mirror of
https://github.com/spantaleev/matrix-docker-ansible-deploy.git
synced 2026-07-29 18:58:44 +10:00
d38573a9eb
The playbook exposes service metrics under a single endpoint (`https://matrix.example.com/metrics/*`), controlled by `matrix_metrics_exposure_enabled` and friends. ntfy was not wired into this at all, so enabling metrics exposure did not expose ntfy's metrics and enabling Basic Authentication did not protect them. We have ntfy serve its metrics on a dedicated port, instead of on its regular HTTP port. Serving them on the regular HTTP port also makes them reachable at `https://ntfy.example.com/metrics`, where nothing protects them, as ntfy does not apply its own access-control rules to the metrics endpoint. Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/5468 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>