From 03f6ed275997bfd9d9da1064925f378b0135cf42 Mon Sep 17 00:00:00 2001 From: Slavi Pantaleev Date: Tue, 29 Sep 2026 22:36:35 +0300 Subject: [PATCH] Document that Matrix RTC requires the federation port even with federation disabled LiveKit JWT Service verifies OpenID tokens via the homeserver's federation API, which it discovers over the public network. Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/5540 Co-Authored-By: Claude Opus 5.5 (1M context) --- docs/configuring-playbook-matrix-rtc.md | 2 +- docs/prerequisites.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/configuring-playbook-matrix-rtc.md b/docs/configuring-playbook-matrix-rtc.md index 919eef9f2..4ea15518f 100644 --- a/docs/configuring-playbook-matrix-rtc.md +++ b/docs/configuring-playbook-matrix-rtc.md @@ -36,7 +36,7 @@ matrix_rtc_enabled: true ## Adjusting firewall rules -In addition to the HTTP/HTTPS ports (which you've already exposed as per the [prerequisites](prerequisites.md) document), you'll also need to open ports required by [LiveKit Server](configuring-playbook-livekit-server.md) as described in its own [Adjusting firewall rules](configuring-playbook-livekit-server.md#adjusting-firewall-rules) section. +In addition to the HTTP/HTTPS ports and the Matrix Federation port (`8448`, required **even with federation disabled**), which you've already exposed as per the [prerequisites](prerequisites.md) document, you'll also need to open ports required by [LiveKit Server](configuring-playbook-livekit-server.md) as described in its own [Adjusting firewall rules](configuring-playbook-livekit-server.md#adjusting-firewall-rules) section. ## Fronting the integrated reverse-proxy with another reverse-proxy diff --git a/docs/prerequisites.md b/docs/prerequisites.md index b9c5f441f..865e2990e 100644 --- a/docs/prerequisites.md +++ b/docs/prerequisites.md @@ -57,7 +57,7 @@ We will be using `example.com` as the domain in the following instruction. Pleas - `80/tcp`: HTTP webserver - `443/tcp` and `443/udp`: HTTPS webserver - - `8448/tcp` and `8448/udp`: Matrix Federation API HTTPS webserver. Some components like [Matrix User Verification Service](configuring-playbook-user-verification-service.md#open-matrix-federation-port) require this port to be opened **even with federation disabled**. + - `8448/tcp` and `8448/udp`: Matrix Federation API HTTPS webserver. Some components like [Matrix User Verification Service](configuring-playbook-user-verification-service.md#open-matrix-federation-port) and the [Matrix RTC stack](configuring-playbook-matrix-rtc.md) require this port to be opened **even with federation disabled**. - potentially some other ports, depending on the additional (non-default) services that you enable in the **configuring the playbook** step (later on). Consult each service's documentation page in `docs/` for that. ---------------------------------------------