mirror of
				https://github.com/spantaleev/matrix-docker-ansible-deploy.git
				synced 2025-10-26 01:53:24 +00:00 
			
		
		
		
	Merge remote-tracking branch 'origin/master' into synapse-workers
Also, replace vague FIXME by a proper NOTE on the complete story of the user_dir endpoints..
This commit is contained in:
		| @@ -34,7 +34,7 @@ DNS records marked with `(*)` above are optional. They refer to services that wi | ||||
|  | ||||
| As the table above illustrates, you need to create 2 subdomains (`matrix.<your-domain>` and `element.<your-domain>`) and point both of them to your new server's IP address (DNS `A` record or `CNAME` record is fine). | ||||
|  | ||||
| The `element.<your-domain>` subdomain is necessary, because this playbook installs the [Element](https://github.com/vector-im/riot-web) web client for you. | ||||
| The `element.<your-domain>` subdomain is necessary, because this playbook installs the [Element](https://github.com/vector-im/element-web) web client for you. | ||||
| If you'd rather instruct the playbook not to install Element (`matrix_client_element_enabled: false` when [Configuring the playbook](configuring-playbook.md) later), feel free to skip the `element.<your-domain>` DNS record. | ||||
|  | ||||
| The `dimension.<your-domain>` subdomain may be necessary, because this playbook could install the [Dimension integrations manager](http://dimension.t2bot.io/) for you. Dimension installation is disabled by default, because it's only possible to install it after the other Matrix services are working (see [Setting up Dimension](configuring-playbook-dimension.md) later). If you do not wish to set up Dimension, feel free to skip the `dimension.<your-domain>` DNS record. | ||||
|   | ||||
| @@ -1,6 +1,6 @@ | ||||
| # Configuring Element (optional) | ||||
|  | ||||
| By default, this playbook installs the [Element](https://github.com/vector-im/riot-web) Matrix client web application. | ||||
| By default, this playbook installs the [Element](https://github.com/vector-im/element-web) Matrix client web application. | ||||
| If that's okay, you can skip this document. | ||||
|  | ||||
|  | ||||
|   | ||||
							
								
								
									
										27
									
								
								docs/configuring-playbook-dynamic-dns.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										27
									
								
								docs/configuring-playbook-dynamic-dns.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,27 @@ | ||||
| # Dynamic DNS | ||||
|  | ||||
| ## Setup | ||||
|  | ||||
| Most cloud providers / ISPs will charge you extra for a static IP address. If you're | ||||
| not hosting a highly reliable homeserver you can workaround this via dynamic DNS. To | ||||
| set this up, you'll need to get the username/password from your DNS provider. For | ||||
| google domains, this process is described [here](https://support.google.com/domains/answer/6147083). | ||||
| After you've gotten the proper credentials you can add the following config to your `inventory/host_vars/matrix.DOMAIN/vars.yml`: | ||||
|  | ||||
| ```yaml | ||||
| matrix_dynamic_dns_enabled: true | ||||
|  | ||||
| matrix_dynamic_dns_domain_configurations: | ||||
|   - provider: domains.google.com | ||||
|     protocol: dyndn2 | ||||
|     username: XXXXXXXXXXXXXXXX | ||||
|     password: XXXXXXXXXXXXXXXX | ||||
|     domain: "{{ matrix_domain }}" | ||||
| ``` | ||||
|  | ||||
|  | ||||
| ## Additional Reading | ||||
|  | ||||
| Additional resources: | ||||
|  | ||||
| - https://matrix.org/docs/guides/free-small-matrix-server | ||||
| @@ -23,3 +23,12 @@ matrix_nginx_proxy_proxy_matrix_nginx_status_allowed_addresses: | ||||
| - 8.8.8.8 | ||||
| - 1.1.1.1 | ||||
| ``` | ||||
|  | ||||
|  | ||||
| ## Synapse + OpenID Connect for Single-Sign-On | ||||
|  | ||||
| If you want to use OpenID Connect as an SSO provider (as per the [Synapse OpenID docs](https://github.com/matrix-org/synapse/blob/develop/docs/openid.md)), you need to use the following configuration (in your `vars.yml` file) to instruct nginx to forward `/_synapse/oidc` to Synapse: | ||||
|  | ||||
| ```yaml | ||||
| matrix_nginx_proxy_proxy_matrix_client_api_forwarded_location_synapse_oidc_api_enabled: true | ||||
| ``` | ||||
|   | ||||
| @@ -193,3 +193,38 @@ Note that this configuration on its own does **not** redirect traffic on port 80 | ||||
|       scheme = "https" | ||||
|       permanent = true | ||||
| ``` | ||||
|  | ||||
| You can use the following `docker-compose.yml` as example to launch Traefik. | ||||
|  | ||||
| ```yaml | ||||
| version: "3.3" | ||||
|  | ||||
| services: | ||||
|  | ||||
|   traefik: | ||||
|     image: "traefik:v2.3" | ||||
|     restart: always | ||||
|     container_name: "traefik" | ||||
|     networks:  | ||||
|       - traefik | ||||
|     command: | ||||
|       - "--api.insecure=true" | ||||
|       - "--providers.docker=true" | ||||
|       - "--providers.docker.network=traefik" | ||||
|       - "--providers.docker.exposedbydefault=false" | ||||
|       - "--entrypoints.web-secure.address=:443" | ||||
|       - "--entrypoints.synapse.address=:8448" | ||||
|       - "--certificatesresolvers.default.acme.tlschallenge=true" | ||||
|       - "--certificatesresolvers.default.acme.email=YOUR EMAIL" | ||||
|       - "--certificatesresolvers.default.acme.storage=/letsencrypt/acme.json" | ||||
|     ports: | ||||
|       - "443:443" | ||||
|       - "8080:8080" | ||||
|     volumes: | ||||
|       - "./letsencrypt:/letsencrypt" | ||||
|       - "/var/run/docker.sock:/var/run/docker.sock:ro" | ||||
|  | ||||
| networks: | ||||
|   traefik: | ||||
|     external: true | ||||
| ``` | ||||
|   | ||||
| @@ -15,6 +15,8 @@ Add the following configuration to your `inventory/host_vars/matrix.DOMAIN/vars. | ||||
| matrix_synapse_admin_enabled: true | ||||
| ``` | ||||
|  | ||||
| **Note**: Synapse Admin requires Synapse's [Admin APIs](https://github.com/matrix-org/synapse/tree/master/docs/admin_api) to function. Access to them is restricted with a valid access token, so exposing them publicly should not be a real security concern. Still, for additional security, we normally leave them unexposed, following [official Synapse reverse-proxying recommendations](https://github.com/matrix-org/synapse/blob/master/docs/reverse_proxy.md#synapse-administration-endpoints). Because Synapse Admin needs these APIs to function, when installing Synapse Admin, we **automatically** exposes them publicly for you (equivalent to `matrix_nginx_proxy_proxy_matrix_client_api_forwarded_location_synapse_admin_api_enabled: true`). | ||||
|  | ||||
|  | ||||
| ## Installing | ||||
|  | ||||
|   | ||||
| @@ -38,3 +38,8 @@ In case any problems occur, make sure to have a look at the [list of synapse iss | ||||
| ## Synapse Admin | ||||
|  | ||||
| Certain Synapse administration tasks (managing users and rooms, etc.) can be performed via a web user-interace, if you install [Synapse Admin](configuring-playbook-synapse-admin.md). | ||||
|  | ||||
|  | ||||
| ## Synapse + OpenID Connect for Single-Sign-On | ||||
|  | ||||
| If you'd like to use OpenID Connect authentication with Synapse, you'll need some additional reverse-proxy configuration (see [our nginx reverse-proxy doc page](configuring-playbook-nginx.md#synapse-openid-connect-for-single-sign-on)). | ||||
|   | ||||
| @@ -33,6 +33,7 @@ When you're done with all the configuration you'd like to do, continue with [Ins | ||||
|  | ||||
| - [Setting up the Jitsi video-conferencing platform](configuring-playbook-jitsi.md) (optional) | ||||
|  | ||||
| - [Setting Dynamic DNS](configuring-playbook-dynamic-dns.md) (optional) | ||||
|  | ||||
| ### Core service adjustments | ||||
|  | ||||
|   | ||||
| @@ -89,7 +89,7 @@ matrix_nginx_proxy_proxy_matrix_federation_api_ssl_certificate_key: /matrix/ssl/ | ||||
| If your files are not in `/matrix/ssl` but in some other location, you would need to mount them into the container: | ||||
|  | ||||
| ```yaml | ||||
| matrix_synapse_container_extra_arguments: | ||||
| matrix_nginx_proxy_container_extra_arguments: | ||||
|   - "--mount type=bind,src=/some/path/on/the/host,dst=/some/path/inside/the/container,ro" | ||||
| ``` | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user