Coolify is free if you host it yourself, and Coolify Cloud costs $5 a month for two servers, plus $3 for each extra one (pricing). It's the most popular open-source self-hosted platform, with about 62,500 GitHub stars (repo), and I think it's the best pick if you want Docker Compose, a large one-click catalog and scheduled backups. The costs are elsewhere: 70 published security advisories, frequent releases, and multi-server support that stops short of load balancing.
Facts checked 2026-10-01 against Coolify's docs, pricing page and GitHub, linked next to each claim. I haven't run Coolify myself for this review. Everything below comes from its documentation, its GitHub repository and what users report on Hacker News and GitHub. I build Ployz, a competing tool, so I've tried hard to say where Coolify is ahead, and it is ahead in several places.
How does Coolify compare with Ployz?
Coolify has more features: Compose files, 300+ one-click services, scheduled database and volume backups to S3, team roles and server provisioning. Ployz is narrower. It stages dashboard edits for review before a deploy, connects servers over an encrypted WireGuard network with private DNS, and puts a load balancer on every server. Both are free on your own servers and both keep serving if their cloud dashboard goes down.
| Coolify | Ployz | |
|---|---|---|
| Price on your own servers | Free, all features (pricing) | Free, unlimited servers and projects |
| Hosted dashboard | Coolify Cloud, $5/month for 2 servers, +$3 per server | Ployz Cloud; custom domains $9/month |
| Fully self-hosted dashboard | Yes | Yes, with Docker Compose, but it still uses Ployz's relay and DNS |
| Docker Compose files | Yes (docs) | No |
| One-click services | 300+ Compose templates (docs) | Postgres, Redis, MySQL, MongoDB |
| Scheduled database backups to S3 | Yes (docs) | No, you back up yourself |
| Preview environment per pull request | Yes (docs) | Yes, settings ship with the merge |
| Dashboard edits reviewed before deploy | No; 4.3.0 removed deploy confirmations (release) | Yes, edits are staged |
| Zero-downtime deploys | Rolling updates, not for Compose or previews (docs) | Yes, once you set a health check; databases restart |
| Private network across servers | Not built in, as far as its docs show | Encrypted WireGuard network, private DNS names |
| Traffic across servers | You add an external load balancer (docs) | A Caddy load balancer on every server, up to 50 replicas |
| Team roles | Yes, with a read-only Member role (release) | No |
| Git providers | GitHub and GitLab, including self-hosted GitLab (release) | GitHub only |
| Creates servers for you | Hetzner, DigitalOcean, Vultr (docs) | No |
| License | Apache-2.0 | CLI and server software Apache-2.0, dashboard AGPL-3.0 |
What does Coolify cost?
Self-hosted Coolify is free with "Full access to all features" and "No limitation or restrictions" (pricing). Coolify Cloud, where the Coolify team runs the dashboard and your apps stay on your servers, is $5 a month including two servers and $3 a month for each extra server, with 20% off yearly. Either way you pay for the servers yourself.
| Setup | Coolify cost | Server cost (Hetzner CX23, Europe) | Monthly total |
|---|---|---|---|
| Self-hosted, apps on the same server | $0 | $6.49 + $0.60 IPv4 | about $7 |
| Coolify Cloud, 1 server | $5 | about $7 | about $12 |
| Coolify Cloud, 3 servers | $5 + $3 = $8 | about $21 | about $29 |
| Coolify Cloud, 5 servers | $5 + $9 = $14 | about $35 | about $49 |
Coolify Cloud adds "Free email alerts", "Community + limited email support" and "Founder-tested updates" (pricing). The Cloud dashboard runs on Hetzner in Germany and reaches your servers over SSH from published IP addresses (Cloud docs).
On the server side, a Hetzner CX23 (2 vCPU, 4 GB RAM, 40 GB) is $6.49 plus $0.60 for IPv4 after Hetzner's 15 June 2026 price rise, and the CX line is Europe only. My first pick is Netcup's VPS 500 (2 vCPU, 4 GB RAM, 64 GB SSD) at €8.26 a month incl. VAT on a 12-month term (netcup VPS), which also has a US datacenter in Manassas. Hetzner pricing covers both 2026 rises.
Compared with hosted platforms, these numbers are tiny. When I was on Railway I paid $500+ a month, and PaaS pricing shows why: per-seat and per-service fees stack up in a way a $7 server doesn't.
What do you need to install Coolify?
Coolify's docs ask for 2 CPU cores, 2 GB RAM and 10 GB free disk on amd64 or arm64, running Debian, Ubuntu, a Red Hat family distro, SUSE, Arch, Alpine or 64-bit Raspberry Pi OS (installation). Install is one command as root: curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash, then open port 8000.
The docs say it can run on "1 CPU core, 512 MB RAM, 4 GB disk, but this is not recommended." Remember that 2 GB is for Coolify itself. Your apps, databases and Docker builds need memory on top, so a 4 GB server is where I'd start.
Two warnings from the install page are worth taking seriously:
- "Anyone who reaches the registration page first can become the instance admin and gain root access to your server." Create the admin account the moment the install finishes, or firewall port 8000 to your own IP first.
- Back up
/data/coolify/source/.envright away. It holds the encryption keys you need to restore the instance.
If you've never prepared a server before, how to set up a VPS covers SSH keys, the firewall and updates, which Coolify leaves to you.
Is Coolify good on Hetzner?
Yes, it's the most common pairing. Hetzner offers a ready-made Coolify app image on Ubuntu 24.04 that sets up Docker and Coolify on first login (Hetzner docs). Coolify can also create Hetzner, DigitalOcean and Vultr servers for you with a cloud API token (docs).
That provisioning is something Ployz doesn't do: with Ployz you rent the server yourself and point Ployz at it. The "Beginner Guide to VPS Hetzner and Coolify" reached 306 points on Hacker News, and one commenter pointed out the Hetzner image as the shortcut. Several commenters there also add Tailscale or Cloudflare in front, which says something about how much hardening people still do by hand.
One note for US readers: Hetzner's US servers got expensive after the June 2026 rise. Netcup's Manassas datacenter or DigitalOcean is the cheaper US option, and Coolify can provision DigitalOcean servers directly.
Does Coolify support Docker Compose?
Yes, and this is Coolify's biggest advantage over Ployz. You can deploy a Compose file from a Git repository or paste one in, and Coolify adds the proxy and network config. "Magic" variables like ${SERVICE_PASSWORD_POSTGRES} and ${SERVICE_URL_API_3000} generate shared passwords and domains for you (Compose docs).
The limits, from the same page:
- No rolling updates for Compose. Compose resources use their own reconciliation, so a redeploy can drop requests.
- Health checks live in the Compose file, not in Coolify's normal health check settings.
- "Raw" mode stops Coolify managing proxy labels and networking, and you configure everything yourself.
The one-click catalog is built on the same mechanism: over 300 Compose templates (services), from Ghost and Plausible to Langfuse. Templates break and get fixed. The v4.0.0 release notes fix Jitsi, Twenty and Logto templates and disable Cal.com after it went closed source. A Hacker News user running Coolify for months wrote that for anything beyond one-click installs they "sometimes feel like bumping into a brick wall" and fall back to a standalone Compose setup.
Ployz doesn't read Compose files at all. You deploy each service separately and they reach each other by private DNS name. If your app already lives in a 10-service Compose file, Coolify is the easier move. For a plain Docker hosting setup, it matters less.
What does Coolify get right?
Scope. Coolify covers almost everything a small team needs on its own servers: Git push deploys with Nixpacks, Railpack or a Dockerfile, preview deployments, scheduled backups for Postgres, MySQL, MariaDB, MongoDB and ClickHouse to S3, volume backups since 4.3.0, team roles, notifications, and an API and MCP server. Users praise how fast new projects go up.
- Backups. Database backups run on a cron schedule, keep a configurable number of copies and can upload to any S3-compatible storage (backups). Version 4.3.0 added scheduled backups for persistent volumes and directory mounts too (release). The docs are honest about it: "A successful backup only proves that Coolify created a file", so test restores. Redis isn't covered.
- Preview deployments. With a GitHub App and a wildcard DNS record, each pull request gets its own URL (
{{pr_id}}.{{domain}}by default), and Coolify deletes it when the PR closes (preview docs). More on the concept in ephemeral environments. - Teams. Teams with roles, and the Member role became read-only in 4.2.0. OIDC single sign-on is in the 4.4 release candidate.
- Real users at scale. On the 2025 Hacker News launch thread (382 points), Zach Latta of Hack Club said they host over 100 services on Coolify and called it "weirdly reliable". Another user reported a year of low maintenance with built-in backups.
Is Coolify secure?
Coolify has published 70 security advisories on GitHub: 21 critical, 26 high, 15 medium and 8 low (advisories). Most are command injection or cross-team access bugs that need a logged-in user. The 2026 batch was fixed in v4 betas before the 4.0 release and disclosed afterwards. Keep it updated and limit who has an account.
The pattern matters more than the count. Coolify builds shell commands from user input in many places, and the advisories keep finding new ones: volume names, health check commands, database credentials, pre-deploy commands. A few examples:
- CVE-2026-34047 (9.9): a WebSocket access control flaw leading to remote code execution, fixed in 4.0.0-beta.471.
- CVE-2026-41896 (7.5): unauthenticated deployment triggers through a webhook HMAC bypass when no secret was set.
- CVE-2026-57498 (9.6): one team could deploy to another team's servers.
- CVE-2025-22609 (10.0): private key hijacking leading to remote code execution, from January 2025.
Most of these require an account on your instance, so a solo developer with one login is at lower risk than a shared instance with many members. But Coolify holds root SSH keys to every server it manages, so a bug in the dashboard is a bug with root on your fleet. Updating promptly is not optional.
Where does Coolify hurt?
Four places, from its own docs and issue tracker. Zero-downtime deploys have many exceptions. Adding servers doesn't spread traffic. Releases come fast, with breaking changes inside minor versions. And there are long-running CPU and proxy bugs. None of these are hidden, which I respect, but you should know them before you put a business on it.
Zero-downtime has exceptions. Coolify does rolling updates for Nixpacks, Railpack, Dockerfile and image apps, but not for Compose, pull-request previews, apps that publish a host port, or apps with custom container names. In those cases "Coolify stops the current container first" (rolling updates). Missing zero-downtime deploys was the deal-breaker for one HN commenter who paid for a month and left.
Multi-server is not a cluster. You can deploy the same app to several servers, but "Adding deployment servers does not distribute traffic by itself." The docs tell you to put a cloud load balancer in front, and they list load balancers, DNS, firewalls, shared storage and monitoring as yours to build (multiple servers). Docker Swarm support is marked deprecated. Coolify's founder has said v5 will bring "full scalability in the core" (v4.0.0 notes), but it isn't out.
Release churn. Coolify shipped 4.0.0 on 27 April 2026 after years of beta, then 24 stable releases between 4.3.0 on 12 August and 4.3.23 on 18 September (releases). 4.3.0 included breaking changes: Member roles became read-only, state-changing API calls now require POST, and deploy confirmation dialogs were removed so deploys start immediately. If you script against the API or have teammates, read every changelog.
Open bugs. The repo has 546 open issues and 191 open pull requests. Some of the most-discussed: an hourly CPU spike open since 2024, a ~400% CPU overload from the scheduler and queue, wrong X-Forwarded-For headers behind the proxy, and preview deployments not triggering on PR open. One user on HN described an evening fighting a proxy that wouldn't start "with no helpful UI feedback".
You still run a server. OS updates, firewalls and disk space are yours. The commenter on HN who wrote that with self-hosted platforms "I find myself maintaining the PaaS instead of maintaining my app" (thread) put the general trade well.
Is Coolify production ready?
For small teams with a handful of apps on one or two servers, yes. The founder says "thousands of companies and people" ran it in production during the beta, and 4.0 ended that beta (v4.0.0 notes). I'd hesitate for anything that needs traffic spread across servers, strict zero-downtime on Compose apps, or a dashboard exposed to many users, given the advisory history. Test your backups and restores before you rely on them.
The top Google result for "coolify" right now is a r/selfhosted appreciation thread, and the HN threads above are mostly positive. People who leave tend to cite the UI, the proxy debugging and zero-downtime gaps rather than data loss.
Coolify or Ployz?
Pick Coolify if your app is a Docker Compose file, you want one-click installs of open-source apps, you need scheduled backups to S3 built in, you use GitLab, you have teammates who need roles, or you want the dashboard fully on your own hardware. Self-hosted it's free, and on Hetzner it's a good setup for about $7 a month.
Pick your own server with Ployz if you want dashboard changes staged and reviewed before they deploy, a preview environment per pull request whose settings ship with the merge, and servers that join an encrypted private network with a load balancer on each, so going from one server to two doesn't mean renting a load balancer. You give up Compose, the template catalog and backups, so plan a pg_dump cron job of your own.
Ployz deploys from GitHub to servers you rent, with zero-downtime deploys and preview environments, and it's free on your own servers.