What changed
Coolify released version 4.4.0 on October 6, 2026, with first-party traffic analytics for Traefik and Caddy proxies, support for Doppler, Infisical and HashiCorp Vault secret references, OpenID Connect sign-in, searchable team audit events, Cloudflare DNS record management, database import APIs, GitHub Actions runners on build servers, Docker registry logins and an experimental SQLite database service. Analytics is disabled by default and uses a Rust Sentinel component to process JSON proxy access logs into aggregate rollups; raw logs rotate on the server. Version 4.4.1 added volume-backup alerting and corrected scheduled backup failures; 4.4.2 followed with further fixes.
Why it matters
Small teams running their own PaaS can now obtain several capabilities usually assembled from separate products: operational traffic visibility, identity-provider login, external secret management and auditability. That changes the complexity and cost of running a modest self-hosted fleet. The operational caveats matter as much as the headline: turning analytics on restarts proxy/Sentinel processes, Caddy workloads need redeployment to acquire log labels, and SQLite support is explicitly experimental.
Traffic analytics runs at the proxy and keeps aggregate rollups
The new Sentinel-based system processes Traefik and Caddy JSON access logs into request, bandwidth, visitor, latency, status, country, device, path and referrer views. The per-server switch is off by default; enabling it restarts the proxy and Sentinel. Caddy applications and services must be redeployed after toggling to refresh their logging labels, and require caddy-docker-proxy 2.9 or newer. Nginx is not included.
External secret managers replace copying secrets into the dashboard
Coolify can resolve `{{vault.KEY}}` references from Doppler, Infisical and HashiCorp Vault when an app deploys or a database starts. Release notes say resolved values are not stored in Coolify's database and are redacted from deployment logs. Build reuse is skipped when build-time secret references may have changed. Teams should still audit where resolved secrets are exposed in running containers and third-party provider access policies.
OIDC and audit logs tighten multi-user operations
OpenID Connect login enables identity-provider authentication, while a searchable Team Audit Log records UI, API, MCP and webhook actions. Coolify says change events are encrypted at rest, sensitive fields are redacted, and events are pruned after 90 days. Audit visibility is a useful operational control but not a substitute for least-privilege access.
SQLite and DNS management reduce small-stack setup work
An experimental standalone SQLite database service supports same-server application volume attachment and scheduled backups. Cloudflare token integration can create or manage matching DNS records from domain settings. SQLite remains a file-based deployment choice with concurrency, backup consistency and availability considerations unlike a managed multi-node database.
Minor releases add operational fixes
Coolify 4.4.1 added missing-volume-backup notifications and fixed some deployment progress and missed-backup tracking; the changelog lists 4.4.2 as a further patch. Review the current patch level before production rollout rather than assuming the original 4.4.0 build is the preferred deployment target.