Software

What Is Coolify and How Do You Install It? Self-Hosted PaaS Guide

Talha Aslan 17 min read 1 views

What is Coolify?

Coolify is an open source PaaS, meaning a deployment platform, that you install on your own server. You ship apps from a Git repository, and you run databases and ready-made services from the same dashboard. Domains and HTTPS live there too. The panel runs on your server, so the responsibility for the infrastructure stays with you.

We are a digital marketing and web team, not a hosting company. So we took every requirement, port and install step in this guide from the official Coolify documentation. We give no version numbers. You always install the current stable release and check the official page.

By the end you will see three things clearly. You will know what Coolify does, how the install runs, and when you should hand the job to your hosting provider or a managed platform instead of doing it yourself.

QuestionShort answer
What does it do?Deploys apps, databases and ready-made services from one dashboard
Where does it run?On a Linux server that you control
Who runs the infrastructure?You do, while the panel gives you automation
Who is it for?Teams that want several projects on their own server

What does Coolify do and what features does it offer?

According to the official docs, Coolify works like a control plane that connects to servers over SSH. You manage deployments from the dashboard, while the app itself runs in Docker containers on your server. If Docker is new to you, read our guide to Docker and containers first.

In practice, the docs highlight these features:

  • Deployments from a Git repository, a Dockerfile, a Docker Compose file or a prebuilt image.
  • Database hosting with persistent storage and lifecycle management.
  • One-click services from maintained Docker Compose templates.
  • Domain, environment variable and health check settings.
  • Proxy routing and automated HTTPS certificates.
  • Log viewing and container lifecycle control.

In short, the panel handles most of the hand-written Nginx config, certificate renewal and restarts for you. In exchange, you hand part of the control to the panel.

Who is Coolify for, and who should skip it?

Coolify fits people who want a few small or mid-sized projects in one place. For example, an agency with several client sites, a developer with side projects, or a team that needs staging and production fits well. Also, you no longer connect over SSH and type commands for every deployment.

On the other hand, Coolify may not suit you in these cases:

  • You do not know Linux, Docker or DNS and have no time to learn them.
  • You plan to put a business-critical store on a single server that needs guaranteed uptime.
  • Nobody on your team will watch security updates and monitoring.

The docs draw the same line. Coolify automates deployment work on infrastructure you supply, but you still operate that infrastructure.

Which scenarios does Coolify suit best?

For example, let us walk through a concrete scenario. This is an example calculation, not a real client case. A small team wants a brochure site, a light API and a PostgreSQL database on one server.

With Coolify, that team defines the three resources in one project. It picks Static or Nixpacks for the site and a Dockerfile for the API. Then it adds the database from the panel and keeps it reachable only by the API. After that, each resource gets its own subdomain.

So shipping a new version takes about as long as pushing code. You can also keep a staging environment on the same server. However, running staging and production on one machine means one failure can hit both.

In short, Coolify is a strong helper for small teams that want tidy, repeatable deployments. Architectures that need high availability across several servers call for separate expertise.

What server requirements does a Coolify install need?

The official installation page lists the minimum: a Linux-based operating system, at least 2 CPU cores, 2 GB of RAM and 10 GB of free storage. It supports amd64 and arm64. These values are a starting floor, so you need more once you run several apps and databases.

RequirementValue in the official docs
Operating systemLinux-based (Debian, Ubuntu, AlmaLinux, Rocky, Fedora and others)
CPUAt least 2 cores
Memory2 GB of RAM
Storage10 GB of free space
Architectureamd64 or arm64

The docs add one more tip: install Coolify on a fresh server to avoid conflicts. A machine that already runs Nginx or another Docker setup can cause trouble. If you are unsure between VPS options, our guide to VPS, cloud server and VDS helps.

What should you prepare before the install?

First, know that five small preparations make the install much smoother. None of them is specific to Coolify. They are simply good server hygiene.

  1. Prepare a fresh Linux server and update its operating system.
  2. Use SSH keys for access and, if possible, turn off password login.
  3. Open ports 22, 80 and 443 in your hosting provider's firewall.
  4. Point the DNS record of your panel domain at the server IP address.
  5. Take a snapshot of the server before you start.

To confirm that DNS has propagated, use our DNS lookup tool. That way you do not wait half an hour for a certificate that cannot arrive.

When should you not do this yourself? If SSH keys, firewalls and snapshots are unfamiliar, ask your hosting provider's technical team to do the preparation.

How do you install Coolify?

The official docs install Coolify with a single script. The script sets up Docker, creates the Coolify containers and prepares the system. You need root or a sudo-capable user. The one-line method in the docs downloads the script and runs it immediately. We split it into two steps, because reading a script before you run it is a good habit.

First, download the script to a file and read it:

curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o install.shless install.sh

Once you understand what it does, run it with a privileged user:

sudo bash install.sh

When the install ends, the terminal shows the panel address. We took the script URL from the docs. However, URLs can change, so compare it with the one on the official installation page before you run it.

How do you create the admin account safely on first login?

After the install, you reach the panel on port 8000 of your server IP address. The format is http://SERVER-IP:8000. On first load, the panel asks you to create an administrator account.

Here the official docs carry a bold warning, and it matters. Create your admin account as soon as the install finishes. Whoever reaches the registration page first can become the instance admin and gain root access to your server. So do not leave the panel open and walk away for a coffee.

  • Pick a long, unique password and store it in a password manager.
  • Turn on two-factor authentication if the panel offers it.
  • Restrict the panel port with a firewall rule so only you can reach it during setup.

After you create the account, move to the next warning in the docs: back up the Coolify .env file. We cover that in the backup section below.

How do you add your first app to Coolify?

The official docs suggest that you start with a simple image as your first app. The logic is simple. You first prove that the infrastructure works with a small example, then you move to your own source code. That way, when something breaks, you can tell whether the problem sits in the code or on the server.

In the panel, the flow generally runs in this order:

  1. You create a project and an environment.
  2. You add a new resource, such as an app, a database or a service.
  3. Next, you choose which server the resource runs on.
  4. Finally, you enter the port and the domain, then start the deployment.

Menu names can change between versions. So follow the current flow in the panel and read the "deploy your first app" section of the official docs instead of hunting for screenshots.

Also, do not run your first trial on a live client site. Learn the process with a throwaway test app.

How do you connect a Git repository to Coolify?

Coolify can connect to GitHub, GitLab, Bitbucket, Gitea or another Git provider. The docs describe three approaches: a public repository, a GitHub App and a deploy key. For private repositories, a deploy key or GitHub App is the safer route, because you never share your own password.

The docs list four build methods:

MethodWhen to use it
NixpacksYou want the panel to detect dependencies on its own
StaticYou have prebuilt static content
DockerfileYou want to define the container yourself
Docker ComposeYou deploy several services together

Next, you set the port your app listens on. Then the panel routes traffic to the right port. If you prefer to set up a Next.js or Node.js app by hand, our Next.js VPS deployment guide and Node.js deployment guide show the way. We do not repeat those steps here.

How do you set up automatic deployments with webhooks and health checks?

According to the docs, you set up a webhook so that a code push triggers a deployment. Then every push to your main branch makes the panel rebuild and release the app. That convenience also means a faulty commit can go live on its own.

So we suggest two safeguards:

  • Connect automatic deployment only to a branch that you have tested.
  • Define a health check, so you notice when the app fails to start.

A health check confirms that the app really responds after the deployment. In other words, "deployment succeeded" and "the site works" are not the same thing. Always open the site in a browser as well.

On a store, shipping every push to production is risky. However, that decision depends on your release process. If you prefer, switch automatic deployment off and approve each release by hand.

How do you set up a domain and automatic SSL?

The docs say Coolify offers proxy routing, domain management and HTTPS certificate automation. In practice, you enter the domain on the app, and its DNS A record must point to your server IP address. Ports 80 and 443 must stay open, because certificate issuing needs HTTP on port 80.

  1. Point your domain's A record at the server IP address.
  2. Confirm that DNS has propagated with the DNS lookup tool.
  3. Type your https address into the domain field of the app.
  4. After deployment, check the certificate with the SSL checker.

If you want one certificate for all subdomains, read our wildcard SSL guide. To refresh what a certificate does, see SSL certificates and HTTPS security.

How do you use databases and one-click service templates?

Also, Coolify hosts databases from the same dashboard. The backup docs mention scheduled backups for PostgreSQL, MySQL, MariaDB, MongoDB and ClickHouse. Thanks to persistent storage, your data stays in place when a container restarts.

The ready-made service templates rest on maintained Docker Compose files. So you can install a popular tool with one click. However, installing a template does not remove the job of keeping it updated and secure.

  • Do not expose the database port to the internet. Your app is the only client that needs it.
  • Do not keep default passwords. Use the strong values the panel generates.
  • Try a restore from backup before you rely on it in production.

To understand databases inside containers, read our guide to PostgreSQL and MySQL in Docker. For a visual view of your containers, see the Portainer guide.

How do you back up Coolify?

Backup has two separate layers, and you should not mix them up. First come database backups. The docs say you can schedule them with a cron expression or with a plain frequency such as daily or weekly. Backups land in the /data/coolify/backups folder on the server, and you can also copy them to S3-compatible storage.

Next comes the Coolify configuration itself. According to the installation docs, the APP_KEY in /data/coolify/source/.env is needed for a future restore, so you should back it up. Pull the file to your own computer:

scp root@203.0.113.10:/data/coolify/source/.env coolify-env-backup

The most important line in the docs is this one: a successful backup only proves that Coolify created a file. So never trust a backup until you restore it into a test database. Also, the docs do not cover application data outside your databases, so those need their own plan. For the general strategy, see our website backup strategy and database backup guide.

How do you update Coolify?

Updates run from the panel. According to the official docs, you open the Updates section under Settings. There you either enable automatic updates or trigger an update by hand. For automatic updates, you pick a cron expression or a preset such as daily or weekly. Advanced users also have a terminal route.

Before you update, follow the checklist from the docs:

  1. Create an instance backup.
  2. Read the release notes of the target version.
  3. Make sure no deployment is running.

The docs say an update only touches the Coolify control plane. Your apps, databases and servers stay as they are. The panel goes offline briefly during the update, usually for under a minute. Afterwards, confirm that the panel opens and your resources run.

Automatic updates are easy to turn on, but they do not spare you from reading release notes. On a critical site, updating by hand at a time you choose is safer.

How do you keep the Coolify panel and server secure?

Security is the most critical topic for a panel like this, because attackers target admin panels first. The panel connects to your server over SSH and manages containers. So anyone who gets into the panel often gets into the server too. The official firewall page lists these ports:

PortPurpose
22/tcpSSH access
80/tcpHTTP and certificate generation
443/tcpHTTPS traffic
8000/tcpDirect dashboard access
6001/tcpReal-time updates
6002/tcpWeb terminal

Once the panel works through a domain behind the proxy, the docs say you can close public access to ports 8000, 6001 and 6002. The advice boils down to this:

  • Use your hosting provider's firewall first.
  • Restrict SSH to known sources whenever you can.
  • Open 80 and 443 to everyone only if you serve public web traffic.
  • Never remove the SSH rule while you edit rules, or you may lock yourself out.

The docs also remind you that Docker can bypass UFW rules, and they mention ufw-docker when no provider firewall exists.

Do you need extra protection against brute force attacks?

Yes, because every SSH port on the internet gets constant password guesses. That is normal and not specific to Coolify. Forcing key-based login, turning off passwords and blocking repeated failures cut the risk sharply.

Our Fail2ban guide explains the idea of blocking repeated attempts automatically. For firewalls on cPanel or a VPS, see the CSF Firewall guide. However, always test how firewall rules interact with Docker on your server, because of the warning above.

To see which ports listen on the server, run this command:

sudo ss -tlnp

If you spot a port you do not expect, first find out why it is open. Closing a setting you do not understand is as risky as opening one. If you cannot tell, ask your provider's support team.

What are the pros and cons of Coolify?

Every tool has a price. So for Coolify, you should put the pros and cons side by side honestly.

AdvantageDrawback
Apps, databases and services in one panelYou own server maintenance and security
Git-based deployment and webhooksA faulty commit can also go live automatically
Automatic HTTPS and domain handlingDNS and port mistakes remain yours to fix
Infrastructure and data stay with youOne server means one point of failure
Open source and self-hostedUpdates, backups and monitoring are your job

The biggest risk is the single server. If the panel, apps and databases share one machine, a full disk or a hardware fault hits all of them. So keep your backups off that server.

Then there is the maintenance load. The install takes an afternoon, but running it takes years. Security patches, disk usage, certificate problems and restore tests need regular attention. Tie these jobs to a calendar. For example, pick a fixed day each month for updates, a restore test and a disk check.

How do Coolify, Docker and Portainer relate to each other?

People often mix up these three tools. However, they do different jobs. Docker is the base technology that runs apps in containers. Coolify sits on top of it and automates the deployment process. Portainer helps you watch and manage running containers visually.

ToolMain jobGit deployment
DockerRun containersNo, you type the commands
PortainerManage containers from a UINot its core job
CoolifyTake an app from source to productionYes, triggered by webhook

So installing Coolify does not make Docker knowledge unnecessary. When something breaks, you still need basic Docker skills to read container logs and understand networking.

How does Coolify differ from a managed PaaS and a classic VPS?

So seeing the options together makes the decision easier. The table below compares them in broad terms. It contains no prices or promotions, because those change often.

RouteWho runs the infrastructure?ControlMaintenance load
Self-hosted CoolifyYouHighMedium to high
Coolify CloudThe Coolify team runs the panel, you supply the workload serversMedium to highMedium
Managed PaaS (services such as Heroku, Vercel or Netlify)The platform providerMore limitedLow
Hand-built VPS (Nginx, systemd)YouHighestHigh

The docs say that on Coolify Cloud the Coolify team operates the control plane, while you provide the workload servers. When you self-host, you install and update the panel too.

In other words, Coolify offers a middle route between a hand-built VPS and a managed platform. You get some of the convenience and keep a large share of the responsibility.

When does a managed platform or hosting provider make more sense?

However, running your own server is not right for everyone. We suggest handing the job to a provider in these cases.

  • Downtime means lost sales directly, and nobody can watch the site around the clock.
  • No colleague can own security, patches and backups.
  • Your traffic swings fast and needs automatic scaling.
  • You handle personal or payment data and carry a high compliance burden.

For example, classic hosting is often enough for a company brochure site. Our guide on how to choose web hosting lists the criteria.

One honest note: we are not a hosting company. So this guide is a roadmap built on documentation. For your production setup, also talk to your infrastructure provider's technical team. If you need custom software or a deployment architecture, see our custom software development service.

What are the most common mistakes during setup?

In practice, most people who get stuck on Coolify stop at the same few places. Often the problem sits in the server or DNS preparation, not in the panel.

  • Installing on a server that already runs Nginx or another Docker setup. The docs recommend a fresh server.
  • Forgetting to open ports 80 and 443 in the provider firewall.
  • Pointing the A record at the wrong IP address, or not waiting for propagation.
  • Leaving the panel on the internet before creating the admin account.
  • Keeping backups on the same server and never testing a restore.
  • Deleting the SSH rule while editing the firewall and losing access.

None of these mistakes is specific to Coolify. They belong to general server care. So reviewing this list once before you install costs less than hours of debugging later.

Also, if an app does not open, do not suspect the code first. Check that the port is correct, the environment variables are complete and the deployment logs show no error.

In what order should you troubleshoot when something breaks?

Changing settings at random makes things worse, so follow a fixed order. Then check one thing at a time.

  1. Can you reach the panel? If not, check that the server is up and that port 8000, or 443 on your domain, is reachable.
  2. Does the domain point to the right IP address? Check it with the DNS lookup tool.
  3. When the certificate fails, make sure port 80 is open and the DNS record is right.
  4. Then, when the deployment fails, read the deployment logs, because the error usually shows up there.
  5. Finally, when the app opens but errors out, check its port and environment variables.

If you still cannot solve it, narrow the problem down and take it to the Coolify community or your provider's support. Include the version, the error message and what you tried. Never share passwords, keys or real IP addresses.

What is the final checklist before you install Coolify?

In short, Coolify is a panel that saves time for people who publish apps on their own server. However, the panel does not remove responsibility. Backups, security and updates stay with you. Review this list before you start.

  • Do you have a fresh Linux server with at least 2 cores, 2 GB of RAM and 10 GB of free space?
  • Does SSH use keys, and are the provider firewall rules ready?
  • Does your domain's A record point at the server?
  • Did you download and read the script before you ran it?
  • Have you created the admin account right after the install?
  • Have you copied the .env file and database backups off the server, and tested a restore?
  • Once the panel worked through a domain, did you close ports 8000, 6001 and 6002?

If you cannot answer yes to most of these, first read the responsibility section of the official documentation. The firewall page covers port details. Also, the upgrade page explains updates. Finally, the backup page describes database backups.

Frequently Asked Questions

Is Coolify free to use?
Coolify is open source and you install it on your own server, so you do not pay a license fee for the panel software. You still pay for the server, the domain, backup storage and your own maintenance time. The docs also describe Coolify Cloud as a managed panel option, so check current terms and any fees on the official site.
What is the minimum server for Coolify?
The official installation page asks for a Linux-based system, at least 2 CPU cores, 2 GB of RAM and 10 GB of free storage. It supports amd64 and arm64. If you plan to run several apps and databases, these values will not be enough, so raise the resources as you watch the load.
What should you do first after installing Coolify?
Create your administrator account immediately. The official docs warn that whoever reaches the registration page first can become the instance admin and gain root access to your server. Then back up the APP_KEY in the .env file off the server, review your firewall and move the panel behind a domain with HTTPS.
Does Coolify back up automatically?
You can schedule database backups, and the panel writes them to the backup folder on the server and can copy them to S3-compatible storage. However, the docs do not cover application data outside your databases. Also, a successful backup does not prove that you can restore it, so test restores on a regular schedule.
Does updating Coolify affect your apps?
According to the official docs, an update only touches the Coolify control plane. It does not update the apps, databases or servers you manage. The panel goes offline briefly during the update. Even so, take an instance backup, read the release notes and make sure no deployment is running before you start.
When is a managed platform better than Coolify?
A managed platform or hosting provider fits better when downtime means lost sales, when nobody can maintain the server, or when you need automatic scaling. Coolify does not remove the burden of running infrastructure, it only eases deployment. Judge your team's maintenance capacity and the cost of an outage honestly.
  • coolify
  • coolify install
  • self-hosted paas
  • docker
  • vps
  • git deployment
  • server security
  • software
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.