// A bridge between ntfy and Alertmanager package main import ( "crypto/sha512" "crypto/subtle" _ "embed" "encoding/base64" "encoding/json" "flag" "fmt" "net/http" "os" "strings" "time" "git.xenrox.net/~xenrox/go-log" "git.xenrox.net/~xenrox/ntfy-alertmanager/cache" "golang.org/x/text/cases" "golang.org/x/text/language" ) var version = "dev" type bridge struct { cfg *config logger *log.Logger cache cache.Cache client *httpClient } type payload struct { Status string `json:"status"` Alerts []alert `json:"alerts"` GroupLabels map[string]string `json:"groupLabels"` CommonLabels map[string]string `json:"commonLabels"` CommonAnnotations map[string]string `json:"commonAnnotations"` ExternalURL string `json:"externalURL"` } type alert struct { Status string `json:"status"` Labels map[string]string `json:"labels"` Annotations map[string]string `json:"annotations"` Fingerprint string `json:"fingerprint"` } type notification struct { title string body string priority string tags string icon string emailAddress string call string silenceBody string fingerprint string status string } type ntfyError struct { Error string `json:"error"` } func (br *bridge) singleAlertNotifications(p *payload) []*notification { var notifications []*notification for _, alert := range p.Alerts { contains, err := br.cache.Contains(alert.Fingerprint, alert.Status) if err != nil { br.logger.Errorf("Failed to lookup alert %q in cache: %v", alert.Fingerprint, err) } if contains { br.logger.Debugf("Alert %q skipped: Still in cache", alert.Fingerprint) continue } n := new(notification) n.fingerprint = alert.Fingerprint n.status = alert.Status // create title n.title = fmt.Sprintf("[%s]", strings.ToUpper(alert.Status)) if name, ok := alert.Labels["alertname"]; ok { n.title = fmt.Sprintf("%s %s", n.title, name) } for _, value := range p.GroupLabels { n.title = fmt.Sprintf("%s %s", n.title, value) } // create body n.body = "Labels:\n" sortedLabelKeys := sortKeys(alert.Labels) for _, key := range sortedLabelKeys { n.body = fmt.Sprintf("%s%s = %s\n", n.body, key, alert.Labels[key]) } n.body += "\nAnnotations:\n" for key, value := range alert.Annotations { n.body = fmt.Sprintf("%s%s = %s\n", n.body, key, value) } var tags []string if alert.Status == "resolved" { tags = append(tags, br.cfg.resolved.Tags...) n.icon = br.cfg.resolved.Icon } n.emailAddress = br.cfg.ntfy.emailAddress n.call = br.cfg.ntfy.call for _, labelName := range br.cfg.labels.Order { val, ok := alert.Labels[labelName] if !ok { continue } labelConfig, ok := br.cfg.labels.Label[fmt.Sprintf("%s:%s", labelName, val)] if !ok { continue } if n.priority == "" { n.priority = labelConfig.Priority } if n.icon == "" { n.icon = labelConfig.Icon } if n.emailAddress == "" { n.emailAddress = labelConfig.emailAddress } if n.call == "" { n.call = labelConfig.call } for _, val := range labelConfig.Tags { if !sliceContains(tags, val) { tags = append(tags, val) } } } n.tags = strings.Join(tags, ",") if br.cfg.am.SilenceDuration != 0 && alert.Status == "firing" { if br.cfg.BaseURL == "" { br.logger.Error("Failed to create silence action: No base-url set") } else { // I could not convince ntfy to accept an Action with a body which contains // a json with more than one key. Instead the json will be base64 encoded // and sent to the ntfy-alertmanager silences endpoint, that operates as // a proxy and will do the Alertmanager API request. s := &silenceBody{AlertManagerURL: p.ExternalURL, Labels: alert.Labels} b, err := json.Marshal(s) if err != nil { br.logger.Errorf("Failed to create silence action: %v", err) } n.silenceBody = base64.StdEncoding.EncodeToString(b) } } notifications = append(notifications, n) } return notifications } func (br *bridge) multiAlertNotification(p *payload) *notification { n := new(notification) // create title count := len(p.Alerts) title := fmt.Sprintf("[%s", strings.ToUpper(p.Status)) if p.Status == "firing" { title = fmt.Sprintf("%s:%d", title, count) } title += "]" for _, value := range p.GroupLabels { title = fmt.Sprintf("%s %s", title, value) } n.title = title // create body var body string c := cases.Title(language.English) for _, alert := range p.Alerts { alertBody := fmt.Sprintf("%s\nLabels:\n", c.String(alert.Status)) sortedLabelKeys := sortKeys(alert.Labels) for _, key := range sortedLabelKeys { alertBody = fmt.Sprintf("%s%s = %s\n", alertBody, key, alert.Labels[key]) } alertBody += "Annotations:\n" for key, value := range alert.Annotations { alertBody = fmt.Sprintf("%s%s = %s\n", alertBody, key, value) } alertBody += "\n" body += alertBody } n.body = body var tags []string if p.Status == "resolved" { tags = append(tags, br.cfg.resolved.Tags...) n.icon = br.cfg.resolved.Icon } n.emailAddress = br.cfg.ntfy.emailAddress n.call = br.cfg.ntfy.call for _, labelName := range br.cfg.labels.Order { val, ok := p.CommonLabels[labelName] if !ok { continue } labelConfig, ok := br.cfg.labels.Label[fmt.Sprintf("%s:%s", labelName, val)] if !ok { continue } if n.priority == "" { n.priority = labelConfig.Priority } if n.icon == "" { n.icon = labelConfig.Icon } if n.emailAddress == "" { n.emailAddress = labelConfig.emailAddress } if n.call == "" { n.call = labelConfig.call } for _, val := range labelConfig.Tags { if !sliceContains(tags, val) { tags = append(tags, val) } } } n.tags = strings.Join(tags, ",") if br.cfg.am.SilenceDuration != 0 && p.Status == "firing" { if br.cfg.BaseURL == "" { br.logger.Error("Failed to create silence action: No base-url set") } else { s := &silenceBody{AlertManagerURL: p.ExternalURL, Labels: p.CommonLabels} b, err := json.Marshal(s) if err != nil { br.logger.Errorf("Failed to create silence action: %v", err) } n.silenceBody = base64.StdEncoding.EncodeToString(b) } } return n } func (br *bridge) publish(n *notification) error { req, err := http.NewRequest(http.MethodPost, br.cfg.ntfy.Topic, strings.NewReader(n.body)) if err != nil { return err } // ntfy authentication if br.cfg.ntfy.Password != "" && br.cfg.ntfy.User != "" { req.SetBasicAuth(br.cfg.ntfy.User, br.cfg.ntfy.Password) } else if br.cfg.ntfy.AccessToken != "" { req.Header.Set("Authorization", fmt.Sprintf("Bearer %s", br.cfg.ntfy.AccessToken)) } req.Header.Set("X-Title", n.title) if n.priority != "" { req.Header.Set("X-Priority", n.priority) } if n.icon != "" { req.Header.Set("X-Icon", n.icon) } if n.tags != "" { req.Header.Set("X-Tags", n.tags) } if n.emailAddress != "" { req.Header.Set("X-Email", n.emailAddress) } if n.call != "" { req.Header.Set("X-Call", n.call) } if n.silenceBody != "" { url := br.cfg.BaseURL + "/silences" var authString string if br.cfg.User != "" && br.cfg.Password != "" { auth := base64.StdEncoding.EncodeToString([]byte(fmt.Sprintf("%s:%s", br.cfg.User, br.cfg.Password))) authString = fmt.Sprintf(", headers.Authorization=Basic %s", auth) } req.Header.Set("Actions", fmt.Sprintf("http, Silence, %s, method=POST, body=%s%s", url, n.silenceBody, authString)) } resp, err := br.client.Do(req) if err != nil { return err } defer resp.Body.Close() if resp.StatusCode != http.StatusOK { var ntfyError ntfyError if err := json.NewDecoder(resp.Body).Decode(&ntfyError); err != nil { br.logger.Debugf("Publish: failed to decode error: %v", err) return fmt.Errorf("ntfy: received status code %d", resp.StatusCode) } return fmt.Errorf("ntfy: %s (status code %d)", ntfyError.Error, resp.StatusCode) } return nil } func (br *bridge) handleWebhooks(w http.ResponseWriter, r *http.Request) { defer r.Body.Close() if r.Method != http.MethodPost { http.Error(w, "Only POST allowed", http.StatusMethodNotAllowed) br.logger.Debugf("illegal HTTP method: expected %q, got %q", "POST", r.Method) return } contentType := r.Header.Get("Content-Type") if contentType != "application/json" { http.Error(w, "Only application/json allowed", http.StatusUnsupportedMediaType) br.logger.Debugf("illegal content type: %s", contentType) return } var event payload if err := json.NewDecoder(r.Body).Decode(&event); err != nil { br.logger.Debug(err) return } if br.logger.Level() == log.Debug { br.logger.Debugf("Received alert %+v", event) } if br.cfg.alertMode == single { notifications := br.singleAlertNotifications(&event) for _, n := range notifications { err := br.publish(n) if err != nil { br.logger.Errorf("Failed to publish notification: %v", err) } else { if err := br.cache.Set(n.fingerprint, n.status); err != nil { br.logger.Errorf("Failed to set alert %q in cache: %v", n.fingerprint, err) } } } } else { notification := br.multiAlertNotification(&event) err := br.publish(notification) if err != nil { br.logger.Errorf("Failed to publish notification: %v", err) } } } func (br *bridge) basicAuthMiddleware(handler http.HandlerFunc) http.HandlerFunc { return func(w http.ResponseWriter, r *http.Request) { user, pass, ok := r.BasicAuth() if !ok { br.logger.Debug("basic auth failure") return } inputUserHash := sha512.Sum512([]byte(user)) inputPassHash := sha512.Sum512([]byte(pass)) configUserHash := sha512.Sum512([]byte(br.cfg.User)) configPassHash := sha512.Sum512([]byte(br.cfg.Password)) validUser := subtle.ConstantTimeCompare(inputUserHash[:], configUserHash[:]) validPass := subtle.ConstantTimeCompare(inputPassHash[:], configPassHash[:]) if validUser != 1 || validPass != 1 { http.Error(w, "Unauthorized", http.StatusUnauthorized) br.logger.Debug("basic auth: wrong user or password") return } handler(w, r) } } func (br *bridge) runCleanup() { for { time.Sleep(br.cfg.cache.CleanupInterval) br.logger.Info("Pruning cache") br.cache.Cleanup() } } func main() { var configPath string flag.StringVar(&configPath, "config", "/etc/ntfy-alertmanager/config", "config file path") var showVersion bool flag.BoolVar(&showVersion, "version", false, "Show version and exit") flag.Parse() if showVersion { fmt.Println(version) os.Exit(0) } logger := log.NewDefaultLogger() cfg, err := readConfig(configPath) if err != nil { logger.Fatalf("Failed to read config: %v", err) } if err := logger.SetLevelFromString(cfg.LogLevel); err != nil { logger.Errorf("Failed to parse logging level: %v", err) } client := &httpClient{&http.Client{Timeout: time.Second * 3}} var c cache.Cache switch cfg.cache.Type { case memory: c = cache.NewMemoryCache(cfg.cache.Duration) case redis: var err error c, err = cache.NewRedisCache(cfg.cache.RedisURL, cfg.cache.Duration) if err != nil { logger.Fatalf("Failed to create redis cache: %v", err) } } bridge := &bridge{cfg: cfg, logger: logger, cache: c, client: client} logger.Infof("Listening on %s, ntfy-alertmanager %s", cfg.HTTPAddress, version) if cfg.User != "" && cfg.Password != "" { logger.Info("Enabling HTTP Basic Authentication") http.HandleFunc("/", bridge.basicAuthMiddleware(bridge.handleWebhooks)) http.HandleFunc("/silences", bridge.basicAuthMiddleware(bridge.handleSilences)) } else { http.HandleFunc("/", bridge.handleWebhooks) http.HandleFunc("/silences", bridge.handleSilences) } if cfg.cache.Type == memory { go bridge.runCleanup() } logger.Fatal(http.ListenAndServe(cfg.HTTPAddress, nil)) }