plex: move the watchtower ntfy URL out of compose into a gitignored .env, and sync the opt-in watchtower changes that were only on the host

This commit is contained in:
2026-08-04 04:44:57 +01:00
parent d279a73e5b
commit 9964b36832
+24 -3
View File
@@ -9,6 +9,12 @@ services:
container_name: plex container_name: plex
restart: unless-stopped restart: unless-stopped
# Watchtower runs in OPT-IN mode (WATCHTOWER_LABEL_ENABLE below), so this
# label is what keeps Plex auto-updating. Remove it and Plex silently
# stops getting updates.
labels:
com.centurylinklabs.watchtower.enable: "true"
# NOT OPTIONAL. Plex's local discovery (GDM) and client auto-detection rely # NOT OPTIONAL. Plex's local discovery (GDM) and client auto-detection rely
# on broadcast traffic that a bridge network silently eats. (DLNA is off on # on broadcast traffic that a bridge network silently eats. (DLNA is off on
# this server, so discovery — not DLNA — is the reason.) This is also why # this server, so discovery — not DLNA — is the reason.) This is also why
@@ -111,13 +117,24 @@ services:
watchtower: watchtower:
# Auto-updater — checks daily at 05:00 local, pulls newer images, # Auto-updater — checks daily at 05:00 local, pulls newer images,
# recreates the container with identical settings, prunes old images, # recreates the container with identical settings, prunes old images,
# and ntfys arrsstack-alerts about anything it did. Local builds # and ntfys arrsstack-alerts about anything it did.
# (shell-mcp) have no registry to compare against and are ignored. #
# OPT-IN MODE (WATCHTOWER_LABEL_ENABLE=true). Watchtower touches ONLY
# containers carrying com.centurylinklabs.watchtower.enable=true.
# Locally-built images (gamelab, shell-mcp) exist in no registry, so under
# the old opt-out mode Watchtower HEAD-requested Docker Hub for them,
# got a 401, and ntfyd a failure every single morning. Opt-in makes the
# safe thing the default: a new local build is ignored unless someone
# deliberately labels it. Anything added here that SHOULD auto-update
# needs enable=true, same as Plex above.
image: containrrr/watchtower image: containrrr/watchtower
container_name: watchtower container_name: watchtower
restart: unless-stopped restart: unless-stopped
labels:
com.centurylinklabs.watchtower.enable: "true"
environment: environment:
- TZ=${TZ:-America/New_York} - TZ=${TZ:-America/New_York}
- WATCHTOWER_LABEL_ENABLE=true
# Watchtower v1.7.1's bundled docker client defaults to API 1.25 and # Watchtower v1.7.1's bundled docker client defaults to API 1.25 and
# its version negotiation fails against Engine 29 (min API 1.40), # its version negotiation fails against Engine 29 (min API 1.40),
# leaving the container in a crash loop. Pinning the API version is # leaving the container in a crash loop. Pinning the API version is
@@ -127,7 +144,11 @@ services:
- WATCHTOWER_SCHEDULE=0 0 5 * * * - WATCHTOWER_SCHEDULE=0 0 5 * * *
- WATCHTOWER_CLEANUP=true - WATCHTOWER_CLEANUP=true
- WATCHTOWER_NOTIFICATIONS=shoutrrr - WATCHTOWER_NOTIFICATIONS=shoutrrr
- WATCHTOWER_NOTIFICATION_URL=ntfy://ntfy.thewichersfamily.com/arrsstack-alerts # Carries ntfy credentials, so it lives in /srv/plex/.env (gitignored,
# 0600) and NEVER in this file. See .env.example. ntfy went deny-all on
# 2026-08-03; before that this URL was anonymous and publishing to
# arrsstack-alerts with no auth at all.
- WATCHTOWER_NOTIFICATION_URL=${WATCHTOWER_NOTIFICATION_URL}
- WATCHTOWER_NOTIFICATION_TEMPLATE={{range .}}{{.Message}}{{println}}{{end}} - WATCHTOWER_NOTIFICATION_TEMPLATE={{range .}}{{.Message}}{{println}}{{end}}
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock