GuidesDevelopers and hostingCoolify app platform

Deploy your apps with Coolify

Coolify on Debian 13, a self-hosted alternative to Heroku and Vercel that builds your apps from Git and runs them with free certificates, databases and backups, with its admin ports closed and its telemetry switched off.

Tested on Coolify 4.3.23 with Docker 29.8.1 on Debian 13 (trixie) on a Melonslab server Updated September 27, 2026

Recommended server for this guide

VC-S Micro · 2 vCPU · 8 GB Memory · 250 GB Storage

Month to month, no lock-in 7-day money-back guarantee

€7.99/mo

Deploy now
On this page

What you will set up

Coolify is a platform for your own apps: point it at a Git repository, and it builds the app, runs it in a container, gives it a certificate and restarts it when it stops. It also runs databases next to your apps and backs them up.

Coolify is different from the apps in our other guides. It installs Docker, takes over ports 80 and 443 for its own proxy, Traefik, and runs as root, so it needs a server of its own, freshly installed.

Every step below was run on a fresh Melonslab VC-P Alloy (2 vCPU, 8 GB) with Debian 13:

  • Coolify 4.3.23 installed in about 2 minutes, and its dashboard got a Let's Encrypt certificate for its own name.
  • A Node.js app was built from a public Git repository in about 2 minutes, got its certificate, and redirected HTTP to HTTPS. Apps saw each visitor's real address, over both IPv4 and IPv6.
  • A PostgreSQL database was reachable from the app but not from the internet, and a backup of it was taken on demand.
  • The dashboard's extra ports were closed to the internet, and everything came back by itself after a reboot.

With two apps and a database, the server used about 1.1 GB of memory.

Before you start

You need:

  • a fresh Melonslab server with Debian 13 and nothing else installed, with at least 2 vCPU and 2 GB of memory, which is Coolify's minimum;
  • a name for the dashboard, such as coolify.example.com, and one for each app, such as app.example.com, with A and AAAA records pointing at the server.

Set up SSH keys and automatic security updates as in steps 1 to 3 of the security guide, and skip its step 4: Docker opens container ports past ufw, so step 5 here closes the ports that should not be public instead.

The examples use coolify.example.com for the dashboard and app.example.com for an app. Replace them with your own throughout.

1. Install Coolify

Anyone who opens a new Coolify first can create its admin account, and with it control the server. So create the account while installing. As root:

apt update
apt install -y curl
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
ROOT_USERNAME=anna ROOT_USER_EMAIL=anna@example.com ROOT_USER_PASSWORD='Choose-a-long-passw0rd!' bash coolify-install.sh

The password needs at least 8 characters, with upper and lower case, a number and a symbol. Coolify also checks it against Have I Been Pwned's list of leaked passwords, and skips creating the account if it is on it. The email address must be on a domain that exists.

The installer finishes with Your instance is ready to use! and the dashboard's address, http:// and the server's IPv4 address with :8000. It saves the account's password in /data/coolify/source/.env, which every user on the server can read. Once you have logged in, remove it:

sed -i '/^ROOT_USER_PASSWORD=/d' /data/coolify/source/.env

The same file holds Coolify's encryption keys. Keep a copy of it somewhere safe, away from the server, such as in a password manager.

2. Log in and connect the server

Open the address, and log in with the email address and password. Coolify's first steps connect it to the server it runs on:

  • Choose Continue, then This machine.
  • Choose Create "My First Project", then Go to dashboard.

Coolify starts its proxy, which answers on ports 80 and 443.

3. Give the dashboard its own name

Open Settings. Under URL, enter https://coolify.example.com, and choose Save changes. Within a minute, the dashboard answers on that name with a Let's Encrypt certificate. From now on, log in there.

Under Settings and Advanced, set Anonymous telemetry to Disabled. It is on by default, and sends a signal at every start and error reports that include your email address and the admin's. Sponsorship reminders can be switched off there too.

4. Deploy an app

Point app.example.com at the server first, with an A and an AAAA record. Then, in Projects, open My first project and its production environment, and choose New Resource:

  • Choose Public Git Repository, enter the repository's address, and choose Check Repository. For a first test, Coolify's own examples work: https://github.com/coollabsio/coolify-examples, with /nodejs as the Base directory.
  • Check the Branch, the Build pack, Railpack by default, which detects the language by itself, and the Port the app listens on. Choose Continue.
  • Coolify gives the app an address under sslip.io, a public service that turns a name into the IP address inside it. Open Domains, and choose Add Domain. Enter app.example.com as the Domain, keep https, and choose Save. Coolify also adds www.app.example.com: point a record at it too, or delete it and the sslip.io address under Actions.
  • Choose Deploy. The deployment log shows the build, and the app answers at https://app.example.com when it is done. Redirect HTTP to HTTPS is on by default.

A private repository needs a deploy key, and GitHub and GitLab can be connected as an app for deploys on every push, both from New Resource and Sources.

Apps behind Coolify's proxy see the visitor's address in the X-Forwarded-For and X-Real-Ip headers.

5. Close the dashboard's extra ports

The dashboard also answers on ports 8000, 6001 and 6002, directly on the server's address. Once it has its own name, it no longer needs them. Docker opens container ports past ufw, so close them in Docker's own chain, with a service that adds the rules again after every restart. Create /etc/systemd/system/coolify-ports.service:

[Unit]
Description=Keep Coolify dashboard ports off the internet
After=docker.service
Requires=docker.service

[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c "for t in iptables ip6tables; do for p in 8000 6001 6002; do $t -C DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport $p -j DROP 2>/dev/null || $t -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport $p -j DROP; done; done"

[Install]
WantedBy=multi-user.target

Then start it:

systemctl daemon-reload
systemctl enable --now coolify-ports.service

The rules drop connections from the internet to those three ports, over IPv4 and IPv6, and leave the dashboard at https://coolify.example.com working.

6. Add a database

In the same environment, choose New Resource, then PostgreSQL, or another database. Coolify starts it with a generated password. It is not reachable from the internet unless you make it public, and your apps reach it at the internal address on the database's page.

7. Back up

Open the database, then Backups, and choose + Add to create a schedule, such as 0 3 * * * for every night at three. Back Up Now on the schedule takes one straight away. The backups are saved in /data/coolify/backups. A backup that stays on the server does not help if the server is lost, so add an S3-compatible bucket under S3 Storage, and choose it in the schedule.

Your apps are rebuilt from Git, so the database backups, your copy of /data/coolify/source/.env, and any files your apps store are what you need to keep.

8. Updates

Coolify updates itself every night by default. You can change that under Settings and Updates. Debian's own packages are covered by the automatic security updates from the security guide.

Troubleshooting

The installer did not create your account. The password was too weak, was on the list of leaked passwords, or the email domain does not exist. Open the dashboard straight away and register, before anyone else can.

An app has no certificate. Its A and AAAA records do not point at the server yet. Domains shows DNS matches for each name that does, and Coolify requests the certificate once it can.

You cannot reach the dashboard at http:// and port 8000. Step 5 closed it. Use https://coolify.example.com. To open the ports again until the next restart, for example when the name does not work, run iptables -F DOCKER-USER and ip6tables -F DOCKER-USER from the console in the client area. systemctl restart coolify-ports.service closes them again.

Run it on your own server

VC-S Micro

€7.99/mo

vCPU
2
Memory
8 GB
Storage
250 GB
Transfer
10 TB
Standard
HDD · RAID 10
  • Full root access
  • Native /64 IPv6
  • RAID-protected storage
  • Malmö, Sweden
  • Month to month, no lock-in
  • 7-day money-back guarantee
All guides