# Coolify 4.4 adds built-in traffic analytics, external secrets and OIDC to self-hosted deployments

Coolify 4.4.0 turns its self-hosted deployment dashboard into a more complete operations control plane with Traefik/Caddy traffic rollups, secret-manager references, OIDC, audit logs and experimental SQLite—but enabling analytics restarts proxies and some integrations require redeployment.

Coolify 4.4.0 adds opt-in proxy traffic analytics, external secret managers, OIDC login, audit trails, Cloudflare DNS and experimental SQLite. Operators need to account for proxy restarts, Caddy redeploys and feature maturity.

- Status: Active
- Published: 2026-10-12T06:09:07+13:00
- Updated: 2026-10-12T06:09:07+13:00
- Categories: Cloud & Infrastructure, Hosting, Deployment & DevOps
- Tags: Coolify, deployment, Observability, OpenID Connect, secrets management, self-hosting
- Canonical HTML: https://beyondthe.news/dossiers/coolify-4-4-traffic-analytics-external-secrets-oidc-sqlite

## What changed

Coolify released version 4.4.0 on October 6, 2026, with first-party traffic analytics for Traefik and Caddy proxies, support for Doppler, Infisical and HashiCorp Vault secret references, OpenID Connect sign-in, searchable team audit events, Cloudflare DNS record management, database import APIs, GitHub Actions runners on build servers, Docker registry logins and an experimental SQLite database service. Analytics is disabled by default and uses a Rust Sentinel component to process JSON proxy access logs into aggregate rollups; raw logs rotate on the server. Version 4.4.1 added volume-backup alerting and corrected scheduled backup failures; 4.4.2 followed with further fixes.

## Why it matters

Small teams running their own PaaS can now obtain several capabilities usually assembled from separate products: operational traffic visibility, identity-provider login, external secret management and auditability. That changes the complexity and cost of running a modest self-hosted fleet. The operational caveats matter as much as the headline: turning analytics on restarts proxy/Sentinel processes, Caddy workloads need redeployment to acquire log labels, and SQLite support is explicitly experimental.

## Traffic analytics runs at the proxy and keeps aggregate rollups

The new Sentinel-based system processes Traefik and Caddy JSON access logs into request, bandwidth, visitor, latency, status, country, device, path and referrer views. The per-server switch is off by default; enabling it restarts the proxy and Sentinel. Caddy applications and services must be redeployed after toggling to refresh their logging labels, and require caddy-docker-proxy 2.9 or newer. Nginx is not included.

## External secret managers replace copying secrets into the dashboard

Coolify can resolve `{{vault.KEY}}` references from Doppler, Infisical and HashiCorp Vault when an app deploys or a database starts. Release notes say resolved values are not stored in Coolify's database and are redacted from deployment logs. Build reuse is skipped when build-time secret references may have changed. Teams should still audit where resolved secrets are exposed in running containers and third-party provider access policies.

## OIDC and audit logs tighten multi-user operations

OpenID Connect login enables identity-provider authentication, while a searchable Team Audit Log records UI, API, MCP and webhook actions. Coolify says change events are encrypted at rest, sensitive fields are redacted, and events are pruned after 90 days. Audit visibility is a useful operational control but not a substitute for least-privilege access.

## SQLite and DNS management reduce small-stack setup work

An experimental standalone SQLite database service supports same-server application volume attachment and scheduled backups. Cloudflare token integration can create or manage matching DNS records from domain settings. SQLite remains a file-based deployment choice with concurrency, backup consistency and availability considerations unlike a managed multi-node database.

## Minor releases add operational fixes

Coolify 4.4.1 added missing-volume-backup notifications and fixed some deployment progress and missed-backup tracking; the changelog lists 4.4.2 as a further patch. Review the current patch level before production rollout rather than assuming the original 4.4.0 build is the preferred deployment target.

## Key details

- Coolify 4.4.0 released October 6, 2026.
- Built-in Traefik/Caddy traffic analytics is off by default and processes aggregate rollups.
- Enabling analytics restarts proxy and Sentinel; Caddy apps require redeployment and caddy-docker-proxy >=2.9.
- Doppler, Infisical and HashiCorp Vault secrets can be resolved at deployment without storing values in Coolify's database.
- OIDC sign-in and team audit logs are included; audit events are pruned after 90 days.
- Experimental SQLite service supports app attachment and backups.
- Cloudflare DNS management and database import API were added.
- 4.4.1 added backup alerts and operational fixes; 4.4.2 is also listed.

## Builder takeaways

- Schedule a maintenance window before enabling proxy analytics, and redeploy Caddy-backed workloads as documented.
- Use secret references for deployment and rotate/test provider credentials rather than copying long-lived values into configuration.
- Configure OIDC access controls and audit retention appropriate to your team's operational needs.
- Treat SQLite as experimental; validate backups and file-volume ownership before trusting it with production data.
- Upgrade to the latest compatible 4.4.x patch after reading fixes and known issues.

## What to watch

- Stability and supported topology of the experimental SQLite service.
- Whether analytics supports Nginx and richer retention/export controls.
- Security review and adoption of external secret-manager integrations and OIDC.
- Post-4.4.x regression reports and release fixes.

## Uncertainties

- The 4.4.0 release notes describe features but do not establish independent production reliability across all deployment types.
- SQLite support is explicitly experimental, and not equivalent to a managed HA database.
- The release does not claim that secrets cannot appear in running application environments; only Coolify storage and deployment log handling are described.

## Sources

- [Coolify v4.4.0 release notes](https://github.com/coollabsio/coolify/releases/tag/v4.4.0) — Coolify maintainers · primary · 2026-10-06T00:00:00+13:00. Feature details, opt-in analytics caveats, secrets, audit logging and experimental SQLite.
- [Coolify Changelog](https://next.coolify.io/changelog) — Coolify · primary documentation · 2026-10-08T00:00:00+13:00. Version 4.4.1/4.4.2 fixes and feature rollout context.
- [Coolify 4.4.0 release mirror](https://freedom.tech/posts/2026-10-06-coolify-4-4-0/) — Freedom.Tech · independent release coverage · 2026-10-06T00:00:00+13:00. Independent republication used for cross-check; does not constitute independent production testing.

