diff --git a/init/scripts/config_gen.sh b/init/scripts/config_gen.sh index 6231f25..f48f750 100755 --- a/init/scripts/config_gen.sh +++ b/init/scripts/config_gen.sh @@ -82,13 +82,13 @@ docker run -it --rm --network matrix_network \ ghcr.io/element-hq/matrix-authentication-service:latest config generate \ | grep -v '^[0-9]\{4\}-[0-9]\{2\}-[0-9]\{2\}' > "${VOLUME_PATH}/mas/config.yaml" || { log_error "Mas config generation failed"; exit 1; } -MAS_CFG="${VOLUME_PATH}/mas/config.json" +MAS_CFG="${VOLUME_PATH}/mas/config.yaml" if ! yq '.clients' "$MAS_CFG" > /dev/null 2>&1; then - yq -i '.clients = []' "$MAS_CFG" + yq -y -i '.clients = []' "$MAS_CFG" fi -yq -i ".public_base_url = \"https://${MAS_FQDN}\"" "$MAS_CFG" -yq -i ".http.listen = \"0.0.0.0:8000\"" "$MAS_CFG" -yq -i ".database.uri = \"postgres://${PG_USER_MAS}:${PG_PASSWORD_MAS}@matrix-db:5432/auth?sslmode=prefer\"" "$MAS_CFG" +yq -y -i ".public_base_url = \"https://${MAS_FQDN}\"" "$MAS_CFG" +yq -y -i ".http.listen = \"0.0.0.0:8000\"" "$MAS_CFG" +yq -y -i ".database.uri = \"postgres://${PG_USER_MAS}:${PG_PASSWORD_MAS}@matrix-db:5432/auth?sslmode=prefer\"" "$MAS_CFG" fix_ownership "${VOLUME_PATH}/mas" @@ -100,55 +100,28 @@ log_info "Linking Synapse and MAS via OIDC..." CLIENT_ID="synapse-client" CLIENT_SECRET=$(openssl rand -hex 32) - -#TEMP_FILTER=$(mktemp) -#trap "rm -f $TEMP_FILTER" EXIT - -#cat > "$TEMP_FILTER" </dev/null || echo "") if [[ -z "$EXISTING_CLIENT" ]]; then - yq -y -i ".clients += [{ - \"client_id\": \"${CLIENT_ID}\", - \"client_secret\": \"${CLIENT_SECRET}\", - \"redirect_uris\": [\"https://${HOMESERVER_FQDN}/_synapse/client/oidc/callback\"], - \"grant_types\": [\"authorization_code\", \"refresh_token\"], - \"response_types\": [\"code\"], - \"scopes\": [\"openid\", \"profile\", \"email\"], - \"application_type\": \"web\" - }]" "$MAS_CFG" || { log_error "Failed to register Synapse client in MAS"; exit 1; } + CLIENT_OBJ="{ + \"client_id\": \"${CLIENT_ID}\", + \"client_secret\": \"${CLIENT_SECRET}\", + \"redirect_uris\": [\"https://${HOMESERVER_FQDN}/_synapse/client/oidc/callback\"], + \"grant_types\": [\"authorization_code\", \"refresh_token\"], + \"response_types\": [\"code\"], + \"scopes\": [\"openid\", \"profile\", \"email\"], + \"application_type\": \"web\" + }" + yq -y -i ".clients += [$CLIENT_OBJ]" "$SYNAPSE_CFG" || { log_error "Failed to register Synapse client in MAS"; exit 1; } log_info " -> Registered Synapse as OIDC client in MAS" else log_info " -> Synapse client already registered in MAS, skipping" fi ISSUER_URL="https://${MAS_FQDN}" - fix_ownership "$SYNAPSE_CFG" -#cat > "$TEMP_FILTER" </dev/null | grep -q "idp_id"; then -# # yq -y -i "$(cat "$TEMP_FILTER")" "$SYNAPSE_CFG" || { log_error "Failed to inject OIDC config"; exit 1; } yq -y -i ".oidc_providers += [{ \"idp_id\": \"mas\", \"idp_name\": \"Matrix Authentication Service\", diff --git a/init/templates/main.yaml b/init/templates/main.yaml index 114c27a..d101ed4 100644 --- a/init/templates/main.yaml +++ b/init/templates/main.yaml @@ -77,7 +77,7 @@ services: - "traefik.http.routers.auth.rule=Host(`${MAS_FQDN}`)" - "traefik.http.routers.auth.entrypoints=websecure" - "traefik.http.routers.auth.tls.certresolver=myresolver" - - "traefik.http.services.auth.loadbalancer.server.port=8000" + - "traefik.http.services.auth.loadbalancer.server.port=8080" # [TRAEFIK_LABELS_END] # --- OPTIONAL: LIVEKIT RTC STACK ---