From 9964b3683277db668c3abda1880a497bcc96eb75 Mon Sep 17 00:00:00 2001 From: thethreemagi Date: Tue, 4 Aug 2026 04:44:57 +0100 Subject: [PATCH] plex: move the watchtower ntfy URL out of compose into a gitignored .env, and sync the opt-in watchtower changes that were only on the host --- plex/docker-compose.yml | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/plex/docker-compose.yml b/plex/docker-compose.yml index 5bd7291..332fd99 100644 --- a/plex/docker-compose.yml +++ b/plex/docker-compose.yml @@ -9,6 +9,12 @@ services: container_name: plex restart: unless-stopped + # Watchtower runs in OPT-IN mode (WATCHTOWER_LABEL_ENABLE below), so this + # label is what keeps Plex auto-updating. Remove it and Plex silently + # stops getting updates. + labels: + com.centurylinklabs.watchtower.enable: "true" + # NOT OPTIONAL. Plex's local discovery (GDM) and client auto-detection rely # on broadcast traffic that a bridge network silently eats. (DLNA is off on # this server, so discovery — not DLNA — is the reason.) This is also why @@ -111,13 +117,24 @@ services: watchtower: # Auto-updater — checks daily at 05:00 local, pulls newer images, # recreates the container with identical settings, prunes old images, - # and ntfys arrsstack-alerts about anything it did. Local builds - # (shell-mcp) have no registry to compare against and are ignored. + # and ntfys arrsstack-alerts about anything it did. + # + # OPT-IN MODE (WATCHTOWER_LABEL_ENABLE=true). Watchtower touches ONLY + # containers carrying com.centurylinklabs.watchtower.enable=true. + # Locally-built images (gamelab, shell-mcp) exist in no registry, so under + # the old opt-out mode Watchtower HEAD-requested Docker Hub for them, + # got a 401, and ntfyd a failure every single morning. Opt-in makes the + # safe thing the default: a new local build is ignored unless someone + # deliberately labels it. Anything added here that SHOULD auto-update + # needs enable=true, same as Plex above. image: containrrr/watchtower container_name: watchtower restart: unless-stopped + labels: + com.centurylinklabs.watchtower.enable: "true" environment: - TZ=${TZ:-America/New_York} + - WATCHTOWER_LABEL_ENABLE=true # Watchtower v1.7.1's bundled docker client defaults to API 1.25 and # its version negotiation fails against Engine 29 (min API 1.40), # leaving the container in a crash loop. Pinning the API version is @@ -127,7 +144,11 @@ services: - WATCHTOWER_SCHEDULE=0 0 5 * * * - WATCHTOWER_CLEANUP=true - WATCHTOWER_NOTIFICATIONS=shoutrrr - - WATCHTOWER_NOTIFICATION_URL=ntfy://ntfy.thewichersfamily.com/arrsstack-alerts + # Carries ntfy credentials, so it lives in /srv/plex/.env (gitignored, + # 0600) and NEVER in this file. See .env.example. ntfy went deny-all on + # 2026-08-03; before that this URL was anonymous and publishing to + # arrsstack-alerts with no auth at all. + - WATCHTOWER_NOTIFICATION_URL=${WATCHTOWER_NOTIFICATION_URL} - WATCHTOWER_NOTIFICATION_TEMPLATE={{range .}}{{.Message}}{{println}}{{end}} volumes: - /var/run/docker.sock:/var/run/docker.sock