Slavi Pantaleev
a198b87455
Upgrade synapse-admin (0.7.2 -> 0.8.0)
Related to https://github.com/Awesome-Technologies/synapse-admin/issues/132
4 jaren geleden
Slavi Pantaleev
61220ea487
Upgrade Synapse (1.33.0 -> 1.33.1)
4 jaren geleden
sakkiii
9174448e5e
get rid of this {% else %}
4 jaren geleden
sakkiii
0d5fe2d9f7
Update roles/matrix-grafana/templates/grafana.ini.j2
Co-authored-by: Aaron Raimist <aaron@raim.ist>
4 jaren geleden
Béla Becker
b10655ebb1
Jitsi XMPP Websocket support
Jitsi-meet enabled websockets by default, claiming better reliability.
Matrix-nginx-proxy configuration has been set up according to the
Prosody documentation: https://prosody.im/doc/websocket
4 jaren geleden
Béla Becker
116bcaa13b
Update jitsi to stable-5765-1
Changelog:
https://github.com/jitsi/docker-jitsi-meet/blob/stable-5765-1/CHANGELOG.md
4 jaren geleden
sakkiii
37de7fc96a
Updated Reference
4 jaren geleden
sakkiii
303de935d5
grafana CSP backward compatible with older browsers
4 jaren geleden
Slavi Pantaleev
d4d1e2e922
Upgrade Synapse (1.32.2 -> 1.33.0)
4 jaren geleden
Dan Arnfield
cfaa3e598a
Update nginx (1.19.10 -> 1.20.0)
4 jaren geleden
Dan Arnfield
bec5933db4
Update grafana (7.5.4 -> 7.5.5)
4 jaren geleden
Michael-GMH
067b61e779
GoMatrixHosting v0.4.5 update
4 jaren geleden
Slavi Pantaleev
2409c33ea2
Upgrade Element (1.7.25 -> 1.7.26)
4 jaren geleden
benkuly
49cb2635a2
updated matrix-sms-bridge
4 jaren geleden
Michael-GMH
a14bf6c2ed
GoMatrixHosting v0.4.4 update
4 jaren geleden
Slavi Pantaleev
689dcea773
Fix self-building for Coturn
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
4 jaren geleden
sakkiii
40fe6bd5c1
variable matrix_nginx_proxy_hsts_preload_enable added
4 jaren geleden
Slavi Pantaleev
389dc26615
Fix Synapse generic worker balancing
Potentially fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1022
4 jaren geleden
sakkiii
0ccf0fbf1c
HSTS preload + X-XSS enables
**HSTS Preloading:**
In its strongest and recommended form, the [HSTS policy](https://www.chromium.org/hsts ) includes all subdomains, and indicates a willingness to be “preloaded” into browsers:
`Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`
**X-Xss-Protection:**
`1; mode=block` which tells the browser to block the response if it detects an attack rather than sanitising the script.
4 jaren geleden
sakkiii
29bba5161b
Element More security headers
More Production ready nginx headers for Matrix client element.
4 jaren geleden
Slavi Pantaleev
f6b371164c
Remove useless variable
4 jaren geleden
Slavi Pantaleev
62c0587b6a
Use Alpine-based Coturn
4 jaren geleden
Slavi Pantaleev
e3fa3e12bc
Upgrade Synapse (1.31 -> 1.32.2)
4 jaren geleden
Michael-GMH
50d7209c5b
GMH v04.3
4 jaren geleden
Slavi Pantaleev
378fabf177
Revert "Upgrade Synapse (1.31 -> 1.32.1)"
This reverts commit 1fb54a37cb .
Seems like it's been pulled or something. It used to exist, but not
anymore. Not sure what's going on.
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1017
Related to
https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4 jaren geleden
Slavi Pantaleev
1fb54a37cb
Upgrade Synapse (1.31 -> 1.32.1)
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4 jaren geleden
Slavi Pantaleev
d691cc0920
Move variable definition a bit
4 jaren geleden
Slavi Pantaleev
e00ef04b57
Add opt-out-of-FLoC headers by default
4 jaren geleden
Slavi Pantaleev
ca786cc343
Revert "Upgrade Synapse (1.31 -> 1.32)"
This reverts commit f825c7c263 .
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
4 jaren geleden
Aaron Raimist
bb64b80697
Upgrade synapse-admin (0.7.0 -> 0.7.2)
4 jaren geleden
Slavi Pantaleev
f825c7c263
Upgrade Synapse (1.31 -> 1.32)
4 jaren geleden
Slavi Pantaleev
adcecaffaf
Fix connectivity between prometheus and prometheus-node-exporter
Expected to have regressed after https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1008
This patch comes with its own downsides (as described in the comments
for matrix_prometheus_node_exporter_container_http_host_bind_port),
but at least there's:
- no security issue
- metrics remain readable from matrix-prometheus (even if the network metrics are inaccurate)
A better patch is certainly welcome.
4 jaren geleden
Dan Arnfield
b2ca1f2829
Add capability required by new image
4 jaren geleden
Dan Arnfield
29177d4922
Switch to official coturn docker image
4 jaren geleden
sak
88a30fb5ed
security** node-exporter data & port publicly exposed
4 jaren geleden
sak
0f9a455719
Revert "security** node-exporter data & port publicly exposed"
This reverts commit d0cd709c08 .
4 jaren geleden
sak
d0cd709c08
security** node-exporter data & port publicly exposed
4 jaren geleden
teutat3s
2bf7c26cfa
Don't expose nginx version with each response
4 jaren geleden
Dan Arnfield
f04614a993
Fix prometheus network for ansible < 2.8
4 jaren geleden
Slavi Pantaleev
badd81e0ec
Revert "Attempt to fix docker_network result discrepancy between Ansible versions"
This reverts commit 68ca81c8c2 .
4 jaren geleden
sakkiii
1958d0792d
Update matrix-client-element.conf.j2
4 jaren geleden
sakkiii
05042f5ff1
Improve security grafana
- duplicate X-Content-Type-Options
- X-Frame-Options header
- Referrer-Policy [Might consider adding variable]
- Secure flag with cookies
- matrix_grafana_content_security_policy variable for [Content Security Policy](https://grafana.com/docs/grafana/latest/administration/configuration/#content_security_policy )
4 jaren geleden
sakkiii
27377e099d
updated matrix_grafana_docker_image to v7.5.4
Latest stable grafana version is [7.5.4 (2021-04-14)](https://github.com/grafana/grafana/releases/tag/v7.5.4 )
4 jaren geleden
Slavi Pantaleev
68ca81c8c2
Attempt to fix docker_network result discrepancy between Ansible versions
Supposedly fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/907
4 jaren geleden
Dan Arnfield
8a550ce67c
Update prometheus (2.24.1->2.26.0)
4 jaren geleden
Dan Arnfield
83cc5c9e6a
Update prometheus node exporter (1.1.0 -> 1.1.2)
4 jaren geleden
sakkiii
5dc642ace1
Nginx element web: XSS protection & nosniff header
X-XSS-Protection: 1; mode=block; header, for basic XSS protection in legacy browsers.
X-Content-Type-Options: nosniff header, to disable MIME sniffing
4 jaren geleden
Slavi Pantaleev
fcb9e9618a
Make Coturn TLSv1/v1.1 configurable
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/999
4 jaren geleden
sakkiii
540416e32d
Disable support for TLS 1.0 and TLS 1.1
These old versions of TLS rely on MD5 and SHA-1, both now broken, and contain other flaws. TLS 1.0 is no longer PCI-DSS compliant and the TLS working group has adopted a document to deprecate TLS 1.0 and TLS 1.1.
4 jaren geleden
Michael-GMH
89cb5a3d7a
GMH v0.4.2 update
4 jaren geleden