ntfy On Loopback, Nobody Anonymous, A Message Round-Tripped
ntfy from the upstream release (sha256-verified) as a hardened system service on loopback with a message cache, a user database and deny-all as the default access. The live test sees an anonymous publish and a wrong password refused, creates a user with ntfy's own command, publishes a message and reads it back from the topic. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
ntfy
ntfy from the upstream release (sha256-verified), as a hardened system service on loopback with a message cache, a user database and no anonymous access, for a proxy that terminates TLS. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
ntfy; ntfy ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by ntfy_version.
A service account, a hardened unit, a loopback listener. ntfy
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:2586 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
Nobody is anonymous. auth-default-access is deny-all, so a
topic is published to and read by accounts only: ntfy user add creates
them and ntfy access grants topics. The live test proves the setting
both ways: an anonymous publish is 403 and a wrong password 401 before a
message is published with a real account and read back from the topic
through /<topic>/json?poll=1, which is the cache doing its work.
The user database is the service's. ntfy user writes user.db
directly, so the live test runs it as the ntfy user; a database created
by root would be one the server cannot write. Signup is off and login on:
accounts are made on the host, not on the web page.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
ansible-nats-server
NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.
ansible-postfix-null-client
Postfix as a send-only relay: no local delivery (a stock install spools root's mail on the box), one smarthost, TLS required rather than opportunistic, SASL credentials in a root-only lmdb map, local recipients rewritten to a real mailbox. Original role, live-tested on Rocky Linux 10.