Nextcloud notify_push¶
ghcr.io/strukturpiloten/nextcloud-notifypush packages the Nextcloud notify_push server as a small, non-root runtime image for AMD64 and ARM64.
Runtime contract¶
- The process runs as Alpine's unprivileged
guestuser (UID 405). - The service listens on TCP port 7867.
- The default command is
/usr/local/bin/notify_push /nextcloud/config/config.php. - Mount the Nextcloud configuration so that the default path is readable, or replace the command with the required config path.
Example:
podman run --rm \
--publish 7867:7867 \
--volume ./nextcloud-config.php:/nextcloud/config/config.php:ro \
ghcr.io/strukturpiloten/nextcloud-notifypush:v1.0.0
CI also starts the server with a temporary SQLite database and synthetic Redis/Nextcloud endpoints, then verifies a WebSocket upgrade. This confirms startup and HTTP interaction; a deployment still needs working Redis, database, and Nextcloud services for push delivery.
Keep the configuration mount read-only and accessible to UID 405. Route the service through the consuming stack's reverse proxy and configure Nextcloud's push endpoint to reach it; the sample port publication is suitable only for a controlled test environment. The image tag is this repository's image contract version, while /usr/share/strukturpiloten/application-components.txt records the upstream notify_push version and source commit.
Build and updates¶
The multi-stage build verifies the metadata-pinned upstream notify_push tag against its immutable commit, requires the upstream Cargo.lock with cargo build --locked, and compiles for the target musl architecture. Git, Rust, and build artifacts are absent from the final image. The image keeps /usr/share/strukturpiloten/application-components.txt with the upstream commit, lockfile hash, and actual Rust/Cargo versions; its build and runtime Alpine package lists are beside it.
container.yaml is authoritative for the paired upstream version and commit, builder, runtime base, architectures, and Strukturpiloten image version. Renovate proposes a version and commit together. Daily rebuilds refresh Alpine packages without silently moving the application source or locked Rust dependencies. Use a maintained tag plus digest for automated updates or a digest alone for an immutable artifact.