How to install Coolify v4 on your own server with HTTPS
Install Coolify v4 with its official script, create the admin safely, move the dashboard to HTTPS, close ports 8000, 6001 and 6002, then back up and update.
- Intermediate
- 35 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13
On this page
- Prerequisites
- Step 1 — Allow key-only root login over SSH
- Step 2 — Prepare the firewall
- Step 3 — Download, review and run the installer
- Step 4 — Sign in and lock down the instance
- Step 5 — Serve the dashboard on your domain with HTTPS
- Step 6 — Close ports 8000, 6001 and 6002
- Back up and restore
- Update Coolify
- Troubleshooting
- The dashboard on port 8000 does not load after installation
- The localhost server fails validation
- The dashboard domain gets no certificate
- Live updates or the terminal stop working after closing the ports
- You lost the administrator password
- Next steps
Coolify is an open-source, self-hostable platform for deploying applications, databases and one-click services onto your own servers, similar in spirit to hosted platforms where you push code and get a running app. It builds and runs everything with Docker and places an integrated proxy (Traefik by default, Caddy optional) in front, which obtains TLS certificates for every https:// domain you assign. Coolify v4 left its long beta with the v4.0.0 release in April 2026; the 4.4 series is current in October 2026.
This guide installs Coolify with the official install script after you download and read it, creates the administrator during the installation so the registration page is never left open, moves the dashboard to your own domain with HTTPS, closes the direct-access ports, and shows Coolify's backup, restore and update procedures.
Prerequisites
- A fresh server running Ubuntu 26.04 LTS, Ubuntu 24.04 LTS, Debian 13 or Debian 12, on amd64 or arm64. Coolify's docs list Debian and Ubuntu as supported, ask for an Ubuntu LTS release (non-LTS releases should use the manual method), and recommend a fresh server to avoid conflicts. They do not publish a per-version matrix.
- A non-root user with
sudorights and SSH key login, as in Secure a new Linux server and Set up SSH keys. Coolify itself also needs key-based root SSH (Step 1). - Ports 80 and 443 free: Coolify's proxy uses them, so do not install Caddy, Nginx or Apache on this server.
- No Docker from snap. If Docker is missing, the installer adds Docker Engine; if Docker came from snap, remove it first.
- A domain such as
coolify.example.comwith an A (and AAAA) record pointing at the server. For apps, you can later add more records or a wildcard such as*.apps.example.com.
| Resource | Minimum (official) | Suggested starting point |
|---|---|---|
| CPU | 2 cores | 4 vCPU if you build images on this server |
| Memory | 2 GB | 4 GB or more |
| Disk | 10 GB free | 60 GB SSD |
The minimums come from Coolify's installation page. The right-hand column is a conservative starting point, not an official or benchmarked figure: building images and running databases on the same server needs headroom, so size it for the apps you plan to deploy.
Step 1 — Allow key-only root login over SSH
Coolify manages the server it runs on (called localhost in the dashboard) over SSH as root, with a key that the installer generates and adds to /root/.ssh/authorized_keys. Coolify's SSH page requires these two settings:
PubkeyAuthentication yes
PermitRootLogin prohibit-passwordprohibit-password lets root log in with a key but never with a password. If you hardened SSH with PermitRootLogin no, find where it is set and change it:
sudo grep -rn PermitRootLogin /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
sudo nano /etc/ssh/sshd_config
sudo sshd -t
sudo systemctl restart ssh
sudo sshd -T | grep -E 'permitrootlogin|pubkeyauthentication'Edit the file that the grep reports (a file in /etc/ssh/sshd_config.d/ wins over the main file). sshd -t prints nothing when the syntax is valid. The last command should show permitrootlogin without-password, OpenSSH's other name for prohibit-password, and pubkeyauthentication yes. Keep your current session open until a second SSH login works.
Step 2 — Prepare the firewall
Allow SSH, HTTP and HTTPS in ufw:
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verboseCoolify also publishes 8000 (dashboard), 6001 (realtime updates) and 6002 (web terminal) through Docker. Coolify's firewall page points out that Docker's NAT rules bypass ufw, so blocking these ports in ufw has no effect. They stay reachable until Step 6, where you bind them to localhost. If your provider offers a network firewall, Coolify recommends using it: allow 22, 80 and 443, and allow 8000, 6001 and 6002 only from your own IP address until Step 6 is done.
Step 3 — Download, review and run the installer
Download the official script and read it before running it as root:
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
less coolify-install.shThe script, which exits unless it runs as root:
- installs
curl,wget,git,jqandopenssl, and an SSH server if none is present; - installs Docker Engine if it is missing (through Docker's convenience script on Debian and Ubuntu) and refuses Docker from snap or older than version 24;
- backs up and edits
/etc/docker/daemon.jsonto enable log rotation and set the default address pool10.0.0.0/8; - creates
/data/coolifywithsource,ssh,applications,databases,services,backupsandproxyfolders; - downloads
docker-compose.yml,docker-compose.prod.yml,.env.productionandupgrade.shinto/data/coolify/source, and generates secrets such asAPP_KEYand the database password in/data/coolify/source/.env; - generates an ed25519 key in
/data/coolify/ssh/keys/and appends the public key to root'sauthorized_keys; - starts Coolify and prints the dashboard URLs on port 8000.
Coolify can create the administrator during installation when you pass ROOT_USERNAME, ROOT_USER_EMAIL and ROOT_USER_PASSWORD. Then the registration page is never exposed. The password needs at least 8 characters with upper- and lower-case letters, a number and a symbol. Reading it with read -s keeps it out of your shell history:
read -rsp "Coolify admin password: " COOLIFY_ROOT_PASSWORD; echo
sudo env ROOT_USERNAME=coolify-admin [email protected] ROOT_USER_PASSWORD="$COOLIFY_ROOT_PASSWORD" bash coolify-install.sh
unset COOLIFY_ROOT_PASSWORDThe installer writes these values into /data/coolify/source/.env. If you prefer not to pass them, run sudo bash coolify-install.sh instead and register at once in Step 4.
When the script finishes, it prints the dashboard address and reminds you to back up /data/coolify/source/.env. Check the containers:
sudo docker psYou should see coolify, coolify-db and coolify-redis running, and a proxy container once the proxy has started.
Step 4 — Sign in and lock down the instance
Open http://your-server-ip:8000 in your browser. Sign in with the account you passed to the installer, or create the administrator account now if you skipped the variables. Follow the onboarding and choose the server Coolify runs on (localhost); Coolify validates it over SSH with the key from Step 3.
Then tighten the instance settings:
- In Settings, open Advanced and set Registration to Registration disabled. Coolify recommends keeping registration off unless you want public sign-ups.
- Change the password in your profile and turn on two-factor authentication.
- Leave API access disabled unless you need it, and if you enable it, fill in Allowed API IPs instead of allowing every address.
Step 5 — Serve the dashboard on your domain with HTTPS
Make sure the A record for coolify.example.com already points at the server, because Coolify's docs ask for DNS to be in place before you change the URL. Then:
- Open Settings, then General.
- Enter
https://coolify.example.comin the URL field and select Save changes. The value must start withhttps://for HTTPS; path-based URLs are not supported. - Leave Redirect HTTP to HTTPS enabled.
Coolify's integrated proxy requests a certificate for the domain. Check it from your computer:
curl -I https://coolify.example.comOpen the dashboard on the new address and confirm three things before you go on: you can sign in, live updates appear (for example during a deployment), and the web terminal opens. If the certificate does not arrive, check under Servers, localhost, that the proxy is running.
Step 6 — Close ports 8000, 6001 and 6002
Once the dashboard, realtime updates and terminal work through your domain, Coolify's docs say you can close public access to the three direct-access ports. Without a provider firewall, bind them to localhost with a Compose override file that Coolify updates never overwrite. Create /data/coolify/source/docker-compose.custom.yml with sudo nano and this content:
services:
coolify:
ports: !override
- "127.0.0.1:${APP_PORT:-8000}:8080"
- "127.0.0.1:${SOKETI_PORT:-6001}:6001"
- "127.0.0.1:6002:6002"This is the layout for current releases, where realtime and terminal run inside the coolify container. If sudo docker ps still shows a coolify-realtime container, update Coolify first (see below). Validate the merged configuration; --quiet prints nothing when it is valid:
cd /data/coolify/source
sudo docker compose --env-file .env -f docker-compose.yml -f docker-compose.prod.yml -f docker-compose.custom.yml config --quietCoolify's firewall guide applies the override by running the installer again. On this fresh installation, download the current script and run it:
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
sudo bash coolify-install.shFrom another machine, nc -vz your-server-ip 8000 should now be refused or time out, while https://coolify.example.com keeps working.
Back up and restore
Coolify's state has three parts: the coolify-db PostgreSQL database (projects, resources, settings, deployment history), the APP_KEY in /data/coolify/source/.env, which encrypts stored secrets, and the SSH keys in /data/coolify/ssh/keys/. Your applications' data is separate.
Scheduled instance backups. Open Settings, then Backup, and select Configure backup. Coolify creates a daily schedule (0 0 * * * by default) with local retention limits. To keep copies off the server, add and validate an S3-compatible storage target, select it and turn on Enable S3. S3 instance backups contain only the database dump, not the encryption key.
Manual backup. Dump the database in PostgreSQL's custom format and archive the key material next to it:
sudo mkdir -p /opt/backups
sudo docker exec coolify-db pg_dump --format=custom --no-acl --no-owner --username=coolify coolify | sudo tee /opt/backups/coolify-db-$(date +%F).dmp > /dev/null
sudo tar czf /opt/backups/coolify-files-$(date +%F).tar.gz /data/coolify/source/.env /data/coolify/ssh/keys
sudo ls -lh /opt/backupsCheck that the .dmp file is not empty, store the APP_KEY= line from .env in your password manager, and copy both archives off the server. Without the APP_KEY, restored secrets cannot be decrypted.
Application data. Databases you deploy with Coolify (PostgreSQL, MySQL, MariaDB, MongoDB, ClickHouse and SQLite) have their own Backups section with schedules, retention and optional S3 upload. Back up application volumes with the tools described in each app's guide.
Restore. On the original or a replacement server, install the same Coolify version you backed up from. Then stop the control plane while the database keeps running, put the saved APP_KEY into .env (change only that value), and load the dump. On a replacement server, also copy the old key files back into /data/coolify/ssh/keys/ and make sure the matching public key is in root's authorized_keys before the last command.
sudo docker stop coolify coolify-redis
sudo nano /data/coolify/source/.env
sudo docker exec -i coolify-db pg_restore --clean --if-exists --exit-on-error --no-acl --no-owner --username=coolify --dbname=coolify < /opt/backups/coolify-db-2026-10-09.dmp
sudo bash coolify-install.sh 4.4.3The last command re-runs the installer with the version you had (4.4.3 is an example; write it without a leading v), which starts the containers and applies migrations. Afterwards the dashboard must open without an encryption error, your projects must be listed and Servers, localhost must validate.
Update Coolify
Before any update, read the release notes, create an instance backup and make sure no deployment is running, because running deployments can fail during the update.
- From the dashboard: open Settings, then Updates, and select Upgrade Now when a new version is available. Under Automatic updates you can choose Enabled and an Update frequency (
0 0 * * *by default); if you do, schedule backups before that window. - From the terminal: download the official upgrade script and pass the target version without a leading
v:
curl -fsSL https://cdn.coollabs.io/coolify/upgrade.sh -o coolify-upgrade.sh
less coolify-upgrade.sh
sudo bash coolify-upgrade.sh 4.4.3Do not omit the version: Coolify's docs warn that the script then writes COOLIFY_VERSION=latest to .env, which breaks update checks. Do not use install.sh for routine updates of an existing instance, because it resets ownership and permissions under /data/coolify. The upgrade script keeps your docker-compose.custom.yml, saves a timestamped copy of .env and writes logs to /data/coolify/source/upgrade-*.log.
Troubleshooting
The dashboard on port 8000 does not load after installation
Give the installer a few minutes; it waits for the containers to become healthy. Then check sudo docker ps and sudo docker logs coolify --tail 50, and read the dated installation log in /data/coolify/source/. If you use a provider firewall, make sure it allows port 8000 from your address.
The localhost server fails validation
Coolify cannot log in to the host as root. Confirm that sudo sshd -T | grep permitrootlogin shows without-password and that root's authorized_keys still contains the key whose comment includes coolify. Check that ufw allows SSH and that SSH listens on the port Coolify expects.
The dashboard domain gets no certificate
The A record must point at this server, and ports 80 and 443 must be open in every firewall, because certificates are issued through the proxy over port 80. Check that the URL starts with https:// and that the proxy runs under Servers, localhost. If the domain is proxied through Cloudflare, keep Redirect HTTP to HTTPS enabled and use Full or Full (strict) SSL mode.
Live updates or the terminal stop working after closing the ports
Open the dashboard only through https://coolify.example.com; after Step 6 the IP address and port 8000 no longer work from outside. If the dashboard sits behind Cloudflare, Coolify's Reverb migration guide asks for PUSHER_PORT=443 and PUSHER_BACKEND_PORT=6001 in .env.
You lost the administrator password
Reset it from the server and enter the new password twice when prompted:
sudo docker exec -it coolify php artisan root:reset-passwordNext steps
- Compare a Docker Swarm based alternative in Install Dokploy.
- Host the Git repositories Coolify deploys from with Gitea or Forgejo.
- Review servers sized for build workloads on the Coolify hosting page.
- Read the official Coolify documentation for applications, services and multi-server setups.
Frequently asked questions
Is Coolify v4 still in beta?
No. Coolify published v4.0.0 as a regular release in April 2026 after a long beta, and the 4.4 series is current in October 2026. Check the project’s GitHub releases page for the latest version before you install or update.
Which ports does a self-hosted Coolify server need?
SSH, plus 80 and 443 for the Coolify proxy, plus 8000, 6001 and 6002 for direct dashboard, realtime and terminal access by IP. Once the dashboard works on your HTTPS domain, Coolify’s docs say you can close 8000, 6001 and 6002.
Why does Coolify need root SSH access to its own server?
Coolify manages every server, including the one it runs on, over SSH. The installer adds its own key to root’s authorized_keys, so root must be allowed to log in with a key. PermitRootLogin prohibit-password keeps password logins blocked.
Can I install Coolify on a server that already hosts websites?
Coolify recommends a fresh server. Its proxy needs ports 80 and 443 and the installer changes Docker’s daemon settings, so existing web servers or containers can conflict with it.
Does the Coolify instance backup include my applications?
No. Instance backups contain Coolify’s own database: projects, resources, settings and deployment history. Back up application volumes and databases separately, for example with the scheduled backups Coolify offers for each database.
Sources
- coolify.io/docs/get-started/installation
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- cdn.coollabs.io/coolify/install.sh
- cdn.coollabs.io/coolify/upgrade.sh
- coolify.io/docs/knowledge-base/server/openssh
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…
- coolify.io/docs/core/instance-management/reverb-migration
- raw.githubusercontent.com/coollabsio/coolify-docs/main/content/docs…