Penv Cloud
Start free
Docs
Reference

Coolify

Sync an environment with a Coolify application's production environment variables.

Sync an environment with a Coolify application's production environment variables.

Connection

WhatThis provider
VendorCoolify
Keycoolify-env
Availabilityavailable. You can connect it today.
Credential we holdcoolify-token
Values read backyes
Activationon-next-deploy

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

on-next-deploy. A new value waits there and arrives with your next deploy.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
tokenAPI tokensecret; we mask it here and seal ityesCreate it under Keys & Tokens, API tokens, while the team that owns the application is active. Give it read, plus read:sensitive to import values and write to export. Coolify shows values only to a token whose user is an admin or owner of that team, even with read:sensitive.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
hostInstance URLtextyesnoYour instance's https address, or https://app.coolify.io for Coolify Cloud. On your own instance, an admin must enable API access, and the instance must be reachable from the internet.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
applicationUuidApplication UUIDtextyesnoThe UUID after /application/ in the application's Coolify URL. We sync its production variables. Each write also gives the key's preview variable the same value, except that create_only leaves an existing one as it is. A prune deletes the preview variable too, and stops if its value differs. We refuse a value with leading or trailing whitespace, because Coolify trims it.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
readevery directionyesPreview cannot list the application's variables.
read:sensitiveimport, exportnoImport stops at the first value Coolify redacts, and a prune stops at a key with a preview variable, because we cannot compare the two. The token's user must also be a team admin or owner.
writeexportyesExport cannot add, change or delete a variable.