fix(ntfy): publish ntfy host port so the external reverse proxy can reach it
The ntfy service was configured with no published host port, on the assumption that the public reverse proxy shares the compose network and can dial ntfy:80 directly. It does not — Pangolin runs outside the compose network and reaches every service through a published host port (exactly why `app` publishes 3000). With no published port there was nothing for the notification subdomain to forward to, so push delivery could never work in production. Publish container :80 on a host port (NTFY_HOST_PORT, default 2586, binds 0.0.0.0 like `app`) and correct the now-inaccurate comments in docker-compose.yml and ntfy/server.yml. Document NTFY_HOST_PORT in .env.example. No code change — deploy config only. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -74,9 +74,20 @@ services:
|
||||
volumes:
|
||||
- ntfydata:/var/lib/ntfy
|
||||
- ./ntfy/server.yml:/etc/ntfy/server.yml:ro
|
||||
# No published host port — devices reach ntfy through the public reverse proxy
|
||||
# on its own hostname; the backend publisher reaches it over the private
|
||||
# compose network. Never publish this directly.
|
||||
# Published so the PUBLIC reverse proxy (Pangolin) can forward the
|
||||
# notification subdomain here. Pangolin lives OUTSIDE the compose network and
|
||||
# reaches every service through a published host port — never by joining the
|
||||
# internal network — exactly like `app` above (3000). So ntfy must publish a
|
||||
# port too: the reverse proxy maps notify.<host> -> host:NTFY_HOST_PORT ->
|
||||
# ntfy:80. Unlike INTERNAL_PORT / the bot, ntfy is DEVICE-facing, so it is
|
||||
# SUPPOSED to be reachable through the proxy. Binds 0.0.0.0 (no 127.0.0.1
|
||||
# prefix) so Pangolin can reach the container. Both the app (SSE subscribe) and
|
||||
# the backend (POSTing content-free tickles to each device's registered
|
||||
# endpoint) reach ntfy on this same public origin — NTFY_ALLOWED_ORIGINS pins
|
||||
# it — so all ntfy traffic flows through the proxy; there is no separate
|
||||
# internal publish port.
|
||||
ports:
|
||||
- "${NTFY_HOST_PORT:-2586}:80"
|
||||
|
||||
bot:
|
||||
# Same as app: prebuilt bot image, pulled in production. Build locally via
|
||||
|
||||
Reference in New Issue
Block a user