Verified the role against the real matrix-stack Helm chart (pulled 26.6.1) and fixed divergences found during review. Bugs: - Add MAS OIDC discovery router: /.well-known/openid-configuration must hit the MAS root listener (8082), not web (8080) — was 404, breaking OIDC login - Add Synapse ip_range_blacklist (full SSRF blocklist for all outbound federation/identity requests; previously only url-preview blacklist present) - Make federation_client_minimum_tls_version unconditional (chart sets it in shared-underrides; role only set it when federation was enabled) - Restart only rendered fed-reader replicas in the handler instead of the whole compose project (missing services: filter) Chart alignment (26.5.1 -> 26.6.1): - Bump chart version and all image tags (mas -> matrix-authentication-service -pro:1.18.0, postgres 17, synapse v1.154.0-pro.1, element-web v1.12.21, etc.) - redis maxmemory 256mb -> chart default 40mb (configurable) - Add element-web map_style_url (configurable) Hardening / hygiene: - Validate ess_rtc_external_ip is a real IP (regex, no extra collection dep) - Read admin password from the in-container secret file instead of passing it on the host process list during mas-cli register-user - apt cache_valid_time, postgres first-boot-only comment, haproxy failover note - Add meta/argument_specs.yml documenting all public variables - README: chart version, service count, OIDC discovery verification step Signed-off-by: Simon Bärlocher <simon@whatwedo.ch>
84 lines
2.7 KiB
YAML
84 lines
2.7 KiB
YAML
# SPDX-License-Identifier: MIT-0
|
|
---
|
|
# Render every component's configuration. Each template uses _ess_secrets
|
|
# facts (loaded in secrets.yml) for password substitution.
|
|
|
|
- name: Render HAProxy config
|
|
ansible.builtin.template:
|
|
src: "{{ item.src }}"
|
|
dest: "{{ ess_compose_conf_dir }}/haproxy/{{ item.dest }}"
|
|
mode: "0640"
|
|
loop:
|
|
- { src: haproxy/haproxy.cfg.j2, dest: haproxy.cfg }
|
|
- { src: haproxy/429.http.j2, dest: 429.http }
|
|
- { src: haproxy/path_map_file.j2, dest: path_map_file }
|
|
- { src: haproxy/path_map_file_get.j2, dest: path_map_file_get }
|
|
- { src: haproxy/admin-allow-ips.lst.j2, dest: admin-allow-ips.lst }
|
|
notify: Restart haproxy
|
|
|
|
- name: Render well-known files
|
|
ansible.builtin.template:
|
|
src: "haproxy/well-known/{{ item }}.j2"
|
|
dest: "{{ ess_compose_conf_dir }}/haproxy/well-known/{{ item }}"
|
|
mode: "0644"
|
|
loop:
|
|
- server
|
|
- client
|
|
- support
|
|
- element.json
|
|
notify: Restart haproxy
|
|
|
|
- name: Render Synapse configs
|
|
ansible.builtin.template:
|
|
src: "{{ item.src }}"
|
|
dest: "{{ ess_compose_conf_dir }}/synapse/{{ item.dest }}"
|
|
mode: "0640"
|
|
loop:
|
|
- { src: synapse/homeserver.yaml.j2, dest: homeserver.yaml }
|
|
- { src: synapse/log_config.yaml.j2, dest: log_config.yaml }
|
|
- { src: synapse/federation-reader.yaml.j2, dest: federation-reader.yaml }
|
|
no_log: true
|
|
notify:
|
|
- Restart synapse-main
|
|
- Restart synapse-fed-reader
|
|
|
|
- name: Render MAS config
|
|
ansible.builtin.template:
|
|
src: mas/config.yaml.j2
|
|
dest: "{{ ess_compose_conf_dir }}/mas/config.yaml"
|
|
mode: "0640"
|
|
no_log: true
|
|
notify: Restart mas
|
|
|
|
- name: Render SFU config
|
|
ansible.builtin.template:
|
|
src: sfu/config.yaml.j2
|
|
dest: "{{ ess_compose_conf_dir }}/sfu/config.yaml"
|
|
mode: "0640"
|
|
no_log: true
|
|
notify: Restart matrix-rtc-sfu
|
|
|
|
- name: Render Element Web config
|
|
ansible.builtin.template:
|
|
src: element-web/config.json.j2
|
|
dest: "{{ ess_compose_conf_dir }}/element-web/config.json"
|
|
mode: "0644"
|
|
notify: Restart element-web
|
|
|
|
# NOTE: This script runs only on FIRST init of an empty PGDATA volume (via
|
|
# /docker-entrypoint-initdb.d/). Re-rendering it on later runs has no effect
|
|
# on an already-initialised database — the chart's postgres-ess-updater
|
|
# sidecar that re-applies it is intentionally omitted (see README). To change
|
|
# DBs/roles after init, run the SQL manually or recreate the volume.
|
|
- name: Render Postgres init script (first-boot only)
|
|
ansible.builtin.template:
|
|
src: postgres/configure-dbs.sh.j2
|
|
dest: "{{ ess_compose_conf_dir }}/postgres/configure-dbs.sh"
|
|
mode: "0755"
|
|
|
|
- name: Render Redis config
|
|
ansible.builtin.template:
|
|
src: redis/redis.conf.j2
|
|
dest: "{{ ess_compose_conf_dir }}/redis/redis.conf"
|
|
mode: "0644"
|
|
notify: Restart redis
|