5 Commits

Author SHA1 Message Date
cortex 4e1fb4b194 mas fix 2026-05-24 11:36:12 +01:00
cortex f872b9e8f5 . 2026-05-24 11:26:17 +01:00
cortex ae5154ee51 Upstream config fix 2026-05-24 11:10:16 +01:00
cortex 56e97b9ead first working version! 2026-05-21 09:54:07 +00:00
cortex 75089cd2e9 various bugfixes during testing 2026-05-21 09:17:29 +00:00
5 changed files with 45 additions and 46 deletions
+1 -7
View File
@@ -54,12 +54,6 @@ toggle_block "$OUTPUT_FILE" "# \[CINNY_START\]" "# \[CINNY_END\]" "$INCLUDE_CINN
toggle_block "$OUTPUT_FILE" "# \[FLUFFYCHAT_START\]" "# \[FLUFFYCHAT_END\]" "$INCLUDE_FLUFFY" toggle_block "$OUTPUT_FILE" "# \[FLUFFYCHAT_START\]" "# \[FLUFFYCHAT_END\]" "$INCLUDE_FLUFFY"
toggle_block "$OUTPUT_FILE" "# \[NGINX_START\]" "# \[NGINX_END\]" "$INCLUDE_NGINX" toggle_block "$OUTPUT_FILE" "# \[NGINX_START\]" "# \[NGINX_END\]" "$INCLUDE_NGINX"
toggle_block "$OUTPUT_FILE" "# \[TRAEFIK_START\]" "# \[TRAEFIK_END\]" "$INCLUDE_TRAEFIK" toggle_block "$OUTPUT_FILE" "# \[TRAEFIK_START\]" "# \[TRAEFIK_END\]" "$INCLUDE_TRAEFIK"
toggle_block "$OUTPUT_FILE" "# \[TRAEFIK_LABELS_START\]" "# \[TRAEFIK_LABELS_END\]" "$INCLUDE_TRAEFIK"
# Handle Traefik Labels
if [[ "$INCLUDE_TRAEFIK" == "true" ]]; then
sed -i "/# \[TRAEFIK_LABELS_START\]/d; /# \[TRAEFIK_LABELS_END\]/d" "$OUTPUT_FILE"
else
sed -i "/# \[TRAEFIK_LABELS_START\]/,/# \[TRAEFIK_LABELS_END\]/d" "$OUTPUT_FILE"
fi
log_info "Compose file generated: $OUTPUT_FILE" log_info "Compose file generated: $OUTPUT_FILE"
+37 -33
View File
@@ -64,8 +64,8 @@ docker run -it --rm --network matrix_network \
-e SYNAPSE_SERVER_NAME="$HOMESERVER_FQDN" \ -e SYNAPSE_SERVER_NAME="$HOMESERVER_FQDN" \
-e SYNAPSE_REPORT_STATS=no \ -e SYNAPSE_REPORT_STATS=no \
ghcr.io/element-hq/synapse:latest generate || { log_error "Synapse config generation failed"; exit 1; } ghcr.io/element-hq/synapse:latest generate || { log_error "Synapse config generation failed"; exit 1; }
SYNAPSE_CFG="${VOLUME_PATH}/synapse/homeserver.yaml" SYNAPSE_CFG="${VOLUME_PATH}/synapse/homeserver.yaml"
fix_ownership "${VOLUME_PATH}/synapse"
yq -y -i '.database.name = "psycopg2"' "$SYNAPSE_CFG" yq -y -i '.database.name = "psycopg2"' "$SYNAPSE_CFG"
yq -y -i ".database.args.user = \"${PG_USER_MATRIX}\"" "$SYNAPSE_CFG" yq -y -i ".database.args.user = \"${PG_USER_MATRIX}\"" "$SYNAPSE_CFG"
yq -y -i ".database.args.password = \"${PG_PASSWORD_MATRIX}\"" "$SYNAPSE_CFG" yq -y -i ".database.args.password = \"${PG_PASSWORD_MATRIX}\"" "$SYNAPSE_CFG"
@@ -76,8 +76,6 @@ yq -y -i ".database.args.sslmode = \"prefer\"" "$SYNAPSE_CFG"
yq -y -i ".public_baseurl = \"https://${HOMESERVER_FQDN}\"" "$SYNAPSE_CFG" yq -y -i ".public_baseurl = \"https://${HOMESERVER_FQDN}\"" "$SYNAPSE_CFG"
yq -y -i ".server_name = \"${HOMESERVER_FQDN}\"" "$SYNAPSE_CFG" yq -y -i ".server_name = \"${HOMESERVER_FQDN}\"" "$SYNAPSE_CFG"
fix_ownership "${VOLUME_PATH}/synapse"
log_info "Generating MAS configuration..." log_info "Generating MAS configuration..."
docker run -it --rm --network matrix_network \ docker run -it --rm --network matrix_network \
-v "${VOLUME_PATH}/mas:/data" \ -v "${VOLUME_PATH}/mas:/data" \
@@ -100,49 +98,55 @@ fix_ownership "${VOLUME_PATH}/mas"
log_info "Linking Synapse and MAS via OIDC..." log_info "Linking Synapse and MAS via OIDC..."
CLIENT_ID="synapse-client" CLIENT_ID="0000000000000000000SYNAPSE"
CLIENT_SECRET=$(openssl rand -hex 32) CLIENT_SECRET=$(openssl rand -hex 32)
ADMIN_SECRET=$(openssl rand -hex 32)
TEMP_FILTER=$(mktemp) MATRIX_SECRET=$(openssl rand -hex 32)
trap "rm -f $TEMP_FILTER" EXIT MATRIX_ENDPOINT="http://synapse:8008"
cat > "$TEMP_FILTER" <<EOF
clients:
- client_id: "${CLIENT_ID}"
client_secret: "${CLIENT_SECRET}"
redirect_uris:
- "https://${HOMESERVER_FQDN}/_synapse/client/oidc/callback"
grant_types:
- "authorization_code"
- "refresh_token"
response_types:
- "code"
scopes:
- "openid"
- "profile"
- "email"
application_type: "web"
EOF
EXISTING_CLIENT=$(yq '.clients[] | select(.client_id == "'"${CLIENT_ID}"'")' "$MAS_CFG" 2>/dev/null || echo "") EXISTING_CLIENT=$(yq '.clients[] | select(.client_id == "'"${CLIENT_ID}"'")' "$MAS_CFG" 2>/dev/null || echo "")
if [[ -z "$EXISTING_CLIENT" ]]; then if [[ -z "$EXISTING_CLIENT" ]]; then
yq -y -i "$(cat "$TEMP_FILTER")" "$MAS_CFG" || { log_error "Failed to register Synapse client in MAS"; exit 1; } CLIENT_OBJ="{
\"client_id\": \"${CLIENT_ID}\",
\"client_auth_method\": \"client_secret_basic\",
\"client_secret\": \"${CLIENT_SECRET}\",
\"redirect_uris\": [\"https://${HOMESERVER_FQDN}/_synapse/client/oidc/callback\"],
\"grant_types\": [\"authorization_code\", \"refresh_token\"],
\"response_types\": [\"code\"],
\"scopes\": [\"openid\", \"profile\", \"email\"],
\"application_type\": \"web\"
}"
yq -y -i ".clients += [$CLIENT_OBJ]" "$MAS_CFG" || { log_error "Failed to register Synapse client in MAS"; exit 1; }
log_info " -> Registered Synapse as OIDC client in MAS" log_info " -> Registered Synapse as OIDC client in MAS"
else else
log_info " -> Synapse client already registered in MAS, skipping" log_info " -> Synapse client already registered in MAS, skipping"
fi fi
ISSUER_URL="https://${MAS_FQDN}" # Ensure the matrix section exists
if ! yq '.matrix' "$MAS_CFG" > /dev/null 2>&1; then
yq -y -i '.matrix = {}' "$MAS_CFG"
fi
yq -y -i ".matrix.homeserver = \"${HOMESERVER_FQDN}\"" "$MAS_CFG"
yq -y -i ".matrix.secret = \"${MATRIX_SECRET}\"" "$MAS_CFG"
yq -y -i ".matrix.endpoint = \"${MATRIX_ENDPOINT}\"" "$MAS_CFG"
ISSUER_URL="https://${MAS_FQDN}"
fix_ownership "$SYNAPSE_CFG" fix_ownership "$SYNAPSE_CFG"
cat > "$TEMP_FILTER" <<EOF
.oidc_providers += [{"idp_id": "mas", "idp_name": "Matrix Authentication Service", "idp_brand": "mas", "issuer": "${ISSUER_URL}", "client_id": "${CLIENT_ID}", "client_secret": "${CLIENT_SECRET}", "scopes": ["openid", "profile"], "skip_verification": false}]
EOF
if ! yq '.oidc_providers' "$SYNAPSE_CFG" 2>/dev/null | grep -q "idp_id"; then if ! yq '.oidc_providers' "$SYNAPSE_CFG" 2>/dev/null | grep -q "idp_id"; then
yq -y -i "$(cat "$TEMP_FILTER")" "$SYNAPSE_CFG" || { log_error "Failed to inject OIDC config"; exit 1; } yq -y -i ".oidc_providers += [{
\"idp_id\": \"mas\",
\"idp_name\": \"Matrix Authentication Service\",
\"idp_brand\": \"mas\",
\"issuer\": \"${ISSUER_URL}\",
\"client_id\": \"${CLIENT_ID}\",
\"client_secret\": \"${CLIENT_SECRET}\",
\"shared_secret\": \"${MATRIX_SECRET}\",
\"scopes\": [\"openid\", \"profile\"],
\"skip_verification\": false
}]" "$SYNAPSE_CFG" || { log_error "Failed to inject OIDC config"; exit 1; }
fi fi
if [[ "${INCLUDE_LIVEKIT:-FALSE}" == "TRUE" ]]; then if [[ "${INCLUDE_LIVEKIT:-FALSE}" == "TRUE" ]]; then
+2 -2
View File
@@ -83,10 +83,10 @@ toggle_block() {
if [[ "$keep_markers" == "true" ]]; then if [[ "$keep_markers" == "true" ]]; then
# Remove lines containing markers individually # Remove lines containing markers individually
sed -i "/${start_marker}/d; /${end_marker}/d" "$target_file" sed -i "\|${start_marker}|d; \|${end_marker}|d" "$target_file"
else else
# Remove block from start to end # Remove block from start to end
sed -i "/${start_marker},/${end_marker}/d" "$target_file" sed -i "\|${start_marker}|,\|${end_marker}|d" "$target_file"
fi fi
} }
+2 -1
View File
@@ -77,7 +77,7 @@ services:
- "traefik.http.routers.auth.rule=Host(`${MAS_FQDN}`)" - "traefik.http.routers.auth.rule=Host(`${MAS_FQDN}`)"
- "traefik.http.routers.auth.entrypoints=websecure" - "traefik.http.routers.auth.entrypoints=websecure"
- "traefik.http.routers.auth.tls.certresolver=myresolver" - "traefik.http.routers.auth.tls.certresolver=myresolver"
- "traefik.http.services.auth.loadbalancer.server.port=8000" - "traefik.http.services.auth.loadbalancer.server.port=8080"
# [TRAEFIK_LABELS_END] # [TRAEFIK_LABELS_END]
# --- OPTIONAL: LIVEKIT RTC STACK --- # --- OPTIONAL: LIVEKIT RTC STACK ---
@@ -234,6 +234,7 @@ services:
- "--entrypoints.web.address=:80" - "--entrypoints.web.address=:80"
- "--entrypoints.websecure.address=:443" - "--entrypoints.websecure.address=:443"
- "--certificatesresolvers.myresolver.acme.tlschallenge=true" - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
- "--certificatesresolvers.myresolver.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
- "--certificatesresolvers.myresolver.acme.email=${PG_USER}@${DOMAIN}" - "--certificatesresolvers.myresolver.acme.email=${PG_USER}@${DOMAIN}"
- "--certificatesresolvers.myresolver.acme.storage=/etc/traefik/acme.json" - "--certificatesresolvers.myresolver.acme.storage=/etc/traefik/acme.json"
networks: networks:
+3 -3
View File
@@ -140,11 +140,11 @@ log_info "1. Generating Compose File..."
log_info "2. Initializing Database & Configs..." log_info "2. Initializing Database & Configs..."
"${SCRIPT_DIR}/init/scripts/config_gen.sh" "${SCRIPT_DIR}/init/scripts/config_gen.sh"
log_info "3. Linking Services (OIDC)..." #log_info "3. Linking Services (OIDC)..."
"${SCRIPT_DIR}/init/scripts/config_link.sh" #"${SCRIPT_DIR}/init/scripts/config_link.sh"
if [[ ${WORKER_INPUT} -gt 1 ]]; then if [[ ${WORKER_INPUT} -gt 1 ]]; then
log_info "4. Generating Workers (${WORKER_INPUT})..." log_info "3. Generating Workers (${WORKER_INPUT})..."
"${SCRIPT_DIR}/init/scripts/worker_gen.sh" -c "$WORKER_INPUT" "${SCRIPT_DIR}/init/scripts/worker_gen.sh" -c "$WORKER_INPUT"
fi fi
log_info "=== Setup Complete ===" log_info "=== Setup Complete ==="