Slavi Pantaleev
e4dd933cf0
Make missing /_synapse/admin correctly return 404 responses
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1058
We may try to capture such calls and return a friendlier response (HTML
or JSON) saying "The Synapse Admin API is not enabled", but that may not
be desirable.
For now, we stick to what "upstream" recommends: "simply
don't proxy these APIs", which should lead to the same kind of 404 that
we have now.
See here: 6660912226/docs/reverse_proxy.md (synapse-administration-endpoints)
4年前
sakkiii
2c3da6599b
Added warning
4年前
sakkiii
0dd4459799
matrix_nginx_proxy_ocsp_stapling_enabled variable added
4年前
sakkiii
c05021640d
Enable OCSP Stapling
4年前
Aaron Raimist
ca361af616
Add Hydrogen
4年前
sakkiii
4bd7d8b5e4
Update grafana (7.5.5->7.5.6)
4年前
sakkiii
d5cd3d443d
Update prometheus (2.26.0->2.27.0)
4年前
Slavi Pantaleev
f481b1a84b
Upgrade matrix-mailer (4.94.2-r0 -> 4.94.2-r0-1)
Related to https://github.com/devture/exim-relay/pull/9
4年前
Slavi Pantaleev
8e6f1876f5
Switch to :latest version of synapse-admin
Related to https://github.com/Awesome-Technologies/synapse-admin/issues/132
We should switch back when >0.8.0 gets released.
4年前
sakkiii
8fc55b30c5
Upgrade Synapse (1.33.1 -> 1.33.2)
This release fixes a denial of service attack (CVE-2021-29471) against Synapse's push rules implementation. Server admins are encouraged to upgrade.
Ref: https://github.com/matrix-org/synapse/releases/tag/v1.33.2
4年前
Michael-GMH
2b4bada72a
fix conditional
4年前
Michael-GMH
0adcef65e6
fix conditional
4年前
Michael-GMH
f70102e40c
no dashes in usernames
4年前
Slavi Pantaleev
f4657b2cdb
Upgrade Element (1.7.26 -> 1.7.27)
4年前
Michael-GMH
4e6f6e179b
GMH 0.4.6 update
4年前
Slavi Pantaleev
3dcc006932
Fix self-building for Coturn
689dcea773 wasn't enough. The `upstream/..` tags are
just upstream sources, without the alpine-based Dockerfile.
We need to use the `docker/..` tags for that (or `master`)
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1032
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
4年前
Slavi Pantaleev
33f0074862
Upgrade matrix-mailer (4.94-r0 -> 4.94.2-r0)
Related to https://github.com/devture/exim-relay/issues/6
4年前
Slavi Pantaleev
a198b87455
Upgrade synapse-admin (0.7.2 -> 0.8.0)
Related to https://github.com/Awesome-Technologies/synapse-admin/issues/132
4年前
Slavi Pantaleev
61220ea487
Upgrade Synapse (1.33.0 -> 1.33.1)
4年前
sakkiii
9174448e5e
get rid of this {% else %}
4年前
sakkiii
0d5fe2d9f7
Update roles/matrix-grafana/templates/grafana.ini.j2
Co-authored-by: Aaron Raimist <aaron@raim.ist>
4年前
Béla Becker
b10655ebb1
Jitsi XMPP Websocket support
Jitsi-meet enabled websockets by default, claiming better reliability.
Matrix-nginx-proxy configuration has been set up according to the
Prosody documentation: https://prosody.im/doc/websocket
4年前
Béla Becker
116bcaa13b
Update jitsi to stable-5765-1
Changelog:
https://github.com/jitsi/docker-jitsi-meet/blob/stable-5765-1/CHANGELOG.md
4年前
sakkiii
37de7fc96a
Updated Reference
4年前
sakkiii
303de935d5
grafana CSP backward compatible with older browsers
4年前
Slavi Pantaleev
d4d1e2e922
Upgrade Synapse (1.32.2 -> 1.33.0)
4年前
Dan Arnfield
cfaa3e598a
Update nginx (1.19.10 -> 1.20.0)
4年前
Dan Arnfield
bec5933db4
Update grafana (7.5.4 -> 7.5.5)
4年前
Michael-GMH
067b61e779
GoMatrixHosting v0.4.5 update
4年前
Slavi Pantaleev
2409c33ea2
Upgrade Element (1.7.25 -> 1.7.26)
4年前
benkuly
49cb2635a2
updated matrix-sms-bridge
4年前
Michael-GMH
a14bf6c2ed
GoMatrixHosting v0.4.4 update
4年前
Slavi Pantaleev
689dcea773
Fix self-building for Coturn
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
5年前
sakkiii
40fe6bd5c1
variable matrix_nginx_proxy_hsts_preload_enable added
5年前
Slavi Pantaleev
389dc26615
Fix Synapse generic worker balancing
Potentially fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1022
5年前
sakkiii
0ccf0fbf1c
HSTS preload + X-XSS enables
**HSTS Preloading:**
In its strongest and recommended form, the [HSTS policy](https://www.chromium.org/hsts ) includes all subdomains, and indicates a willingness to be “preloaded” into browsers:
`Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`
**X-Xss-Protection:**
`1; mode=block` which tells the browser to block the response if it detects an attack rather than sanitising the script.
5年前
sakkiii
29bba5161b
Element More security headers
More Production ready nginx headers for Matrix client element.
5年前
Slavi Pantaleev
f6b371164c
Remove useless variable
5年前
Slavi Pantaleev
62c0587b6a
Use Alpine-based Coturn
5年前
Slavi Pantaleev
e3fa3e12bc
Upgrade Synapse (1.31 -> 1.32.2)
5年前
Michael-GMH
50d7209c5b
GMH v04.3
5年前
Slavi Pantaleev
378fabf177
Revert "Upgrade Synapse (1.31 -> 1.32.1)"
This reverts commit 1fb54a37cb .
Seems like it's been pulled or something. It used to exist, but not
anymore. Not sure what's going on.
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1017
Related to
https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
5年前
Slavi Pantaleev
1fb54a37cb
Upgrade Synapse (1.31 -> 1.32.1)
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
5年前
Slavi Pantaleev
d691cc0920
Move variable definition a bit
5年前
Slavi Pantaleev
e00ef04b57
Add opt-out-of-FLoC headers by default
5年前
Slavi Pantaleev
ca786cc343
Revert "Upgrade Synapse (1.31 -> 1.32)"
This reverts commit f825c7c263 .
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
5年前
Aaron Raimist
bb64b80697
Upgrade synapse-admin (0.7.0 -> 0.7.2)
5年前
Slavi Pantaleev
f825c7c263
Upgrade Synapse (1.31 -> 1.32)
5年前
Slavi Pantaleev
adcecaffaf
Fix connectivity between prometheus and prometheus-node-exporter
Expected to have regressed after https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1008
This patch comes with its own downsides (as described in the comments
for matrix_prometheus_node_exporter_container_http_host_bind_port),
but at least there's:
- no security issue
- metrics remain readable from matrix-prometheus (even if the network metrics are inaccurate)
A better patch is certainly welcome.
5年前
Dan Arnfield
b2ca1f2829
Add capability required by new image
5年前