Bugsink as Coolify optimized installation
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Renovate Bot 3cc17c7f1b
All checks were successful
validate / compose (push) Successful in 6s
chore(actions): update actions/checkout action (v4.4.0 → v7.0.1) (#5)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://github.com/actions/checkout) | action | major | `v4` → `v7` |

---

### Release Notes

<details>
<summary>actions/checkout (actions/checkout)</summary>

### [`v7.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)

[Compare Source](https://github.com/actions/checkout/compare/v7.0.0...v7.0.1)

- Skip running unsafe pr check if input is default by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2518](https://github.com/actions/checkout/pull/2518)
- Trim only ascii whitespace for branch by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2521](https://github.com/actions/checkout/pull/2521)
- Escape values passed to --unset by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2530](https://github.com/actions/checkout/pull/2530)
- Various dependency updates

### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare Source](https://github.com/actions/checkout/compare/v6.1.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2454](https://github.com/actions/checkout/pull/2454)
- Various dependency updates

### [`v6.1.0`](https://github.com/actions/checkout/releases/tag/v6.1.0)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.3...v6.1.0)

#### What's Changed

- **\[BREAKING]** backport `allow-unsafe-pr-checkout` to v6 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2500](https://github.com/actions/checkout/pull/2500)
- backport fixes to releases-v6 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2527](https://github.com/actions/checkout/pull/2527)

<https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/> for more details about this breaking change

**Full Changelog**: <https://github.com/actions/checkout/compare/v6.0.3...v6.1.0>

### [`v6.0.3`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.2...v6.0.3)

- Fix checkout init for SHA-256 repositories by [@&#8203;yaananth](https://github.com/yaananth) in [#&#8203;2439](https://github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by [@&#8203;yaananth](https://github.com/yaananth) in [#&#8203;2414](https://github.com/actions/checkout/pull/2414)

### [`v6.0.2`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v602)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.1...v6.0.2)

- Fix tag handling: preserve annotations and explicit fetch-tags by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2356](https://github.com/actions/checkout/pull/2356)

### [`v6.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v601)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.0...v6.0.1)

- Add worktree support for persist-credentials includeIf by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2327](https://github.com/actions/checkout/pull/2327)

### [`v6.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v600)

[Compare Source](https://github.com/actions/checkout/compare/v5.1.0...v6.0.0)

- Persist creds to a separate file by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2286](https://github.com/actions/checkout/pull/2286)
- Update README to include Node.js 24 support details and requirements by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;2248](https://github.com/actions/checkout/pull/2248)

### [`v5.1.0`](https://github.com/actions/checkout/releases/tag/v5.1.0)

[Compare Source](https://github.com/actions/checkout/compare/v5.0.1...v5.1.0)

#### What's Changed

- **\[BREAKING]** backport `allow-unsafe-pr-checkout` to v5 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2501](https://github.com/actions/checkout/pull/2501)
- backport fixes to releases-v5 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2523](https://github.com/actions/checkout/pull/2523)

<https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/> for more details about this breaking change

**Full Changelog**: <https://github.com/actions/checkout/compare/v5.0.1...v5.1.0>

### [`v5.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare Source](https://github.com/actions/checkout/compare/v5.0.0...v5.0.1)

- Port v6 cleanup to v5 by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2301](https://github.com/actions/checkout/pull/2301)

### [`v5.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v500)

[Compare Source](https://github.com/actions/checkout/compare/v4.4.0...v5.0.0)

- Update actions checkout to use node 24 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;2226](https://github.com/actions/checkout/pull/2226)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Helsinki)

- Branch creation
  - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday (`* 0-4,22-23 * * 1-5`)
  - Only on Sunday and Saturday (`* * * * 0,6`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZS9naXRodWItYWN0aW9uIiwicmVub3ZhdGUvZ2l0aHViLXJlbGVhc2UiLCJ0eXBlL21ham9yIl19-->

Reviewed-on: #5
2026-09-26 16:32:35 +00:00
.forgejo/workflows chore(actions): update actions/checkout action (v4.4.0 → v7.0.1) (#5) 2026-09-26 16:32:35 +00:00
docs/audit/findings docs: add the audit findings ledger 2026-09-01 15:43:18 +02:00
docker-compose.yaml feat: Bugsink on Coolify, Postgres variant 2026-09-01 15:34:32 +02:00
LICENSE chore: add MIT license 2026-09-01 15:34:32 +02:00
README.md feat: Bugsink on Coolify, Postgres variant 2026-09-01 15:34:32 +02:00
renovate.json chore: Configure Renovate (#1) 2026-09-26 13:03:30 +00:00

coolify-bugsink

Bugsink (Postgres) as a Coolify Docker Compose resource.

Coolify ships a built-in Bugsink template, but it uses MySQL and an unpinned image. This is the upstream Postgres sample adapted to Coolify.

Deploy

  1. Coolify → project → + New → Docker Compose → point at this repo.
  2. Set BUGSINK_ADMIN_EMAIL. It is marked required, so it appears at the top of the environment list. Do this before the first deploy — see below.
  3. Deploy. Coolify generates the domain and all secrets.
  4. Log in with that email and the generated SERVICE_PASSWORD_ADMIN, visible under Environment Variables.

What Coolify fills in

Variable Source
SERVICE_URL_BUGSINK_8000 Registers the domain and routes the proxy to port 8000
BASE_URL SERVICE_URL_BUGSINK — the same URL, without the port
SECRET_KEY SERVICE_PASSWORD_64_BUGSINK (64 chars; Bugsink requires at least 50)
SERVICE_USER_BUGSINK / SERVICE_PASSWORD_BUGSINK Postgres credentials, shared by both services
SERVICE_PASSWORD_ADMIN Initial superuser password

Yours to set

Variable Default
BUGSINK_ADMIN_EMAIL admin@example.org — required; first deploy only
POSTGRES_DB bugsink — first deploy only

BEHIND_HTTPS_PROXY=true assumes you serve Bugsink over HTTPS, which is Coolify's default. Flip it if you don't.

First deploy only

BUGSINK_ADMIN_EMAIL, POSTGRES_DB, SERVICE_USER_BUGSINK, and SERVICE_PASSWORD_BUGSINK are consumed once, when the stack initialises. Bugsink creates the superuser only if none exists; Postgres reads its credentials only when it initialises an empty data directory. Editing any of them later in Coolify's UI changes what the web container sends without changing what the database expects, so the web container crash-loops on authentication while Postgres keeps reporting healthy.

Rotating secrets

To change the database password after deployment, change it in Postgres first:

# in Coolify's terminal for the db container
psql -U "$POSTGRES_USER" -d "$POSTGRES_DB" \
  -c "ALTER USER \"$POSTGRES_USER\" WITH PASSWORD 'new-password';"

Then update SERVICE_PASSWORD_BUGSINK in Coolify to match and redeploy.

To change the admin password, use Bugsink's own UI, or manage.py changepassword in the web container. Rotating SERVICE_PASSWORD_ADMIN in Coolify has no effect on an existing user.

Keep replacement secrets alphanumeric

Two secrets are parsed, not just passed: SERVICE_PASSWORD_BUGSINK goes into DATABASE_URL and SERVICE_PASSWORD_ADMIN is split on :. Coolify's SERVICE_PASSWORD_* generator is symbol-free, so the defaults are safe. If you replace either by hand, keep it alphanumeric — :, @, /, and # corrupt the value, and neither failure names the cause.

Sending events

Point a Sentry SDK at the DSN from Bugsink's UI. Any Sentry SDK works.

License

MIT — see LICENSE.