All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
0.1.19 (2026-08-29)
- application: keep noindex_domains configured order (#820) (114f480), closes #818
- ci: upsert one social preview reminder issue (#816) (a8dedc5), closes #774
- extra-key probe smtp_ehlo_domain on CI edge (#814) (3bcdf6b)
- service: preserve configured urls order on read-back (#819) (d2c3b30), closes #818
- wait for social preview confirm before leaving Settings (#817) (864c709)
0.1.18 (2026-08-22)
- add instance email settings data source (#804) (4632a5a)
- notification: add smtp_ehlo_domain to email notifications (#800) (f49d954)
- pin Coolify v4.3.10 and add instance email settings (#802) (6346ad7)
0.1.17 (2026-08-19)
- application: keep explicit docker image tag on update (#788) (4043caf)
- application: split docker image into name and tag on update (#784) (7dd47f7)
- database: omit Coolify-rejected fields from create PATCH (#790) (2a0b5a6), closes #789
- deployment: deploy on first apply instead of restart (#785) (fd0208f)
- union Coolify allowlists and cover service PATCH (#795) (2d01c95)
0.1.16 (2026-08-16)
- pin Coolify API contract to v4.3.3 (#777) (ee3bc76)
- pin Coolify API contract to v4.3.5 (#779) (6160fac)
0.1.15 (2026-08-14)
- application: consistent container name docs and API parity acc depth (#756) (005cb91)
- Coolify API parity for GitLab Apps, tags, shared envs, and server control (#752) (f7bf746)
- enable Hetzner backups and cover DO/Vultr list clients (#767) (ee666bd), closes #764 #765
- expose Coolify 4.3.3 tip GET fields (#758) (1427672), closes #719
- hetzner: attach networks and firewalls on coolify_server_hetzner (#761) (bc1dd32), closes #760
- floor acc skips, shared env key validation, and docs counts (#757) (4455b56)
- redact API keys in logs and cover server control-plane (#769) (06fdb83)
- send Hetzner SSH key IDs as JSON arrays (#766) (eb7198f)
- stop server proxy acc from setting redirect_enabled false (#768) (c9e743d)
0.1.14 (2026-08-13)
- coolify_notification_discord and coolify_notification_slack (#703) (46f8388)
- coolify_notification_email and coolify_notification_telegram (#706) (cf398bb)
- coolify_notification_webhook and coolify_notification_pushover (#705) (fb0d7ad)
- coolify_s3_storage and CI OpenTofu flake hardening (#689) (23c5952)
- coolify_s3_storage_validate and shared create read-back helpers (#698) (f333989)
- drive API_COVERAGE from Coolify contract routes (#702) (b250364)
- expose Coolify tip docker/compose version probes on servers (#708) (c8a1699)
- notification data sources, 404 tests, and event mapping errors (#725) (2d4e4e1)
- pin Coolify API contract to v4.3.2 (#709) (d791afa), closes #699
- pin Coolify contract to v4.3.1 and watch tip API early (#686) (8da70af)
- shared notification helpers and acme-notifications scenario (#715) (fac7535)
- align notification mapping errors and thread tests (#729) (fe28850)
- bump Go 1.26.5 to 1.26.6 for stdlib CVEs (#734) (2ec06ce)
- include Coolify deploy logs and retry acme-github-cicd (#730) (8a2df24), closes #728
- S3 docs accuracy, CI scenario path filter, DS error IDs (#694) (336b046)
0.1.13 (2026-08-10)
- expose destination_uuid on applications and databases (#678) (ee533a0)
- service: expose destination_uuid on coolify_service (#680) (3da5208)
0.1.12 (2026-08-05)
- application: normalize docker_compose_domains array vs object (#658) (90bfe97)
- contract: expand PHP ...self::CONST spreads in allow-list extract (#665) (d280f37), closes #661
- security: scorecard improvements (vulns, provenance, branch) (#669) (3677e33)
- version-gate Coolify 4.2-only application write fields (#662) (91814a5)
0.1.11 (2026-08-01)
- clear deferred contract field umbrella (#626) (#641) (ac8ebdc)
- expose autogenerate_domain and related domain controls (#646) (802a9fc)
0.1.10 (2026-07-30)
- application preview/build secrets/stop grace and scheduled task container/timeout (#630) (7581335)
- expose env is_runtime, is_literal, is_multiline, and comment (#625) (a5dad15)
- github_app SSH fields plus MPI test and docs polish (#633) (fb4746a)
- accept legacy short Coolify identifiers in UUID validation (8009c61)
- accept unknown docker_compose_raw/type in service ValidateConfig (#618) (4ad9ae0)
- ci: skip Auto Approve on fork PRs (#613) (fff6810)
- richer API error context and Coolify id troubleshooting (#617) (e54443c)
- ValidateConfig unknown guards for backups and richer client errors (#620) (c37c0af)
0.1.9 (2026-07-27)
- Coolify v4.2 contract, DigitalOcean/Vultr servers, destinations (#589) (6ae4681)
- coolify_storage_backup for volume backup schedules (#601) (e5a9ed5)
- accept Coolify bare human cron schedules (#603) (e0f641f)
- destination coverage, empty UUID guards, and v4.2 docs (#598) (d184aba)
- preserve raw custom_nginx_configuration on read (#604) (7e3a33b)
- use POST for Coolify action/validate endpoints (#587) (e03c47f)
0.1.8 (2026-07-18)
- application webhook secrets, import safety, seed fields, docs (#579) (6d03dc3)
- bump Go 1.26.4 to 1.26.5 (GO-2026-5856) (#570) (3334377)
- compound import server validation for databases and services (#580) (6b20719)
0.1.7 (2026-06-26)
- github_app: import by app_id instead of internal id (#559) (7250183)
- multi-perspective improvement rotation (client tests, doc fixes) (#561) (3e531b1)
0.1.6 (2026-06-24)
- address AI code quality findings (#537) (7d8d5c1)
- database health_check 422 on Coolify < v4.1.2, bump min version to 4.1.0 (#550) (01c1e57)
- document RELEASE_NOTES.md must be on main, not release branch (#527) (3e39513), closes #526
- release notes cleanup respects branch protection (#529) (55b897d), closes #526
- trigger social preview update on release, add upload script (#533) (8c2ea20), closes #530
0.1.5 (2026-06-13)
- support RELEASE_NOTES.md override for curated release descriptions (#525) (2597aa8), closes #524
- update contract to Coolify v4.1.2 (#518) (092ab4e), closes #517
- multi-perspective improvement cycle 1 (#515) (3aa4252)
- multi-perspective improvement cycle 2 (#520) (4bfec53)
0.1.4 (2026-06-03)
- handle PATCH decode error in mock, deduplicate test mux, simplify merge target (#508) (93fef84)
- increase polling timeout test context + bump Go 1.26.4 (#503) (6223542)
0.1.3 (2026-06-02)
- add coolify-v4-latest.json to .gitignore (09bc849)
- improve test honesty, CI safety, and error handling (#485) (ab40882)
0.1.2 (2026-06-01)
- ci: exclude release-please compare URLs from lychee link check (715124c)
0.1.1 (2026-06-01)
- add auto-approve workflow for solo maintainer PRs (de9e28f), closes #457
- adopt release-please for automated releases (#447) (56e1add)
- add deleted_at to internal fields exclusion test (#442) (8b89d2a)
- add make merge target and FOSSA false-positive filter (#435) (5323f97)
- ci: use original filename for FOSSA CLI sha256 verification (#440) (f2fe25f)
- remove unused Python imports and variables (#441) (24c928d)
- update CI job count to 9, add DCO, validate in counts-check (#461) (d5d78c0), closes #460
- update contract with new POST /sentinel/push route (#472) (c446a7f), closes #471
- update dependencies and pin FOSSA CLI for Scorecard (#438) (626f0bf)
- update stale CHANGELOG URL to current org (e5e698a)
- upgrade golang.org/x/crypto in tools module to v0.52.0 (#466) (87c90cf)
- use stable PR author check in auto-approve workflow (7f7599b)
- use workflow badge for FOSSA instead of API badge (#437) (ca8c4c1)
0.1.0 (2026-05-30)
coolify_github_app: Theprivate_keyattribute has been renamed toprivate_key_uuidto match the Coolify API spec. This field now accepts a UUID referencing an existingcoolify_private_keyresource instead of raw key content.coolify_database_backup: Theretain_daysattribute has been renamed toretain_amount_locally. The old name was misleading (it stored a count of backup copies, not days). Users must update their.tffiles to use the new name.coolify_s3_storageresource,coolify_s3_storagedata source, andcoolify_s3_storagesdata source have been removed. Current Coolify v4 has no public top-level S3 storage API. Manage S3 storages in the Coolify web UI and reference their UUIDs fromcoolify_database_backup.s3_storage_uuid. Before upgrading, remove these from state:terraform state rm coolify_s3_storage.<name>.
- UUID format validation on 13 attributes across server, Hetzner, backup, scheduled task, and GitHub App resources/data sources (catches malformed input at plan time instead of API time)
coolify_deployment:wait_for_completionattribute polls deployment status untilfinishedorerror;timeoutsblock for configurable Create timeoutcoolify_database_backup: 12 new fields for S3 toggle, selective backup, retention policies, and job timeout- All application resources: 16 new fields for resource limits, health checks, and auto-deploy control
- All database and service resources:
timeoutsblock with configurable Create timeout (default 10 minutes) - 4 new singular data sources:
coolify_deployment,coolify_environment_variable,coolify_scheduled_task,coolify_storage tflog.Debugstructured logging in all resource CRUD methods- Provider configuration with
endpointandtokenattributes (env var fallback:COOLIFY_ENDPOINT,COOLIFY_TOKEN) - Health check during
Configurevalidates API connection by calling/api/v1/version - Resources:
coolify_project- Manage projectscoolify_server- Register and configure serverscoolify_private_key- Manage SSH keyscoolify_application- Deploy applications from public Git repositoriescoolify_application_dockerfile- Deploy applications from Dockerfilescoolify_application_docker_image- Deploy applications from Docker images (Docker Hub, GHCR, etc.)coolify_application_private_git- Deploy applications from private Git repositories (SSH deploy key)coolify_application_github_app- Deploy applications via GitHub App integrationcoolify_environment- Manage project environmentscoolify_environment_variable- Manage env vars for applications, services, and databasescoolify_deployment- Trigger application deployments (withtriggersmap for force-redeploy)coolify_service- Deploy one-click services from the Coolify catalogcoolify_database_postgresql- Provision PostgreSQL databasescoolify_database_mysql- Provision MySQL databasescoolify_database_mariadb- Provision MariaDB databasescoolify_database_redis- Provision Redis databasescoolify_database_mongodb- Provision MongoDB databasescoolify_database_clickhouse- Provision ClickHouse databasescoolify_database_keydb- Provision KeyDB databases (Redis-compatible)coolify_database_dragonfly- Provision DragonFly databases (Redis-compatible in-memory store)coolify_database_backup- Schedule automated database backups with S3 storage and retentioncoolify_scheduled_task- Manage scheduled tasks on applications/servicescoolify_storage- Manage persistent storage volumescoolify_cloud_token- Manage cloud provider tokens (Hetzner)coolify_github_app- Manage GitHub App integrationscoolify_server_hetzner- Provision Hetzner Cloud servers via Coolify
- Data Sources:
coolify_project/coolify_projects- Read project(s)coolify_server/coolify_servers- Read server(s)coolify_server_resources- List all resources deployed on a servercoolify_server_domains- List all domains configured on a servercoolify_server_validation- Validate a server's connectivitycoolify_private_key/coolify_private_keys- Read SSH key(s)coolify_application/coolify_applications- Read application(s)coolify_application_logs- Read application logscoolify_database/coolify_databases- Read database(s)coolify_service/coolify_services- Read service(s)coolify_environment/coolify_environments- Read environment(s)coolify_environment_variable/coolify_environment_variables- Read / list environment variables for an application, service, or databasecoolify_deployment/coolify_deployments- Read / list deployments for an applicationcoolify_scheduled_task/coolify_scheduled_tasks/coolify_task_executions- Read scheduled task(s) and executionscoolify_storage/coolify_storages- Read / list persistent storage volumescoolify_cloud_token/coolify_cloud_tokens- Read cloud token(s)coolify_github_app/coolify_github_apps/coolify_github_app_repositories/coolify_github_app_branches- Read GitHub App(s) and reposcoolify_backup_executions- List backup execution historycoolify_resources- List all resources on a servercoolify_team/coolify_teams/coolify_team_members- Read team(s) and memberscoolify_health- Read Coolify instance health statuscoolify_version- Read the Coolify instance versioncoolify_hetzner_images/coolify_hetzner_locations/coolify_hetzner_server_types/coolify_hetzner_ssh_keys- Read Hetzner cloud resources
- All stateful resources support
terraform import(action/validation resources are lifecycle-only) - 99%+ Coolify v4 API coverage (134/135 endpoints)
- OpenAPI spec-driven test validation with libopenapi-validator
- API coverage tracking with auto-generated
API_COVERAGE.md - UUID format validators on all UUID input fields
- Retryable HTTP client with automatic retry on 429/5xx (3 retries, 30s timeout)
- Input validators:
build_packOneOf, FQDN format, cron syntax, port range (1-65535), UUID format, environment variable name format - Configurable
timeoutsblock on all application resources - Graceful handling of out-of-band resource deletion (404 in Read removes from state)
- 750+ unit tests with race detection across 40 packages
- CI pipeline: 8 jobs (detect changes, test, lint, validate, scenario tests, acceptance tests, spec freshness, CI gate)
- GoReleaser config for GPG-signed releases
- Computed
statusfield on all application resources - Full-stack deployment example
redeploy_on_updatenow triggers a restart for all configuration fields includingname,description, webhook secrets, auto-deploy settings, and container label options. Previously only runtime-affecting fields (ports, limits, health checks, build settings) were covered. Only immutable, computed-only, and theredeploy_on_updateflag itself are excluded.dockerfileanddocker_compose_rawattributes are now markedSensitive(they can contain embedded secrets such as build arguments or service credentials)- Redundant
UseStateForUnknownplan modifier removed fromdeployment_queue_limiton server resources (theDefaultvalue already handles this; no user-visible behavior change) - Consolidated
is_include_timestamps,enable_ssl, andssl_modehandling into shared database helpers, reducing duplication across all 8 database resources - Minimum Terraform version requirement updated to >= 1.6 (consistent across all documentation)
- Added TRACE-level logging to version and health check endpoints for easier connection debugging
coolify_github_app:app_id,installation_id,client_id,client_secret,private_key_uuid, andorganization_namecan now be updated in-place (previously forced destroy/recreate). This matches the Coolify API's PATCH support for these fields.coolify_application_github_app:github_app_uuidcan now be updated in-place (previously forced destroy/recreate).
-
API response bodies are now redacted in TRACE logs, preventing sensitive fields (passwords, keys) from appearing in debug output
-
Custom TLS configuration (
ca_cert,insecure) no longer silently disables HTTP retry logic -
redactJSONnow handles JSON arrays and nested objects (previously only top-level objects were redacted) -
coolify_serviceresource: changingname,description, orenvironment_namenow triggers destroy/recreate (previously produced an "Update not supported" error during apply) -
coolify_database_clickhouse:clickhouse_admin_userandclickhouse_admin_passwordare now sent during resource creation (previously silently ignored, only applied on update) -
All 8 database resources: removing
descriptionfrom config no longer leaves stale values in state (now correctly sets null when API returns empty) -
All 8 database resources:
environment_namenow hasRequiresReplace(changing it forces a new resource, matching the API's actual behavior) -
coolify_storageresource:UpdateStorageInputnow includesUUIDfield so PATCH correctly identifies the target storage -
coolify_deploymentresource:GetDeploymenterrors during Create now produce a warning diagnostic instead of silently defaulting to "queued" status -
coolify_private_keyresource: empty description from API now correctly becomesnullin state (consistent with all other resources) -
PollUntilDeleted(used by application and service Delete) now respects the parent context's deadline instead of always using a hardcoded 2-minute timeout. Resources with atimeoutsblock now have their configured timeout honored during delete polling.