Skip to content

Repository files navigation

Quarkus GateLink Web Push

GateLink is a Java 21 / Quarkus Web Push gateway with PostgreSQL and an Angular UI served by Nginx.

The implementation is modern-only:

  • RFC 8030 Web Push;
  • RFC 8188 / RFC 8291 aes128gcm;
  • RFC 8292 VAPID;
  • no obsolete aesgcm delivery path.

Runtime architecture

Browser
   |
   | HTTPS :443
   v
quarkus-gatelink-webpush-ui
Angular + Nginx
   |
   | /api/*
   | HTTPS :8443
   | Docker DNS: quarkus-gatelink-webpush-server
   v
quarkus-gatelink-webpush-server
Quarkus / Java 21
   |
   | JDBC
   v
postgres :5432

The fixed Compose service, container and hostname values are:

quarkus-gatelink-webpush-ui
quarkus-gatelink-webpush-server

Published ports:

Component Port Purpose
UI 80 HTTP redirect to HTTPS; local /healthz
UI 443 normal user/browser entry point
Quarkus 8080 direct HTTP REST/operations access
Quarkus 8443 direct HTTPS REST/operations access
PostgreSQL 5432 internal only subscription registry

Repository layout

.
├── docker-compose.yml
├── .env.example
├── config/
│   └── nginx.conf
├── data/
│   └── quarkus-gatelink-webpush-server/
│       ├── logs/
│       └── tmp/
├── quarkus-gatelink-webpush-server/
│   ├── Dockerfile
│   ├── docker-entrypoint.sh
│   ├── application.properties
│   ├── pom.xml
│   ├── README.md
│   └── src/
└── quarkus-gatelink-webpush-ui/
    ├── Dockerfile
    ├── docker-entrypoint.sh
    ├── package.json
    ├── angular.json
    ├── README.md
    └── src/

config/nginx.conf is the reverse-proxy configuration used by the UI container.

data/quarkus-gatelink-webpush-server/ contains host-visible runtime data for Quarkus logs and temporary files.

quarkus-gatelink-webpush-server/application.properties is the external Docker/production configuration. Compose mounts it read-only at /opt/app/config/application.properties.

The normal Quarkus source configuration remains under src/main/resources/application.properties for Maven/dev/test use.

Quick start

cp .env.example .env

sudo chown -R 10001:10001 data/quarkus-gatelink-webpush-server/logs
sudo chown -R 10001:10001 data/quarkus-gatelink-webpush-server/tmp

docker compose -f docker-compose.yml build
docker compose -f docker-compose.yml up -d --wait
docker compose -f docker-compose.yml ps

Normal browser entry:

https://localhost/

Direct Quarkus access:

http://localhost:8080/
https://localhost:8443/

The supplied TLS certificates are generated automatically and are self-signed. Add deployment DNS names/IP addresses to UI_TLS_SAN and SERVER_TLS_SAN before first start when needed.

Nginx proxy

The canonical proxy file is:

config/nginx.conf

Angular uses same-origin /api/... URLs. Nginx forwards them to:

https://quarkus-gatelink-webpush-server:8443/

For the self-signed internal certificate, Nginx currently uses proxy_ssl_verify off. A deployment with an internal CA can enable upstream verification.

Persistence

Data Persistence
browser PushSubscriptions Docker volume postgres_data
server TLS certificate/key Docker volume server_tls
UI TLS certificate/key Docker volume ui_tls
Quarkus logs data/quarkus-gatelink-webpush-server/logs/
Quarkus temp files data/quarkus-gatelink-webpush-server/tmp/
runtime Quarkus config quarkus-gatelink-webpush-server/application.properties
proxy config config/nginx.conf

PostgreSQL stores endpoint, p256dh and auth for browser subscriptions. It is not a notification queue or delivery-history database.

Server Maven identity

<groupId>com.quarkus</groupId>
<artifactId>quarkus-gatelink-webpush-server</artifactId>

The current server uses Java 21 and Quarkus 3.33.3 LTS.

Web Push implementation

GateLink uses:

nl.martijndwars:web-push:5.1.2

with:

Encoding.AES128GCM

GateLink itself owns subscription persistence, VAPID identity/JWT creation, JDK HttpClient delivery, OIDC/RBAC, rate limiting, metrics and tracing.

The maximum plaintext payload is 3993 UTF-8 bytes.

Release artifacts

A GitHub Release generates:

quarkus-gatelink-webpush-server-<version>.jar
quarkus-gatelink-webpush-ui-<version>.zip
quarkus-gatelink-webpush-ui-<version>.tar.gz
quarkus-gatelink-webpush-compose-<version>.zip
quarkus-gatelink-webpush-compose-<version>.tar.gz
SHA256SUMS

The Compose bundle mirrors the same runtime layout: docker-compose.yml, config/, data/, quarkus-gatelink-webpush-server/ and quarkus-gatelink-webpush-ui/.

Documentation

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages