Add self-hosted ntfy deployment for ntfy.schwenk.online.

Docker Compose with Traefik routing, auth-enabled server config, and local cache volume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Frank Schwenk
2026-07-06 11:12:14 +02:00
commit e285b23534
3 changed files with 73 additions and 0 deletions
+2
View File
@@ -0,0 +1,2 @@
# Runtime data (auth DB, message cache, attachments)
cache/
+38
View File
@@ -0,0 +1,38 @@
services:
ntfy:
image: binwiederhier/ntfy
container_name: ntfy.schwenk.online
command:
- serve
environment:
- TZ=Europe/Berlin
user: 1002:1002
volumes:
- ./cache:/var/cache/ntfy
- ./config:/etc/ntfy
- /etc/localtime:/etc/localtime:ro
healthcheck:
test: ["CMD-SHELL", "wget -q --tries=1 http://localhost:80/v1/health -O - | grep -Eo '\"healthy\"\\s*:\\s*true' || exit 1"]
interval: 60s
timeout: 10s
retries: 3
start_period: 40s
restart: unless-stopped
init: true
networks:
- traefik
labels:
- "traefik.enable=true"
- "traefik.http.routers.ntfyschwenkonline.rule=Host(`ntfy.schwenk.online`)"
- "traefik.http.routers.ntfyschwenkonline.entrypoints=websecure"
- "traefik.http.routers.ntfyschwenkonline.tls.certresolver=myresolver"
- "traefik.http.services.ntfyschwenkonline.loadbalancer.server.port=80"
# HSTS at TLS terminator (Traefik)
- "traefik.http.middlewares.ntfyschwenkonline-headers.headers.stsSeconds=31536000"
- "traefik.http.middlewares.ntfyschwenkonline-headers.headers.stsIncludeSubdomains=true"
- "traefik.http.routers.ntfyschwenkonline.middlewares=ntfyschwenkonline-headers"
networks:
traefik:
external: true
+33
View File
@@ -0,0 +1,33 @@
# ntfy.schwenk.online — personal push server (TLS terminated by Traefik)
base-url: "https://ntfy.schwenk.online"
listen-http: ":80"
behind-proxy: true
# Message cache (survives restarts, supports since= polling)
cache-file: "/var/cache/ntfy/cache.db"
cache-duration: "12h"
cache-startup-queries: |
pragma journal_mode = WAL;
pragma synchronous = normal;
pragma temp_store = memory;
pragma busy_timeout = 15000;
# Access control — create your first admin user after start:
# docker exec -it ntfy.schwenk.online ntfy user add frank --role=admin
auth-file: "/var/cache/ntfy/auth.db"
auth-default-access: "deny-all"
enable-login: true
require-login: true
enable-signup: false
# Attachments (e.g. Grafana alerts, backup reports)
attachment-cache-dir: "/var/cache/ntfy/attachments"
attachment-total-size-limit: "500M"
attachment-file-size-limit: "5M"
attachment-expiry-duration: "24h"
# iOS app: uses ntfy.sh only for poll_request signaling; message content stays here
upstream-base-url: "https://ntfy.sh"
keepalive-interval: "45s"