Aaron Raimist
9437f78c9e
Build using custom config.json, add CSP, update to 0.1.53
há 4 anos
Slavi Pantaleev
47b4608b96
Fail in a friendlier way when trying to self-build on Ansible <= 2.8
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1070
Related discussion here: 1ab507349c (commitcomment-51108407)
há 4 anos
Slavi Pantaleev
1ab507349c
Fix self-building for various components on Ansible < 2.8
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1070
há 4 anos
Tobias K
3dcbed6353
roles/matrix-grafana: Set root_url in granafa.ini
há 4 anos
sakkiii
8529ca4c17
Update grafana (7.5.6->7.5.7)
há 4 anos
Toni Spets
544915ff76
Add Heisenbridge
há 4 anos
Slavi Pantaleev
21eb39f986
Mention matrix_common_after_systemd_service_start_wait_for_timeout_seconds in failure message
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1062
há 4 anos
Slavi Pantaleev
ee46fabdca
Make waiting time for --tags=start configurable
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1062
há 4 anos
sakkiii
e9b878b9e9
Optimize SSL session
há 4 anos
Slavi Pantaleev
e6afa05f7b
Enable OCSP stapling for the federation port
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1057
Not sure if this is beneficial though.
há 4 anos
Slavi Pantaleev
57a6a98a50
Fix incorrect SSL certificate path
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1057
há 4 anos
sakkiii
d31b55b2a7
SSL-enabled block only
há 4 anos
rakshazi
400371f6dd
Updated Element version (1.7.27 -> 1.7.28)
há 4 anos
Slavi Pantaleev
d156c8caa2
Upgrade Synapse (1.33.2 -> 1.34.0)
há 4 anos
Slavi Pantaleev
e4dd933cf0
Make missing /_synapse/admin correctly return 404 responses
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1058
We may try to capture such calls and return a friendlier response (HTML
or JSON) saying "The Synapse Admin API is not enabled", but that may not
be desirable.
For now, we stick to what "upstream" recommends: "simply
don't proxy these APIs", which should lead to the same kind of 404 that
we have now.
See here: 6660912226/docs/reverse_proxy.md (synapse-administration-endpoints)
há 4 anos
sakkiii
2c3da6599b
Added warning
há 4 anos
sakkiii
0dd4459799
matrix_nginx_proxy_ocsp_stapling_enabled variable added
há 4 anos
sakkiii
c05021640d
Enable OCSP Stapling
há 4 anos
Aaron Raimist
ca361af616
Add Hydrogen
há 4 anos
sakkiii
4bd7d8b5e4
Update grafana (7.5.5->7.5.6)
há 4 anos
sakkiii
d5cd3d443d
Update prometheus (2.26.0->2.27.0)
há 4 anos
Slavi Pantaleev
f481b1a84b
Upgrade matrix-mailer (4.94.2-r0 -> 4.94.2-r0-1)
Related to https://github.com/devture/exim-relay/pull/9
há 4 anos
Slavi Pantaleev
8e6f1876f5
Switch to :latest version of synapse-admin
Related to https://github.com/Awesome-Technologies/synapse-admin/issues/132
We should switch back when >0.8.0 gets released.
há 4 anos
sakkiii
8fc55b30c5
Upgrade Synapse (1.33.1 -> 1.33.2)
This release fixes a denial of service attack (CVE-2021-29471) against Synapse's push rules implementation. Server admins are encouraged to upgrade.
Ref: https://github.com/matrix-org/synapse/releases/tag/v1.33.2
há 4 anos
Michael-GMH
2b4bada72a
fix conditional
há 4 anos
Michael-GMH
0adcef65e6
fix conditional
há 4 anos
Michael-GMH
f70102e40c
no dashes in usernames
há 4 anos
Slavi Pantaleev
f4657b2cdb
Upgrade Element (1.7.26 -> 1.7.27)
há 4 anos
Michael-GMH
4e6f6e179b
GMH 0.4.6 update
há 4 anos
Slavi Pantaleev
3dcc006932
Fix self-building for Coturn
689dcea773 wasn't enough. The `upstream/..` tags are
just upstream sources, without the alpine-based Dockerfile.
We need to use the `docker/..` tags for that (or `master`)
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1032
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
há 4 anos
Slavi Pantaleev
33f0074862
Upgrade matrix-mailer (4.94-r0 -> 4.94.2-r0)
Related to https://github.com/devture/exim-relay/issues/6
há 4 anos
Slavi Pantaleev
a198b87455
Upgrade synapse-admin (0.7.2 -> 0.8.0)
Related to https://github.com/Awesome-Technologies/synapse-admin/issues/132
há 4 anos
Slavi Pantaleev
61220ea487
Upgrade Synapse (1.33.0 -> 1.33.1)
há 4 anos
sakkiii
9174448e5e
get rid of this {% else %}
há 4 anos
sakkiii
0d5fe2d9f7
Update roles/matrix-grafana/templates/grafana.ini.j2
Co-authored-by: Aaron Raimist <aaron@raim.ist>
há 4 anos
Béla Becker
b10655ebb1
Jitsi XMPP Websocket support
Jitsi-meet enabled websockets by default, claiming better reliability.
Matrix-nginx-proxy configuration has been set up according to the
Prosody documentation: https://prosody.im/doc/websocket
há 4 anos
Béla Becker
116bcaa13b
Update jitsi to stable-5765-1
Changelog:
https://github.com/jitsi/docker-jitsi-meet/blob/stable-5765-1/CHANGELOG.md
há 4 anos
sakkiii
37de7fc96a
Updated Reference
há 4 anos
sakkiii
303de935d5
grafana CSP backward compatible with older browsers
há 4 anos
Slavi Pantaleev
d4d1e2e922
Upgrade Synapse (1.32.2 -> 1.33.0)
há 4 anos
Dan Arnfield
cfaa3e598a
Update nginx (1.19.10 -> 1.20.0)
há 4 anos
Dan Arnfield
bec5933db4
Update grafana (7.5.4 -> 7.5.5)
há 4 anos
Michael-GMH
067b61e779
GoMatrixHosting v0.4.5 update
há 4 anos
Slavi Pantaleev
2409c33ea2
Upgrade Element (1.7.25 -> 1.7.26)
há 4 anos
benkuly
49cb2635a2
updated matrix-sms-bridge
há 4 anos
Michael-GMH
a14bf6c2ed
GoMatrixHosting v0.4.4 update
há 4 anos
Slavi Pantaleev
689dcea773
Fix self-building for Coturn
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
há 4 anos
sakkiii
40fe6bd5c1
variable matrix_nginx_proxy_hsts_preload_enable added
há 4 anos
Slavi Pantaleev
389dc26615
Fix Synapse generic worker balancing
Potentially fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1022
há 4 anos
sakkiii
0ccf0fbf1c
HSTS preload + X-XSS enables
**HSTS Preloading:**
In its strongest and recommended form, the [HSTS policy](https://www.chromium.org/hsts ) includes all subdomains, and indicates a willingness to be “preloaded” into browsers:
`Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`
**X-Xss-Protection:**
`1; mode=block` which tells the browser to block the response if it detects an attack rather than sanitising the script.
há 4 anos