Signed webhook ingestion
Senders sign the payload with HMAC-SHA256 and the platform checks it in constant time.
Anyone can POST to a URL. The signature is what lets a team trust that an event came from its own tooling.
DevNotify is an open source notification pipeline in development. It accepts signed events from the tools a team already uses, processes them outside the request, applies that team's rules, and delivers by email and WebSocket. Every delivery attempt is stored and searchable.
Early stage. The backend is implemented and runs locally. There is no hosted service yet.
Alerting on a build, a deploy or a pull request looks small. The work behind it is not: verifying who sent the event, keeping senders from waiting on email, deciding who hears about what, and knowing afterwards what was delivered.
DevNotify is built on the hypothesis that this work can live in one reusable pipeline instead of being rewritten per application. That is a design goal, not a proven market claim.
Five stages, each a separate responsibility. The sender's request ends at the queue, and everything to the right of it runs asynchronously.
Each webhook is signed with the tenant's API key. The secret never crosses the network, and a bad signature never reaches the queue.
The event is saved to PostgreSQL first, then published to RabbitMQ, so a queued message always points at a real row.
The queue consumer and the gRPC interface call the same rule-matching code, so results do not depend on how an event arrived.
Five capabilities implemented in the backend and exercised through its local setup.
Senders sign the payload with HMAC-SHA256 and the platform checks it in constant time.
Anyone can POST to a URL. The signature is what lets a team trust that an event came from its own tooling.
Ingestion stores the event and hands it to RabbitMQ. Failed messages go to a dead letter queue instead of being lost.
A slow mail server cannot make a CI system's webhook time out.
Each team defines rules by event type, source and channel. Leaving type and source empty makes a catch-all.
What a team is notified about changes through the API, with no redeploy.
Email is sent asynchronously. WebSocket push reaches an individual member or a whole tenant topic.
Some alerts belong in an inbox and some in an open browser tab.
Every attempt is recorded as PENDING, SENT or FAILED, and notification history is indexed in Elasticsearch.
When something does not arrive, there is a record of what was tried and why it failed.
These are hypotheses about use cases. DevNotify has no customers or users to point to.
Spring Boot, PostgreSQL, RabbitMQ, Redis, Elasticsearch, gRPC.
The backend is a modular monolith with versioned SQL migrations, two deliberate caching strategies and a synchronous gRPC path beside the asynchronous one. The engineering page documents the API, versions, local setup and the known gaps.
The backend is implemented and documented, and it runs on a developer machine with Docker. There is no hosted service and no commercial offering. The current backend should not be deployed for real users yet, because authorization on its management endpoints still needs work.
Read the code, follow the build.