| @@ -110,16 +110,6 @@ matrix_dendrite_turn_uris: [] | |||||
| matrix_dendrite_turn_shared_secret: "" | matrix_dendrite_turn_shared_secret: "" | ||||
| matrix_dendrite_turn_allow_guests: False | matrix_dendrite_turn_allow_guests: False | ||||
| matrix_s3_media_store_enabled: false | |||||
| matrix_s3_media_store_custom_endpoint_enabled: false | |||||
| matrix_s3_goofys_docker_image: "ewoutp/goofys:latest" | |||||
| matrix_s3_goofys_docker_image_force_pull: "{{ matrix_s3_goofys_docker_image.endswith(':latest') }}" | |||||
| matrix_s3_media_store_custom_endpoint: "your-custom-endpoint" | |||||
| matrix_s3_media_store_bucket_name: "your-bucket-name" | |||||
| matrix_s3_media_store_aws_access_key: "your-aws-access-key" | |||||
| matrix_s3_media_store_aws_secret_key: "your-aws-secret-key" | |||||
| matrix_s3_media_store_region: "eu-central-1" | |||||
| # Controls whether the self-check feature should validate TLS certificates. | # Controls whether the self-check feature should validate TLS certificates. | ||||
| matrix_dendrite_disable_tls_validation: false | matrix_dendrite_disable_tls_validation: false | ||||
| @@ -1,7 +0,0 @@ | |||||
| --- | |||||
| - import_tasks: "{{ role_path }}/tasks/goofys/setup_install.yml" | |||||
| when: matrix_s3_media_store_enabled|bool | |||||
| - import_tasks: "{{ role_path }}/tasks/goofys/setup_uninstall.yml" | |||||
| when: "not matrix_s3_media_store_enabled|bool" | |||||
| @@ -1,41 +0,0 @@ | |||||
| - name: Ensure Goofys Docker image is pulled | |||||
| docker_image: | |||||
| name: "{{ matrix_s3_goofys_docker_image }}" | |||||
| source: "{{ 'pull' if ansible_version.major > 2 or ansible_version.minor > 7 else omit }}" | |||||
| force_source: "{{ matrix_s3_goofys_docker_image_force_pull if ansible_version.major > 2 or ansible_version.minor >= 8 else omit }}" | |||||
| force: "{{ omit if ansible_version.major > 2 or ansible_version.minor >= 8 else matrix_s3_goofys_docker_image_force_pull }}" | |||||
| # This will throw a Permission Denied error if already mounted | |||||
| - name: Check Matrix Goofys external storage mountpoint path | |||||
| stat: | |||||
| path: "{{ matrix_dendrite_media_store_path }}" | |||||
| register: local_path_matrix_dendrite_media_store_path_stat | |||||
| ignore_errors: yes | |||||
| - name: Ensure Matrix Goofys external storage mountpoint exists | |||||
| file: | |||||
| path: "{{ matrix_dendrite_media_store_path if matrix_dendrite_enabled else matrix_dendrite_media_store_path }}" | |||||
| state: directory | |||||
| mode: 0750 | |||||
| owner: "{{ matrix_user_username }}" | |||||
| group: "{{ matrix_user_groupname }}" | |||||
| when: "not local_path_matrix_dendrite_media_store_path_stat.failed and not local_path_matrix_dendrite_media_store_path_stat.stat.exists" | |||||
| - name: Ensure goofys environment variables file created | |||||
| template: | |||||
| src: "{{ role_path }}/templates/goofys/env-goofys.j2" | |||||
| dest: "{{ matrix_dendrite_config_dir_path }}/env-goofys" | |||||
| owner: root | |||||
| mode: 0600 | |||||
| - name: Ensure matrix-goofys.service installed | |||||
| template: | |||||
| src: "{{ role_path }}/templates/goofys/systemd/matrix-goofys.service.j2" | |||||
| dest: "{{ matrix_systemd_path }}/matrix-goofys.service" | |||||
| mode: 0644 | |||||
| register: matrix_goofys_systemd_service_result | |||||
| - name: Ensure systemd reloaded after matrix-goofys.service installation | |||||
| service: | |||||
| daemon_reload: yes | |||||
| when: "matrix_goofys_systemd_service_result.changed" | |||||
| @@ -1,33 +0,0 @@ | |||||
| - name: Check existence of matrix-goofys service | |||||
| stat: | |||||
| path: "{{ matrix_systemd_path }}/matrix-goofys.service" | |||||
| register: matrix_goofys_service_stat | |||||
| - name: Ensure matrix-goofys is stopped | |||||
| service: | |||||
| name: matrix-goofys | |||||
| state: stopped | |||||
| daemon_reload: yes | |||||
| register: stopping_result | |||||
| when: "matrix_goofys_service_stat.stat.exists" | |||||
| - name: Ensure matrix-goofys.service doesn't exist | |||||
| file: | |||||
| path: "{{ matrix_systemd_path }}/matrix-goofys.service" | |||||
| state: absent | |||||
| when: "matrix_goofys_service_stat.stat.exists" | |||||
| - name: Ensure systemd reloaded after matrix-goofys.service removal | |||||
| service: | |||||
| daemon_reload: yes | |||||
| when: "matrix_goofys_service_stat.stat.exists" | |||||
| - name: Ensure goofys environment variables file doesn't exist | |||||
| file: | |||||
| path: "{{ matrix_dendrite_config_dir_path }}/env-goofys" | |||||
| state: absent | |||||
| - name: Ensure Goofys Docker image doesn't exist | |||||
| docker_image: | |||||
| name: "{{ matrix_s3_goofys_docker_image }}" | |||||
| state: absent | |||||
| @@ -1,81 +0,0 @@ | |||||
| --- | |||||
| # Pre-checks | |||||
| - name: Fail if playbook called incorrectly | |||||
| fail: | |||||
| msg: "The `server_path_media_store` variable needs to be provided to this playbook, via --extra-vars" | |||||
| when: "server_path_media_store is not defined or server_path_media_store.startswith('<')" | |||||
| - name: Fail if media store is on Amazon S3 | |||||
| fail: | |||||
| msg: "Your media store is on Amazon S3. Due to technical limitations, restoring is not supported." | |||||
| when: matrix_s3_media_store_enabled|bool | |||||
| - name: Check if the provided media store directory exists | |||||
| stat: | |||||
| path: "{{ server_path_media_store }}" | |||||
| register: server_path_media_store_stat | |||||
| - name: Fail if provided media store directory doesn't exist on the server | |||||
| fail: | |||||
| msg: "{{ server_path_media_store }} cannot be found on the server" | |||||
| when: "not server_path_media_store_stat.stat.exists or not server_path_media_store_stat.stat.isdir" | |||||
| - name: Check if media store contains local_content | |||||
| stat: | |||||
| path: "{{ server_path_media_store }}/local_content" | |||||
| register: server_path_media_store_local_content_stat | |||||
| - name: Check if media store contains remote_content | |||||
| stat: | |||||
| path: "{{ server_path_media_store }}/remote_content" | |||||
| register: server_path_media_store_remote_content_stat | |||||
| - name: Fail if media store directory doesn't look okay (lacking remote and local content) | |||||
| fail: | |||||
| msg: "{{ server_path_media_store }} contains neither local_content nor remote_content directories. It's most likely a mistake and is not a media store directory." | |||||
| when: "not server_path_media_store_local_content_stat.stat.exists and not server_path_media_store_remote_content_stat.stat.exists" | |||||
| # Actual import work | |||||
| - name: Ensure matrix-dendrite is stopped | |||||
| service: | |||||
| name: matrix-dendrite | |||||
| state: stopped | |||||
| daemon_reload: yes | |||||
| register: stopping_result | |||||
| # This can only work with local files, not if the media store is on Amazon S3, | |||||
| # as it won't be accessible in such a case. | |||||
| - name: Ensure provided media store directory is synchronized | |||||
| synchronize: | |||||
| src: "{{ server_path_media_store }}/" | |||||
| dest: "{{ matrix_dendrite_media_store_path }}" | |||||
| delete: yes | |||||
| # It's wasteful to preserve owner/group now. We chown below anyway. | |||||
| owner: no | |||||
| group: no | |||||
| times: yes | |||||
| delegate_to: "{{ inventory_hostname }}" | |||||
| # This is for the generic case and fails in other cases (remote file systems), | |||||
| # because in such cases the base path (matrix_dendrite_media_store_path) is a mount point. | |||||
| - name: Ensure media store permissions are correct (generic case) | |||||
| file: | |||||
| path: "{{ matrix_dendrite_media_store_path }}" | |||||
| owner: "{{ matrix_user_username }}" | |||||
| group: "{{ matrix_user_groupname }}" | |||||
| recurse: yes | |||||
| when: "not matrix_s3_media_store_enabled|bool" | |||||
| # We don't chown for Goofys, because due to the way it's mounted, | |||||
| # all files become owned by whoever needs to own them. | |||||
| - name: Ensure Dendrite is started (if it previously was) | |||||
| service: | |||||
| name: "{{ item }}" | |||||
| state: started | |||||
| daemon_reload: yes | |||||
| when: "stopping_result.changed" | |||||
| with_items: | |||||
| - matrix-dendrite | |||||
| @@ -14,11 +14,6 @@ | |||||
| - setup-all | - setup-all | ||||
| - setup-dendrite | - setup-dendrite | ||||
| - import_tasks: "{{ role_path }}/tasks/import_media_store.yml" | |||||
| when: run_dendrite_import_media_store|bool | |||||
| tags: | |||||
| - import-dendrite-media-store | |||||
| - import_tasks: "{{ role_path }}/tasks/register_user.yml" | - import_tasks: "{{ role_path }}/tasks/register_user.yml" | ||||
| when: run_dendrite_register_user|bool | when: run_dendrite_register_user|bool | ||||
| tags: | tags: | ||||
| @@ -15,5 +15,3 @@ | |||||
| when: "(matrix_dendrite_enabled|bool or matrix_s3_media_store_enabled|bool) and item.when" | when: "(matrix_dendrite_enabled|bool or matrix_s3_media_store_enabled|bool) and item.when" | ||||
| - import_tasks: "{{ role_path }}/tasks/dendrite/setup.yml" | - import_tasks: "{{ role_path }}/tasks/dendrite/setup.yml" | ||||
| - import_tasks: "{{ role_path }}/tasks/goofys/setup.yml" | |||||
| @@ -1,3 +0,0 @@ | |||||
| #jinja2: lstrip_blocks: "True" | |||||
| AWS_ACCESS_KEY={{ matrix_s3_media_store_aws_access_key }} | |||||
| AWS_SECRET_KEY={{ matrix_s3_media_store_aws_secret_key }} | |||||
| @@ -1,39 +0,0 @@ | |||||
| #jinja2: lstrip_blocks: "True" | |||||
| [Unit] | |||||
| Description=Matrix Goofys media store | |||||
| After=docker.service | |||||
| Requires=docker.service | |||||
| DefaultDependencies=no | |||||
| [Service] | |||||
| Type=simple | |||||
| Environment="HOME={{ matrix_systemd_unit_home_path }}" | |||||
| ExecStartPre=-{{ matrix_host_command_docker }} kill %n | |||||
| ExecStartPre=-{{ matrix_host_command_docker }} rm %n | |||||
| ExecStart={{ matrix_host_command_docker }} run --rm --name %n \ | |||||
| --log-driver=none \ | |||||
| --user={{ matrix_user_uid }}:{{ matrix_user_gid }} \ | |||||
| --mount type=bind,src=/etc/passwd,dst=/etc/passwd,ro \ | |||||
| --mount type=bind,src=/etc/group,dst=/etc/group,ro \ | |||||
| --mount type=bind,src={{ matrix_dendrite_media_store_path }},dst=/s3,bind-propagation=shared \ | |||||
| --security-opt apparmor:unconfined \ | |||||
| --cap-add mknod \ | |||||
| --cap-add sys_admin \ | |||||
| --device=/dev/fuse \ | |||||
| --env-file={{ matrix_dendrite_config_dir_path }}/env-goofys \ | |||||
| --entrypoint /bin/sh \ | |||||
| {{ matrix_s3_goofys_docker_image }} \ | |||||
| -c 'goofys -f{% if not matrix_s3_media_store_custom_endpoint_enabled %} --storage-class=STANDARD_IA{% endif %}{% if matrix_s3_media_store_custom_endpoint_enabled %} --endpoint={{ matrix_s3_media_store_custom_endpoint }}{% endif %} --region {{ matrix_s3_media_store_region }} --stat-cache-ttl 60m0s --type-cache-ttl 60m0s --dir-mode 0700 --file-mode 0700 {{ matrix_s3_media_store_bucket_name }} /s3' | |||||
| TimeoutStartSec=5min | |||||
| ExecStop=-{{ matrix_host_command_docker }} stop %n | |||||
| ExecStop=-{{ matrix_host_command_docker }} kill %n | |||||
| ExecStop=-{{ matrix_host_command_docker }} rm %n | |||||
| ExecStop=-{{ matrix_host_command_fusermount }} -u {{ matrix_dendrite_media_store_path }} | |||||
| Restart=always | |||||
| RestartSec=5 | |||||
| SyslogIdentifier=matrix-goofys | |||||
| [Install] | |||||
| WantedBy=multi-user.target | |||||