Slavi Pantaleev
61220ea487
Upgrade Synapse (1.33.0 -> 1.33.1)
il y a 4 ans
sakkiii
9174448e5e
get rid of this {% else %}
il y a 4 ans
sakkiii
0d5fe2d9f7
Update roles/matrix-grafana/templates/grafana.ini.j2
Co-authored-by: Aaron Raimist <aaron@raim.ist>
il y a 4 ans
Béla Becker
b10655ebb1
Jitsi XMPP Websocket support
Jitsi-meet enabled websockets by default, claiming better reliability.
Matrix-nginx-proxy configuration has been set up according to the
Prosody documentation: https://prosody.im/doc/websocket
il y a 4 ans
Béla Becker
116bcaa13b
Update jitsi to stable-5765-1
Changelog:
https://github.com/jitsi/docker-jitsi-meet/blob/stable-5765-1/CHANGELOG.md
il y a 4 ans
sakkiii
37de7fc96a
Updated Reference
il y a 4 ans
sakkiii
303de935d5
grafana CSP backward compatible with older browsers
il y a 4 ans
Slavi Pantaleev
d4d1e2e922
Upgrade Synapse (1.32.2 -> 1.33.0)
il y a 4 ans
Dan Arnfield
cfaa3e598a
Update nginx (1.19.10 -> 1.20.0)
il y a 4 ans
Dan Arnfield
bec5933db4
Update grafana (7.5.4 -> 7.5.5)
il y a 4 ans
Michael-GMH
067b61e779
GoMatrixHosting v0.4.5 update
il y a 4 ans
Slavi Pantaleev
2409c33ea2
Upgrade Element (1.7.25 -> 1.7.26)
il y a 4 ans
benkuly
49cb2635a2
updated matrix-sms-bridge
il y a 4 ans
Michael-GMH
a14bf6c2ed
GoMatrixHosting v0.4.4 update
il y a 4 ans
Slavi Pantaleev
689dcea773
Fix self-building for Coturn
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1023
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1009
il y a 4 ans
sakkiii
40fe6bd5c1
variable matrix_nginx_proxy_hsts_preload_enable added
il y a 4 ans
Slavi Pantaleev
389dc26615
Fix Synapse generic worker balancing
Potentially fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1022
il y a 4 ans
sakkiii
0ccf0fbf1c
HSTS preload + X-XSS enables
**HSTS Preloading:**
In its strongest and recommended form, the [HSTS policy](https://www.chromium.org/hsts ) includes all subdomains, and indicates a willingness to be “preloaded” into browsers:
`Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`
**X-Xss-Protection:**
`1; mode=block` which tells the browser to block the response if it detects an attack rather than sanitising the script.
il y a 4 ans
sakkiii
29bba5161b
Element More security headers
More Production ready nginx headers for Matrix client element.
il y a 4 ans
Slavi Pantaleev
f6b371164c
Remove useless variable
il y a 4 ans
Slavi Pantaleev
62c0587b6a
Use Alpine-based Coturn
il y a 4 ans
Slavi Pantaleev
e3fa3e12bc
Upgrade Synapse (1.31 -> 1.32.2)
il y a 4 ans
Michael-GMH
50d7209c5b
GMH v04.3
il y a 4 ans
Slavi Pantaleev
378fabf177
Revert "Upgrade Synapse (1.31 -> 1.32.1)"
This reverts commit 1fb54a37cb .
Seems like it's been pulled or something. It used to exist, but not
anymore. Not sure what's going on.
Fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1017
Related to
https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
il y a 4 ans
Slavi Pantaleev
1fb54a37cb
Upgrade Synapse (1.31 -> 1.32.1)
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
il y a 4 ans
Slavi Pantaleev
d691cc0920
Move variable definition a bit
il y a 4 ans
Slavi Pantaleev
e00ef04b57
Add opt-out-of-FLoC headers by default
il y a 4 ans
Slavi Pantaleev
ca786cc343
Revert "Upgrade Synapse (1.31 -> 1.32)"
This reverts commit f825c7c263 .
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/1010
il y a 4 ans
Aaron Raimist
bb64b80697
Upgrade synapse-admin (0.7.0 -> 0.7.2)
il y a 4 ans
Slavi Pantaleev
f825c7c263
Upgrade Synapse (1.31 -> 1.32)
il y a 4 ans
Slavi Pantaleev
adcecaffaf
Fix connectivity between prometheus and prometheus-node-exporter
Expected to have regressed after https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/1008
This patch comes with its own downsides (as described in the comments
for matrix_prometheus_node_exporter_container_http_host_bind_port),
but at least there's:
- no security issue
- metrics remain readable from matrix-prometheus (even if the network metrics are inaccurate)
A better patch is certainly welcome.
il y a 4 ans
Dan Arnfield
b2ca1f2829
Add capability required by new image
il y a 4 ans
Dan Arnfield
29177d4922
Switch to official coturn docker image
il y a 4 ans
sak
88a30fb5ed
security** node-exporter data & port publicly exposed
il y a 4 ans
sak
0f9a455719
Revert "security** node-exporter data & port publicly exposed"
This reverts commit d0cd709c08 .
il y a 4 ans
sak
d0cd709c08
security** node-exporter data & port publicly exposed
il y a 4 ans
teutat3s
2bf7c26cfa
Don't expose nginx version with each response
il y a 4 ans
Dan Arnfield
f04614a993
Fix prometheus network for ansible < 2.8
il y a 4 ans
Slavi Pantaleev
badd81e0ec
Revert "Attempt to fix docker_network result discrepancy between Ansible versions"
This reverts commit 68ca81c8c2 .
il y a 4 ans
sakkiii
1958d0792d
Update matrix-client-element.conf.j2
il y a 4 ans
sakkiii
05042f5ff1
Improve security grafana
- duplicate X-Content-Type-Options
- X-Frame-Options header
- Referrer-Policy [Might consider adding variable]
- Secure flag with cookies
- matrix_grafana_content_security_policy variable for [Content Security Policy](https://grafana.com/docs/grafana/latest/administration/configuration/#content_security_policy )
il y a 4 ans
sakkiii
27377e099d
updated matrix_grafana_docker_image to v7.5.4
Latest stable grafana version is [7.5.4 (2021-04-14)](https://github.com/grafana/grafana/releases/tag/v7.5.4 )
il y a 4 ans
Slavi Pantaleev
68ca81c8c2
Attempt to fix docker_network result discrepancy between Ansible versions
Supposedly fixes https://github.com/spantaleev/matrix-docker-ansible-deploy/issues/907
il y a 4 ans
Dan Arnfield
8a550ce67c
Update prometheus (2.24.1->2.26.0)
il y a 4 ans
Dan Arnfield
83cc5c9e6a
Update prometheus node exporter (1.1.0 -> 1.1.2)
il y a 4 ans
sakkiii
5dc642ace1
Nginx element web: XSS protection & nosniff header
X-XSS-Protection: 1; mode=block; header, for basic XSS protection in legacy browsers.
X-Content-Type-Options: nosniff header, to disable MIME sniffing
il y a 4 ans
Slavi Pantaleev
fcb9e9618a
Make Coturn TLSv1/v1.1 configurable
Related to https://github.com/spantaleev/matrix-docker-ansible-deploy/pull/999
il y a 4 ans
sakkiii
540416e32d
Disable support for TLS 1.0 and TLS 1.1
These old versions of TLS rely on MD5 and SHA-1, both now broken, and contain other flaws. TLS 1.0 is no longer PCI-DSS compliant and the TLS working group has adopted a document to deprecate TLS 1.0 and TLS 1.1.
il y a 4 ans
Michael-GMH
89cb5a3d7a
GMH v0.4.2 update
il y a 4 ans
Slavi Pantaleev
c7c137df74
Upgrade nginx and certbot
il y a 4 ans