What you will set up
Coolify is a platform for your own apps: point it at a Git repository, and it builds the app, runs it in a container, gives it a certificate and restarts it when it stops. It also runs databases next to your apps and backs them up.
Coolify is different from the apps in our other guides. It installs Docker, takes over ports 80 and 443 for its own proxy, Traefik, and runs as root, so it needs a server of its own, freshly installed.
Every step below was run on a fresh Melonslab VC-P Alloy (2 vCPU, 8 GB) with Debian 13:
- Coolify 4.3.23 installed in about 2 minutes, and its dashboard got a Let's Encrypt certificate for its own name.
- A Node.js app was built from a public Git repository in about 2 minutes, got its certificate, and redirected HTTP to HTTPS. Apps saw each visitor's real address, over both IPv4 and IPv6.
- A PostgreSQL database was reachable from the app but not from the internet, and a backup of it was taken on demand.
- The dashboard's extra ports were closed to the internet, and everything came back by itself after a reboot.
With two apps and a database, the server used about 1.1 GB of memory.
Before you start
You need:
- a fresh Melonslab server with Debian 13 and nothing else installed, with at least 2 vCPU and 2 GB of memory, which is Coolify's minimum;
- a name for the dashboard, such as
coolify.example.com, and one for each app, such asapp.example.com, with A and AAAA records pointing at the server.
Set up SSH keys and automatic security updates as in steps 1 to 3 of the security guide, and skip its step 4: Docker opens container ports past ufw, so step 5 here closes the ports that should not be public instead.
The examples use coolify.example.com for the dashboard and app.example.com for an app. Replace them with your own throughout.
1. Install Coolify
Anyone who opens a new Coolify first can create its admin account, and with it control the server. So create the account while installing. As root:
apt update
apt install -y curl
curl -fsSL https://cdn.coollabs.io/coolify/install.sh -o coolify-install.sh
ROOT_USERNAME=anna ROOT_USER_EMAIL=anna@example.com ROOT_USER_PASSWORD='Choose-a-long-passw0rd!' bash coolify-install.sh
The password needs at least 8 characters, with upper and lower case, a number and a symbol. Coolify also checks it against Have I Been Pwned's list of leaked passwords, and skips creating the account if it is on it. The email address must be on a domain that exists.
The installer finishes with Your instance is ready to use! and the dashboard's address, http:// and the server's IPv4 address with :8000. It saves the account's password in /data/coolify/source/.env, which every user on the server can read. Once you have logged in, remove it:
sed -i '/^ROOT_USER_PASSWORD=/d' /data/coolify/source/.env
The same file holds Coolify's encryption keys. Keep a copy of it somewhere safe, away from the server, such as in a password manager.
2. Log in and connect the server
Open the address, and log in with the email address and password. Coolify's first steps connect it to the server it runs on:
- Choose Continue, then This machine.
- Choose Create "My First Project", then Go to dashboard.
Coolify starts its proxy, which answers on ports 80 and 443.
3. Give the dashboard its own name
Open Settings. Under URL, enter https://coolify.example.com, and choose Save changes. Within a minute, the dashboard answers on that name with a Let's Encrypt certificate. From now on, log in there.
Under Settings and Advanced, set Anonymous telemetry to Disabled. It is on by default, and sends a signal at every start and error reports that include your email address and the admin's. Sponsorship reminders can be switched off there too.
4. Deploy an app
Point app.example.com at the server first, with an A and an AAAA record. Then, in Projects, open My first project and its production environment, and choose New Resource:
- Choose Public Git Repository, enter the repository's address, and choose Check Repository. For a first test, Coolify's own examples work:
https://github.com/coollabsio/coolify-examples, with/nodejsas the Base directory. - Check the Branch, the Build pack, Railpack by default, which detects the language by itself, and the Port the app listens on. Choose Continue.
- Coolify gives the app an address under
sslip.io, a public service that turns a name into the IP address inside it. Open Domains, and choose Add Domain. Enterapp.example.comas the Domain, keep https, and choose Save. Coolify also addswww.app.example.com: point a record at it too, or delete it and thesslip.ioaddress under Actions. - Choose Deploy. The deployment log shows the build, and the app answers at
https://app.example.comwhen it is done. Redirect HTTP to HTTPS is on by default.
A private repository needs a deploy key, and GitHub and GitLab can be connected as an app for deploys on every push, both from New Resource and Sources.
Apps behind Coolify's proxy see the visitor's address in the X-Forwarded-For and X-Real-Ip headers.
5. Close the dashboard's extra ports
The dashboard also answers on ports 8000, 6001 and 6002, directly on the server's address. Once it has its own name, it no longer needs them. Docker opens container ports past ufw, so close them in Docker's own chain, with a service that adds the rules again after every restart. Create /etc/systemd/system/coolify-ports.service:
[Unit]
Description=Keep Coolify dashboard ports off the internet
After=docker.service
Requires=docker.service
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c "for t in iptables ip6tables; do for p in 8000 6001 6002; do $t -C DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport $p -j DROP 2>/dev/null || $t -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport $p -j DROP; done; done"
[Install]
WantedBy=multi-user.target
Then start it:
systemctl daemon-reload
systemctl enable --now coolify-ports.service
The rules drop connections from the internet to those three ports, over IPv4 and IPv6, and leave the dashboard at https://coolify.example.com working.
6. Add a database
In the same environment, choose New Resource, then PostgreSQL, or another database. Coolify starts it with a generated password. It is not reachable from the internet unless you make it public, and your apps reach it at the internal address on the database's page.
7. Back up
Open the database, then Backups, and choose + Add to create a schedule, such as 0 3 * * * for every night at three. Back Up Now on the schedule takes one straight away. The backups are saved in /data/coolify/backups. A backup that stays on the server does not help if the server is lost, so add an S3-compatible bucket under S3 Storage, and choose it in the schedule.
Your apps are rebuilt from Git, so the database backups, your copy of /data/coolify/source/.env, and any files your apps store are what you need to keep.
8. Updates
Coolify updates itself every night by default. You can change that under Settings and Updates. Debian's own packages are covered by the automatic security updates from the security guide.
Troubleshooting
The installer did not create your account. The password was too weak, was on the list of leaked passwords, or the email domain does not exist. Open the dashboard straight away and register, before anyone else can.
An app has no certificate. Its A and AAAA records do not point at the server yet. Domains shows DNS matches for each name that does, and Coolify requests the certificate once it can.
You cannot reach the dashboard at http:// and port 8000. Step 5 closed it. Use https://coolify.example.com. To open the ports again until the next restart, for example when the name does not work, run iptables -F DOCKER-USER and ip6tables -F DOCKER-USER from the console in the client area. systemctl restart coolify-ports.service closes them again.