Files
ntfy-bridge/ntfy-bridge.example.yaml
T
bruno 1a4808f5f7
CI / test (push) Has been cancelled
feat: v0.6.0 — ACLs multi-utilisateurs + Plugin system
**ACLs (Access Control Lists):**
- Ajout du type AclConfig dans sources/event.v (allowed_ips CIDR + allowed_tokens)
- Chaque source webhook (Gitea, Uptime Kuma, Cron, Generic) supporte les ACLs
- Validation IP via X-Forwarded-For / X-Real-IP avant HMAC
- Validation Bearer token via Authorization header
- Tests: 7 tests ACL (IP exact, CIDR, parse IPv4, ACL vide, IP+token combiné)

**Plugin system:**
- sources/plugin.v: runner exécutable externe, stdout JSON → Event
- Exit 0 = publish, exit ≠ 0 = skip. Timeout configurable
- Plugin loop dans server.v (goroutine, toutes les 60s)
- Example: scripts/example-plugin-disk.sh (vérifie espace disque)

**Docs:**
- README.md: ajout source Plugin + section Features complète
- ARCHITECTURE.md: flux Plugin, flux ACL, endpoints /metrics /api/silence
- ROADMAP.md: Phase 5 → 8/8 complet, ajout v0.6.0
- ntfy-bridge.example.yaml: sections ACLs et Plugins commentées
- Version bump: 0.5.0 → 0.6.0
2026-08-04 22:25:48 -04:00

177 lines
7.4 KiB
YAML

# ntfy-bridge configuration
# ============================
# ── Server ────────────────────────────────────────────
server:
# URL de ton serveur Ntfy
url: https://ntfy.dracodev.net
# Token d'authentification (optionnel, si ton serveur Ntfy a auth activée)
# Peut aussi être passé via variable d'environnement NTFY_TOKEN
# auth_token: tk_xxxxxxxxxxxx
# Adresse d'écoute du serveur HTTP interne
# Mettre "0.0.0.0:9090" pour exposer réseau, "127.0.0.1:9090" pour localhost
listen: "127.0.0.1:9090"
# Secret partagé pour validation HMAC-SHA256 des webhooks (optionnel)
# Si défini, tous les webhooks doivent inclure le header X-Hub-Signature-256
# Peut aussi être passé via variable d'environnement NTFY_HMAC_SECRET
# hmac_secret: "mon-secret-partage"
# ── Defaults ──────────────────────────────────────────
# Appliqués à toutes les sources sauf override explicite
defaults:
priority: 3 # 1=min, 2=low, 3=default, 4=high, 5=urgent
tags: ["loudspeaker"] # Tags/emojis Ntfy
# ── Sources ───────────────────────────────────────────
sources:
# ═══════════════════════════════════════════════════
# GITEA — webhooks depuis git.dracodev.net
# ═══════════════════════════════════════════════════
gitea:
- name: "FlowDeck activity"
webhook_path: /webhooks/gitea-flowdeck
repo: bruno/flowdeck
topic: dev-notifs
priority_map:
pull_request: 4
issue: 3
push: 2
# Template de message (variables dispo: {repo}, {user}, {action}, {title}, {sha})
template: |
🔨 **[{repo}]** {user} {action}: "{title}"
`{sha}`
- name: "ObsiGate activity"
webhook_path: /webhooks/gitea-obsigate
repo: bruno/obsigate
topic: dev-notifs
# ═══════════════════════════════════════════════════
# UPTIME KUMA — alertes de monitoring
# ═══════════════════════════════════════════════════
uptime_kuma:
- name: "Services critiques"
webhook_path: /webhooks/kuma-critical
topic: alerts
state_map:
down: { priority: 5, tags: ["rotating_light", "x"] }
up: { priority: 1, tags: ["white_check_mark"] }
# ═══════════════════════════════════════════════════
# DOCKER — surveillance des conteneurs
# ═══════════════════════════════════════════════════
docker:
- name: "Production containers"
hosts:
- unix:///var/run/docker.sock
# Hôtes distants:
# - tcp://192.168.30.101:2375
# - tcp://192.168.30.20:2375
events: [die, health_status, oom]
topic: infra
template: |
🐳 **{container_name}** → {status}
Image: `{image}`
Exit code: {exit_code}
Host: {host}
# ═══════════════════════════════════════════════════
# HTTP POLL — health checks périodiques
# ═══════════════════════════════════════════════════
http_poll:
- name: "Health endpoints"
interval: 60 # secondes entre chaque check
checks:
- url: https://og.dracodev.net/health
topic: alerts
priority: 5 # priorité si DOWN
expect_status: 200
timeout: 10 # secondes
- url: https://flowdeck.dracodev.net/health
topic: alerts
priority: 5
expect_status: 200
timeout: 10
- url: https://git.dracodev.net/api/v1/version
topic: alerts
priority: 5
expect_status: 200
timeout: 10
- url: http://raspi.8gb.home:3001/ping
topic: alerts
priority: 5 # Uptime Kuma lui-même — critique
expect_status: 200
timeout: 10
- url: http://raspi.8gb.home:9119/api/status
topic: alerts
priority: 5
expect_status: 200
timeout: 10
# ═══════════════════════════════════════════════════
# CRON — reçoit des notifs depuis des scripts shell
# ═══════════════════════════════════════════════════
cron:
- name: "Disk usage quotidien"
webhook_path: /webhooks/cron-disk
topic: daily
- name: "Backup report"
webhook_path: /webhooks/cron-backup
topic: daily
# ═══════════════════════════════════════════════════
# GENERIC — webhook passe-partout
# ═══════════════════════════════════════════════════
generic:
- name: "Custom alerts"
webhook_path: /webhooks/generic
topic: custom
# ── ACLs (Access Control Lists) ─────────────────────────
# Optionnel — restreint l'accès à certains webhooks par IP ou token.
# Si aucune ACL n'est définie, le webhook est ouvert (soumis au HMAC).
#
# Exemple avec ACL IP:
# gitea:
# - name: "FlowDeck"
# webhook_path: /webhooks/gitea-flowdeck
# topic: dev-notifs
# acl:
# allowed_ips: ["192.168.30.5", "10.0.0.0/8"]
#
# Exemple avec ACL token:
# generic:
# - name: "Secure alerts"
# webhook_path: /webhooks/secure
# topic: secure
# acl:
# allowed_tokens: ["my-secret-webhook-token"]
# → Le client doit envoyer: Authorization: Bearer my-secret-webhook-token
# ── Plugins — scripts externes exécutés périodiquement ──
# Chaque plugin est un exécutable appelé toutes les 60s.
# Il lit (optionnel) sur stdin et doit écrire un objet JSON Event sur stdout.
# Exit 0 = envoyer la notif, exit ≠ 0 = ignorer.
#
# plugin:
# - name: "Disk space check"
# topic: daily
# command: /etc/ntfy-bridge/plugins/disk-check.sh
# timeout: 10
# ── Déduplication ──────────────────────────────────────
dedup:
enabled: true
ttl_seconds: 300 # 5 minutes — durée du cache de déduplication
rate_limit:
max_per_minute: 10 # max notifications/minute par topic
max_per_source: 30 # max notifications/minute toute source confondue