Skip to content

Features

Ship. Recover. Keep moving.

The complete overview: what you can do, what runs in the background, and the limits today.

From repo to release.

Everything needed to get your application running.

Bring your own server

Adopt a fresh VPS from your provider. Keep your account, region and hosting bill. Adoption replaces the existing operating system.

Auto-detected setup

PHP, extensions, database, cache, workers and scheduler, read from your repository. Review the proposal before provisioning.

Zero-downtime deploys

A push builds the next release while the previous one serves traffic. Verified webhooks are deduplicated.

Editable deploy plans

Add commands, reorder steps and hook start, success, failure or rollback. Override a single deploy without changing the saved plan.

Domains & HTTPS

Every environment gets an HTTPS URL. Attach custom domains; certificates are issued and renewed automatically.

Managed databases

MariaDB, PostgreSQL and Valkey, provisioned with credentials for your app. Database versions stay on supported releases.

Live activity

Watch deploys and provisioning as they run. Inspect the steps, output and result afterwards.

The life of a pull request

A preview for every PR.

GitHub pull requests get an isolated database and a URL to share.

ProductionmainServing visitors
  1. 01

    Open PR

    feature/checkout

    Open a pull request to create a preview environment.

    Source environment
    Production
    Cleanup rule
    When the PR is merged
  2. 02

    Build

    Building

    Build and deploy the branch into its own environment.

    Database
    Separate from production
    Branch
    feature/checkout
  3. 03

    Review

    Ready to review

    Share the preview URL and test the change before merging.

    URL
    shop--pr-42.example.test
    Production
    Unchanged by preview deploys
  4. 04

    Clean up

    Removed

    After merge, remove the preview using the configured cleanup rule.

    Cleanup rule
    PR merged
    Temporary environment
    Released
Cleanup follows your settings

A closed PR does not trigger cleanup unless that rule is enabled.

Delete on merge
Enabled
Delete on close
Disabled
Idle timeout
Disabled in this example

Illustrative preview. Merge, close, and idle-time cleanup are configurable; the preview URL is an example.

When something goes wrong

Choose what goes back.

A previous release, a local restore point, or an off-server copy.

Code release

Roll back in seconds

Application code
Previous release
Application data
Stays current

Return to a previous application release.

Source
Release history
Use when
A code change broke the app

Database recovery is a separate action. Check that the selected code can run against the current database.

Local restore point

Files and data, at a point in time

Application files
At checkpoint
Application data
At checkpoint

Restore the files and data included in the selected checkpoint.

Source
Completed local checkpoint
Use when
You need to restore changed data

Requires a completed checkpoint on a server with checkpoint support. Later changes can be lost; the original storage must still be available.

Off-server backup

Backups you actually own

Application files
From backup
Application data
From backup

Restore from a completed encrypted backup in your own S3 bucket.

Source
Completed off-server backup
Use when
The original storage is unavailable

Keep your encryption key. A configured destination alone is not a completed backup. Restore completed backups with stock restic, without strackt.

Illustrative recovery choices. Check the selected point, its contents, and its availability before restoring.

Run it your way.

Control the application, access and connections around it.

Move between servers

Move an environment between providers or regions, with its data and history. Prepare and verify the destination before a brief cutover.

Private application network

Connect apps and databases across your servers over an encrypted network, without exposing their service ports publicly.

Signed SSH

Open a shell with strackt ssh. Access certificates are signed on demand and expire automatically.

CLI & API

Deploy, edit application config and roll back from scripts. JSON output and idempotent API requests support CI and agents.

Care that keeps going.

The server work between your deployments.

Configuration enforcement

Managed operations reapply the recorded configuration. Packages, services, users and firewall rules have a versioned source of truth.

Security detection & patching

Advisories are matched to installed packages. Fixes are prepared and distributed across affected servers; actively exploited issues are escalated.

Versions & planned reboots

Regular software and distribution upgrades include compatibility checks. Routine reboots follow your window; urgent ones can override it with notice.

Reversible infrastructure

Prepare and check a new system before activation. Keep previous configurations for rollback, or rebuild a replacement from code. Data needs its own backup.

Private management access

Management uses an encrypted private path and short-lived access credentials. Operations are recorded; application secrets are held in an encrypted vault.

The smaller things, covered too.

The remaining capabilities, each listed once.

Build & configure

  • Direct provisioning at eight providers; Git connections to GitHub, GitLab, Bitbucket Cloud and Gitea
  • Environment editor with secret references
  • Deploy preflight checks before server work
  • Production, staging and custom environments
  • Shared services across applications
  • Spotlight (⌘K) search and actions

Operate & recover

  • Per-server firewall rules and source allowlists
  • Signed notifications and webhooks with delivery history
  • Backup schedules: every 15 minutes through weekly, in your timezone
  • DNS and certificate health checks
  • Per-application isolation
  • Verified server detachment and credential cleanup

WordPress sites

  • Core, plugin and theme inventory with vulnerability checks
  • Protected updates: checkpoint, update, then health check
  • Opt-in automatic security fixes
  • Archive import or fresh installation; live pull in alpha
  • Fleet update rounds with separate site restore histories
  • WP-CLI commands against a selected site

Supported today.

Scope is part of the feature.

  • Laravel, WordPress and plain PHP. Laravel and plain PHP deploy from your repositories; WordPress is managed as an operated site. Node.js, Next.js and static sites are not supported.
  • GitHub previews. PR previews and deploy feedback in the pull request are GitHub-only today.
  • Dashboard controls. Firewall, provisioning, maintenance and backup controls remain in the dashboard. The CLI covers the application lifecycle.
  • Maintenance policy. Patch and reboot timing includes notice and urgent exceptions. See how configuration recovery works.
  • Commercial scope. Flat application pricing, with your hosting billed separately. Lapsed billing freezes managed applications rather than deleting them. Beta support has no published SLA.
  • Apps you build. For installing packaged software such as Nextcloud or Immich, Coolify is a better fit.
  • Infrastructure boundaries. No scale-to-zero, bundled CDN, multi-region failover, Docker/Compose deployment or bring-your-own Kubernetes. Bring a CDN or S3 storage when needed. Self-service configuration revert is rolling out team by team.