Compare commits

..
Author SHA1 Message Date
3wordchant ade6147f35 chore: publish 3.6.0+v1.81.0 release 2023-04-23 15:36:37 -04:00
3wordchant 50e0aa06cc Support separate DOMAIN vs SERVER_NAME 2023-04-23 15:34:58 -04:00
3wordchant f3732c8392 Goodbye, foo.yaml! 2023-04-13 12:14:35 -04:00
decentral1se e171ce052e chore: publish 3.5.0+v1.81.0 release 2023-04-11 16:29:41 +02:00
knoflook 5d5bd70818 Merge branch 'main' of https://git.coopcloud.tech/coop-cloud/matrix-synapse 2023-04-08 23:09:33 +02:00
knoflook fd1a6c7a4a fix keyserver problems when federating 2023-04-08 23:09:16 +02:00
decentral1se 39a47a2515 chore: publish 3.4.0+v1.80.0 release 2023-04-02 14:25:02 +02:00
knoflook 6e556c8b2d fix: put smtp password in quotes 2023-03-05 12:05:26 +01:00
decentral1se 74fb8014fa chore: publish 3.3.0+v1.78.0 release 2023-03-04 14:12:33 +01:00
decentral1se 787e0fb3a9 chore: publish 3.2.0+v1.77.0 release 2023-02-27 19:33:34 +01:00
knoflook ead52c1acd Merge branch 'main' of https://git.coopcloud.tech/coop-cloud/matrix-synapse 2023-02-21 13:56:06 +01:00
knoflook fca551b735 add keycloak 2 and 3 2023-02-21 13:56:01 +01:00
decentral1se f43a47d4c8 fix: use new mount for shared secret auth
See https://github.com/devture/matrix-synapse-shared-secret-auth/commit/b3dfa110976206173db0efe46a3924a4445891c5
2023-02-14 10:00:28 +01:00
decentral1se beeb1e47b1 chore: publish 3.1.0+v1.76.0 release 2023-02-13 09:26:27 +01:00
decentral1se 931e89f5f5 Merge pull request 'homserver -> homeserver' (#34) from speling into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/matrix-synapse/pulls/34
2023-02-02 19:09:48 +00:00
josef 5a72540db2 homserver -> homeserver 2023-02-02 18:12:12 +00:00
3wordchant 703b8d91d2 Switch to self-hosted stack-ssh-deploy image [mass update] 2023-01-21 11:49:56 -08:00
3wordchant 05e9ee0732 Add drone configs / secrets [mass update] 2023-01-20 21:32:06 -08:00
3wordchant ec22040bd3 Add CI and catalogue generation [mass update] 2023-01-20 10:45:03 -08:00
3wordchant d5c70f5567 Update abra syntax in examples (finally) [mass update] 2023-01-19 16:02:28 -08:00
decentral1se 4445e0249f docs: README pass 2023-01-08 02:09:55 +01:00
decentral1se 89f5069aa2 chore: new v3 recipe release 2023-01-08 02:05:27 +01:00
decentral1se 77b3dbdaa9 fix: use correct user, role does exist 2023-01-08 01:59:46 +01:00
decentral1se 1a0211b743 fix: quote YAML inline dicts correctly 2023-01-08 01:56:30 +01:00
decentral1se eb541c41ee fix: consistent compression config 2023-01-08 01:56:13 +01:00
decentral1se 008ec1126b docs: comments in env sample (getting large!) 2023-01-08 01:28:15 +01:00
decentral1se 0c26ea22f9 docs: write release notes 2023-01-08 01:22:30 +01:00
decentral1se e3bf165da0 refactor!: remove KEYCLOAK2* env vars
The experiment is over.
2023-01-08 01:15:36 +01:00
decentral1se 245e81e4bb fix: make bridge logging ERROR only
Decryption happens on the bridges (between systems) so in order to stop
plaintext logging of chat messages, we default to ERROR. If people need
more, they can submit changes for customisation.
2023-01-08 01:11:58 +01:00
decentral1se 9b12e4a0eb refactor!: unlimited permissions bridge config 2023-01-08 01:04:52 +01:00
decentral1se e7f81cb9ea fix: support openid + federation
Closes https://git.coopcloud.tech/coop-cloud/matrix-synapse/issues/30
2023-01-08 00:46:05 +01:00
decentral1se 88bcc2186b chore: bump homeserver config version 2023-01-08 00:12:03 +01:00
decentral1se 9b3e1793e0 fix: reduce config to match upstream
Closes https://git.coopcloud.tech/coop-cloud/matrix-synapse/issues/33
2023-01-08 00:10:28 +01:00
decentral1se ee6d1e92f4 fix: media retention is configurable
Closes https://git.coopcloud.tech/coop-cloud/matrix-synapse/issues/32
2023-01-08 00:10:03 +01:00
decentral1se 3e3c239c88 fix: drop missing role 2023-01-07 23:49:36 +01:00
decentral1se e905c24eb2 style: sort config env vars 2023-01-07 23:44:56 +01:00
decentral1se 91d29cfe92 chore: publish 2.6.0+v1.74.0 release 2022-12-20 20:49:03 +01:00
decentral1se 9eb0856888 chore: publish 2.5.0+v1.73.0 release 2022-12-12 17:29:50 +01:00
decentral1se 2cc70498f6 feat: patch bump signal/telegram bridges 2022-12-06 02:40:40 +01:00
decentral1se 92a9ea2f22 chore: publish 2.4.0+v1.72.0 release 2022-11-23 15:46:59 +01:00
decentral1se ca2e0d7dc0 chore: new signal/telegram minor/patch versions 2022-11-18 09:48:56 +01:00
16 changed files with 215 additions and 2021 deletions
+49
View File
@@ -0,0 +1,49 @@
---
kind: pipeline
name: deploy to swarm-test.autonomic.zone
steps:
- name: deployment
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
settings:
host: swarm-test.autonomic.zone
stack: matrix-synapse
generate_secrets: true
purge: true
deploy_key:
from_secret: drone_ssh_swarm_test
networks:
- proxy
environment:
DOMAIN: matrix-synapse.swarm-test.autonomic.zone
STACK_NAME: matrix-synapse
LETS_ENCRYPT_ENV: production
DISCORD_BRIDGE_YAML_VERSION: v1
ENTRYPOINT_CONF_VERSION: v1
HOMESERVER_YAML_VERSION: v17
LOG_CONFIG_VERSION: v1
SHARED_SECRET_AUTH_VERSION: v1
SIGNAL_BRIDGE_YAML_VERSION: v1
TELEGRAM_BRIDGE_YAML_VERSION: v1
SECRET_DB_PASSWORD_VERSION: v1
SECRET_FORM_SECRET_VERSION: v1
SECRET_MACAROON_SECRET_KEY_VERSION: v1
SECRET_REGISTRATION_SHARED_SECRET_VERSION: v1
trigger:
branch:
- main
---
kind: pipeline
name: generate recipe catalogue
steps:
- name: release a new version
image: plugins/downstream
settings:
server: https://build.coopcloud.tech
token:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
trigger:
event: tag
+57 -25
View File
@@ -1,35 +1,43 @@
TYPE=matrix-synapse TYPE=matrix-synapse
DOMAIN=matrix.example.com DOMAIN=matrix.example.com
LETS_ENCRYPT_ENV=production LETS_ENCRYPT_ENV=production
COMPOSE_FILE="compose.yml"
SECRET_DB_PASSWORD_VERSION=v1 ## Admin details
SYNAPSE_ADMIN_EMAIL=admin@example.com SYNAPSE_ADMIN_EMAIL=admin@example.com
SECRET_REGISTRATION_SHARED_SECRET_VERSION=v1 ## Secrets
SECRET_MACAROON_SECRET_KEY_VERSION=v1
SECRET_FORM_SECRET_VERSION=v1
COMPOSE_FILE="compose.yml" SECRET_DB_PASSWORD_VERSION=v1
SECRET_FORM_SECRET_VERSION=v1
SECRET_MACAROON_SECRET_KEY_VERSION=v1
SECRET_REGISTRATION_SHARED_SECRET_VERSION=v1
## Federation
#DISABLE_FEDERATION=1 #DISABLE_FEDERATION=1
# Set "true" to enable federation endpoint on $DOMAIN/.well-known/matrix/server # Set "true" to enable federation endpoint on $DOMAIN/.well-known/matrix/server
SERVE_SERVER_WELLKNOWN=false SERVE_SERVER_WELLKNOWN=false
## Registration
ENABLE_REGISTRATION=false ENABLE_REGISTRATION=false
PASSWORD_LOGIN_ENABLED=true PASSWORD_LOGIN_ENABLED=true
## Room auto-join
#AUTO_JOIN_ROOM_ENABLED=1 #AUTO_JOIN_ROOM_ENABLED=1
#AUTO_JOIN_ROOM="#example:example.com" #AUTO_JOIN_ROOM="#example:example.com"
## Logging
# for the homserver
SQL_LOG_LEVEL=WARN SQL_LOG_LEVEL=WARN
ROOT_LOG_LEVEL=WARN ROOT_LOG_LEVEL=WARN
REDACTION_RETENTION_PERIOD=7d ## Privacy
RETENTION_MAX_LIFETIME=4w
ENABLE_3PID_LOOKUP=true ENABLE_3PID_LOOKUP=true
@@ -37,11 +45,24 @@ USER_IPS_MAX_AGE=1d
ENCRYPTED_BY_DEFAULT=all ENCRYPTED_BY_DEFAULT=all
ALLOWED_LIFETIME_MAX=4w
#ENABLE_ALLOWLIST=1 #ENABLE_ALLOWLIST=1
#FEDERATION_ALLOWLIST="[]" #FEDERATION_ALLOWLIST="[]"
# Set these to keyservers you trust - usually the same as your federation allowlist
#TRUSTED_KEYSERVERS="trusted_key_servers:\n - server_name: 'example.com'\n - server_name: 'example2.com'"
## Retention
ALLOWED_LIFETIME_MAX=4w
REDACTION_RETENTION_PERIOD=7d
RETENTION_MAX_LIFETIME=4w
#MEDIA_RETENTION_LOCAL_LIFETIME=30d
#MEDIA_RETENTION_REMOTE_LIFETIME=14d
## Keycloak SSO
#COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak.yml"
#KEYCLOAK_ENABLED=1 #KEYCLOAK_ENABLED=1
#KEYCLOAK_ID=keycloak #KEYCLOAK_ID=keycloak
@@ -52,23 +73,26 @@ ALLOWED_LIFETIME_MAX=4w
#KEYCLOAK_ALLOW_EXISTING_USERS=false #KEYCLOAK_ALLOW_EXISTING_USERS=false
#SECRET_KEYCLOAK_CLIENT_SECRET_VERSION=v1 #SECRET_KEYCLOAK_CLIENT_SECRET_VERSION=v1
#COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak2.yml" ## TURN
#KEYCLOAK2_ENABLED=1
#KEYCLOAK2_ID=keycloak2 #COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak3.yml"
#KEYCLOAK2_NAME= #KEYCLOAK3_ENABLED=1
#KEYCLOAK2_URL= #KEYCLOAK3_ID=keycloak3
#KEYCLOAK2_CLIENT_ID= #KEYCLOAK3_NAME=
#KEYCLOAK2_CLIENT_DOMAIN= #KEYCLOAK3_URL=
#KEYCLOAK2_ALLOW_EXISTING_USERS=false #KEYCLOAK3_CLIENT_ID=
#SECRET_KEYCLOAK2_CLIENT_SECRET_VERSION=v1 #KEYCLOAK3_CLIENT_DOMAIN=
#KEYCLOAK3_ALLOW_EXISTING_USERS=false
#SECRET_KEYCLOAK3_CLIENT_SECRET_VERSION=v1
#COMPOSE_FILE="$COMPOSE_FILE:compose.turn.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.turn.yml"
#TURN_ENABLED=1 #TURN_ENABLED=1
#TURN_URIS="[\"turns:coturn.foo.zone?transport=udp\", \"turns:coturn.foo.zone?transport=tcp\"]" #TURN_URIS="[\"turns:coturn.foo.zone?transport=udp\", \"turns:coturn.foo.zone?transport=tcp\"]"
#TURN_ALLOW_GUESTS=true #TURN_ALLOW_GUESTS=true
#KEYCLOAK2_ALLOW_EXISTING_USERS=false
#SECRET_TURN_SHARED_SECRET_VERSION=v1 #SECRET_TURN_SHARED_SECRET_VERSION=v1
## SMTP
#COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
#SMTP_ENABLED=1 #SMTP_ENABLED=1
#SMTP_APP_NAME= #SMTP_APP_NAME=
@@ -78,9 +102,13 @@ ALLOWED_LIFETIME_MAX=4w
#SMTP_USER= #SMTP_USER=
#SECRET_SMTP_PASSWORD_VERSION=v1 #SECRET_SMTP_PASSWORD_VERSION=v1
## App services
#APP_SERVICES_ENABLED=1 #APP_SERVICES_ENABLED=1
#APP_SERVICE_CONFIGS="[\"...\"]" #APP_SERVICE_CONFIGS="[\"...\"]"
## Telegram bridge
#COMPOSE_FILE="$COMPOSE_FILE:compose.telegram.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.telegram.yml"
#APP_SERVICE_BOT_USERNAME=telegrambot #APP_SERVICE_BOT_USERNAME=telegrambot
#APP_SERVICE_DISPLAY_NAME="Telegram bridge bot" #APP_SERVICE_DISPLAY_NAME="Telegram bridge bot"
@@ -90,28 +118,32 @@ ALLOWED_LIFETIME_MAX=4w
#VERIFY_SSL=false #VERIFY_SSL=false
#ENABLE_ENCRYPTION=true #ENABLE_ENCRYPTION=true
#TELEGRAM_APP_ID= #TELEGRAM_APP_ID=
#TELEGRAM_BRIDGE_ADMIN_1= #TELEGRAM_BRIDGE_PERMISSIONS="{ \"*\": \"relaybot\" }"
#TELEGRAM_BRIDGE_ADMIN_2=
#SECRET_TELEGRAM_DB_PASSWORD_VERSION=v1 #SECRET_TELEGRAM_DB_PASSWORD_VERSION=v1
#SECRET_TELEGRAM_API_HASH_VERSION=v1 #SECRET_TELEGRAM_API_HASH_VERSION=v1
#SECRET_TELEGRAM_BOT_TOKEN_VERSION=v1 #SECRET_TELEGRAM_BOT_TOKEN_VERSION=v1
#SECRET_TELEGRAM_AS_TOKEN_VERSION=v1 #SECRET_TELEGRAM_AS_TOKEN_VERSION=v1
#SECRET_TELEGRAM_HS_TOKEN_VERSION=v1 #SECRET_TELEGRAM_HS_TOKEN_VERSION=v1
## Discord bridge
#COMPOSE_FILE="$COMPOSE_FILE:compose.discord.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.discord.yml"
#DISCORD_CLIENT_ID= #DISCORD_CLIENT_ID=
#DISCORD_BRIDGE_ADMIN= #DISCORD_BRIDGE_ADMIN=
#SECRET_DISCORD_BOT_TOKEN_VERSION=v1 #SECRET_DISCORD_BOT_TOKEN_VERSION=v1
#SECRET_DISCORD_DB_PASSWORD_VERSION=v1 #SECRET_DISCORD_DB_PASSWORD_VERSION=v1
## Signal bridge
#COMPOSE_FILE="$COMPOSE_FILE:compose.signal.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.signal.yml"
#SIGNAL_ENABLE_ENCRYPTION=true #SIGNAL_ENABLE_ENCRYPTION=true
#SIGNAL_BRIDGE_ADMIN_1="@foo:example.com" #SIGNAL_BRIDGE_PERMISSIONS="{ \"*\": \"relay\" }"
#SIGNAL_BRIDGE_ADMIN_2="@bar:example.com"
#SECRET_SIGNAL_AS_TOKEN_VERSION=v1 #SECRET_SIGNAL_AS_TOKEN_VERSION=v1
#SECRET_SIGNAL_DB_PASSWORD_VERSION=v1 #SECRET_SIGNAL_DB_PASSWORD_VERSION=v1
#SECRET_SIGNAL_HS_TOKEN_VERSION=v1 #SECRET_SIGNAL_HS_TOKEN_VERSION=v1
## Shared auth
#COMPOSE_FILE="$COMPOSE_FILE:compose.shared_secret_auth.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.shared_secret_auth.yml"
#SHARED_SECRET_AUTH_ENABLED=1 #SHARED_SECRET_AUTH_ENABLED=1
#SECRET_SHARED_SECRET_AUTH_VERSION=v1 # length=128 #SECRET_SHARED_SECRET_AUTH_VERSION=v1 # length=128
+11 -56
View File
@@ -18,73 +18,28 @@
1. Set up Docker Swarm and [`abra`](https://docs.coopcloud.tech/abra/) 1. Set up Docker Swarm and [`abra`](https://docs.coopcloud.tech/abra/)
2. Deploy [`coop-cloud/traefik`](https://git.coopcloud.tech/coop-cloud/traefik) 2. Deploy [`coop-cloud/traefik`](https://git.coopcloud.tech/coop-cloud/traefik)
3. `abra app new matrix-synapse --secrets` (optionally with `--pass` if you'd like to save secrets in `pass`) 3. `abra app new matrix-synapse --secrets` (optionally with `--pass` if you'd like to save secrets in `pass`)
4. `abra app YOURAPPDOMAIN config` - be sure to change `$DOMAIN` to something that resolves to your Docker swarm box 4. `abra app config YOURAPPDOMAIN` - be sure to change `$DOMAIN` to something that resolves to your Docker swarm box
5. `abra app YOURAPPDOMAIN deploy` 5. `abra app deploy YOURAPPDOMAIN`
6. Create an initial user: `abra app YOURAPPDOMAIN run app register_new_matrix_user -c /data/homeserver.yaml http://localhost:8008` 6. Create an initial user: `abra app run YOURAPPDOMAIN app register_new_matrix_user -c /data/homeserver.yaml http://localhost:8008`
## Tips & Tricks ## Tips & Tricks
### Disabling federation ### Disabling federation
> We're not sure this does it exactly and there is still a discussion running - Use `DISABLE_FEDERATION=1` to turn off federation listeners
> upstream about whether this is the right way to do it & whether it could be - Don't use [`compose.matrix.yml`](https://git.coopcloud.tech/coop-cloud/traefik/src/branch/master/compose.matrix.yml) in your traefik config to keep the federation ports closed
> more convenient. We welcome issues / change sets to close up more federation
> functionality.
- use `DISABLE_FEDERATION=1` to turn off federation listeners
- don't use [`compose.matrix.yml`](https://git.coopcloud.tech/coop-cloud/traefik/src/branch/master/compose.matrix.yml) in your traefik config to keep the federation ports closed
### Enabling federation ### Enabling federation
See [`#27`](https://git.coopcloud.tech/coop-cloud/matrix-synapse/pulls/27) for more. See [`#27`](https://git.coopcloud.tech/coop-cloud/matrix-synapse/pulls/27) for more. Depending on your setup, using `SERVE_SERVER_WELLKNOWN=true` might work to start federating. Make sure you don't leave `DISABLE_FEDERATION=1` set!
Depending on your setup, using `SERVE_SERVER_WELLKNOWN=true` might work to start federating.
Make sure you don't leave `DISABLE_FEDERATION=1` set!
### Seeing what changed in `homeserver.yaml` between versions
Change the version range to suit your needs.
```
git clone https://github.com/matrix-org/synapse
cd synapse/docs
git log --follow -p v1.48.0..v1.51.0 sample_config.yaml
```
### Generating a new `homeserver.yaml`
The default is also available to see [here](https://matrix-org.github.io/synapse/latest/usage/configuration/homeserver_sample_config.html).
```
docker run -it \
--entrypoint="" \
-e SYNAPSE_SERVER_NAME=foo.com \
-e SYNAPSE_REPORT_STATS=no \
matrixdotorg/synapse:v1.48.0 \
sh -c '/start.py generate; cat /data/homeserver.yaml' > homeserver.yaml.tmpl`
```
### Generating a new `<server>.log.config`
```
docker run -it \
--entrypoint="" \
-e SYNAPSE_SERVER_NAME=foo.com \
-e SYNAPSE_REPORT_STATS=no \
matrixdotorg/synapse:v1.48.0 \
sh -c '/start.py generate; cat /data/foo.com.log.config' > log.config
```
### Getting client discovery on a custom domain ### Getting client discovery on a custom domain
You'll need to deploy something like [this](https://git.autonomic.zone/ruangrupa/well-known-uris). You'll need to deploy something like [this](https://git.autonomic.zone/ruangrupa/well-known-uris). This could be implemented in this recipe but we haven't merged it in yet. Change sets are welcome.
This could be implemented in this recipe but we haven't merged it in yet. Change sets are welcome.
### Telegram bridging ### Telegram bridging
> WIP > WIP docs
Setting it up is a bit of a chicken/egg & chasing cats moment. Setting it up is a bit of a chicken/egg & chasing cats moment.
@@ -123,7 +78,7 @@ Some helpful documentation:
### Discord bridging ### Discord bridging
> WIP > WIP docs
Just as messy as the Telegram bridging above! Rough guide: Just as messy as the Telegram bridging above! Rough guide:
@@ -142,9 +97,9 @@ Some helpful documentation:
### Signal bridging ### Signal bridging
> WIP > WIP docs
OK, it's also awful to set this up. Do you see a pattern emerging? :) OK, it's also awful to set this up. Do you see a pattern emerging :)
- fake that you have the required tokens: - fake that you have the required tokens:
- `abra app secret insert example.com signal_hs_token v1 foo` - `abra app secret insert example.com signal_hs_token v1 foo`
+4 -4
View File
@@ -1,7 +1,7 @@
export DISCORD_BRIDGE_YAML_VERSION=v2
export ENTRYPOINT_CONF_VERSION=v1 export ENTRYPOINT_CONF_VERSION=v1
export HOMESERVER_YAML_VERSION=v13 export HOMESERVER_YAML_VERSION=v22
export LOG_CONFIG_VERSION=v2 export LOG_CONFIG_VERSION=v2
export TELEGRAM_BRIDGE_YAML_VERSION=v3
export DISCORD_BRIDGE_YAML_VERSION=v1
export SIGNAL_BRIDGE_YAML_VERSION=v2
export SHARED_SECRET_AUTH_VERSION=v1 export SHARED_SECRET_AUTH_VERSION=v1
export SIGNAL_BRIDGE_YAML_VERSION=v4
export TELEGRAM_BRIDGE_YAML_VERSION=v5
+1 -1
View File
@@ -43,7 +43,7 @@ services:
networks: networks:
- internal - internal
healthcheck: healthcheck:
test: ["CMD", "pg_isready", "-U", "synapse"] test: ["CMD", "pg_isready", "-U", "$POSTGRES_USER" ]
volumes: volumes:
- discord-postgres:/var/lib/postgresql/data - discord-postgres:/var/lib/postgresql/data
-2
View File
@@ -6,10 +6,8 @@ services:
secrets: secrets:
- keycloak2_client_secret - keycloak2_client_secret
environment: environment:
- KEYCLOAK2_ALLOW_EXISTING_USERS
- KEYCLOAK2_CLIENT_ID - KEYCLOAK2_CLIENT_ID
- KEYCLOAK2_ENABLED - KEYCLOAK2_ENABLED
- KEYCLOAK2_ID
- KEYCLOAK2_NAME - KEYCLOAK2_NAME
- KEYCLOAK2_URL - KEYCLOAK2_URL
+19
View File
@@ -0,0 +1,19 @@
---
version: "3.8"
services:
app:
secrets:
- keycloak3_client_secret
environment:
- KEYCLOAK3_ALLOW_EXISTING_USERS
- KEYCLOAK3_CLIENT_ID
- KEYCLOAK3_ENABLED
- KEYCLOAK3_ID
- KEYCLOAK3_NAME
- KEYCLOAK3_URL
secrets:
keycloak3_client_secret:
external: true
name: ${STACK_NAME}_keycloak3_client_secret_${SECRET_KEYCLOAK3_CLIENT_SECRET_VERSION}
+1 -1
View File
@@ -9,7 +9,7 @@ services:
- shared_secret_auth - shared_secret_auth
configs: configs:
- source: shared_secret_auth - source: shared_secret_auth
target: /usr/local/lib/python3.9/site-packages/shared_secret_authenticator.py target: /usr/local/lib/python3.11/site-packages/shared_secret_authenticator.py
configs: configs:
shared_secret_auth: shared_secret_auth:
+4 -5
View File
@@ -10,14 +10,14 @@ services:
- signal-data:/signal-data - signal-data:/signal-data
signald: signald:
image: docker.io/signald/signald:0.22.1-non-root image: docker.io/signald/signald:0.23.2-non-root
networks: networks:
- internal - internal
volumes: volumes:
- signald-data:/signald - signald-data:/signald
signalbridge: signalbridge:
image: dock.mau.dev/mautrix/signal:v0.4.0 image: dock.mau.dev/mautrix/signal:v0.4.2
depends_on: depends_on:
- signaldb - signaldb
configs: configs:
@@ -26,8 +26,7 @@ services:
environment: environment:
- HOMESERVER_DOMAIN - HOMESERVER_DOMAIN
- HOMESERVER_URL - HOMESERVER_URL
- SIGNAL_BRIDGE_ADMIN_1 - SIGNAL_BRIDGE_PERMISSIONS
- SIGNAL_BRIDGE_ADMIN_2
- SIGNAL_ENABLE_ENCRYPTION - SIGNAL_ENABLE_ENCRYPTION
- VERIFY_SSL - VERIFY_SSL
secrets: secrets:
@@ -55,7 +54,7 @@ services:
networks: networks:
- internal - internal
healthcheck: healthcheck:
test: ["CMD", "pg_isready", "-U", "synapse"] test: ["CMD", "pg_isready", "-U", "$POSTGRES_USER" ]
volumes: volumes:
- signal-postgres:/var/lib/postgresql/data - signal-postgres:/var/lib/postgresql/data
+3 -4
View File
@@ -10,7 +10,7 @@ services:
- telegram-data:/telegram-data - telegram-data:/telegram-data
telegrambridge: telegrambridge:
image: dock.mau.dev/mautrix/telegram:v0.12.0 image: dock.mau.dev/mautrix/telegram:v0.13.0
depends_on: depends_on:
- telegramdb - telegramdb
configs: configs:
@@ -24,8 +24,7 @@ services:
- HOMESERVER_DOMAIN - HOMESERVER_DOMAIN
- HOMESERVER_URL - HOMESERVER_URL
- TELEGRAM_APP_ID - TELEGRAM_APP_ID
- TELEGRAM_BRIDGE_ADMIN_1 - TELEGRAM_BRIDGE_PERMISSIONS
- TELEGRAM_BRIDGE_ADMIN_2
- VERIFY_SSL - VERIFY_SSL
secrets: secrets:
- telegram_api_hash - telegram_api_hash
@@ -53,7 +52,7 @@ services:
networks: networks:
- internal - internal
healthcheck: healthcheck:
test: ["CMD", "pg_isready", "-U", "synapse"] test: ["CMD", "pg_isready", "-U", "$POSTGRES_USER" ]
volumes: volumes:
- telegram-postgres:/var/lib/postgresql/data - telegram-postgres:/var/lib/postgresql/data
+6 -4
View File
@@ -3,7 +3,7 @@ version: "3.8"
services: services:
app: app:
image: "matrixdotorg/synapse:v1.71.0" image: "matrixdotorg/synapse:v1.81.0"
volumes: volumes:
- "data:/data" - "data:/data"
depends_on: depends_on:
@@ -25,6 +25,8 @@ services:
- ENCRYPTED_BY_DEFAULT - ENCRYPTED_BY_DEFAULT
- FEDERATION_ALLOWLIST - FEDERATION_ALLOWLIST
- LETSENCRYPT_HOST=${DOMAIN} - LETSENCRYPT_HOST=${DOMAIN}
- MEDIA_RETENTION_LOCAL_LIFETIME
- MEDIA_RETENTION_REMOTE_LIFETIME
- PASSWORD_LOGIN_ENABLED - PASSWORD_LOGIN_ENABLED
- REDACTION_RETENTION_PERIOD - REDACTION_RETENTION_PERIOD
- RETENTION_MAX_LIFETIME - RETENTION_MAX_LIFETIME
@@ -59,7 +61,7 @@ services:
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`)" - "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure" - "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}" - "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "coop-cloud.${STACK_NAME}.version=2.3.0+v1.71.0" - "coop-cloud.${STACK_NAME}.version=3.6.0+v1.81.0"
db: db:
image: postgres:13-alpine image: postgres:13-alpine
@@ -75,7 +77,7 @@ services:
networks: networks:
- internal - internal
healthcheck: healthcheck:
test: ["CMD", "pg_isready", "-U", "synapse"] test: ["CMD", "pg_isready", "-U", "$POSTGRES_USER" ]
volumes: volumes:
- postgres:/var/lib/postgresql/data - postgres:/var/lib/postgresql/data
deploy: deploy:
@@ -100,7 +102,7 @@ configs:
file: entrypoint.sh.tmpl file: entrypoint.sh.tmpl
template_driver: golang template_driver: golang
homeserver_yaml: homeserver_yaml:
name: ${STACK_NAME}_homserver_yaml_${HOMESERVER_YAML_VERSION} name: ${STACK_NAME}_homeserver_yaml_${HOMESERVER_YAML_VERSION}
file: homeserver.yaml.tmpl file: homeserver.yaml.tmpl
template_driver: golang template_driver: golang
log_config: log_config:
+1 -1
View File
@@ -50,7 +50,7 @@ auth:
logging: logging:
# What level should the logger output to the console at. # What level should the logger output to the console at.
console: "warn" #silly, verbose, info, http, warn, error, silent console: "error" #silly, verbose, info, http, warn, error, silent
lineDateFormat: "MMM-D HH:mm:ss.SSS" # This is in moment.js format lineDateFormat: "MMM-D HH:mm:ss.SSS" # This is in moment.js format
files: files:
- file: "debug.log" - file: "debug.log"
+31 -1902
View File
File diff suppressed because it is too large Load Diff
+17
View File
@@ -0,0 +1,17 @@
WARNING: There are a lot of config breaking changes in this one, watch out!
* KEYCLOAK2* env vars have gone away, they were experimental.
* TELEGRAM_BRIDGE_ADMIN* is replaced by TELEGRAM_BRIDGE_PERMISSIONS.
* SIGNAL_BRIDGE_ADMIN* is replaced by SIGNAL_BRIDGE_PERMISSIONS.
* The homeserver config has been trimmed, see coop-cloud/matrix-synapse#33 for more.
* Bridge logging is only ERROR level now to minimise leaking plaintext.
* It is possible to use SSO & federation env vars in combination now.
* Media retention is now configurable with #MEDIA_RETENTION_* env vars.
@decentral1se
+5 -7
View File
@@ -267,10 +267,8 @@ bridge:
# * - All Matrix users # * - All Matrix users
# domain - All users on that homeserver # domain - All users on that homeserver
# mxid - Specific user # mxid - Specific user
permissions: permissions: {{ env "SIGNAL_BRIDGE_PERMISSIONS" }}
"*": "relay"
"{{ env "SIGNAL_BRIDGE_ADMIN_1" }}": "admin"
"{{ env "SIGNAL_BRIDGE_ADMIN_2" }}": "admin"
relay: relay:
# Whether relay mode should be allowed. If allowed, `!signal set-relay` can be used to turn any # Whether relay mode should be allowed. If allowed, `!signal set-relay` can be used to turn any
# authenticated user into a relaybot for that chat. # authenticated user into a relaybot for that chat.
@@ -318,9 +316,9 @@ logging:
formatter: colored formatter: colored
loggers: loggers:
mau: mau:
level: DEBUG level: ERROR
aiohttp: aiohttp:
level: INFO level: ERROR
root: root:
level: DEBUG level: ERROR
handlers: [console] handlers: [console]
+5 -8
View File
@@ -412,10 +412,7 @@ bridge:
# * - All Matrix users # * - All Matrix users
# domain - All users on that homeserver # domain - All users on that homeserver
# mxid - Specific user # mxid - Specific user
permissions: permissions: {{ env "TELEGRAM_BRIDGE_PERMISSIONS" }}
"*": "relaybot"
"{{ env "TELEGRAM_BRIDGE_ADMIN_1" }}": "admin"
"{{ env "TELEGRAM_BRIDGE_ADMIN_2" }}": "admin"
# Options related to the message relay Telegram bot. # Options related to the message relay Telegram bot.
relaybot: relaybot:
@@ -537,11 +534,11 @@ logging:
formatter: colored formatter: colored
loggers: loggers:
mau: mau:
level: DEBUG level: ERROR
telethon: telethon:
level: INFO level: ERROR
aiohttp: aiohttp:
level: INFO level: ERROR
root: root:
level: DEBUG level: ERROR
handlers: [file, console] handlers: [file, console]