--- title: Instance settings description: Configure self-hosted Coolify instance settings for URL, access, updates, backups, email, authentication. --- import { CloudStorage, Database, Mailbox, Refresh23, Settings, Setting2, } from 'reicon-react'; # Instance settings Instance settings control the Coolify control plane itself. These settings change the Coolify instance itself, not a project, application, database, service, or server. If you use **Coolify Cloud**, the Coolify team manages the Coolify instance for you. Coolify Cloud users cannot access or edit these settings. The following data is used as an example in this guide. Please replace it with your actual data when following the steps: - **Domain Name:** `shadowarcanist.com` - **Coolify Dashboard:** `https://coolify.shadowarcanist.com` Open **Settings** in the left sidebar, or visit: ```bash https://coolify.shadowarcanist.com/settings ``` The Settings page groups options under **Configuration** (General, Advanced, and Updates) and **Instance** (Backup, Email, and Authentication). Select a section from the Settings navigation, then use **Save changes** to apply your edits. ## Configuration Use General for the dashboard URL, HTTP-to-HTTPS behavior, instance label, timezone, and network addresses Coolify should use. ### URL This is the address you use to open the Coolify dashboard. Coolify also uses it when it needs to generate links back to the instance. If you want the dashboard to use HTTPS, the value must start with `https://`. Enter the full dashboard URL in **URL** and click **Save changes**. Before changing it, make sure DNS for the domain points to the server where Coolify is running. If DNS validation is enabled, Coolify checks the domain. Coolify also warns you when the instance URL is already used by another resource. **Accepted values:** - A full URL with a protocol, for example `https://coolify.shadowarcanist.com`. - Use `https://` when the dashboard should be served over HTTPS. - A root domain or subdomain. **Notes:** - Path-based URLs such as `https://shadowarcanist.com/coolify` are not supported. - Do not reuse an application or service domain for the dashboard. If the instance URL conflicts with a resource domain, SSL certificates and routing can become unpredictable. --- ### Redirect HTTP to HTTPS Controls whether requests to the Coolify dashboard over HTTP are redirected to HTTPS. Choose **Enabled** or **Disabled**, then click **Save changes**. **Notes:** - If a reverse proxy or Cloudflare Tunnel connects to Coolify over HTTP while users access the dashboard over HTTPS, enabling this setting can create a redirect loop. Disable the redirect in Coolify when your proxy handles HTTPS redirection. - Keep this enabled when Cloudflare uses **Full** or **Full (Strict)** SSL. **Accepted values:** - Enabled: redirect HTTP requests to HTTPS. - Disabled: do not redirect HTTP requests. --- ### Name Adds the instance name in brackets before the page title shown in the browser tab. For example, a name of `Production` appears as `[Production] Settings | Coolify`. It does not change the Coolify name or logo in the sidebar. Update **Name** and click **Save changes**. **Accepted values:** - Any text value up to 255 characters. - Leave it empty to keep the default Coolify instance name. --- ### Instance timezone This timezone is used by instance-level schedules, including update checks and automatic updates. It does not change the timezone inside your applications or databases. Search for the timezone in **Instance timezone**, select it from the list, and click **Save changes**. **Accepted values:** - A valid timezone identifier from the dashboard list, for example `UTC`, `Europe/Berlin`, or `America/New_York`. **Notes:** - Database backup schedules can use the server timezone when the server has one configured. Otherwise, they fall back to the instance timezone. --- ### Instance public IPv4 Coolify normally detects the public IPv4 address of the server that runs the instance. Use this field only when the detected address is wrong, usually on servers with multiple public IPs. Enter the IPv4 address Coolify should use and click **Save changes**. **Accepted values:** - Leave it empty to let Coolify use the detected address. - A valid IPv4 address, for example `203.0.113.10`. --- ### Instance public IPv6 Coolify normally detects the public IPv6 address of the server that runs the instance. Use this field only when Coolify picks the wrong IPv6 address or cannot detect it. Enter the IPv6 address Coolify should use and click **Save changes**. **Accepted values:** - Leave it empty to let Coolify use the detected address. - A valid IPv6 address, for example `2001:db8::1`. Advanced contains access, DNS validation, API and MCP, outbound endpoint, interface and telemetry, and image storage controls. ## Access ### Registration Controls whether users can create their own accounts from the registration page. Choose **Anyone can register** or **Registration disabled**, then click **Save changes**. **Accepted values:** - **Anyone can register:** anyone who can reach the registration page can create an account. - **Registration disabled:** only administrators can create accounts. **Notes:** - Keep registration disabled unless you intentionally want public self-registration. --- ### Destructive action confirmation Controls whether destructive actions require password and text confirmation. Choose **Require two-step confirmation** or **Skip two-step confirmation**, then click **Save changes**. **Accepted values:** - **Require two-step confirmation:** destructive actions require the extra confirmation step. - **Skip two-step confirmation:** destructive actions do not require the extra confirmation step. **Notes:** - Skipping confirmation increases the chance of accidental deletions or unwanted changes. --- ## DNS ### DNS validation Checks whether custom domains point to the right server before deployment. Choose **Enabled** or **Disabled**, then click **Save changes**. **Accepted values:** - **Enabled:** validate custom domains before deployment. - **Disabled:** skip DNS validation. --- ### Custom DNS servers Changes which DNS resolvers Coolify uses for domain validation. Enter the resolver IPs in **Custom DNS servers**, then click **Save changes**. **Accepted values:** - Leave it empty to use the system default DNS resolvers. - A comma-separated list of valid IPv4 or IPv6 addresses, for example `1.1.1.1,8.8.8.8`. --- ## API and MCP ### API access Controls whether authenticated requests to the Coolify REST API are allowed. Choose **Enabled** or **Disabled**, then click **Save changes**. For API tokens, follow [API tokens](/core/security/credentials/api-tokens). **Accepted values:** - **Enabled:** authenticated API requests are accepted. - **Disabled:** API requests are blocked. --- ### MCP server Enables the MCP endpoint at `/mcp` for authenticated clients. Use your instance URL followed by `/mcp` and authenticate with a Sanctum bearer token created from [API tokens](/core/security/credentials/api-tokens). **Accepted values:** - **Enabled:** the instance MCP endpoint is available to authenticated clients. - **Disabled:** the instance MCP endpoint is unavailable. For the detailed guide, follow [MCP integration](/mcp/what-is-mcp). --- ### Allowed API IPs Restricts which source IP addresses can call the Coolify API. Enter comma-separated IPs or CIDR ranges, then click **Save changes**. **Accepted values:** - Empty or `0.0.0.0` allows API access from anywhere. - Single IPv4 or IPv6 addresses, for example `192.168.1.100` or `2001:db8::10`. - CIDR ranges, for example `10.0.0.0/8` or `203.0.113.0/24`. **Notes:** - Allowing access from anywhere is not recommended for production instances. --- ## Outbound endpoints These controls limit which internal destinations Coolify can reach when making outbound requests. ### Allowed internal targets Lists the internal destinations Coolify can reach when making outbound requests. Enter the hostnames, IP addresses, or CIDR ranges required by your integrations. Separate entries with commas or new lines, then click **Save changes**. --- ### Localhost targets Controls whether outbound requests can target localhost addresses. Choose **Allowed** or **Blocked**, then click **Save changes**. **Notes:** - Loopback targets must also be included in **Allowed internal targets**. --- ## Interface and telemetry ### Navigation Enables SPA-style navigation and prefetching for smoother dashboard page transitions. Choose **SPA navigation** or **Full page navigation**, then click **Save changes**. **Accepted values:** - **SPA navigation:** dashboard links can prefetch and move between pages without full reloads. - **Full page navigation:** dashboard navigation uses full page loads. **Notes:** - Choose full page navigation if the dashboard has navigation issues after a browser or Livewire change. --- ### Anonymous telemetry Controls whether this instance sends an anonymous installation count to Coolify, contributing to the self-hosted installation count shown on [coolify.io](https://coolify.io/). Coolify does not store IP addresses or send error reports. Choose **Enabled** or **Disabled**, then click **Save changes**. **Accepted values:** - **Enabled:** do not send anonymous installation counts. - **Disabled:** allow anonymous installation counts. --- ### Sponsorship reminders Controls whether Coolify displays a sponsorship popup each month. Choose **Enabled** or **Disabled**, then click **Save changes**. **Accepted values:** - **Enabled:** monthly sponsorship reminders can be shown. - **Disabled:** sponsorship reminders are hidden for the instance. --- ## Image storage These controls determine where compressed profile pictures and project icons are stored and how Coolify serves them. ### Storage destination Choose **Local storage** or a configured S3-compatible storage destination, then click **Save changes**. Add and test an S3 storage under **Storages** before selecting it here. --- ### Image CDN URL Optionally sets the public CDN URL for profile pictures and project icons stored on S3. Enter the URL provided by your CDN, then click **Save changes**. Use the Updates page to check for new Coolify releases, install an update manually, or configure automatic updates. ### Update Coolify When an update is available, click **Upgrade Now** to start the update. Coolify installs the latest version automatically. Follow [Update Coolify](/core/instance-management/update) for details. --- ### Update checks Sets how often Coolify checks the [Coolify versions file](https://cdn.coollabs.io/coolify/versions.json) for a new release. Set **Check frequency**, then click **Save changes**. Click **Check Now** to check for an update immediately. **Accepted values:** - `every_minute`, `hourly`, `daily`, `weekly`, `monthly`, `yearly`, or a valid cron expression. - The default is `0 * * * *`, which checks every hour. --- ### Automatic updates Controls whether Coolify installs updates automatically on the configured schedule. Choose **Enabled** or **Disabled** under **Automatic updates**. This setting saves immediately. When enabled, set **Update frequency** and click **Save changes**. If the control is disabled, `AUTOUPDATE` is set in `/data/coolify/source/.env` and controls automatic updates instead. **Accepted values:** - **Enabled:** Coolify installs updates on the configured schedule. - **Disabled:** Coolify does not install updates automatically. --- ### Update frequency Sets how often Coolify installs updates when automatic updates are enabled. Enter the schedule in **Update frequency**, then click **Save changes**. This field is available when automatic updates are enabled and is managed by `AUTOUPDATE` in `/data/coolify/source/.env` when that variable is set. **Accepted values:** - `every_minute`, `hourly`, `daily`, `weekly`, `monthly`, `yearly`, or a valid cron expression. - The default is `0 0 * * *`, which runs every day at `00:00`. --- ### Image registry Choose the registry Coolify uses to pull its images. Switch registries if the current source is rate limited or unreachable, then click **Save changes**. **Accepted values:** - **Docker Hub** - **GitHub Container Registry** ## Instance The Backup page manages backups of Coolify's internal database. It does not back up application volumes or external databases. For the full backup guide, see [Instance backup](/core/backup-and-recovery/instance-backup). ### First-time setup When instance backup has not been configured, the page shows **Backup is not configured**. Click **Configure backup** to create the internal `coolify-db` resource and its scheduled backup. The localhost server must be functional; if it is not, open server settings and validate the localhost connection first. --- ### Instance database This section shows Coolify's internal `coolify-db` resource used for instance backups. Its **Name**, **UUID**, **User**, and **Password** are read-only. You can edit the **Description** and click **Save changes**. --- ### Backup schedule #### Enable or disable backups Use **Enable backup** or **Disable backup** to turn the scheduled backup job on or off. This action saves immediately. Click **Back up now** to start a backup without waiting for the next scheduled run. The database must be running for this action. #### Frequency Sets how often the internal Coolify database is backed up. Enter a preset such as `hourly`, `daily`, `weekly`, `monthly`, or `yearly`, `every_minute`, or a valid cron expression, then click **Save changes**. For example, `0 0 * * *` runs daily at midnight. #### Timezone Shows the timezone Coolify uses for the backup schedule. This field is read-only and uses the timezone set for Coolify's localhost server, or the instance timezone if no server timezone is set. #### Timeout Sets the maximum backup runtime in seconds. If a backup exceeds this time, Coolify marks that execution as failed. Enter a value from `60` to `36000`, then click **Save changes**. #### Missing backup alert after Sets how many days can pass without a backup execution before Coolify sends an alert through backup failure notification channels. Enter `0` to disable this alert, or a value from `1` to `365`, then click **Save changes**. --- ### S3 storage Use S3 storage to keep a remote copy of each instance backup. [Set up and validate an S3 storage destination](/core/s3-storage/overview) before enabling S3 backups. Click **Enable S3** to turn on uploads, then select an **S3 storage** destination. Choose whether **Local copy** should **Keep local backup** or **Delete after S3 upload**. Save changes after updating the local copy option. The storage selector is unavailable until a validated destination exists. --- ### Retention Set separate retention limits for **Local backups** and **S3 backups**. The first limit reached removes the oldest backup. A value of `0` means unlimited for that limit. Enter the limits, then click **Save changes**. For each location, you can set: - **Backups to keep:** maximum number of recent backups. - **Days to keep:** remove backups older than this many days. - **Maximum storage (GB):** remove the oldest backups after the total size reaches this value. Decimal values are accepted. --- ### Executions Review backup status, database, file path, finish time, duration, size, and local or S3 availability. To delete a backup, click its delete icon. Whether Coolify asks for password confirmation depends on [Destructive action confirmation](#destructive-action-confirmation): **Require two-step confirmation** shows the prompt, while **Skip two-step confirmation** skips it. Coolify deletes the local backup file, if it is still present, and removes the execution from the list. Click the download icon on a successful run to download its backup. **Clean failed backups** removes rows for unsuccessful runs. **Clean deleted entries** removes rows for backups whose local files have already been deleted; it does not delete files. Successful runs appear here after a scheduled or manual backup completes. Configure the sender identity and choose SMTP or Resend to deliver Coolify's transactional email. ### Sender Sender settings are shared by SMTP and Resend. #### From name Sets the display name shown in outgoing email, such as password resets and invitations. Enter a name, then click **Save changes**. **Accepted values:** - A required text value, for example `Coolify`. #### From address Sets the sender address used for outgoing email. Enter a valid email address, then click **Save changes**. **Accepted values:** - A required email address, for example `noreply@shadowarcanist.com`. --- ### SMTP server Connect Coolify to an SMTP-compatible email provider. Enter the required **Host**, **Port**, and **Encryption** values supplied by your provider. Fill the remaining fields as needed. #### SMTP delivery Choose **Enabled** to send email through SMTP or **Disabled** to turn SMTP off. This selection saves immediately. Enabling SMTP turns off Resend. #### Host Enter the SMTP server hostname provided by your email provider, for example `smtp.mailgun.org`. #### Port Enter the port provided by your email provider. It must be between `1` and `65535`; common values are `587`, `465`, and `25`. #### Encryption Select the encryption method required by your email provider: - **StartTLS** - **TLS / SSL** - **None** #### Username and password Enter the credentials required by your SMTP provider. Leave these fields empty if the provider does not require authentication. #### Timeout Sets the maximum delivery time in seconds. Leave it empty to use the default mailer behavior. #### EHLO domain Optionally set the fully qualified domain Coolify sends in the SMTP EHLO command. Leave it empty to use the system default. After editing SMTP connection settings, click **Save changes**. --- ### Resend Connect Coolify to [Resend](https://resend.com) to send transactional email through that provider. Create an API key in Resend and enter it in **API key**. The key is required when Resend is enabled. Choose **Enabled** under **Resend delivery** to use Resend, or **Disabled** to turn it off. This selection saves immediately, and enabling Resend turns off SMTP. Click **Save changes** to save the API key and sender fields. The **Authentication** page lists the OAuth providers supported by Coolify. Each provider has its own section with an **Enable** action, credentials, a redirect URI, and any additional fields that provider requires. The page also controls password registration while OAuth is enabled. Each provider can auto-join newly created users to the Root team as members. For OIDC user creation and verification controls, see [OpenID Connect](/core/security/authentication/sso/oidc). ### OAuth providers Currently supported providers are: - Authentik - Bitbucket - Clerk - Discord - GitHub - GitLab - Google - Infomaniak - Microsoft - OpenID Connect (OIDC) - Zitadel For the detailed guide, follow [OAuth setup](/core/security/authentication/oauth/overview). --- ### Enabled providers Controls whether the provider appears as a sign-in option on the Coolify login page. Fill in the required provider fields, then click **Enable**. Click **Disable** to remove the provider from the login page. --- ### Redirect URI Defines the callback URL the identity provider redirects back to after authorization. Copy the **Redirect URI** shown by Coolify into the OAuth application at the provider, then save the same value in Coolify if you override it. **Accepted values:** - A full URL matching the provider callback, usually `https://coolify.shadowarcanist.com/auth//callback`. --- ### Client ID Stores the OAuth application client ID from the identity provider. Create an OAuth application with the provider, copy its client ID, paste it into **Client ID**, then click **Save changes**. **Accepted values:** - Any provider-issued client ID string required by the provider. --- ### Client Secret Stores the OAuth application secret from the identity provider. Copy the provider client secret, paste it into **Client Secret**, then click **Save changes**. **Accepted values:** - Any provider-issued client secret string required by the provider. --- ### Provider-specific fields Provider sections show additional fields when required by that provider. ### Base URL Stores the provider base URL for self-hosted or issuer-based OAuth providers. Enter the provider base URL, then click **Save changes**. **Accepted values:** - Use a full URL from the provider, for example `https://auth.shadowarcanist.com`. --- ### Tenant Stores tenant information for providers that support or require tenant scoping. For Azure, enter the required tenant value. Google uses a **Hosted domain** field that restricts sign-in to the configured Workspace domain; `*` allows any Workspace account. **Accepted values:** - Azure: required tenant value. - Google: optional allowed Workspace domain, for example `shadowarcanist.com`, or `*`. ## Instance environment settings Set `HORIZON_ALLOWED_EMAILS` in the instance environment to grant additional users access to Laravel Horizon. See [Coolify development](/contribute/coolify) for the Horizon URL. `SSH_COMMAND_TIMEOUT` defaults to `3600` seconds. A value of `0` or an invalid value uses that default rather than disabling the timeout. `PROXY_CONNECT_NETWORKS_INTERVAL_SECONDS` and `NIGHTWATCH_ENABLED` are removed. Proxy networks are connected during destination creation, deployment, and proxy startup/restart. Laravel Nightwatch no longer runs inside the Coolify container.