fix(ntfy): publish ntfy host port so the external reverse proxy can reach it
All checks were successful
PR Checks / bot-install (pull_request) Successful in 18s
PR Checks / client-build (pull_request) Successful in 30s
PR Checks / server-tests (pull_request) Successful in 9m29s

The ntfy service was configured with no published host port, on the
assumption that the public reverse proxy shares the compose network and
can dial ntfy:80 directly. It does not — Pangolin runs outside the
compose network and reaches every service through a published host port
(exactly why `app` publishes 3000). With no published port there was
nothing for the notification subdomain to forward to, so push delivery
could never work in production.

Publish container :80 on a host port (NTFY_HOST_PORT, default 2586,
binds 0.0.0.0 like `app`) and correct the now-inaccurate comments in
docker-compose.yml and ntfy/server.yml. Document NTFY_HOST_PORT in
.env.example. No code change — deploy config only.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-07-22 03:57:32 -05:00
parent 4f1a4902e8
commit 4151f7d44e
3 changed files with 26 additions and 5 deletions

View File

@@ -13,8 +13,12 @@
# a placeholder for a bare `ntfy serve`.
base-url: "https://ntfy.localhost"
# Served on the private compose network; the public reverse proxy terminates TLS
# and forwards to this port. docker-compose.yml publishes NO host port for ntfy.
# ntfy listens on :80 inside the container. docker-compose.yml publishes this on
# a host port (NTFY_HOST_PORT, default 2586) so the public reverse proxy — which
# lives OUTSIDE the compose network — can terminate TLS and forward the
# notification subdomain to it. Both the app (SSE subscribe) and the backend
# (POSTing content-free tickles to registered device endpoints) reach ntfy on
# that public origin, so all traffic flows through the proxy.
listen-http: ":80"
behind-proxy: true