Critical-risk tools in Coolify
16 of the 111 tools in Coolify are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_applicationDestructiveDelete an application by UUID.
-
delete_application_envDestructiveDelete an environment variable from an application.
-
delete_application_scheduled_taskDestructiveDelete a scheduled task from an application.
-
delete_application_storageDestructiveDelete a storage from an application.
-
delete_cloud_tokenDestructiveDelete a cloud provider token. Fails if used by any servers.
-
delete_databaseDestructiveDelete a database by UUID.
-
delete_database_envDestructiveDelete an environment variable from a database.
-
delete_environmentDestructiveDelete an environment (must be empty) from a project.
-
delete_github_appDestructiveDelete a GitHub App (only if not used by any applications).
-
delete_private_keyDestructiveDelete a private key by UUID.
-
delete_projectDestructiveDelete a project by UUID.
-
delete_serverDestructiveDelete a server by UUID.
-
delete_serviceDestructiveDelete a service by UUID.
-
delete_service_envDestructiveDelete an environment variable from a service.
-
delete_service_scheduled_taskDestructiveDelete a scheduled task from a service.
-
disable_apiDestructiveDisable the Coolify API. Requires root-level token.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.