CI / test (push) Has been cancelled
**ACLs (Access Control Lists):** - Ajout du type AclConfig dans sources/event.v (allowed_ips CIDR + allowed_tokens) - Chaque source webhook (Gitea, Uptime Kuma, Cron, Generic) supporte les ACLs - Validation IP via X-Forwarded-For / X-Real-IP avant HMAC - Validation Bearer token via Authorization header - Tests: 7 tests ACL (IP exact, CIDR, parse IPv4, ACL vide, IP+token combiné) **Plugin system:** - sources/plugin.v: runner exécutable externe, stdout JSON → Event - Exit 0 = publish, exit ≠ 0 = skip. Timeout configurable - Plugin loop dans server.v (goroutine, toutes les 60s) - Example: scripts/example-plugin-disk.sh (vérifie espace disque) **Docs:** - README.md: ajout source Plugin + section Features complète - ARCHITECTURE.md: flux Plugin, flux ACL, endpoints /metrics /api/silence - ROADMAP.md: Phase 5 → 8/8 complet, ajout v0.6.0 - ntfy-bridge.example.yaml: sections ACLs et Plugins commentées - Version bump: 0.5.0 → 0.6.0
177 lines
7.4 KiB
YAML
177 lines
7.4 KiB
YAML
# ntfy-bridge configuration
|
|
# ============================
|
|
|
|
# ── Server ────────────────────────────────────────────
|
|
server:
|
|
# URL de ton serveur Ntfy
|
|
url: https://ntfy.dracodev.net
|
|
|
|
# Token d'authentification (optionnel, si ton serveur Ntfy a auth activée)
|
|
# Peut aussi être passé via variable d'environnement NTFY_TOKEN
|
|
# auth_token: tk_xxxxxxxxxxxx
|
|
|
|
# Adresse d'écoute du serveur HTTP interne
|
|
# Mettre "0.0.0.0:9090" pour exposer réseau, "127.0.0.1:9090" pour localhost
|
|
listen: "127.0.0.1:9090"
|
|
|
|
# Secret partagé pour validation HMAC-SHA256 des webhooks (optionnel)
|
|
# Si défini, tous les webhooks doivent inclure le header X-Hub-Signature-256
|
|
# Peut aussi être passé via variable d'environnement NTFY_HMAC_SECRET
|
|
# hmac_secret: "mon-secret-partage"
|
|
|
|
# ── Defaults ──────────────────────────────────────────
|
|
# Appliqués à toutes les sources sauf override explicite
|
|
defaults:
|
|
priority: 3 # 1=min, 2=low, 3=default, 4=high, 5=urgent
|
|
tags: ["loudspeaker"] # Tags/emojis Ntfy
|
|
|
|
# ── Sources ───────────────────────────────────────────
|
|
sources:
|
|
# ═══════════════════════════════════════════════════
|
|
# GITEA — webhooks depuis git.dracodev.net
|
|
# ═══════════════════════════════════════════════════
|
|
gitea:
|
|
- name: "FlowDeck activity"
|
|
webhook_path: /webhooks/gitea-flowdeck
|
|
repo: bruno/flowdeck
|
|
topic: dev-notifs
|
|
priority_map:
|
|
pull_request: 4
|
|
issue: 3
|
|
push: 2
|
|
# Template de message (variables dispo: {repo}, {user}, {action}, {title}, {sha})
|
|
template: |
|
|
🔨 **[{repo}]** {user} {action}: "{title}"
|
|
`{sha}`
|
|
|
|
- name: "ObsiGate activity"
|
|
webhook_path: /webhooks/gitea-obsigate
|
|
repo: bruno/obsigate
|
|
topic: dev-notifs
|
|
|
|
# ═══════════════════════════════════════════════════
|
|
# UPTIME KUMA — alertes de monitoring
|
|
# ═══════════════════════════════════════════════════
|
|
uptime_kuma:
|
|
- name: "Services critiques"
|
|
webhook_path: /webhooks/kuma-critical
|
|
topic: alerts
|
|
state_map:
|
|
down: { priority: 5, tags: ["rotating_light", "x"] }
|
|
up: { priority: 1, tags: ["white_check_mark"] }
|
|
|
|
# ═══════════════════════════════════════════════════
|
|
# DOCKER — surveillance des conteneurs
|
|
# ═══════════════════════════════════════════════════
|
|
docker:
|
|
- name: "Production containers"
|
|
hosts:
|
|
- unix:///var/run/docker.sock
|
|
# Hôtes distants:
|
|
# - tcp://192.168.30.101:2375
|
|
# - tcp://192.168.30.20:2375
|
|
events: [die, health_status, oom]
|
|
topic: infra
|
|
template: |
|
|
🐳 **{container_name}** → {status}
|
|
Image: `{image}`
|
|
Exit code: {exit_code}
|
|
Host: {host}
|
|
|
|
# ═══════════════════════════════════════════════════
|
|
# HTTP POLL — health checks périodiques
|
|
# ═══════════════════════════════════════════════════
|
|
http_poll:
|
|
- name: "Health endpoints"
|
|
interval: 60 # secondes entre chaque check
|
|
checks:
|
|
- url: https://og.dracodev.net/health
|
|
topic: alerts
|
|
priority: 5 # priorité si DOWN
|
|
expect_status: 200
|
|
timeout: 10 # secondes
|
|
|
|
- url: https://flowdeck.dracodev.net/health
|
|
topic: alerts
|
|
priority: 5
|
|
expect_status: 200
|
|
timeout: 10
|
|
|
|
- url: https://git.dracodev.net/api/v1/version
|
|
topic: alerts
|
|
priority: 5
|
|
expect_status: 200
|
|
timeout: 10
|
|
|
|
- url: http://raspi.8gb.home:3001/ping
|
|
topic: alerts
|
|
priority: 5 # Uptime Kuma lui-même — critique
|
|
expect_status: 200
|
|
timeout: 10
|
|
|
|
- url: http://raspi.8gb.home:9119/api/status
|
|
topic: alerts
|
|
priority: 5
|
|
expect_status: 200
|
|
timeout: 10
|
|
|
|
# ═══════════════════════════════════════════════════
|
|
# CRON — reçoit des notifs depuis des scripts shell
|
|
# ═══════════════════════════════════════════════════
|
|
cron:
|
|
- name: "Disk usage quotidien"
|
|
webhook_path: /webhooks/cron-disk
|
|
topic: daily
|
|
|
|
- name: "Backup report"
|
|
webhook_path: /webhooks/cron-backup
|
|
topic: daily
|
|
|
|
# ═══════════════════════════════════════════════════
|
|
# GENERIC — webhook passe-partout
|
|
# ═══════════════════════════════════════════════════
|
|
generic:
|
|
- name: "Custom alerts"
|
|
webhook_path: /webhooks/generic
|
|
topic: custom
|
|
|
|
# ── ACLs (Access Control Lists) ─────────────────────────
|
|
# Optionnel — restreint l'accès à certains webhooks par IP ou token.
|
|
# Si aucune ACL n'est définie, le webhook est ouvert (soumis au HMAC).
|
|
#
|
|
# Exemple avec ACL IP:
|
|
# gitea:
|
|
# - name: "FlowDeck"
|
|
# webhook_path: /webhooks/gitea-flowdeck
|
|
# topic: dev-notifs
|
|
# acl:
|
|
# allowed_ips: ["192.168.30.5", "10.0.0.0/8"]
|
|
#
|
|
# Exemple avec ACL token:
|
|
# generic:
|
|
# - name: "Secure alerts"
|
|
# webhook_path: /webhooks/secure
|
|
# topic: secure
|
|
# acl:
|
|
# allowed_tokens: ["my-secret-webhook-token"]
|
|
# → Le client doit envoyer: Authorization: Bearer my-secret-webhook-token
|
|
|
|
# ── Plugins — scripts externes exécutés périodiquement ──
|
|
# Chaque plugin est un exécutable appelé toutes les 60s.
|
|
# Il lit (optionnel) sur stdin et doit écrire un objet JSON Event sur stdout.
|
|
# Exit 0 = envoyer la notif, exit ≠ 0 = ignorer.
|
|
#
|
|
# plugin:
|
|
# - name: "Disk space check"
|
|
# topic: daily
|
|
# command: /etc/ntfy-bridge/plugins/disk-check.sh
|
|
# timeout: 10
|
|
|
|
# ── Déduplication ──────────────────────────────────────
|
|
dedup:
|
|
enabled: true
|
|
ttl_seconds: 300 # 5 minutes — durée du cache de déduplication
|
|
rate_limit:
|
|
max_per_minute: 10 # max notifications/minute par topic
|
|
max_per_source: 30 # max notifications/minute toute source confondue
|