Point LiveKit JWT Service at our homeserver directly, instead of having it discover it

lk-jwt-service v0.6.0 stopped honoring the delay_cs_api_url request parameter
and now locates a user's Client-Server API by fetching the
/.well-known/matrix/client file of that user's base domain itself.

For our own homeserver, this makes the service leave the server over the
public network only to come back to it, which is wasteful at best and does
not work at all where the base domain is not reachable from the host.
Since we know where our homeserver is, we tell the service directly via the
new LIVEKIT_CS_API_URL_OVERRIDES environment variable. Federated homeservers
keep being resolved through discovery.

The service now also joins the container network that the homeserver's
Client-Server API is reachable on, like our other add-on services do.
It used to only be connected to it by coincidence, via the reverse-proxy
network, which left it unable to reach the homeserver when the playbook is
not managing Traefik.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Slavi Pantaleev
2026-08-19 14:01:53 +03:00
co-authored by Claude Opus 5
parent 1127365126
commit ddd99ba244
3 changed files with 26 additions and 0 deletions
@@ -13,4 +13,6 @@ LIVEKIT_SECRET={{ matrix_livekit_jwt_service_environment_variable_livekit_secret
LIVEKIT_FULL_ACCESS_HOMESERVERS={{ matrix_livekit_jwt_service_environment_variable_livekit_full_access_homeservers }}
LIVEKIT_CS_API_URL_OVERRIDES={{ matrix_livekit_jwt_service_environment_variable_livekit_cs_api_url_overrides }}
{{ matrix_livekit_jwt_service_environment_variables_extension }}