diff --git a/docs/configuring-dns.md b/docs/configuring-dns.md index 862534584..d7ccf17e7 100644 --- a/docs/configuring-dns.md +++ b/docs/configuring-dns.md @@ -42,7 +42,6 @@ When you're done configuring DNS, proceed to [Configuring the playbook](configur | [Etherpad](configuring-playbook-etherpad.md) collaborative text editor | CNAME | `etherpad` | - | - | - | `matrix.` | | [Hydrogen](configuring-playbook-client-hydrogen.md) web client | CNAME | `hydrogen` | - | - | - | `matrix.` | | [Cinny](configuring-playbook-client-cinny.md) web client | CNAME | `cinny` | - | - | - | `matrix.` | -| [wsproxy](configuring-playbook-bridge-mautrix-wsproxy.md) sms bridge | CNAME | `wsproxy` | - | - | - | `matrix.` | | [Buscarron](configuring-playbook-bot-buscarron.md) helpdesk bot | CNAME | `buscarron` | - | - | - | `matrix.` | | [Postmoogle](configuring-playbook-bot-postmoogle.md)/[Email2Matrix](configuring-playbook-email2matrix.md) email bridges | MX | `matrix` | 10 | 0 | - | `matrix.` | | [Postmoogle](configuring-playbook-bot-postmoogle.md) email bridge | TXT | `matrix` | - | - | - | `v=spf1 ip4: -all` | @@ -76,8 +75,6 @@ The `hydrogen.` subdomain may be necessary, because this playbook c The `cinny.` subdomain may be necessary, because this playbook could install the [Cinny](https://github.com/ajbura/cinny) web client. The installation of cinny is disabled by default, it is not a core required component. To learn how to install it, see our [configuring cinny guide](configuring-playbook-client-cinny.md). If you do not wish to set up cinny, feel free to skip the `cinny.` DNS record. -The `wsproxy.` subdomain may be necessary, because this playbook could install the [wsproxy](https://github.com/mautrix/wsproxy) web client. The installation of wsproxy is disabled by default, it is not a core required component. To learn how to install it, see our [configuring wsproxy guide](configuring-playbook-bridge-mautrix-wsproxy.md). If you do not wish to set up wsproxy, feel free to skip the `wsproxy.` DNS record. - The `buscarron.` subdomain may be necessary, because this playbook could install the [buscarron](https://gitlab.com/etke.cc/buscarron) bot. The installation of buscarron is disabled by default, it is not a core required component. To learn how to install it, see our [configuring buscarron guide](configuring-playbook-bot-buscarron.md). If you do not wish to set up buscarron, feel free to skip the `buscarron.` DNS record. ## `_matrix-identity._tcp` SRV record setup diff --git a/docs/configuring-playbook-bridge-mautrix-wsproxy.md b/docs/configuring-playbook-bridge-mautrix-wsproxy.md deleted file mode 100644 index 3c3324d52..000000000 --- a/docs/configuring-playbook-bridge-mautrix-wsproxy.md +++ /dev/null @@ -1,22 +0,0 @@ -# Setting up Mautrix wsproxy (optional) - -The playbook can install and configure [mautrix-wsproxy](https://github.com/mautrix/wsproxy) for you. - -See the project's [documentation](https://github.com/mautrix/wsproxy#readme) to learn what it does and why it might be useful to you. - -Use the following playbook configuration: - -```yaml -matrix_mautrix_wsproxy_enabled: true -matrix_mautrix_androidsms_appservice_token: 'random string' -matrix_mautrix_androidsms_homeserver_token: 'random string' -matrix_mautrix_imessage_appservice_token: 'random string' -matrix_mautrix_imessage_homeserver_token: 'random string' -matrix_mautrix_wsproxy_syncproxy_shared_secret: 'random string' -``` - -Note that the tokens must match what is compiled into the `mautrix-imessage` bridge running on Mac and Android. - -## Usage - -Follow the [matrix-imessage documenation](https://docs.mau.fi/bridges/go/imessage/index.html) for running `android-sms` and/or `matrix-imessage` on your device(s). diff --git a/group_vars/matrix_servers b/group_vars/matrix_servers index a745443e1..5fc5c25d8 100755 --- a/group_vars/matrix_servers +++ b/group_vars/matrix_servers @@ -1249,34 +1249,6 @@ matrix_mautrix_whatsapp_database_password: "{{ '%s' | format(matrix_homeserver_g # ###################################################################### -###################################################################### -# -# matrix-bridge-mautrix-wsproxy -# -###################################################################### - -# We don't enable bridges by default. -matrix_mautrix_wsproxy_enabled: false - -matrix_mautrix_wsproxy_systemd_required_services_list: | - {{ - ['docker.service'] - + - (['matrix-synapse.service'] if matrix_synapse_enabled else []) - + - (['matrix-postgres.service'] if matrix_postgres_enabled else []) - }} - -matrix_mautrix_wsproxy_homeserver_domain: '{{ matrix_domain }}' - -matrix_mautrix_wsproxy_homeserver_address: "{{ 'http://matrix-synapse:8008' if matrix_synapse_enabled else '' }}" - -###################################################################### -# -# /matrix-bridge-mautrix-wsproxy -# -###################################################################### - ###################################################################### # # matrix-sms-bridge @@ -2731,7 +2703,6 @@ matrix_nginx_proxy_proxy_jitsi_enabled: "{{ jitsi_enabled and matrix_playbook_re matrix_nginx_proxy_proxy_grafana_enabled: "{{ grafana_enabled and matrix_playbook_reverse_proxy_type in ['playbook-managed-nginx', 'other-nginx-non-container'] }}" matrix_nginx_proxy_proxy_sygnal_enabled: "{{ matrix_sygnal_enabled and matrix_playbook_reverse_proxy_type in ['playbook-managed-nginx', 'other-nginx-non-container'] }}" -matrix_nginx_proxy_proxy_mautrix_wsproxy_enabled: "{{ matrix_mautrix_wsproxy_enabled }}" matrix_nginx_proxy_proxy_ntfy_enabled: "{{ ntfy_enabled and matrix_playbook_reverse_proxy_type in ['playbook-managed-nginx', 'other-nginx-non-container'] }}" matrix_nginx_proxy_container_labels_traefik_enabled: "{{ matrix_playbook_traefik_labels_enabled }}" @@ -2866,8 +2837,6 @@ matrix_ssl_domains_to_obtain_certificates_for: | + ([matrix_server_fqn_sygnal] if matrix_sygnal_enabled else []) + - ([matrix_server_fqn_mautrix_wsproxy] if matrix_mautrix_wsproxy_enabled else []) - + ([ntfy_hostname] if ntfy_enabled else []) + ([matrix_server_fqn_rageshake] if matrix_rageshake_enabled else []) @@ -3086,12 +3055,6 @@ devture_postgres_managed_databases_auto: | 'password': matrix_mautrix_signal_database_password, }] if (matrix_mautrix_signal_enabled and matrix_mautrix_signal_database_engine == 'postgres' and matrix_mautrix_signal_database_hostname == devture_postgres_connection_hostname) else []) + - ([{ - 'name': matrix_mautrix_wsproxy_syncproxy_database_name, - 'username': matrix_mautrix_wsproxy_syncproxy_database_username, - 'password': matrix_mautrix_wsproxy_syncproxy_database_password, - }] if (matrix_mautrix_wsproxy_enabled and matrix_mautrix_wsproxy_syncproxy_database_engine == 'postgres' and matrix_mautrix_wsproxy_syncproxy_database_hostname == 'matrix-postgres') else []) - + ([{ 'name': matrix_mautrix_telegram_database_name, 'username': matrix_mautrix_telegram_database_username, diff --git a/roles/custom/matrix-base/defaults/main.yml b/roles/custom/matrix-base/defaults/main.yml index 47cbcb935..35974bba9 100644 --- a/roles/custom/matrix-base/defaults/main.yml +++ b/roles/custom/matrix-base/defaults/main.yml @@ -90,9 +90,6 @@ matrix_server_fqn_grafana: "stats.{{ matrix_domain }}" # This is where you access the Sygnal push gateway. matrix_server_fqn_sygnal: "sygnal.{{ matrix_domain }}" -# This is where you access the mautrix wsproxy push gateway. -matrix_server_fqn_mautrix_wsproxy: "wsproxy.{{ matrix_domain }}" - # This is where you access the ntfy push notification service. matrix_server_fqn_ntfy: "ntfy.{{ matrix_domain }}" diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/defaults/main.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/defaults/main.yml deleted file mode 100644 index 986f35d3b..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/defaults/main.yml +++ /dev/null @@ -1,122 +0,0 @@ ---- -# mautrix-wsproxy is a Matrix <-> websocket bridge -# See: https://github.com/mautrix/wsproxy - -matrix_mautrix_wsproxy_enabled: true - -matrix_mautrix_wsproxy_version: latest -# See: https://mau.dev/mautrix/wsproxy/container_registry -matrix_mautrix_wsproxy_docker_image: "dock.mau.dev/mautrix/wsproxy:{{ matrix_mautrix_wsproxy_version }}" -matrix_mautrix_wsproxy_docker_image_force_pull: "{{ matrix_mautrix_wsproxy_docker_image.endswith(':latest') }}" - -matrix_mautrix_wsproxy_base_path: "{{ matrix_base_data_path }}/wsproxy" -matrix_mautrix_wsproxy_config_path: "{{ matrix_mautrix_wsproxy_base_path }}/config" -matrix_mautrix_wsproxy_data_path: "{{ matrix_mautrix_wsproxy_base_path }}/data" - -matrix_mautrix_wsproxy_homeserver_address: "{{ matrix_homeserver_container_url }}" -matrix_mautrix_wsproxy_homeserver_domain: "{{ matrix_domain }}" - -matrix_mautrix_wsproxy_port: 29331 - -matrix_mautrix_wsproxy_appservice_address: "http://matrix-mautrix-wsproxy:{{ matrix_mautrix_wsproxy_port }}" - - -# A list of extra arguments to pass to the container -matrix_mautrix_wsproxy_container_extra_arguments: [] - -# List of systemd services that matrix-mautrix-wsproxy.service depends on. -matrix_mautrix_wsproxy_systemd_required_services_list: ['docker.service'] - -# List of systemd services that matrix-mautrix-wsproxy.service wants -matrix_mautrix_wsproxy_systemd_wanted_services_list: [] - -matrix_mautrix_androidsms_appservice_token: '' -matrix_mautrix_androidsms_homeserver_token: '' - -matrix_mautrix_imessage_appservice_token: '' -matrix_mautrix_imessage_homeserver_token: '' - -matrix_mautrix_androidsms_appservice_bot_username: androidsmsbot -matrix_mautrix_imessage_appservice_bot_username: imessagebot - -# Default mautrix-wsproxy configuration template which covers the generic use case. -# You can customize it by controlling the various variables inside it. -# -# For a more advanced customization, you can extend the default (see `matrix_mautrix_wsproxy_configuration_extension_yaml`) -# or completely replace this variable with your own template. -matrix_mautrix_wsproxy_configuration_yaml: "{{ lookup('template', 'templates/config.yaml.j2') }}" - -matrix_mautrix_wsproxy_configuration_extension_yaml: | - # Your custom YAML configuration goes here. - # This configuration extends the default starting configuration (`matrix_mautrix_wsproxy_configuration_yaml`). - # - # You can override individual variables from the default configuration, or introduce new ones. - # - # If you need something more special, you can take full control by - # completely redefining `matrix_mautrix_wsproxy_configuration_yaml`. - -matrix_mautrix_wsproxy_configuration_extension: "{{ matrix_mautrix_wsproxy_configuration_extension_yaml|from_yaml if matrix_mautrix_wsproxy_configuration_extension_yaml|from_yaml is mapping else {} }}" - -# Holds the final configuration (a combination of the default and its extension). -# You most likely don't need to touch this variable. Instead, see `matrix_mautrix_wsproxy_configuration_yaml`. -matrix_mautrix_wsproxy_configuration: "{{ matrix_mautrix_wsproxy_configuration_yaml|from_yaml|combine(matrix_mautrix_wsproxy_configuration_extension, recursive=True) }}" - -matrix_mautrix_androidsms_registration_yaml: | - id: androidsms - url: {{ matrix_mautrix_wsproxy_appservice_address }} - as_token: "{{ matrix_mautrix_androidsms_appservice_token }}" - hs_token: "{{ matrix_mautrix_androidsms_homeserver_token }}" - sender_localpart: _bot_{{ matrix_mautrix_androidsms_appservice_bot_username }} - rate_limited: false - namespaces: - users: - - regex: '@androidsms_.+:{{ matrix_mautrix_wsproxy_homeserver_domain|regex_escape }}$' - exclusive: true - - exclusive: true - regex: '^@{{ matrix_mautrix_androidsms_appservice_bot_username|regex_escape }}:{{ matrix_mautrix_wsproxy_homeserver_domain|regex_escape }}$' - -matrix_mautrix_androidsms_registration: "{{ matrix_mautrix_androidsms_registration_yaml|from_yaml }}" - -matrix_mautrix_imessage_registration_yaml: | - id: imessage - url: {{ matrix_mautrix_wsproxy_appservice_address }} - as_token: "{{ matrix_mautrix_imessage_appservice_token }}" - hs_token: "{{ matrix_mautrix_imessage_homeserver_token }}" - sender_localpart: _bot_{{ matrix_mautrix_imessage_appservice_bot_username }} - rate_limited: false - namespaces: - users: - - regex: '@imessage_.+:{{ matrix_mautrix_wsproxy_homeserver_domain|regex_escape }}$' - exclusive: true - - exclusive: true - regex: '^@{{ matrix_mautrix_imessage_appservice_bot_username|regex_escape }}:{{ matrix_mautrix_wsproxy_homeserver_domain|regex_escape }}$' - -matrix_mautrix_imessage_registration: "{{ matrix_mautrix_imessage_registration_yaml|from_yaml }}" - -# Syncproxy-related configuration fields -matrix_mautrix_wsproxy_syncproxy_version: latest -# See: https://mau.dev/mautrix/wsproxy/container_registry -matrix_mautrix_wsproxy_syncproxy_docker_image: "dock.mau.dev/mautrix/syncproxy:{{ matrix_mautrix_wsproxy_syncproxy_version }}" -matrix_mautrix_wsproxy_syncproxy_docker_image_force_pull: "{{ matrix_mautrix_wsproxy_syncproxy_docker_image.endswith(':latest') }}" -matrix_mautrix_wsproxy_syncproxy_container_extra_arguments: [] - -matrix_mautrix_wsproxy_syncproxy_systemd_required_services_list: ['docker.service', 'matrix-mautrix-wsproxy.service'] -matrix_mautrix_wsproxy_syncproxy_systemd_wanted_services_list: [] - -matrix_mautrix_wsproxy_syncproxy_shared_secret: '' -matrix_mautrix_wsproxy_syncproxy_port: 29332 -matrix_mautrix_wsproxy_syncproxy_appservice_address: "http://matrix-mautrix-wsproxy-syncproxy:{{ matrix_mautrix_wsproxy_syncproxy_port }}" - -# Database-related configuration fields -# -# This bridge supports Postgres and SQLite. -# -matrix_mautrix_wsproxy_syncproxy_database_engine: 'postgres' - -matrix_mautrix_wsproxy_syncproxy_database_username: 'matrix_mautrix_wsproxy_syncproxy' -matrix_mautrix_wsproxy_syncproxy_database_password: 'some-password' -matrix_mautrix_wsproxy_syncproxy_database_hostname: 'matrix-postgres' -matrix_mautrix_wsproxy_syncproxy_database_port: 5432 -matrix_mautrix_wsproxy_syncproxy_database_name: 'matrix_mautrix_wsproxy_syncproxy' - -matrix_mautrix_signal_wsproxy_syncproxy_connection_string: 'postgres://{{ matrix_mautrix_wsproxy_syncproxy_database_username }}:{{ matrix_mautrix_wsproxy_syncproxy_database_password }}@{{ matrix_mautrix_wsproxy_syncproxy_database_hostname }}:{{ matrix_mautrix_wsproxy_syncproxy_database_port }}/{{ matrix_mautrix_wsproxy_syncproxy_database_name }}' diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/init.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/init.yml deleted file mode 100644 index dcb1617a4..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/init.yml +++ /dev/null @@ -1,72 +0,0 @@ ---- -- ansible.builtin.set_fact: - matrix_systemd_services_list: "{{ matrix_systemd_services_list + ['matrix-mautrix-wsproxy.service'] }}" - when: matrix_mautrix_wsproxy_enabled|bool - -# If the matrix-synapse role is not used, these variables may not exist. -- ansible.builtin.set_fact: - matrix_synapse_container_extra_arguments: > - {{ - matrix_synapse_container_extra_arguments | default([]) - + - ["--mount type=bind,src={{ matrix_mautrix_wsproxy_config_path }}/androidsms-registration.yaml,dst=/matrix-mautrix-androidsms-registration.yaml,ro"] - + - ["--mount type=bind,src={{ matrix_mautrix_wsproxy_config_path }}/imessage-registration.yaml,dst=/matrix-mautrix-imessage-registration.yaml,ro"] - }} - - matrix_synapse_app_service_config_files: > - {{ - matrix_synapse_app_service_config_files | default([]) - + - ["/matrix-mautrix-androidsms-registration.yaml"] - + - ["/matrix-mautrix-imessage-registration.yaml"] - }} - when: matrix_mautrix_wsproxy_enabled|bool - -- block: - - name: Fail if matrix-nginx-proxy role already executed - ansible.builtin.fail: - msg: >- - Trying to append Mautrix Wsproxy reverse-proxying configuration to matrix-nginx-proxy, - but it's pointless since the matrix-nginx-proxy role had already executed. - To fix this, please change the order of roles in your playbook, - so that the matrix-nginx-proxy role would run after the matrix-bridge-mautrix-wsproxy role. - when: matrix_nginx_proxy_role_executed|default(False)|bool - - - name: Generate Mautrix Wsproxy proxying configuration for matrix-nginx-proxy - ansible.builtin.set_fact: - matrix_mautrix_wsproxy_matrix_nginx_proxy_configuration: | - location ~ ^/(_matrix/wsproxy/.*) { - {% if matrix_nginx_proxy_enabled|default(False) %} - {# Use the embedded DNS resolver in Docker containers to discover the service #} - resolver 127.0.0.11 valid=5s; - set $backend "matrix-mautrix-wsproxy:29331"; - proxy_pass http://$backend; - {% else %} - {# Generic configuration for use outside of our container setup #} - proxy_pass http://127.0.0.1:29331; - {% endif %} - } - - - name: Register Mautrix Wsproxy proxying configuration with matrix-nginx-proxy - ansible.builtin.set_fact: - matrix_nginx_proxy_proxy_matrix_additional_server_configuration_blocks: | - {{ - matrix_nginx_proxy_proxy_matrix_additional_server_configuration_blocks|default([]) - + - [matrix_mautrix_wsproxy_matrix_nginx_proxy_configuration] - }} - tags: - - always - when: matrix_mautrix_wsproxy_enabled|bool - -- name: Warn about reverse-proxying if matrix-nginx-proxy not used - ansible.builtin.debug: - msg: >- - NOTE: You've enabled the Mautrix wsproxy bridge but are not using the matrix-nginx-proxy - reverse proxy. - Please make sure that you're proxying the `{{ matrix_mautrix_wsproxy_public_endpoint }}` - URL endpoint to the matrix-mautrix-wsproxy container. - You can expose the container's port using the `matrix_mautrix_wsproxy_container_http_host_bind_port` variable. - when: "matrix_mautrix_wsproxy_enabled|bool and matrix_nginx_proxy_enabled is not defined" diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/main.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/main.yml deleted file mode 100644 index 90f5d66d7..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/main.yml +++ /dev/null @@ -1,22 +0,0 @@ ---- -- ansible.builtin.import_tasks: "{{ role_path }}/tasks/init.yml" - tags: - - always - -- ansible.builtin.import_tasks: "{{ role_path }}/tasks/validate_config.yml" - when: "run_setup|bool and matrix_mautrix_wsproxy_enabled|bool" - tags: - - setup-all - - setup-mautrix-wsproxy - -- ansible.builtin.import_tasks: "{{ role_path }}/tasks/setup_install.yml" - when: "run_setup and matrix_mautrix_wsproxy_enabled" - tags: - - setup-all - - setup-mautrix-wsproxy - -- ansible.builtin.import_tasks: "{{ role_path }}/tasks/setup_uninstall.yml" - when: "run_setup and not matrix_mautrix_wsproxy_enabled" - tags: - - setup-all - - setup-mautrix-wsproxy diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_install.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_install.yml deleted file mode 100644 index 1f47e9edf..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_install.yml +++ /dev/null @@ -1,106 +0,0 @@ ---- - -# If the matrix-synapse role is not used, `matrix_synapse_role_executed` won't exist. -# We don't want to fail in such cases. -- name: Fail if matrix-synapse role already executed - ansible.builtin.fail: - msg: >- - The matrix-bridge-mautrix-wsproxy role needs to execute before the matrix-synapse role. - when: "matrix_synapse_role_executed|default(False)" - -- ansible.builtin.set_fact: - matrix_mautrix_wsproxy_requires_restart: false - -- ansible.builtin.set_fact: - matrix_mautrix_wsproxy_syncproxy_requires_restart: false - -- name: Ensure Mautrix wsproxy image is pulled - docker_image: - name: "{{ matrix_mautrix_wsproxy_docker_image }}" - source: "{{ 'pull' if ansible_version.major > 2 or ansible_version.minor > 7 else omit }}" - force_source: "{{ matrix_mautrix_wsproxy_docker_image_force_pull if ansible_version.major > 2 or ansible_version.minor >= 8 else omit }}" - force: "{{ omit if ansible_version.major > 2 or ansible_version.minor >= 8 else matrix_mautrix_wsproxy_docker_image_force_pull }}" - -- name: Ensure Mautrix syncproxy image is pulled - docker_image: - name: "{{ matrix_mautrix_wsproxy_syncproxy_docker_image }}" - source: "{{ 'pull' if ansible_version.major > 2 or ansible_version.minor > 7 else omit }}" - force_source: "{{ matrix_mautrix_wsproxy_syncproxy_docker_image_force_pull if ansible_version.major > 2 or ansible_version.minor >= 8 else omit }}" - force: "{{ omit if ansible_version.major > 2 or ansible_version.minor >= 8 else matrix_mautrix_wsproxy_syncproxy_docker_image_force_pull }}" - -- name: Ensure Mautrix wsproxy paths exists - ansible.builtin.file: - path: "{{ item }}" - state: directory - mode: 0750 - owner: "{{ matrix_user_username }}" - group: "{{ matrix_user_groupname }}" - with_items: - - "{{ matrix_mautrix_wsproxy_base_path }}" - - "{{ matrix_mautrix_wsproxy_config_path }}" - - "{{ matrix_mautrix_wsproxy_data_path }}" - -- name: Check if an old matrix state file exists - ansible.builtin.stat: - path: "{{ matrix_mautrix_wsproxy_base_path }}/mx-state.json" - register: matrix_mautrix_wsproxy_stat_mx_state - -- name: Ensure mautrix-wsproxy config.yaml installed - ansible.builtin.copy: - content: "{{ matrix_mautrix_wsproxy_configuration|to_nice_yaml }}" - dest: "{{ matrix_mautrix_wsproxy_config_path }}/config.yaml" - mode: 0644 - owner: "{{ matrix_user_username }}" - group: "{{ matrix_user_groupname }}" - -- name: Ensure mautrix-androidsms registration.yaml installed - ansible.builtin.copy: - content: "{{ matrix_mautrix_androidsms_registration|to_nice_yaml }}" - dest: "{{ matrix_mautrix_wsproxy_config_path }}/androidsms-registration.yaml" - mode: 0644 - owner: "{{ matrix_user_username }}" - group: "{{ matrix_user_groupname }}" - -- name: Ensure mautrix-imessage registration.yaml installed - ansible.builtin.copy: - content: "{{ matrix_mautrix_imessage_registration|to_nice_yaml }}" - dest: "{{ matrix_mautrix_wsproxy_config_path }}/imessage-registration.yaml" - mode: 0644 - owner: "{{ matrix_user_username }}" - group: "{{ matrix_user_groupname }}" - -- name: Ensure matrix-mautrix-wsproxy.service installed - ansible.builtin.template: - src: "{{ role_path }}/templates/systemd/matrix-mautrix-wsproxy.service.j2" - dest: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy.service" - mode: 0644 - register: matrix_mautrix_wsproxy_systemd_service_result - -- name: Ensure systemd reloaded after matrix-mautrix-wsproxy.service installation - ansible.builtin.service: - daemon_reload: true - when: "matrix_mautrix_wsproxy_systemd_service_result.changed" - -- name: Ensure matrix-mautrix-wsproxy.service restarted, if necessary - ansible.builtin.service: - name: "matrix-mautrix-wsproxy.service" - state: restarted - when: "matrix_mautrix_wsproxy_requires_restart|bool" - -- name: Ensure matrix-mautrix-wsproxy-syncproxy.service installed - ansible.builtin.template: - src: "{{ role_path }}/templates/systemd/matrix-mautrix-wsproxy-syncproxy.service.j2" - dest: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy-syncproxy.service" - mode: 0644 - register: matrix_mautrix_wsproxy_syncproxy_systemd_service_result - -- name: Ensure systemd reloaded after matrix-mautrix-wsproxy-syncproxy.service installation - ansible.builtin.service: - daemon_reload: true - when: "matrix_mautrix_wsproxy_syncproxy_systemd_service_result.changed" - -- name: Ensure matrix-mautrix-wsproxy-syncproxy.service restarted, if necessary - ansible.builtin.service: - name: "matrix-mautrix-wsproxy-syncproxy.service" - state: restarted - when: "matrix_mautrix_wsproxy_syncproxy_requires_restart|bool" diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_uninstall.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_uninstall.yml deleted file mode 100644 index c39fd29f4..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/setup_uninstall.yml +++ /dev/null @@ -1,47 +0,0 @@ ---- - -- name: Check existence of matrix-mautrix-wsproxy service - ansible.builtin.stat: - path: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy.service" - register: matrix_mautrix_wsproxy_service_stat - -- name: Ensure matrix-mautrix-wsproxy is stopped - ansible.builtin.service: - name: matrix-mautrix-wsproxy - state: stopped - daemon_reload: true - when: "matrix_mautrix_wsproxy_service_stat.stat.exists" - -- name: Ensure matrix-mautrix-wsproxy.service doesn't exist - ansible.builtin.file: - path: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy.service" - state: absent - when: "matrix_mautrix_wsproxy_service_stat.stat.exists" - -- name: Ensure systemd reloaded after matrix-mautrix-wsproxy.service removal - ansible.builtin.service: - daemon_reload: true - when: "matrix_mautrix_wsproxy_service_stat.stat.exists" - -- name: Check existence of matrix-mautrix-wsproxy-syncproxy service - ansible.builtin.stat: - path: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy-syncproxy.service" - register: matrix_mautrix_wsproxy_syncproxy_service_stat - -- name: Ensure matrix-mautrix-wsproxy-syncproxy is stopped - ansible.builtin.service: - name: matrix-mautrix-wsproxy-syncproxy - state: stopped - daemon_reload: true - when: "matrix_mautrix_wsproxy_syncproxy_service_stat.stat.exists" - -- name: Ensure matrix-mautrix-wsproxy-syncproxy.service doesn't exist - ansible.builtin.file: - path: "{{ devture_systemd_docker_base_systemd_path }}/matrix-mautrix-wsproxy-syncproxy.service" - state: absent - when: "matrix_mautrix_wsproxy_syncproxy_service_stat.stat.exists" - -- name: Ensure systemd reloaded after matrix-mautrix-wsproxy-syncproxy.service removal - ansible.builtin.service: - daemon_reload: true - when: "matrix_mautrix_wsproxy_syncproxy_service_stat.stat.exists" diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/validate_config.yml b/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/validate_config.yml deleted file mode 100644 index 0db36f959..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/tasks/validate_config.yml +++ /dev/null @@ -1,13 +0,0 @@ ---- - -- name: Fail if required settings not defined - ansible.builtin.fail: - msg: >- - You need to define a required configuration setting (`{{ item }}`). - when: "vars[item] == ''" - with_items: - - "matrix_mautrix_androidsms_appservice_token" - - "matrix_mautrix_androidsms_homeserver_token" - - "matrix_mautrix_imessage_appservice_token" - - "matrix_mautrix_imessage_homeserver_token" - - "matrix_mautrix_wsproxy_syncproxy_shared_secret" diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/config.yaml.j2 b/roles/custom/matrix-bridge-mautrix-wsproxy/templates/config.yaml.j2 deleted file mode 100644 index 2c7932614..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/config.yaml.j2 +++ /dev/null @@ -1,14 +0,0 @@ -listen_address: 0.0.0.0:29331 -appservices: - - id: androidsms - as: {{ matrix_mautrix_androidsms_appservice_token | to_json }} - hs: {{ matrix_mautrix_androidsms_homeserver_token | to_json }} - - id: imessage - as: {{ matrix_mautrix_imessage_appservice_token | to_json }} - hs: {{ matrix_mautrix_imessage_homeserver_token | to_json }} -sync_proxy: - # The URL that mautrix-wsproxy can use to reach mautrix-syncproxy - url: {{ matrix_mautrix_wsproxy_syncproxy_appservice_address | to_json }} - # The URL that mautrix-syncproxy can use to reach mautrix-wsproxy - wsproxy_url: {{ matrix_mautrix_wsproxy_appservice_address | to_json }} - shared_secret: {{ matrix_mautrix_wsproxy_syncproxy_shared_secret | to_json }} diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy-syncproxy.service.j2 b/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy-syncproxy.service.j2 deleted file mode 100644 index 8ae276bc6..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy-syncproxy.service.j2 +++ /dev/null @@ -1,43 +0,0 @@ -#jinja2: lstrip_blocks: "True" -[Unit] -Description=Matrix Mautrix wsproxy bridge -{% for service in matrix_mautrix_wsproxy_syncproxy_systemd_required_services_list %} -Requires={{ service }} -After={{ service }} -{% endfor %} -{% for service in matrix_mautrix_wsproxy_syncproxy_systemd_wanted_services_list %} -Wants={{ service }} -{% endfor %} -DefaultDependencies=no - -[Service] -Type=simple -Environment="HOME={{ devture_systemd_docker_base_systemd_unit_home_path }}" -ExecStartPre=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} kill matrix-mautrix-wsproxy-syncproxy 2>/dev/null' -ExecStartPre=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} rm matrix-mautrix-wsproxy-syncproxy 2>/dev/null' - -# Intentional delay, so that the homeserver (we likely depend on) can manage to start. -ExecStartPre={{ matrix_host_command_sleep }} 5 - -ExecStart={{ devture_systemd_docker_base_host_command_docker }} run --rm --name matrix-mautrix-wsproxy-syncproxy \ - --log-driver=none \ - --user={{ matrix_user_uid }}:{{ matrix_user_gid }} \ - --cap-drop=ALL \ - --network={{ matrix_docker_network }} \ - -p {{ matrix_mautrix_wsproxy_syncproxy_port }}:29331 \ - -e DATABASE_URL={{ matrix_mautrix_signal_wsproxy_syncproxy_connection_string }} \ - -e HOMESERVER_URL={{ matrix_homeserver_container_url }} \ - -e SHARED_SECRET={{ matrix_mautrix_wsproxy_syncproxy_shared_secret }} \ - {% for arg in matrix_mautrix_wsproxy_syncproxy_container_extra_arguments %} - {{ arg }} \ - {% endfor %} - {{ matrix_mautrix_wsproxy_syncproxy_docker_image }} - -ExecStop=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} kill matrix-mautrix-wsproxy-syncproxy 2>/dev/null' -ExecStop=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} rm matrix-mautrix-wsproxy-syncproxy 2>/dev/null' -Restart=always -RestartSec=30 -SyslogIdentifier=matrix-mautrix-wsproxy-syncproxy - -[Install] -WantedBy=multi-user.target diff --git a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy.service.j2 b/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy.service.j2 deleted file mode 100644 index e945bb62f..000000000 --- a/roles/custom/matrix-bridge-mautrix-wsproxy/templates/systemd/matrix-mautrix-wsproxy.service.j2 +++ /dev/null @@ -1,42 +0,0 @@ -#jinja2: lstrip_blocks: "True" -[Unit] -Description=Matrix Mautrix wsproxy bridge -{% for service in matrix_mautrix_wsproxy_systemd_required_services_list %} -Requires={{ service }} -After={{ service }} -{% endfor %} -{% for service in matrix_mautrix_wsproxy_systemd_wanted_services_list %} -Wants={{ service }} -{% endfor %} -DefaultDependencies=no - -[Service] -Type=simple -Environment="HOME={{ devture_systemd_docker_base_systemd_unit_home_path }}" -ExecStartPre=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} kill matrix-mautrix-wsproxy 2>/dev/null' -ExecStartPre=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} rm matrix-mautrix-wsproxy 2>/dev/null' - -# Intentional delay, so that the homeserver (we likely depend on) can manage to start. -ExecStartPre={{ matrix_host_command_sleep }} 5 - -ExecStart={{ devture_systemd_docker_base_host_command_docker }} run --rm --name matrix-mautrix-wsproxy \ - --log-driver=none \ - --user={{ matrix_user_uid }}:{{ matrix_user_gid }} \ - --cap-drop=ALL \ - --network={{ matrix_docker_network }} \ - -v {{ matrix_mautrix_wsproxy_config_path }}:/data:z \ - -p {{ matrix_mautrix_wsproxy_port }}:29331 \ - {% for arg in matrix_mautrix_wsproxy_container_extra_arguments %} - {{ arg }} \ - {% endfor %} - {{ matrix_mautrix_wsproxy_docker_image }} \ - /usr/bin/mautrix-wsproxy -config /data/config.yaml - -ExecStop=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} kill matrix-mautrix-wsproxy 2>/dev/null' -ExecStop=-{{ devture_systemd_docker_base_host_command_sh }} -c '{{ devture_systemd_docker_base_host_command_docker }} rm matrix-mautrix-wsproxy 2>/dev/null' -Restart=always -RestartSec=30 -SyslogIdentifier=matrix-mautrix-wsproxy - -[Install] -WantedBy=multi-user.target diff --git a/roles/custom/matrix-nginx-proxy/defaults/main.yml b/roles/custom/matrix-nginx-proxy/defaults/main.yml index c34e92a92..d8d73a869 100644 --- a/roles/custom/matrix-nginx-proxy/defaults/main.yml +++ b/roles/custom/matrix-nginx-proxy/defaults/main.yml @@ -253,10 +253,6 @@ matrix_nginx_proxy_proxy_grafana_hostname: "{{ matrix_server_fqn_grafana }}" matrix_nginx_proxy_proxy_sygnal_enabled: false matrix_nginx_proxy_proxy_sygnal_hostname: "{{ matrix_server_fqn_sygnal }}" -# Controls whether proxying the mautrix wsproxy should be done. -matrix_nginx_proxy_proxy_mautrix_wsproxy_enabled: false -matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname: "{{ matrix_server_fqn_mautrix_wsproxy }}" - # Controls whether proxying the ntfy domain should be done. matrix_nginx_proxy_proxy_ntfy_enabled: false matrix_nginx_proxy_proxy_ntfy_hostname: "{{ matrix_server_fqn_ntfy }}" @@ -445,9 +441,6 @@ matrix_nginx_proxy_proxy_grafana_additional_server_configuration_blocks: [] # A list of strings containing additional configuration blocks to add to Sygnal's server configuration (matrix-sygnal.conf). matrix_nginx_proxy_proxy_sygnal_additional_server_configuration_blocks: [] -# A list of strings containing additional configuration blocks to add to mautrix wsproxy server configuration (matrix-mautrix-wsproxy.conf). -matrix_nginx_proxy_proxy_mautrix_wsproxy_additional_server_configuration_blocks: [] - # A list of strings containing additional configuration blocks to add to ntfy's server configuration (matrix-ntfy.conf). matrix_nginx_proxy_proxy_ntfy_additional_server_configuration_blocks: [] diff --git a/roles/custom/matrix-nginx-proxy/tasks/setup_nginx_proxy.yml b/roles/custom/matrix-nginx-proxy/tasks/setup_nginx_proxy.yml index 2c54d6759..1a55e28f7 100644 --- a/roles/custom/matrix-nginx-proxy/tasks/setup_nginx_proxy.yml +++ b/roles/custom/matrix-nginx-proxy/tasks/setup_nginx_proxy.yml @@ -178,13 +178,6 @@ mode: 0644 when: matrix_nginx_proxy_proxy_ntfy_enabled | bool -- name: Ensure Matrix nginx-proxy configuration for mautrix wsproxy exists - ansible.builtin.template: - src: "{{ role_path }}/templates/nginx/conf.d/matrix-mautrix-wsproxy.conf.j2" - dest: "{{ matrix_nginx_proxy_confd_path }}/matrix-mautrix-wsproxy.conf" - mode: 0644 - when: matrix_nginx_proxy_proxy_mautrix_wsproxy_enabled|bool - - name: Ensure Matrix nginx-proxy configuration for Matrix domain exists ansible.builtin.template: src: "{{ role_path }}/templates/nginx/conf.d/matrix-domain.conf.j2" @@ -341,12 +334,6 @@ state: absent when: "not matrix_nginx_proxy_proxy_ntfy_enabled | bool" -- name: Ensure Matrix nginx-proxy configuration for mautrix wsproxy deleted - ansible.builtin.file: - path: "{{ matrix_nginx_proxy_confd_path }}/matrix-mautrix-wsproxy.conf" - state: absent - when: "not matrix_nginx_proxy_proxy_mautrix_wsproxy_enabled|bool" - - name: Ensure Matrix nginx-proxy configuration for etherpad domain deleted ansible.builtin.file: path: "{{ matrix_nginx_proxy_confd_path }}/matrix-etherpad.conf" diff --git a/roles/custom/matrix-nginx-proxy/templates/nginx/conf.d/matrix-mautrix-wsproxy.conf.j2 b/roles/custom/matrix-nginx-proxy/templates/nginx/conf.d/matrix-mautrix-wsproxy.conf.j2 deleted file mode 100644 index 47e4c4328..000000000 --- a/roles/custom/matrix-nginx-proxy/templates/nginx/conf.d/matrix-mautrix-wsproxy.conf.j2 +++ /dev/null @@ -1,110 +0,0 @@ -#jinja2: lstrip_blocks: "True" - -{% macro render_vhost_directives() %} - gzip on; - gzip_types text/plain application/json application/javascript text/css image/x-icon font/ttf image/gif; - - {% if matrix_nginx_proxy_hsts_preload_enabled %} - add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; - {% else %} - add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; - {% endif %} - add_header X-Content-Type-Options nosniff; - add_header X-XSS-Protection "{{ matrix_nginx_proxy_xss_protection }}"; - add_header X-Frame-Options SAMEORIGIN; - - {% if matrix_nginx_proxy_floc_optout_enabled %} - add_header Permissions-Policy interest-cohort=() always; - {% endif %} - - - {% for configuration_block in matrix_nginx_proxy_proxy_mautrix_wsproxy_additional_server_configuration_blocks %} - {{- configuration_block }} - {% endfor %} - - location / { - {% if matrix_nginx_proxy_enabled %} - {# Use the embedded DNS resolver in Docker containers to discover the service #} - resolver 127.0.0.11 valid=5s; - set $backend "wsproxy:29331"; - proxy_pass http://$backend; - {% else %} - {# Generic configuration for use outside of our container setup #} - proxy_pass http://127.0.0.1:29331; - {% endif %} - - proxy_set_header Host $host; - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - proxy_http_version 1.1; - proxy_send_timeout 1d; - proxy_read_timeout 1d; - - tcp_nodelay on; - } -{% endmacro %} - -server { - listen {{ 8080 if matrix_nginx_proxy_enabled else 80 }}; - - server_name {{ matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname }}; - - server_tokens off; - root /dev/null; - - {% if matrix_nginx_proxy_https_enabled %} - location /.well-known/acme-challenge { - {% if matrix_nginx_proxy_enabled %} - {# Use the embedded DNS resolver in Docker containers to discover the service #} - resolver 127.0.0.11 valid=5s; - set $backend "matrix-certbot:8080"; - proxy_pass http://$backend; - {% else %} - {# Generic configuration for use outside of our container setup #} - proxy_pass http://127.0.0.1:{{ matrix_ssl_lets_encrypt_certbot_standalone_http_port }}; - {% endif %} - } - - location / { - return 301 https://$http_host$request_uri; - } - {% else %} - {{ render_vhost_directives() }} - {% endif %} -} - -{% if matrix_nginx_proxy_https_enabled %} -server { - listen {{ 8443 if matrix_nginx_proxy_enabled else 443 }} ssl http2; - listen [::]:{{ 8443 if matrix_nginx_proxy_enabled else 443 }} ssl http2; - - server_name {{ matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname }}; - - server_tokens off; - root /dev/null; - - ssl_certificate {{ matrix_ssl_config_dir_path }}/live/{{ matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname }}/fullchain.pem; - ssl_certificate_key {{ matrix_ssl_config_dir_path }}/live/{{ matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname }}/privkey.pem; - - ssl_protocols {{ matrix_nginx_proxy_ssl_protocols }}; - {% if matrix_nginx_proxy_ssl_ciphers != "" %} - ssl_ciphers {{ matrix_nginx_proxy_ssl_ciphers }}; - {% endif %} - ssl_prefer_server_ciphers {{ matrix_nginx_proxy_ssl_prefer_server_ciphers }}; - - {% if matrix_nginx_proxy_ocsp_stapling_enabled %} - ssl_stapling on; - ssl_stapling_verify on; - ssl_trusted_certificate {{ matrix_ssl_config_dir_path }}/live/{{ matrix_nginx_proxy_proxy_mautrix_wsproxy_hostname }}/chain.pem; - {% endif %} - - {% if matrix_nginx_proxy_ssl_session_tickets_off %} - ssl_session_tickets off; - {% endif %} - ssl_session_cache {{ matrix_nginx_proxy_ssl_session_cache }}; - ssl_session_timeout {{ matrix_nginx_proxy_ssl_session_timeout }}; - - {{ render_vhost_directives() }} -} -{% endif %} diff --git a/setup.yml b/setup.yml index 0c324700f..4da64ff4b 100644 --- a/setup.yml +++ b/setup.yml @@ -61,7 +61,6 @@ - custom/matrix-bridge-mautrix-telegram - custom/matrix-bridge-mautrix-gmessages - custom/matrix-bridge-mautrix-whatsapp - - custom/matrix-bridge-mautrix-wsproxy - custom/matrix-bridge-mautrix-discord - custom/matrix-bridge-mautrix-slack - custom/matrix-bridge-mx-puppet-discord