Coolify Review 2026: What It Gets Right, and Where It Hurts

Nick Potts, who builds Ployz. Published , updated .

Coolify is free if you host it yourself, and Coolify Cloud costs $5 a month for two servers, plus $3 for each extra one (pricing). It's the most popular open-source self-hosted platform, with about 62,500 GitHub stars (repo), and I think it's the best pick if you want Docker Compose, a large one-click catalog and scheduled backups. The costs are elsewhere: 70 published security advisories, frequent releases, and multi-server support that stops short of load balancing.

Facts checked 2026-10-01 against Coolify's docs, pricing page and GitHub, linked next to each claim. I haven't run Coolify myself for this review. Everything below comes from its documentation, its GitHub repository and what users report on Hacker News and GitHub. I build Ployz, a competing tool, so I've tried hard to say where Coolify is ahead, and it is ahead in several places.

How does Coolify compare with Ployz?

Coolify has more features: Compose files, 300+ one-click services, scheduled database and volume backups to S3, team roles and server provisioning. Ployz is narrower. It stages dashboard edits for review before a deploy, connects servers over an encrypted WireGuard network with private DNS, and puts a load balancer on every server. Both are free on your own servers and both keep serving if their cloud dashboard goes down.

CoolifyPloyz
Price on your own serversFree, all features (pricing)Free, unlimited servers and projects
Hosted dashboardCoolify Cloud, $5/month for 2 servers, +$3 per serverPloyz Cloud; custom domains $9/month
Fully self-hosted dashboardYesYes, with Docker Compose, but it still uses Ployz's relay and DNS
Docker Compose filesYes (docs)No
One-click services300+ Compose templates (docs)Postgres, Redis, MySQL, MongoDB
Scheduled database backups to S3Yes (docs)No, you back up yourself
Preview environment per pull requestYes (docs)Yes, settings ship with the merge
Dashboard edits reviewed before deployNo; 4.3.0 removed deploy confirmations (release)Yes, edits are staged
Zero-downtime deploysRolling updates, not for Compose or previews (docs)Yes, once you set a health check; databases restart
Private network across serversNot built in, as far as its docs showEncrypted WireGuard network, private DNS names
Traffic across serversYou add an external load balancer (docs)A Caddy load balancer on every server, up to 50 replicas
Team rolesYes, with a read-only Member role (release)No
Git providersGitHub and GitLab, including self-hosted GitLab (release)GitHub only
Creates servers for youHetzner, DigitalOcean, Vultr (docs)No
LicenseApache-2.0CLI and server software Apache-2.0, dashboard AGPL-3.0

What does Coolify cost?

Self-hosted Coolify is free with "Full access to all features" and "No limitation or restrictions" (pricing). Coolify Cloud, where the Coolify team runs the dashboard and your apps stay on your servers, is $5 a month including two servers and $3 a month for each extra server, with 20% off yearly. Either way you pay for the servers yourself.

SetupCoolify costServer cost (Hetzner CX23, Europe)Monthly total
Self-hosted, apps on the same server$0$6.49 + $0.60 IPv4about $7
Coolify Cloud, 1 server$5about $7about $12
Coolify Cloud, 3 servers$5 + $3 = $8about $21about $29
Coolify Cloud, 5 servers$5 + $9 = $14about $35about $49

Coolify Cloud adds "Free email alerts", "Community + limited email support" and "Founder-tested updates" (pricing). The Cloud dashboard runs on Hetzner in Germany and reaches your servers over SSH from published IP addresses (Cloud docs).

On the server side, a Hetzner CX23 (2 vCPU, 4 GB RAM, 40 GB) is $6.49 plus $0.60 for IPv4 after Hetzner's 15 June 2026 price rise, and the CX line is Europe only. My first pick is Netcup's VPS 500 (2 vCPU, 4 GB RAM, 64 GB SSD) at €8.26 a month incl. VAT on a 12-month term (netcup VPS), which also has a US datacenter in Manassas. Hetzner pricing covers both 2026 rises.

Compared with hosted platforms, these numbers are tiny. When I was on Railway I paid $500+ a month, and PaaS pricing shows why: per-seat and per-service fees stack up in a way a $7 server doesn't.

What do you need to install Coolify?

Coolify's docs ask for 2 CPU cores, 2 GB RAM and 10 GB free disk on amd64 or arm64, running Debian, Ubuntu, a Red Hat family distro, SUSE, Arch, Alpine or 64-bit Raspberry Pi OS (installation). Install is one command as root: curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash, then open port 8000.

The docs say it can run on "1 CPU core, 512 MB RAM, 4 GB disk, but this is not recommended." Remember that 2 GB is for Coolify itself. Your apps, databases and Docker builds need memory on top, so a 4 GB server is where I'd start.

Two warnings from the install page are worth taking seriously:

  • "Anyone who reaches the registration page first can become the instance admin and gain root access to your server." Create the admin account the moment the install finishes, or firewall port 8000 to your own IP first.
  • Back up /data/coolify/source/.env right away. It holds the encryption keys you need to restore the instance.

If you've never prepared a server before, how to set up a VPS covers SSH keys, the firewall and updates, which Coolify leaves to you.

Is Coolify good on Hetzner?

Yes, it's the most common pairing. Hetzner offers a ready-made Coolify app image on Ubuntu 24.04 that sets up Docker and Coolify on first login (Hetzner docs). Coolify can also create Hetzner, DigitalOcean and Vultr servers for you with a cloud API token (docs).

That provisioning is something Ployz doesn't do: with Ployz you rent the server yourself and point Ployz at it. The "Beginner Guide to VPS Hetzner and Coolify" reached 306 points on Hacker News, and one commenter pointed out the Hetzner image as the shortcut. Several commenters there also add Tailscale or Cloudflare in front, which says something about how much hardening people still do by hand.

One note for US readers: Hetzner's US servers got expensive after the June 2026 rise. Netcup's Manassas datacenter or DigitalOcean is the cheaper US option, and Coolify can provision DigitalOcean servers directly.

Does Coolify support Docker Compose?

Yes, and this is Coolify's biggest advantage over Ployz. You can deploy a Compose file from a Git repository or paste one in, and Coolify adds the proxy and network config. "Magic" variables like ${SERVICE_PASSWORD_POSTGRES} and ${SERVICE_URL_API_3000} generate shared passwords and domains for you (Compose docs).

The limits, from the same page:

  • No rolling updates for Compose. Compose resources use their own reconciliation, so a redeploy can drop requests.
  • Health checks live in the Compose file, not in Coolify's normal health check settings.
  • "Raw" mode stops Coolify managing proxy labels and networking, and you configure everything yourself.

The one-click catalog is built on the same mechanism: over 300 Compose templates (services), from Ghost and Plausible to Langfuse. Templates break and get fixed. The v4.0.0 release notes fix Jitsi, Twenty and Logto templates and disable Cal.com after it went closed source. A Hacker News user running Coolify for months wrote that for anything beyond one-click installs they "sometimes feel like bumping into a brick wall" and fall back to a standalone Compose setup.

Ployz doesn't read Compose files at all. You deploy each service separately and they reach each other by private DNS name. If your app already lives in a 10-service Compose file, Coolify is the easier move. For a plain Docker hosting setup, it matters less.

What does Coolify get right?

Scope. Coolify covers almost everything a small team needs on its own servers: Git push deploys with Nixpacks, Railpack or a Dockerfile, preview deployments, scheduled backups for Postgres, MySQL, MariaDB, MongoDB and ClickHouse to S3, volume backups since 4.3.0, team roles, notifications, and an API and MCP server. Users praise how fast new projects go up.

  • Backups. Database backups run on a cron schedule, keep a configurable number of copies and can upload to any S3-compatible storage (backups). Version 4.3.0 added scheduled backups for persistent volumes and directory mounts too (release). The docs are honest about it: "A successful backup only proves that Coolify created a file", so test restores. Redis isn't covered.
  • Preview deployments. With a GitHub App and a wildcard DNS record, each pull request gets its own URL ({{pr_id}}.{{domain}} by default), and Coolify deletes it when the PR closes (preview docs). More on the concept in ephemeral environments.
  • Teams. Teams with roles, and the Member role became read-only in 4.2.0. OIDC single sign-on is in the 4.4 release candidate.
  • Real users at scale. On the 2025 Hacker News launch thread (382 points), Zach Latta of Hack Club said they host over 100 services on Coolify and called it "weirdly reliable". Another user reported a year of low maintenance with built-in backups.

Is Coolify secure?

Coolify has published 70 security advisories on GitHub: 21 critical, 26 high, 15 medium and 8 low (advisories). Most are command injection or cross-team access bugs that need a logged-in user. The 2026 batch was fixed in v4 betas before the 4.0 release and disclosed afterwards. Keep it updated and limit who has an account.

The pattern matters more than the count. Coolify builds shell commands from user input in many places, and the advisories keep finding new ones: volume names, health check commands, database credentials, pre-deploy commands. A few examples:

  • CVE-2026-34047 (9.9): a WebSocket access control flaw leading to remote code execution, fixed in 4.0.0-beta.471.
  • CVE-2026-41896 (7.5): unauthenticated deployment triggers through a webhook HMAC bypass when no secret was set.
  • CVE-2026-57498 (9.6): one team could deploy to another team's servers.
  • CVE-2025-22609 (10.0): private key hijacking leading to remote code execution, from January 2025.

Most of these require an account on your instance, so a solo developer with one login is at lower risk than a shared instance with many members. But Coolify holds root SSH keys to every server it manages, so a bug in the dashboard is a bug with root on your fleet. Updating promptly is not optional.

Where does Coolify hurt?

Four places, from its own docs and issue tracker. Zero-downtime deploys have many exceptions. Adding servers doesn't spread traffic. Releases come fast, with breaking changes inside minor versions. And there are long-running CPU and proxy bugs. None of these are hidden, which I respect, but you should know them before you put a business on it.

Zero-downtime has exceptions. Coolify does rolling updates for Nixpacks, Railpack, Dockerfile and image apps, but not for Compose, pull-request previews, apps that publish a host port, or apps with custom container names. In those cases "Coolify stops the current container first" (rolling updates). Missing zero-downtime deploys was the deal-breaker for one HN commenter who paid for a month and left.

Multi-server is not a cluster. You can deploy the same app to several servers, but "Adding deployment servers does not distribute traffic by itself." The docs tell you to put a cloud load balancer in front, and they list load balancers, DNS, firewalls, shared storage and monitoring as yours to build (multiple servers). Docker Swarm support is marked deprecated. Coolify's founder has said v5 will bring "full scalability in the core" (v4.0.0 notes), but it isn't out.

Release churn. Coolify shipped 4.0.0 on 27 April 2026 after years of beta, then 24 stable releases between 4.3.0 on 12 August and 4.3.23 on 18 September (releases). 4.3.0 included breaking changes: Member roles became read-only, state-changing API calls now require POST, and deploy confirmation dialogs were removed so deploys start immediately. If you script against the API or have teammates, read every changelog.

Open bugs. The repo has 546 open issues and 191 open pull requests. Some of the most-discussed: an hourly CPU spike open since 2024, a ~400% CPU overload from the scheduler and queue, wrong X-Forwarded-For headers behind the proxy, and preview deployments not triggering on PR open. One user on HN described an evening fighting a proxy that wouldn't start "with no helpful UI feedback".

You still run a server. OS updates, firewalls and disk space are yours. The commenter on HN who wrote that with self-hosted platforms "I find myself maintaining the PaaS instead of maintaining my app" (thread) put the general trade well.

Is Coolify production ready?

For small teams with a handful of apps on one or two servers, yes. The founder says "thousands of companies and people" ran it in production during the beta, and 4.0 ended that beta (v4.0.0 notes). I'd hesitate for anything that needs traffic spread across servers, strict zero-downtime on Compose apps, or a dashboard exposed to many users, given the advisory history. Test your backups and restores before you rely on them.

The top Google result for "coolify" right now is a r/selfhosted appreciation thread, and the HN threads above are mostly positive. People who leave tend to cite the UI, the proxy debugging and zero-downtime gaps rather than data loss.

Coolify or Ployz?

Pick Coolify if your app is a Docker Compose file, you want one-click installs of open-source apps, you need scheduled backups to S3 built in, you use GitLab, you have teammates who need roles, or you want the dashboard fully on your own hardware. Self-hosted it's free, and on Hetzner it's a good setup for about $7 a month.

Pick your own server with Ployz if you want dashboard changes staged and reviewed before they deploy, a preview environment per pull request whose settings ship with the merge, and servers that join an encrypted private network with a load balancer on each, so going from one server to two doesn't mean renting a load balancer. You give up Compose, the template catalog and backups, so plan a pg_dump cron job of your own.

Ployz deploys from GitHub to servers you rent, with zero-downtime deploys and preview environments, and it's free on your own servers.

Run the same app on a server you rent. Ployz is free on your own servers.

Deploy your app