization into shared helpers so installation URLs use the canonical GitHub slug. Encode GHE organization path segments and keep the app-scoped fallback for blank organizations.
2026-06-09 15:27:35 +02:00
vuguul
4c77504b5e
fix(service): limit Grafana extra fields to Grafana images
2026-06-05 14:29:29 -06:00