Reference
Coolify
Sync an environment with a Coolify application's production environment variables.
Sync an environment with a Coolify application's production environment variables.
Connection
| What | This provider |
|---|---|
| Vendor | Coolify |
| Key | coolify-env |
| Availability | available. You can connect it today. |
| Credential we hold | coolify-token |
| Values read back | yes |
| Activation | on-next-deploy |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
on-next-deploy. A new value waits there and arrives with your next deploy.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
Paste a credential from the vendor. We seal it and never show it again.
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
token | API token | secret; we mask it here and seal it | yes | Create it under Keys & Tokens, API tokens, while the team that owns the application is active. Give it read, plus read:sensitive to import values and write to export. Coolify shows values only to a token whose user is an admin or owner of that team, even with read:sensitive. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
host | Instance URL | text | yes | no | Your instance's https address, or https://app.coolify.io for Coolify Cloud. On your own instance, an admin must enable API access, and the instance must be reachable from the internet. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
applicationUuid | Application UUID | text | yes | no | The UUID after /application/ in the application's Coolify URL. We sync its production variables. Each write also gives the key's preview variable the same value, except that create_only leaves an existing one as it is. A prune deletes the preview variable too, and stops if its value differs. We refuse a value with leading or trailing whitespace, because Coolify trims it. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
read | every direction | yes | Preview cannot list the application's variables. |
read:sensitive | import, export | no | Import stops at the first value Coolify redacts, and a prune stops at a key with a preview variable, because we cannot compare the two. The token's user must also be a team admin or owner. |
write | export | yes | Export cannot add, change or delete a variable. |