Back to articles
Technology Insight

Self-Hosted Push Notifications: A Guide to Deploying Gotify on a VPS for Secure Business Alerts

May 30, 2026

Introduction: The Case for Self-Hosted Notifications

In today's fast-paced digital ecosystem, real-time communication is the backbone of efficient operations. From server health alerts and deployment success logs to security breach warnings, businesses rely heavily on instant notifications. Traditionally, developers and system administrators have turned to third-party services like Pushover, Slack, or Telegram. While convenient, these proprietary platforms come with distinct trade-offs: data privacy concerns, potential vendor lock-in, API rate limits, and recurring subscription costs.

For organizations handling sensitive data or aiming for maximum infrastructure independence, a self-hosted alternative is the gold standard. Enter Gotify—a powerful, open-source, and lightweight server designed specifically for sending and receiving push notifications. When deployed on a Virtual Private Server (VPS), Gotify provides an isolated, ultra-fast notification hub under your absolute control. This comprehensive guide walks you through the architectural advantages of Gotify and provides a step-by-step technical blueprint for deploying it within a production-ready VPS environment.

Why Gotify? Architectural Advantages for Enterprise and Devops

Gotify stands out in the open-source landscape due to its simplicity and minimalist design philosophy. It is written in Go, which ensures high performance, minimal memory usage, and rapid execution times—crucial attributes for a background utility service running on a budget-conscious VPS. Here is why it fits perfectly into modern DevOps workflows:

  • Absolute Data Privacy: Because the server resides entirely on your private infrastructure, your notification payloads—which often contain sensitive details like IP addresses, database errors, or system paths—never traverse third-party servers.
  • Simple REST API: Sending a message is as straightforward as executing a standard POST request. This simplicity allows Gotify to integrate seamlessly with any programming language, bash script, or web hook.
  • WebSockets for Real-Time Delivery: Gotify utilizes a persistent WebSocket connection to stream messages to clients instantly, eliminating the polling overhead that drains mobile battery life and introduces latency.
  • Multi-Application Isolation: You can create separate "Applications" within the Gotify dashboard, each with its own unique API token. This ensures that an alert from your backup script is completely isolated from your website's contact form notifications.
  • User and Client Management: The built-in administration panel allows managers to provision separate user accounts and link multiple physical devices (Android app or Web UI clients) effortlessly.

Prerequisites and Environment Setup

Before initiating the deployment process, ensure your infrastructure meets the following baseline requirements to guarantee stability and security:

  1. A Linux VPS: A modest instance (e.g., 1 vCPU, 1GB RAM) running Ubuntu 22.04 LTS or newer is more than sufficient for Gotify, thanks to its low resource footprint.
  2. A Fully Qualified Domain Name (FQDN): A domain or subdomain (e.g., gotify.yourcompany.com) pointed directly to your VPS public IP via an A Record. This is mandatory for securing connections with SSL/TLS.
  3. Docker and Docker Compose: Using containerization ensures clean installations, trivial updates, and isolated dependencies.
Security Note: Always keep your host operating system updated. Before proceeding, run sudo apt update && sudo apt upgrade -y on your server to patch any underlying vulnerabilities.

Step-by-Step Deployment Guide

We will configure Gotify behind a reverse proxy (Nginx) using Docker Compose. The reverse proxy handles SSL termination, shielding the core Gotify application from direct public exposure and enforcing encrypted traffic via HTTPS.

Step 1: Directory Structure and Docker Configuration

First, log into your VPS via SSH and create a dedicated directory to organize the deployment files:

mkdir -p ~/gotify-server/data
cd ~/gotify-server

Next, construct the docker-compose.yml file. This declarative file outlines our application services, volume persistence, and environment configurations:

version: '3.8'

services:
  gotify:
    image: gotify/server:latest
    container_name: gotify_service
    restart: always
    ports:
      - "127.0.0.1:8080:80"
    environment:
      - GOTIFY_DEFAULTUSER_PASS=ChangeThisInitialSecurePassword
      - TZ=Asia/Ho_Chi_MinH
    volumes:
      - "./data:/app/data"

Note: Binding the port explicitly to 127.0.0.1:8080 ensures that the Gotify port is inaccessible from the outside world directly, forcing all incoming traffic to pass safely through our local reverse proxy.

Step 2: Nginx Reverse Proxy and SSL Integration

To encrypt communication and ensure mobile clients can connect securely, install Nginx and obtain a Let's Encrypt SSL certificate using Certbot:

sudo apt install nginx certbot python3-certbot-nginx -y

Create a new Nginx server block configuration for your Gotify subdomain:

sudo nano /etc/nginx/sites-available/gotify.yourcompany.com

Insert the following configuration layout, optimized specifically to support Gotify's long-lived WebSocket connections:

server {
    listen 80;
    server_name gotify.yourcompany.com;

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Support for WebSockets
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_connect_timeout 7d;
        proxy_send_timeout 7d;
        proxy_read_timeout 7d;
    }
}

Enable the site configuration by creating a symbolic link and reload the Nginx engine:

sudo ln -s /etc/nginx/sites-available/gotify.yourcompany.com /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx

Finally, run Certbot to automate the acquisition and deployment of your free SSL/TLS certificate:

sudo certbot --nginx -d gotify.yourcompany.com

Follow the interactive prompts to complete the process and select the option to automatically redirect all HTTP traffic to HTTPS.

Step 3: Launching the Service

With the proxy and security layers firmly in place, navigate back to your configuration directory and spin up the Docker container in detached mode:

cd ~/gotify-server
docker-compose up -d

Verify that the service is running correctly by inspecting the container status using docker ps. You should see the container running stably on local port 8080.

Configuring and Utilizing Your Gotify Instance

Open your preferred web browser and navigate to your chosen domain: [https://gotify.yourcompany.com](https://gotify.yourcompany.com). Log in using the default administrative credentials defined in your configuration file. Crucial action item: Immediately navigate to the user management tab to modify your default administrative credentials and establish strong, unique passwords.

Creating an Application Token

To send alerts from your automated workflows, you must register a new sending application within the UI dashboard:

  1. Navigate to the Apps tab in the navigation menu.
  2. Click on Create Application, assign a meaningful name (e.g., "Server Monitor"), and optionally upload an icon.
  3. Save the entry and copy the automatically generated token string (e.g., An389X_d92kLsa). This token authenticates your scripts to send alerts securely.

Testing via Command Line

You can verify your end-to-end setup instantly by dispatching a test payload from your command terminal using curl. Execute the following command string, substituting your actual domain and specific application token:

curl -X POST "[https://gotify.yourcompany.com/message?token=YOUR_APP_TOKEN](https://gotify.yourcompany.com/message?token=YOUR_APP_TOKEN)" \
     -F "title=System Alert" \
     -F "message=The backup sequence completed successfully." \
     -F "priority=5"

Gotify messages natively support adjustable priority integers ranging from 0 to 10. Higher-priority numbers can be configured to bypass do-not-disturb profiles or trigger loud, distinct notification tones on client devices.

Practical DevOps Integration Scenarios

Now that your personal push notification engine is active, you can embed it directly into your everyday infrastructure management protocols. Here are three practical production examples:

1. Automatic SSH Login Alerts

Monitor administrative access in real-time by adding a simple triggering script to your server profile. Append the following block to /etc/profile to get alerted instantly whenever someone authenticates via SSH:

if [ -n "$SSH_CLIENT" ]; then
  TEXT="User ${USER} logged into $(hostname) from $(echo $SSH_CLIENT | awk '{print $1}')"
  curl -s -X POST "[https://gotify.yourcompany.com/message?token=YOUR_TOKEN](https://gotify.yourcompany.com/message?token=YOUR_TOKEN)" -F "title=SSH Access Detected" -F "message=$TEXT" -F "priority=7"
fi

2. Automated System Resource Tracking

A simple bash routine can monitor host storage thresholds via cron-jobs, proactively alerting system administrators before a storage volume fills up completely and causes operational outages:

#!/bin/bash
THRESHOLD=85
CURRENT=$(df / | grep / | awk '{ print $5 }' | sed 's/%//g')

if [ "$CURRENT" -gt "$THRESHOLD" ]; then
  curl -s -X POST "[https://gotify.yourcompany.com/message?token=YOUR_TOKEN](https://gotify.yourcompany.com/message?token=YOUR_TOKEN)" \
       -F "title=Storage Warning" \
       -F "message=Disk usage has surged past safe thresholds and is currently at ${CURRENT}%." \
       -F "priority=8"
fi

Connecting Client Mobile Devices

To receive these push alerts on the go, download the official Gotify client application directly from the Google Play Store or F-Droid marketplace. Launch the app, provide your self-hosted server URL (e.g., [https://gotify.yourcompany.com](https://gotify.yourcompany.com)), and authenticate with your user credentials. The app establishes a low-power persistent connection via WebSockets, ensuring your operational warnings land in your notification tray immediately without excessive battery drain or messaging latency.

Conclusion

Deploying Gotify on a VPS provides modern technical teams with a robust, highly optimized, and structurally independent solution for managing operational alerts. By bypassing proprietary notification networks, you secure your operational metadata, control user access comprehensively, and enjoy unlimited notifications free from arbitrary subscription pricing. With Docker managing the underlying execution and an enterprise-grade reverse proxy handling encryption, your private messaging pipeline is fully secure, exceptionally scalable, and completely ready to support your production infrastructure.

Self-Hosted Push Notifications: A Guide to Deploying Gotify on a VPS for Secure Business Alerts | DPTCloud