Skip to content

TutorialsGit & DevOps

How to install Coolify v4 on your own server with HTTPS

Install Coolify v4 with its official script, create the admin safely, move the dashboard to HTTPS, close ports 8000, 6001 and 6002, then back up and update.

  • Intermediate
  • 35 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Allow key-only root login over SSH
  3. Step 2 — Prepare the firewall
  4. Step 3 — Download, review and run the installer
  5. Step 4 — Sign in and lock down the instance
  6. Step 5 — Serve the dashboard on your domain with HTTPS
  7. Step 6 — Close ports 8000, 6001 and 6002
  8. Back up and restore
  9. Update Coolify
  10. Troubleshooting
  11. The dashboard on port 8000 does not load after installation
  12. The localhost server fails validation
  13. The dashboard domain gets no certificate
  14. Live updates or the terminal stop working after closing the ports
  15. You lost the administrator password
  16. Next steps

Coolify is an open-source, self-hostable platform for deploying applications, databases and one-click services onto your own servers, similar in spirit to hosted platforms where you push code and get a running app. It builds and runs everything with Docker and places an integrated proxy (Traefik by default, Caddy optional) in front, which obtains TLS certificates for every https:// domain you assign. Coolify v4 left its long beta with the v4.0.0 release in April 2026; the 4.4 series is current in October 2026.

This guide installs Coolify with the official install script after you download and read it, creates the administrator during the installation so the registration page is never left open, moves the dashboard to your own domain with HTTPS, closes the direct-access ports, and shows Coolify's backup, restore and update procedures.

Prerequisites

  • A fresh server running Ubuntu 26.04 LTS, Ubuntu 24.04 LTS, Debian 13 or Debian 12, on amd64 or arm64. Coolify's docs list Debian and Ubuntu as supported, ask for an Ubuntu LTS release (non-LTS releases should use the manual method), and recommend a fresh server to avoid conflicts. They do not publish a per-version matrix.
  • A non-root user with sudo rights and SSH key login, as in Secure a new Linux server and Set up SSH keys. Coolify itself also needs key-based root SSH (Step 1).
  • Ports 80 and 443 free: Coolify's proxy uses them, so do not install Caddy, Nginx or Apache on this server.
  • No Docker from snap. If Docker is missing, the installer adds Docker Engine; if Docker came from snap, remove it first.
  • A domain such as coolify.example.com with an A (and AAAA) record pointing at the server. For apps, you can later add more records or a wildcard such as *.apps.example.com.
ResourceMinimum (official)Suggested starting point
CPU2 cores4 vCPU if you build images on this server
Memory2 GB4 GB or more
Disk10 GB free60 GB SSD

The minimums come from Coolify's installation page. The right-hand column is a conservative starting point, not an official or benchmarked figure: building images and running databases on the same server needs headroom, so size it for the apps you plan to deploy.

Step 1 — Allow key-only root login over SSH

Coolify manages the server it runs on (called localhost in the dashboard) over SSH as root, with a key that the installer generates and adds to /root/.ssh/authorized_keys. Coolify's SSH page requires these two settings:

Config
PubkeyAuthentication yes
PermitRootLogin prohibit-password

prohibit-password lets root log in with a key but never with a password. If you hardened SSH with PermitRootLogin no, find where it is set and change it:

Bash
sudo grep -rn PermitRootLogin /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
sudo nano /etc/ssh/sshd_config
sudo sshd -t
sudo systemctl restart ssh
sudo sshd -T | grep -E 'permitrootlogin|pubkeyauthentication'

Edit the file that the grep reports (a file in /etc/ssh/sshd_config.d/ wins over the main file). sshd -t prints nothing when the syntax is valid. The last command should show permitrootlogin without-password, OpenSSH's other name for prohibit-password, and pubkeyauthentication yes. Keep your current session open until a second SSH login works.

Step 2 — Prepare the firewall

Allow SSH, HTTP and HTTPS in ufw:

Bash
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

Coolify also publishes 8000 (dashboard), 6001 (realtime updates) and 6002 (web terminal) through Docker. Coolify's firewall page points out that Docker's NAT rules bypass ufw, so blocking these ports in ufw has no effect. They stay reachable until Step 6, where you bind them to localhost. If your provider offers a network firewall, Coolify recommends using it: allow 22, 80 and 443, and allow 8000, 6001 and 6002 only from your own IP address until Step 6 is done.

Step 3 — Download, review and run the installer

Download the official script and read it before running it as root:

Bash
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
less coolify-install.sh

The script, which exits unless it runs as root:

  • installs curl, wget, git, jq and openssl, and an SSH server if none is present;
  • installs Docker Engine if it is missing (through Docker's convenience script on Debian and Ubuntu) and refuses Docker from snap or older than version 24;
  • backs up and edits /etc/docker/daemon.json to enable log rotation and set the default address pool 10.0.0.0/8;
  • creates /data/coolify with source, ssh, applications, databases, services, backups and proxy folders;
  • downloads docker-compose.yml, docker-compose.prod.yml, .env.production and upgrade.sh into /data/coolify/source, and generates secrets such as APP_KEY and the database password in /data/coolify/source/.env;
  • generates an ed25519 key in /data/coolify/ssh/keys/ and appends the public key to root's authorized_keys;
  • starts Coolify and prints the dashboard URLs on port 8000.

Coolify can create the administrator during installation when you pass ROOT_USERNAME, ROOT_USER_EMAIL and ROOT_USER_PASSWORD. Then the registration page is never exposed. The password needs at least 8 characters with upper- and lower-case letters, a number and a symbol. Reading it with read -s keeps it out of your shell history:

Bash
read -rsp "Coolify admin password: " COOLIFY_ROOT_PASSWORD; echo
sudo env ROOT_USERNAME=coolify-admin [email protected] ROOT_USER_PASSWORD="$COOLIFY_ROOT_PASSWORD" bash coolify-install.sh
unset COOLIFY_ROOT_PASSWORD

The installer writes these values into /data/coolify/source/.env. If you prefer not to pass them, run sudo bash coolify-install.sh instead and register at once in Step 4.

When the script finishes, it prints the dashboard address and reminds you to back up /data/coolify/source/.env. Check the containers:

Bash
sudo docker ps

You should see coolify, coolify-db and coolify-redis running, and a proxy container once the proxy has started.

Step 4 — Sign in and lock down the instance

Open http://your-server-ip:8000 in your browser. Sign in with the account you passed to the installer, or create the administrator account now if you skipped the variables. Follow the onboarding and choose the server Coolify runs on (localhost); Coolify validates it over SSH with the key from Step 3.

Then tighten the instance settings:

  1. In Settings, open Advanced and set Registration to Registration disabled. Coolify recommends keeping registration off unless you want public sign-ups.
  2. Change the password in your profile and turn on two-factor authentication.
  3. Leave API access disabled unless you need it, and if you enable it, fill in Allowed API IPs instead of allowing every address.

Step 5 — Serve the dashboard on your domain with HTTPS

Make sure the A record for coolify.example.com already points at the server, because Coolify's docs ask for DNS to be in place before you change the URL. Then:

  1. Open Settings, then General.
  2. Enter https://coolify.example.com in the URL field and select Save changes. The value must start with https:// for HTTPS; path-based URLs are not supported.
  3. Leave Redirect HTTP to HTTPS enabled.

Coolify's integrated proxy requests a certificate for the domain. Check it from your computer:

Bash
curl -I https://coolify.example.com

Open the dashboard on the new address and confirm three things before you go on: you can sign in, live updates appear (for example during a deployment), and the web terminal opens. If the certificate does not arrive, check under Servers, localhost, that the proxy is running.

Step 6 — Close ports 8000, 6001 and 6002

Once the dashboard, realtime updates and terminal work through your domain, Coolify's docs say you can close public access to the three direct-access ports. Without a provider firewall, bind them to localhost with a Compose override file that Coolify updates never overwrite. Create /data/coolify/source/docker-compose.custom.yml with sudo nano and this content:

YAML
services:
  coolify:
    ports: !override
      - "127.0.0.1:${APP_PORT:-8000}:8080"
      - "127.0.0.1:${SOKETI_PORT:-6001}:6001"
      - "127.0.0.1:6002:6002"

This is the layout for current releases, where realtime and terminal run inside the coolify container. If sudo docker ps still shows a coolify-realtime container, update Coolify first (see below). Validate the merged configuration; --quiet prints nothing when it is valid:

Bash
cd /data/coolify/source
sudo docker compose --env-file .env -f docker-compose.yml -f docker-compose.prod.yml -f docker-compose.custom.yml config --quiet

Coolify's firewall guide applies the override by running the installer again. On this fresh installation, download the current script and run it:

Bash
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
sudo bash coolify-install.sh

From another machine, nc -vz your-server-ip 8000 should now be refused or time out, while https://coolify.example.com keeps working.

Back up and restore

Coolify's state has three parts: the coolify-db PostgreSQL database (projects, resources, settings, deployment history), the APP_KEY in /data/coolify/source/.env, which encrypts stored secrets, and the SSH keys in /data/coolify/ssh/keys/. Your applications' data is separate.

Scheduled instance backups. Open Settings, then Backup, and select Configure backup. Coolify creates a daily schedule (0 0 * * * by default) with local retention limits. To keep copies off the server, add and validate an S3-compatible storage target, select it and turn on Enable S3. S3 instance backups contain only the database dump, not the encryption key.

Manual backup. Dump the database in PostgreSQL's custom format and archive the key material next to it:

Bash
sudo mkdir -p /opt/backups
sudo docker exec coolify-db pg_dump --format=custom --no-acl --no-owner --username=coolify coolify | sudo tee /opt/backups/coolify-db-$(date +%F).dmp > /dev/null
sudo tar czf /opt/backups/coolify-files-$(date +%F).tar.gz /data/coolify/source/.env /data/coolify/ssh/keys
sudo ls -lh /opt/backups

Check that the .dmp file is not empty, store the APP_KEY= line from .env in your password manager, and copy both archives off the server. Without the APP_KEY, restored secrets cannot be decrypted.

Application data. Databases you deploy with Coolify (PostgreSQL, MySQL, MariaDB, MongoDB, ClickHouse and SQLite) have their own Backups section with schedules, retention and optional S3 upload. Back up application volumes with the tools described in each app's guide.

Restore. On the original or a replacement server, install the same Coolify version you backed up from. Then stop the control plane while the database keeps running, put the saved APP_KEY into .env (change only that value), and load the dump. On a replacement server, also copy the old key files back into /data/coolify/ssh/keys/ and make sure the matching public key is in root's authorized_keys before the last command.

Bash
sudo docker stop coolify coolify-redis
sudo nano /data/coolify/source/.env
sudo docker exec -i coolify-db pg_restore --clean --if-exists --exit-on-error --no-acl --no-owner --username=coolify --dbname=coolify < /opt/backups/coolify-db-2026-10-09.dmp
sudo bash coolify-install.sh 4.4.3

The last command re-runs the installer with the version you had (4.4.3 is an example; write it without a leading v), which starts the containers and applies migrations. Afterwards the dashboard must open without an encryption error, your projects must be listed and Servers, localhost must validate.

Update Coolify

Before any update, read the release notes, create an instance backup and make sure no deployment is running, because running deployments can fail during the update.

  • From the dashboard: open Settings, then Updates, and select Upgrade Now when a new version is available. Under Automatic updates you can choose Enabled and an Update frequency (0 0 * * * by default); if you do, schedule backups before that window.
  • From the terminal: download the official upgrade script and pass the target version without a leading v:
Bash
curl -fsSL https://cdn.coollabs.io/coolify/upgrade.sh -o coolify-upgrade.sh
less coolify-upgrade.sh
sudo bash coolify-upgrade.sh 4.4.3

Do not omit the version: Coolify's docs warn that the script then writes COOLIFY_VERSION=latest to .env, which breaks update checks. Do not use install.sh for routine updates of an existing instance, because it resets ownership and permissions under /data/coolify. The upgrade script keeps your docker-compose.custom.yml, saves a timestamped copy of .env and writes logs to /data/coolify/source/upgrade-*.log.

Troubleshooting

The dashboard on port 8000 does not load after installation

Give the installer a few minutes; it waits for the containers to become healthy. Then check sudo docker ps and sudo docker logs coolify --tail 50, and read the dated installation log in /data/coolify/source/. If you use a provider firewall, make sure it allows port 8000 from your address.

The localhost server fails validation

Coolify cannot log in to the host as root. Confirm that sudo sshd -T | grep permitrootlogin shows without-password and that root's authorized_keys still contains the key whose comment includes coolify. Check that ufw allows SSH and that SSH listens on the port Coolify expects.

The dashboard domain gets no certificate

The A record must point at this server, and ports 80 and 443 must be open in every firewall, because certificates are issued through the proxy over port 80. Check that the URL starts with https:// and that the proxy runs under Servers, localhost. If the domain is proxied through Cloudflare, keep Redirect HTTP to HTTPS enabled and use Full or Full (strict) SSL mode.

Live updates or the terminal stop working after closing the ports

Open the dashboard only through https://coolify.example.com; after Step 6 the IP address and port 8000 no longer work from outside. If the dashboard sits behind Cloudflare, Coolify's Reverb migration guide asks for PUSHER_PORT=443 and PUSHER_BACKEND_PORT=6001 in .env.

You lost the administrator password

Reset it from the server and enter the new password twice when prompted:

Bash
sudo docker exec -it coolify php artisan root:reset-password

Next steps

Frequently asked questions

Is Coolify v4 still in beta?

No. Coolify published v4.0.0 as a regular release in April 2026 after a long beta, and the 4.4 series is current in October 2026. Check the project’s GitHub releases page for the latest version before you install or update.

Which ports does a self-hosted Coolify server need?

SSH, plus 80 and 443 for the Coolify proxy, plus 8000, 6001 and 6002 for direct dashboard, realtime and terminal access by IP. Once the dashboard works on your HTTPS domain, Coolify’s docs say you can close 8000, 6001 and 6002.

Why does Coolify need root SSH access to its own server?

Coolify manages every server, including the one it runs on, over SSH. The installer adds its own key to root’s authorized_keys, so root must be allowed to log in with a key. PermitRootLogin prohibit-password keeps password logins blocked.

Can I install Coolify on a server that already hosts websites?

Coolify recommends a fresh server. Its proxy needs ports 80 and 443 and the installer changes Docker’s daemon settings, so existing web servers or containers can conflict with it.

Does the Coolify instance backup include my applications?

No. Instance backups contain Coolify’s own database: projects, resources, settings and deployment history. Back up application volumes and databases separately, for example with the scheduled backups Coolify offers for each database.

Sources

Jelszó létrehozása

Please confirm