Michael-GMH
a14bf6c2ed
GoMatrixHosting v0.4.4 update
4年前
Slavi Pantaleev
689dcea773
Fix self-building for Coturn
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
4年前
sakkiii
40fe6bd5c1
variable matrix_nginx_proxy_hsts_preload_enable added
4年前
Slavi Pantaleev
389dc26615
Fix Synapse generic worker balancing
Potentially fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1022
4年前
sakkiii
0ccf0fbf1c
HSTS preload + X-XSS enables
**HSTS Preloading:**
In its strongest and recommended form, the [HSTS policy](https://www.chromium.org/hsts ) includes all subdomains, and indicates a willingness to be “preloaded” into browsers:
`Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`
**X-Xss-Protection:**
`1; mode=block` which tells the browser to block the response if it detects an attack rather than sanitising the script.
4年前
sakkiii
29bba5161b
Element More security headers
More Production ready nginx headers for Matrix client element.
4年前
Slavi Pantaleev
f6b371164c
Remove useless variable
4年前
Slavi Pantaleev
62c0587b6a
Use Alpine-based Coturn
4年前
Slavi Pantaleev
e3fa3e12bc
Upgrade Synapse (1.31 -> 1.32.2)
4年前
Michael-GMH
50d7209c5b
GMH v04.3
4年前
Slavi Pantaleev
378fabf177
Revert "Upgrade Synapse (1.31 -> 1.32.1)"
This reverts commit 1fb54a37cb .
Seems like it's been pulled or something. It used to exist, but not
anymore. Not sure what's going on.
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1017
Related to
https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4年前
Slavi Pantaleev
1fb54a37cb
Upgrade Synapse (1.31 -> 1.32.1)
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4年前
Slavi Pantaleev
d691cc0920
Move variable definition a bit
4年前
Slavi Pantaleev
e00ef04b57
Add opt-out-of-FLoC headers by default
4年前
Slavi Pantaleev
ca786cc343
Revert "Upgrade Synapse (1.31 -> 1.32)"
This reverts commit f825c7c263 .
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4年前
Aaron Raimist
bb64b80697
Upgrade synapse-admin (0.7.0 -> 0.7.2)
4年前
Slavi Pantaleev
f825c7c263
Upgrade Synapse (1.31 -> 1.32)
4年前
Slavi Pantaleev
adcecaffaf
Fix connectivity between prometheus and prometheus-node-exporter
Expected to have regressed after https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1008
This patch comes with its own downsides (as described in the comments
for matrix_prometheus_node_exporter_container_http_host_bind_port),
but at least there's:
- no security issue
- metrics remain readable from matrix-prometheus (even if the network metrics are inaccurate)
A better patch is certainly welcome.
5年前
Dan Arnfield
b2ca1f2829
Add capability required by new image
5年前
Dan Arnfield
29177d4922
Switch to official coturn docker image
5年前
sak
88a30fb5ed
security** node-exporter data & port publicly exposed
5年前
sak
0f9a455719
Revert "security** node-exporter data & port publicly exposed"
This reverts commit d0cd709c08 .
5年前
sak
d0cd709c08
security** node-exporter data & port publicly exposed
5年前
teutat3s
2bf7c26cfa
Don't expose nginx version with each response
5年前
Dan Arnfield
f04614a993
Fix prometheus network for ansible < 2.8
5年前
Slavi Pantaleev
badd81e0ec
Revert "Attempt to fix docker_network result discrepancy between Ansible versions"
This reverts commit 68ca81c8c2 .
5年前
sakkiii
1958d0792d
Update matrix-client-element.conf.j2
5年前
sakkiii
05042f5ff1
Improve security grafana
- duplicate X-Content-Type-Options
- X-Frame-Options header
- Referrer-Policy [Might consider adding variable]
- Secure flag with cookies
- matrix_grafana_content_security_policy variable for [Content Security Policy](https://grafana.com/docs/grafana/latest/administration/configuration/#content_security_policy )
5年前
sakkiii
27377e099d
updated matrix_grafana_docker_image to v7.5.4
Latest stable grafana version is [7.5.4 (2021-04-14)](https://github.com/grafana/grafana/releases/tag/v7.5.4 )
5年前
Slavi Pantaleev
68ca81c8c2
Attempt to fix docker_network result discrepancy between Ansible versions
Supposedly fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/907
5年前
Dan Arnfield
8a550ce67c
Update prometheus (2.24.1->2.26.0)
5年前
Dan Arnfield
83cc5c9e6a
Update prometheus node exporter (1.1.0 -> 1.1.2)
5年前
sakkiii
5dc642ace1
Nginx element web: XSS protection & nosniff header
X-XSS-Protection: 1; mode=block; header, for basic XSS protection in legacy browsers.
X-Content-Type-Options: nosniff header, to disable MIME sniffing
5年前
Slavi Pantaleev
fcb9e9618a
Make Coturn TLSv1/v1.1 configurable
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/999
5年前
sakkiii
540416e32d
Disable support for TLS 1.0 and TLS 1.1
These old versions of TLS rely on MD5 and SHA-1, both now broken, and contain other flaws. TLS 1.0 is no longer PCI-DSS compliant and the TLS working group has adopted a document to deprecate TLS 1.0 and TLS 1.1.
5年前
Michael-GMH
89cb5a3d7a
GMH v0.4.2 update
5年前
Slavi Pantaleev
c7c137df74
Upgrade nginx and certbot
5年前
Slavi Pantaleev
931452bb06
Upgrade exim (4.93 -> 4.94)
5年前
rakshazi
4f8e1bd43a
Updated Element Web 1.7.24.1 -> 1.7.25
5年前
Ahmad Haghighi
e335f3fc77
rename matrix_global_registry to matrix_container_global_registry_prefix related to #990
Signed-off-by: Ahmad Haghighi <haghighi@fedoraproject.org>
5年前
Ahmad Haghighi
f52a8b6484
use custom docker registry
5年前
Aaron Raimist
3d2142f88b
Add sanity check for server architecture
5年前
Marcus
3e119e483e
Update init.yml
fix nginx boot loop
5年前
Slavi Pantaleev
4830b7d830
Upgrade Synapse for ARM64 (1.30.1 -> 1.31.0)
5年前
Slavi Pantaleev
3f426de599
Upgrade Synapse (1.30.1 -> 1.31.0)
5年前
Slavi Pantaleev
c386e8e9db
Use integers for some variables
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/868
5年前
Slavi Pantaleev
832e191ab8
Fix incorrect variable usage in when statement
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/868
5年前
Slavi Pantaleev
1b55766927
Do not redefine matrix-postgres role vars in matrix-postgres-backup
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/868
5年前
Slavi Pantaleev
298556e02e
Fix undefined matrix_postgres_backup_detected_version_corresponding_docker_image
.. and prevent variable name overlap with `matrix-postgres` for the
other variables as well.
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/868
5年前
foxcris
2178f3612f
- matrix_postgres_backup_databases now uses more simple structure
5年前