fix(ntfy): publish ntfy host port so the external reverse proxy can reach it
The ntfy service was configured with no published host port, on the assumption that the public reverse proxy shares the compose network and can dial ntfy:80 directly. It does not — Pangolin runs outside the compose network and reaches every service through a published host port (exactly why `app` publishes 3000). With no published port there was nothing for the notification subdomain to forward to, so push delivery could never work in production. Publish container :80 on a host port (NTFY_HOST_PORT, default 2586, binds 0.0.0.0 like `app`) and correct the now-inaccurate comments in docker-compose.yml and ntfy/server.yml. Document NTFY_HOST_PORT in .env.example. No code change — deploy config only. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -13,8 +13,12 @@
|
||||
# a placeholder for a bare `ntfy serve`.
|
||||
base-url: "https://ntfy.localhost"
|
||||
|
||||
# Served on the private compose network; the public reverse proxy terminates TLS
|
||||
# and forwards to this port. docker-compose.yml publishes NO host port for ntfy.
|
||||
# ntfy listens on :80 inside the container. docker-compose.yml publishes this on
|
||||
# a host port (NTFY_HOST_PORT, default 2586) so the public reverse proxy — which
|
||||
# lives OUTSIDE the compose network — can terminate TLS and forward the
|
||||
# notification subdomain to it. Both the app (SSE subscribe) and the backend
|
||||
# (POSTing content-free tickles to registered device endpoints) reach ntfy on
|
||||
# that public origin, so all traffic flows through the proxy.
|
||||
listen-http: ":80"
|
||||
behind-proxy: true
|
||||
|
||||
|
||||
Reference in New Issue
Block a user