# How to install Coolify v4 on your own server with HTTPS

> Install Coolify v4 with its official script, create the admin safely, move the dashboard to HTTPS, close ports 8000, 6001 and 6002, then back up and update.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

Coolify is an open-source, self-hostable platform for deploying applications, databases and one-click services onto your own servers, similar in spirit to hosted platforms where you push code and get a running app. It builds and runs everything with Docker and places an integrated proxy (Traefik by default, Caddy optional) in front, which obtains TLS certificates for every `https://` domain you assign. Coolify v4 left its long beta with the v4.0.0 release in April 2026; the 4.4 series is current in October 2026.

This guide installs Coolify with the **official install script** after you download and read it, creates the administrator during the installation so the registration page is never left open, moves the dashboard to your own domain with HTTPS, closes the direct-access ports, and shows Coolify's backup, restore and update procedures.

> **Warning**
>
> Coolify's documentation warns that whoever reaches the registration page first becomes the instance administrator and gains root access to your server. Create the administrator during installation (Step 3) or register immediately after the installer finishes.

## Prerequisites

- A **fresh** server running **Ubuntu 26.04 LTS**, **Ubuntu 24.04 LTS**, **Debian 13** or **Debian 12**, on amd64 or arm64. Coolify's docs list Debian and Ubuntu as supported, ask for an Ubuntu LTS release (non-LTS releases should use the manual method), and recommend a fresh server to avoid conflicts. They do not publish a per-version matrix.
- A non-root user with `sudo` rights and SSH key login, as in [Secure a new Linux server](/guides/secure-a-new-linux-server) and [Set up SSH keys](/guides/ssh-keys). Coolify itself also needs key-based root SSH (Step 1).
- Ports 80 and 443 free: Coolify's proxy uses them, so do not install Caddy, Nginx or Apache on this server.
- No Docker from snap. If Docker is missing, the installer adds Docker Engine; if Docker came from snap, remove it first.
- A domain such as `coolify.example.com` with an A (and AAAA) record pointing at the server. For apps, you can later add more records or a wildcard such as `*.apps.example.com`.

| Resource | Minimum (official) | Suggested starting point |
|---|---|---|
| CPU | 2 cores | 4 vCPU if you build images on this server |
| Memory | 2 GB | 4 GB or more |
| Disk | 10 GB free | 60 GB SSD |

The minimums come from Coolify's installation page. The right-hand column is a conservative starting point, not an official or benchmarked figure: building images and running databases on the same server needs headroom, so size it for the apps you plan to deploy.

## Step 1 — Allow key-only root login over SSH

Coolify manages the server it runs on (called `localhost` in the dashboard) over SSH as root, with a key that the installer generates and adds to `/root/.ssh/authorized_keys`. Coolify's SSH page requires these two settings:

```conf
PubkeyAuthentication yes
PermitRootLogin prohibit-password
```

`prohibit-password` lets root log in with a key but never with a password. If you hardened SSH with `PermitRootLogin no`, find where it is set and change it:

```bash
sudo grep -rn PermitRootLogin /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
sudo nano /etc/ssh/sshd_config
sudo sshd -t
sudo systemctl restart ssh
sudo sshd -T | grep -E 'permitrootlogin|pubkeyauthentication'
```

Edit the file that the `grep` reports (a file in `/etc/ssh/sshd_config.d/` wins over the main file). `sshd -t` prints nothing when the syntax is valid. The last command should show `permitrootlogin without-password`, OpenSSH's other name for `prohibit-password`, and `pubkeyauthentication yes`. Keep your current session open until a second SSH login works.

## Step 2 — Prepare the firewall

Allow SSH, HTTP and HTTPS in ufw:

```bash
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose
```

Coolify also publishes 8000 (dashboard), 6001 (realtime updates) and 6002 (web terminal) through Docker. Coolify's firewall page points out that Docker's NAT rules bypass ufw, so blocking these ports in ufw has no effect. They stay reachable until Step 6, where you bind them to localhost. If your provider offers a network firewall, Coolify recommends using it: allow 22, 80 and 443, and allow 8000, 6001 and 6002 only from your own IP address until Step 6 is done.

## Step 3 — Download, review and run the installer

Download the official script and read it before running it as root:

```bash
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
less coolify-install.sh
```

The script, which exits unless it runs as root:

- installs `curl`, `wget`, `git`, `jq` and `openssl`, and an SSH server if none is present;
- installs Docker Engine if it is missing (through Docker's convenience script on Debian and Ubuntu) and refuses Docker from snap or older than version 24;
- backs up and edits `/etc/docker/daemon.json` to enable log rotation and set the default address pool `10.0.0.0/8`;
- creates `/data/coolify` with `source`, `ssh`, `applications`, `databases`, `services`, `backups` and `proxy` folders;
- downloads `docker-compose.yml`, `docker-compose.prod.yml`, `.env.production` and `upgrade.sh` into `/data/coolify/source`, and generates secrets such as `APP_KEY` and the database password in `/data/coolify/source/.env`;
- generates an ed25519 key in `/data/coolify/ssh/keys/` and appends the public key to root's `authorized_keys`;
- starts Coolify and prints the dashboard URLs on port 8000.

Coolify can create the administrator during installation when you pass `ROOT_USERNAME`, `ROOT_USER_EMAIL` and `ROOT_USER_PASSWORD`. Then the registration page is never exposed. The password needs at least 8 characters with upper- and lower-case letters, a number and a symbol. Reading it with `read -s` keeps it out of your shell history:

```bash
read -rsp "Coolify admin password: " COOLIFY_ROOT_PASSWORD; echo
sudo env ROOT_USERNAME=coolify-admin ROOT_USER_EMAIL=admin@example.com ROOT_USER_PASSWORD="$COOLIFY_ROOT_PASSWORD" bash coolify-install.sh
unset COOLIFY_ROOT_PASSWORD
```

The installer writes these values into `/data/coolify/source/.env`. If you prefer not to pass them, run `sudo bash coolify-install.sh` instead and register at once in Step 4.

> **Tip**
>
> The official one-line equivalent, run as root, is `curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash`.

When the script finishes, it prints the dashboard address and reminds you to back up `/data/coolify/source/.env`. Check the containers:

```bash
sudo docker ps
```

You should see `coolify`, `coolify-db` and `coolify-redis` running, and a proxy container once the proxy has started.

## Step 4 — Sign in and lock down the instance

Open `http://your-server-ip:8000` in your browser. Sign in with the account you passed to the installer, or create the administrator account now if you skipped the variables. Follow the onboarding and choose the server Coolify runs on (`localhost`); Coolify validates it over SSH with the key from Step 3.

Then tighten the instance settings:

1. In **Settings**, open **Advanced** and set **Registration** to **Registration disabled**. Coolify recommends keeping registration off unless you want public sign-ups.
2. Change the password in your profile and turn on two-factor authentication.
3. Leave **API access** disabled unless you need it, and if you enable it, fill in **Allowed API IPs** instead of allowing every address.

## Step 5 — Serve the dashboard on your domain with HTTPS

Make sure the A record for `coolify.example.com` already points at the server, because Coolify's docs ask for DNS to be in place before you change the URL. Then:

1. Open **Settings**, then **General**.
2. Enter `https://coolify.example.com` in the **URL** field and select **Save changes**. The value must start with `https://` for HTTPS; path-based URLs are not supported.
3. Leave **Redirect HTTP to HTTPS** enabled.

Coolify's integrated proxy requests a certificate for the domain. Check it from your computer:

```bash
curl -I https://coolify.example.com
```

Open the dashboard on the new address and confirm three things before you go on: you can sign in, live updates appear (for example during a deployment), and the web terminal opens. If the certificate does not arrive, check under **Servers**, `localhost`, that the proxy is running.

## Step 6 — Close ports 8000, 6001 and 6002

Once the dashboard, realtime updates and terminal work through your domain, Coolify's docs say you can close public access to the three direct-access ports. Without a provider firewall, bind them to localhost with a Compose override file that Coolify updates never overwrite. Create `/data/coolify/source/docker-compose.custom.yml` with `sudo nano` and this content:

```yaml
services:
  coolify:
    ports: !override
      - "127.0.0.1:${APP_PORT:-8000}:8080"
      - "127.0.0.1:${SOKETI_PORT:-6001}:6001"
      - "127.0.0.1:6002:6002"
```

This is the layout for current releases, where realtime and terminal run inside the `coolify` container. If `sudo docker ps` still shows a `coolify-realtime` container, update Coolify first (see below). Validate the merged configuration; `--quiet` prints nothing when it is valid:

```bash
cd /data/coolify/source
sudo docker compose --env-file .env -f docker-compose.yml -f docker-compose.prod.yml -f docker-compose.custom.yml config --quiet
```

Coolify's firewall guide applies the override by running the installer again. On this fresh installation, download the current script and run it:

```bash
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
sudo bash coolify-install.sh
```

From another machine, `nc -vz your-server-ip 8000` should now be refused or time out, while `https://coolify.example.com` keeps working.

## Back up and restore

Coolify's state has three parts: the `coolify-db` PostgreSQL database (projects, resources, settings, deployment history), the `APP_KEY` in `/data/coolify/source/.env`, which encrypts stored secrets, and the SSH keys in `/data/coolify/ssh/keys/`. Your applications' data is separate.

**Scheduled instance backups.** Open **Settings**, then **Backup**, and select **Configure backup**. Coolify creates a daily schedule (`0 0 * * *` by default) with local retention limits. To keep copies off the server, add and validate an S3-compatible storage target, select it and turn on **Enable S3**. S3 instance backups contain only the database dump, not the encryption key.

**Manual backup.** Dump the database in PostgreSQL's custom format and archive the key material next to it:

```bash
sudo mkdir -p /opt/backups
sudo docker exec coolify-db pg_dump --format=custom --no-acl --no-owner --username=coolify coolify | sudo tee /opt/backups/coolify-db-$(date +%F).dmp > /dev/null
sudo tar czf /opt/backups/coolify-files-$(date +%F).tar.gz /data/coolify/source/.env /data/coolify/ssh/keys
sudo ls -lh /opt/backups
```

Check that the `.dmp` file is not empty, store the `APP_KEY=` line from `.env` in your password manager, and copy both archives off the server. Without the `APP_KEY`, restored secrets cannot be decrypted.

**Application data.** Databases you deploy with Coolify (PostgreSQL, MySQL, MariaDB, MongoDB, ClickHouse and SQLite) have their own **Backups** section with schedules, retention and optional S3 upload. Back up application volumes with the tools described in each app's guide.

**Restore.** On the original or a replacement server, install the same Coolify version you backed up from. Then stop the control plane while the database keeps running, put the saved `APP_KEY` into `.env` (change only that value), and load the dump. On a replacement server, also copy the old key files back into `/data/coolify/ssh/keys/` and make sure the matching public key is in root's `authorized_keys` before the last command.

> **Danger**
>
> `pg_restore --clean` replaces the current Coolify database with the backup.

```bash
sudo docker stop coolify coolify-redis
sudo nano /data/coolify/source/.env
sudo docker exec -i coolify-db pg_restore --clean --if-exists --exit-on-error --no-acl --no-owner --username=coolify --dbname=coolify < /opt/backups/coolify-db-2026-10-09.dmp
sudo bash coolify-install.sh 4.4.3
```

The last command re-runs the installer with the version you had (4.4.3 is an example; write it without a leading `v`), which starts the containers and applies migrations. Afterwards the dashboard must open without an encryption error, your projects must be listed and **Servers**, `localhost` must validate.

## Update Coolify

Before any update, read the release notes, create an instance backup and make sure no deployment is running, because running deployments can fail during the update.

- **From the dashboard:** open **Settings**, then **Updates**, and select **Upgrade Now** when a new version is available. Under **Automatic updates** you can choose **Enabled** and an **Update frequency** (`0 0 * * *` by default); if you do, schedule backups before that window.
- **From the terminal:** download the official upgrade script and pass the target version without a leading `v`:

```bash
curl -fsSL https://cdn.coollabs.io/coolify/upgrade.sh -o coolify-upgrade.sh
less coolify-upgrade.sh
sudo bash coolify-upgrade.sh 4.4.3
```

Do not omit the version: Coolify's docs warn that the script then writes `COOLIFY_VERSION=latest` to `.env`, which breaks update checks. Do not use `install.sh` for routine updates of an existing instance, because it resets ownership and permissions under `/data/coolify`. The upgrade script keeps your `docker-compose.custom.yml`, saves a timestamped copy of `.env` and writes logs to `/data/coolify/source/upgrade-*.log`.

## Troubleshooting

### The dashboard on port 8000 does not load after installation

Give the installer a few minutes; it waits for the containers to become healthy. Then check `sudo docker ps` and `sudo docker logs coolify --tail 50`, and read the dated installation log in `/data/coolify/source/`. If you use a provider firewall, make sure it allows port 8000 from your address.

### The localhost server fails validation

Coolify cannot log in to the host as root. Confirm that `sudo sshd -T | grep permitrootlogin` shows `without-password` and that root's `authorized_keys` still contains the key whose comment includes `coolify`. Check that ufw allows SSH and that SSH listens on the port Coolify expects.

### The dashboard domain gets no certificate

The A record must point at this server, and ports 80 and 443 must be open in every firewall, because certificates are issued through the proxy over port 80. Check that the URL starts with `https://` and that the proxy runs under **Servers**, `localhost`. If the domain is proxied through Cloudflare, keep **Redirect HTTP to HTTPS** enabled and use Full or Full (strict) SSL mode.

### Live updates or the terminal stop working after closing the ports

Open the dashboard only through `https://coolify.example.com`; after Step 6 the IP address and port 8000 no longer work from outside. If the dashboard sits behind Cloudflare, Coolify's Reverb migration guide asks for `PUSHER_PORT=443` and `PUSHER_BACKEND_PORT=6001` in `.env`.

### You lost the administrator password

Reset it from the server and enter the new password twice when prompted:

```bash
sudo docker exec -it coolify php artisan root:reset-password
```

## Next steps

- Compare a Docker Swarm based alternative in [Install Dokploy](/guides/install-dokploy).
- Host the Git repositories Coolify deploys from with [Gitea or Forgejo](/guides/install-gitea-forgejo).
- Review servers sized for build workloads on the [Coolify hosting](/coolify-hosting) page.
- Read the official [Coolify documentation](https://coolify.io/docs/) for applications, services and multi-server setups.

## Frequently asked questions

### Is Coolify v4 still in beta?

No. Coolify published v4.0.0 as a regular release in April 2026 after a long beta, and the 4.4 series is current in October 2026. Check the project’s GitHub releases page for the latest version before you install or update.

### Which ports does a self-hosted Coolify server need?

SSH, plus 80 and 443 for the Coolify proxy, plus 8000, 6001 and 6002 for direct dashboard, realtime and terminal access by IP. Once the dashboard works on your HTTPS domain, Coolify’s docs say you can close 8000, 6001 and 6002.

### Why does Coolify need root SSH access to its own server?

Coolify manages every server, including the one it runs on, over SSH. The installer adds its own key to root’s authorized_keys, so root must be allowed to log in with a key. PermitRootLogin prohibit-password keeps password logins blocked.

### Can I install Coolify on a server that already hosts websites?

Coolify recommends a fresh server. Its proxy needs ports 80 and 443 and the installer changes Docker’s daemon settings, so existing web servers or containers can conflict with it.

### Does the Coolify instance backup include my applications?

No. Instance backups contain Coolify’s own database: projects, resources, settings and deployment history. Back up application volumes and databases separately, for example with the scheduled backups Coolify offers for each database.

---

Source: <https://hyperdc.com/guides/tutorials/install-coolify>\
Updated: 2026-10-09
