Matrix Docker Ansible eploy
Non puoi selezionare più di 25 argomenti Gli argomenti devono iniziare con una lettera o un numero, possono includere trattini ('-') e possono essere lunghi fino a 35 caratteri.
 
 

361 righe
20 KiB

  1. ---
  2. # A bridge between Matrix and multiple project management services, such as GitHub, GitLab and JIRA.
  3. # Project source code URL: https://github.com/matrix-org/matrix-hookshot
  4. matrix_hookshot_enabled: true
  5. matrix_hookshot_identifier: matrix-hookshot
  6. matrix_hookshot_container_image_self_build: false
  7. matrix_hookshot_container_image_self_build_repo: "https://github.com/matrix-org/matrix-hookshot.git"
  8. matrix_hookshot_container_image_self_build_branch: "{{ 'main' if matrix_hookshot_version == 'latest' else matrix_hookshot_version }}"
  9. # Specifies additional networks for the Hookshot container to connect with
  10. matrix_hookshot_container_additional_networks: "{{ matrix_hookshot_container_additional_networks_auto + matrix_hookshot_container_additional_networks_custom }}"
  11. matrix_hookshot_container_additional_networks_auto: []
  12. matrix_hookshot_container_additional_networks_custom: []
  13. # renovate: datasource=docker depName=halfshot/matrix-hookshot
  14. matrix_hookshot_version: 5.3.0
  15. matrix_hookshot_docker_image: "{{ matrix_hookshot_docker_image_name_prefix }}halfshot/matrix-hookshot:{{ matrix_hookshot_version }}"
  16. matrix_hookshot_docker_image_name_prefix: "{{ 'localhost/' if matrix_hookshot_container_image_self_build else matrix_container_global_registry_prefix }}"
  17. matrix_hookshot_docker_image_force_pull: "{{ matrix_hookshot_docker_image.endswith(':latest') }}"
  18. matrix_hookshot_base_path: "{{ matrix_base_data_path }}/hookshot"
  19. matrix_hookshot_docker_src_files_path: "{{ matrix_hookshot_base_path }}/docker-src"
  20. matrix_hookshot_homeserver_address: ""
  21. matrix_hookshot_container_url: 'matrix-hookshot'
  22. matrix_hookshot_public_scheme: https
  23. matrix_hookshot_public_hostname: "{{ matrix_server_fqn_matrix }}"
  24. matrix_hookshot_public_endpoint: /hookshot
  25. matrix_hookshot_urlprefix: "{{ matrix_hookshot_public_scheme }}://{{ matrix_hookshot_public_hostname }}{{ matrix_hookshot_public_endpoint }}"
  26. # There is no need to edit ports. use matrix_hookshot_container_http_host_bind_ports below to expose ports instead.
  27. matrix_hookshot_appservice_port: 9993
  28. matrix_hookshot_appservice_hostname: "{{ matrix_hookshot_public_hostname }}"
  29. matrix_hookshot_appservice_endpoint: "{{ matrix_hookshot_public_endpoint }}/_matrix/app"
  30. # The variables below control the Redis cache parameters.
  31. # Using caching is required when experimental encryption is enabled (`matrix_hookshot_experimental_encryption_enabled`)
  32. # but may also speed up Hookshot startup, etc.
  33. matrix_hookshot_cache_redis_host: ''
  34. matrix_hookshot_cache_redis_port: "6379"
  35. matrix_hookshot_cache_redisUri: "{{ ('redis://' + matrix_hookshot_cache_redis_host + ':' + matrix_hookshot_cache_redis_port) if matrix_hookshot_cache_redis_host else '' }}" # noqa var-naming
  36. # Controls whether the experimental end-to-bridge encryption support is enabled.
  37. # This requires that:
  38. # - support to also be enabled in the homeserver, see the documentation of Hookshot.
  39. # - Hookshot to be pointed at a Redis instance via the `matrix_hookshot_cache_redis*` variables.
  40. matrix_hookshot_experimental_encryption_enabled: false
  41. # Controls whether metrics are enabled in the bridge configuration.
  42. # Enabling them is usually enough for a local (in-container) Prometheus to consume them.
  43. # If metrics need to be consumed by another (external) Prometheus server, consider exposing them via `matrix_hookshot_metrics_proxying_enabled`.
  44. matrix_hookshot_metrics_enabled: false
  45. # Controls whether Hookshot metrics should be proxied (exposed) on a public URL.
  46. matrix_hookshot_metrics_proxying_enabled: false
  47. matrix_hookshot_metrics_proxying_hostname: ''
  48. matrix_hookshot_metrics_proxying_path_prefix: ''
  49. # There is no need to edit ports.
  50. # Read the documentation to learn about using Hookshot metrics with external Prometheus
  51. # If you still want something different, use matrix_hookshot_container_http_host_bind_ports below to expose ports instead.
  52. matrix_hookshot_metrics_port: 9001
  53. # There is no need to edit ports. use matrix_hookshot_container_http_host_bind_ports below to expose ports instead.
  54. matrix_hookshot_webhook_port: 9000
  55. matrix_hookshot_webhook_hostname: "{{ matrix_hookshot_public_hostname }}"
  56. matrix_hookshot_webhook_endpoint: "{{ matrix_hookshot_public_endpoint }}/webhooks"
  57. # You need to create a GitHub app to enable this and fill in the empty variables below
  58. # https://matrix-org.github.io/matrix-hookshot/setup/github.html
  59. matrix_hookshot_github_enabled: false
  60. matrix_hookshot_github_auth_id: ''
  61. # Set this variable to the contents of the generated and downloaded GitHub private key:
  62. # matrix_hookshot_github_private_key: |
  63. # -----BEGIN RSA PRIVATE KEY-----
  64. # 0123456789ABCDEF...
  65. # -----END RSA PRIVATE KEY-----
  66. # Alternatively, leave it empty and do it manually or use matrix-aux instead, see docs/matrix-bridge-hookshot.md for info.
  67. matrix_hookshot_github_private_key: ''
  68. matrix_hookshot_github_private_key_file: 'private-key.pem'
  69. matrix_hookshot_github_webhook_secret: '' # "Webhook secret" on the GitHub App page
  70. matrix_hookshot_github_oauth_enabled: false
  71. # You need to configure oauth settings only when you have enabled oauth (optional)
  72. matrix_hookshot_github_oauth_client_id: '' # "Client ID" on the GitHub App page
  73. matrix_hookshot_github_oauth_client_secret: '' # "Client Secret" on the GitHub App page
  74. # Default value of matrix_hookshot_github_oauth_endpoint: "/hookshot/webhooks/oauth"
  75. matrix_hookshot_github_oauth_endpoint: "{{ matrix_hookshot_webhook_endpoint }}/oauth"
  76. matrix_hookshot_github_oauth_redirect_uri: "{{ matrix_hookshot_urlprefix }}{{ matrix_hookshot_github_oauth_endpoint }}"
  77. # These are the default settings mentioned here and don't need to be modified: https://matrix-org.github.io/matrix-hookshot/usage/room_configuration/github_repo.html#configuration
  78. matrix_hookshot_github_defaultOptions_ignoreHooks: {} # noqa var-naming
  79. matrix_hookshot_github_defaultOptions_commandPrefix: '!gh' # noqa var-naming
  80. matrix_hookshot_github_defaultOptions_showIssueRoomLink: false # noqa var-naming
  81. matrix_hookshot_github_defaultOptions_prDiff: # noqa var-naming
  82. enabled: false
  83. maxLines: 5
  84. matrix_hookshot_github_defaultOptions_includingLabels: '' # noqa var-naming
  85. matrix_hookshot_github_defaultOptions_excludingLabels: '' # noqa var-naming
  86. matrix_hookshot_github_defaultOptions_hotlinkIssues_prefix: "#" # noqa var-naming
  87. matrix_hookshot_gitlab_enabled: true
  88. # Optionally add your instances, e.g.
  89. # matrix_hookshot_gitlab_instances:
  90. # gitlab.com:
  91. # url: https://gitlab.com
  92. # mygitlab:
  93. # url: https://gitlab.example.org
  94. matrix_hookshot_gitlab_instances:
  95. gitlab.com:
  96. url: https://gitlab.com
  97. # This will be the "Secret token" you have to enter into all GitLab instances for authentication
  98. matrix_hookshot_gitlab_webhook_secret: ''
  99. matrix_hookshot_figma_enabled: false
  100. # Default value of matrix_hookshot_figma_endpoint: "/hookshot/webhooks/figma/webhook"
  101. matrix_hookshot_figma_endpoint: "{{ matrix_hookshot_webhook_endpoint }}/figma/webhook"
  102. matrix_hookshot_figma_publicUrl: "{{ matrix_hookshot_urlprefix }}{{ matrix_hookshot_figma_endpoint }}" # noqa var-naming
  103. # To bridge figma webhooks, you need to configure one of multiple instances like this:
  104. # matrix_hookshot_figma_instances:
  105. # your-instance:
  106. # teamId: your-team-id
  107. # accessToken: your-personal-access-token
  108. # passcode: your-webhook-passcode
  109. matrix_hookshot_figma_instances: {}
  110. matrix_hookshot_jira_enabled: false
  111. # Get the these values from https://matrix-org.github.io/matrix-hookshot/setup/jira.html#jira-oauth
  112. matrix_hookshot_jira_webhook_secret: ''
  113. matrix_hookshot_jira_oauth_enabled: false
  114. matrix_hookshot_jira_oauth_client_id: ''
  115. matrix_hookshot_jira_oauth_client_secret: ''
  116. # Default value of matrix_hookshot_jira_oauth_endpoint: "/hookshot/webhooks/jira/oauth"
  117. matrix_hookshot_jira_oauth_endpoint: "{{ matrix_hookshot_webhook_endpoint }}/jira/oauth"
  118. matrix_hookshot_jira_oauth_redirect_uri: "{{ matrix_hookshot_urlprefix }}{{ matrix_hookshot_jira_oauth_endpoint }}"
  119. # No need to change these
  120. matrix_hookshot_generic_enabled: true
  121. matrix_hookshot_generic_enableHttpGet: false # noqa var-naming
  122. # Default value of matrix_hookshot_generic_endpoint: "/hookshot/webhooks"
  123. matrix_hookshot_generic_endpoint: "{{ matrix_hookshot_webhook_endpoint }}"
  124. # urlprefix gets updated with protocol & port in group_vars/matrix_servers
  125. matrix_hookshot_generic_urlPrefix: "{{ matrix_hookshot_urlprefix }}{{ matrix_hookshot_generic_endpoint }}" # noqa var-naming
  126. # If you're also using matrix-appservice-webhooks, take care that these prefixes don't overlap
  127. matrix_hookshot_generic_userIdPrefix: '_webhooks_' # noqa var-naming
  128. matrix_hookshot_generic_allowJsTransformationFunctions: false # noqa var-naming
  129. matrix_hookshot_generic_waitForComplete: false # noqa var-naming
  130. matrix_hookshot_feeds_enabled: true
  131. matrix_hookshot_feeds_pollIntervalSeconds: 600 # noqa var-naming
  132. matrix_hookshot_feeds_pollTimeoutSeconds: 30 # noqa var-naming
  133. matrix_hookshot_provisioning_enabled: false
  134. # There is no need to edit ports. use matrix_hookshot_container_http_host_bind_ports below to expose ports instead.
  135. matrix_hookshot_provisioning_port: 9002
  136. matrix_hookshot_provisioning_secret: ''
  137. # Provisioning will be automatically enabled if dimension is enabled and you have provided a provisioning secret, unless you override it
  138. matrix_hookshot_provisioning_internal: "/v1"
  139. matrix_hookshot_provisioning_hostname: "{{ matrix_hookshot_public_hostname }}"
  140. matrix_hookshot_provisioning_endpoint: "{{ matrix_hookshot_public_endpoint }}{{ matrix_hookshot_provisioning_internal }}"
  141. # Valid logging levels are: debug, info, warn, error
  142. matrix_hookshot_logging_level: warn
  143. matrix_hookshot_widgets_enabled: true
  144. matrix_hookshot_widgets_port: 9003
  145. matrix_hookshot_widgets_addToAdminRooms: false # default off as it is a beta feature # noqa var-naming
  146. matrix_hookshot_widgets_roomSetupWidget_enabled: true # noqa var-naming
  147. matrix_hookshot_widgets_roomSetupWidget_addOnInvite: false # noqa var-naming
  148. # `disallowedIpRanges` describes which IP ranges should be disallowed when resolving homeserver IP addresses (for security reasons). Unless you know what you are doing, it is recommended to not include this key. The following IPs are blocked by default, unless you supply another list.
  149. # matrix_hookshot_widgets_disallowedIpRanges:
  150. # - 127.0.0.0/8
  151. # - 10.0.0.0/8
  152. # - 172.16.0.0/12
  153. # - 192.168.0.0/16
  154. # - 100.64.0.0/10
  155. # - 192.0.0.0/24
  156. # - 169.254.0.0/16
  157. # - 192.88.99.0/24
  158. # - 198.18.0.0/15
  159. # - 192.0.2.0/24
  160. # - 198.51.100.0/24
  161. # - 203.0.113.0/24
  162. # - 224.0.0.0/4
  163. # - ::1/128
  164. # - fe80::/10
  165. # - fc00::/7
  166. # - 2001:db8::/32
  167. # - ff00::/8
  168. # - fec0::/10
  169. matrix_hookshot_widgets_disallowedIpRanges: '' # noqa var-naming
  170. matrix_hookshot_widgets_internal: "/widgetapi"
  171. matrix_hookshot_widgets_hostname: "{{ matrix_hookshot_public_hostname }}"
  172. matrix_hookshot_widgets_endpoint: "{{ matrix_hookshot_public_endpoint }}{{ matrix_hookshot_widgets_internal }}"
  173. matrix_hookshot_widgets_publicUrl: "{{ matrix_hookshot_urlprefix }}{{ matrix_hookshot_widgets_endpoint }}/v1/static/" # noqa var-naming
  174. matrix_hookshot_widgets_branding_widgetTitle: "Hookshot Configuration" # noqa var-naming
  175. # You can configure access to the bridge as documented here https://matrix-org.github.io/matrix-hookshot/setup.html#permissions
  176. # When empty, the default permissions are applied.
  177. # Example:
  178. # matrix_hookshot_permissions:
  179. # - actor: *
  180. # services:
  181. # - service: *
  182. # level: commands
  183. # - actor: example.com
  184. # services:
  185. # - service: "*"
  186. # level: admin
  187. matrix_hookshot_permissions: []
  188. matrix_hookshot_bot_displayname: Hookshot Bot
  189. matrix_hookshot_bot_avatar: 'mxc://half-shot.uk/2876e89ccade4cb615e210c458e2a7a6883fe17d'
  190. matrix_hookshot_container_network: ""
  191. # A list of extra arguments to pass to the container
  192. matrix_hookshot_container_extra_arguments: []
  193. # matrix_hookshot_container_labels_traefik_enabled controls whether labels to assist a Traefik reverse-proxy will be attached to the container.
  194. # See `../templates/labels.j2` for details.
  195. #
  196. # To inject your own other container labels, see `matrix_hookshot_container_labels_additional_labels`.
  197. matrix_hookshot_container_labels_traefik_enabled: true
  198. matrix_hookshot_container_labels_traefik_docker_network: "{{ matrix_hookshot_container_network }}"
  199. matrix_hookshot_container_labels_traefik_entrypoints: web-secure
  200. matrix_hookshot_container_labels_traefik_tls_certResolver: default # noqa var-naming
  201. # Controls whether labels will be added that expose Hookshot's webhooks endpoint
  202. matrix_hookshot_container_labels_webhooks_enabled: true
  203. matrix_hookshot_container_labels_webhooks_traefik_rule: "Host(`{{ matrix_hookshot_webhook_hostname }}`) && PathPrefix(`{{ matrix_hookshot_webhook_endpoint }}`)"
  204. matrix_hookshot_container_labels_webhooks_traefik_priority: 0
  205. matrix_hookshot_container_labels_webhooks_traefik_entrypoints: "{{ matrix_hookshot_container_labels_traefik_entrypoints }}"
  206. matrix_hookshot_container_labels_webhooks_traefik_tls: "{{ matrix_hookshot_container_labels_webhooks_traefik_entrypoints != 'web' }}"
  207. matrix_hookshot_container_labels_webhooks_traefik_tls_certResolver: "{{ matrix_hookshot_container_labels_traefik_tls_certResolver }}" # noqa var-naming
  208. # Controls whether labels will be added that expose Hookshot's generic endpoint
  209. matrix_hookshot_container_labels_appservice_enabled: true
  210. matrix_hookshot_container_labels_appservice_traefik_rule: "Host(`{{ matrix_hookshot_appservice_hostname }}`) && PathPrefix(`{{ matrix_hookshot_appservice_endpoint }}`)"
  211. matrix_hookshot_container_labels_appservice_traefik_priority: 0
  212. matrix_hookshot_container_labels_appservice_traefik_entrypoints: "{{ matrix_hookshot_container_labels_traefik_entrypoints }}"
  213. matrix_hookshot_container_labels_appservice_traefik_tls: "{{ matrix_hookshot_container_labels_appservice_traefik_entrypoints != 'web' }}"
  214. matrix_hookshot_container_labels_appservice_traefik_tls_certResolver: "{{ matrix_hookshot_container_labels_traefik_tls_certResolver }}" # noqa var-naming
  215. # Controls whether labels will be added that expose Hookshot's widgets endpoint
  216. matrix_hookshot_container_labels_widgets_enabled: "{{ matrix_hookshot_widgets_enabled }}"
  217. matrix_hookshot_container_labels_widgets_traefik_rule: "Host(`{{ matrix_hookshot_widgets_hostname }}`) && PathPrefix(`{{ matrix_hookshot_widgets_endpoint }}`)"
  218. matrix_hookshot_container_labels_widgets_traefik_priority: 0
  219. matrix_hookshot_container_labels_widgets_traefik_entrypoints: "{{ matrix_hookshot_container_labels_traefik_entrypoints }}"
  220. matrix_hookshot_container_labels_widgets_traefik_tls: "{{ matrix_hookshot_container_labels_widgets_traefik_entrypoints != 'web' }}"
  221. matrix_hookshot_container_labels_widgets_traefik_tls_certResolver: "{{ matrix_hookshot_container_labels_traefik_tls_certResolver }}" # noqa var-naming
  222. # Controls whether labels will be added that expose Hookshot's provisioning endpoint
  223. matrix_hookshot_container_labels_provisioning_enabled: "{{ matrix_hookshot_provisioning_enabled }}"
  224. matrix_hookshot_container_labels_provisioning_traefik_rule: "Host(`{{ matrix_hookshot_provisioning_hostname }}`) && PathPrefix(`{{ matrix_hookshot_provisioning_endpoint }}`)"
  225. matrix_hookshot_container_labels_provisioning_traefik_priority: 0
  226. matrix_hookshot_container_labels_provisioning_traefik_entrypoints: "{{ matrix_hookshot_container_labels_traefik_entrypoints }}"
  227. matrix_hookshot_container_labels_provisioning_traefik_tls: "{{ matrix_hookshot_container_labels_provisioning_traefik_entrypoints != 'web' }}"
  228. matrix_hookshot_container_labels_provisioning_traefik_tls_certResolver: "{{ matrix_hookshot_container_labels_traefik_tls_certResolver }}" # noqa var-naming
  229. # Controls whether labels will be added that expose Hookshot's provisioning endpoint
  230. matrix_hookshot_container_labels_metrics_enabled: "{{ matrix_hookshot_metrics_enabled and matrix_hookshot_metrics_proxying_enabled }}"
  231. matrix_hookshot_container_labels_metrics_traefik_rule: "Host(`{{ matrix_hookshot_metrics_proxying_hostname }}`) && PathPrefix(`{{ matrix_hookshot_metrics_proxying_path_prefix }}`)"
  232. matrix_hookshot_container_labels_metrics_traefik_priority: 0
  233. matrix_hookshot_container_labels_metrics_traefik_entrypoints: "{{ matrix_hookshot_container_labels_traefik_entrypoints }}"
  234. matrix_hookshot_container_labels_metrics_traefik_tls: "{{ matrix_hookshot_container_labels_metrics_traefik_entrypoints != 'web' }}"
  235. matrix_hookshot_container_labels_metrics_traefik_tls_certResolver: "{{ matrix_hookshot_container_labels_traefik_tls_certResolver }}" # noqa var-naming
  236. matrix_hookshot_container_labels_metrics_middleware_basic_auth_enabled: false
  237. # See: https://doc.traefik.io/traefik/middlewares/http/basicauth/#users
  238. matrix_hookshot_container_labels_metrics_middleware_basic_auth_users: ''
  239. # matrix_hookshot_container_labels_additional_labels contains a multiline string with additional labels to add to the container label file.
  240. # See `../templates/labels.j2` for details.
  241. #
  242. # Example:
  243. # matrix_hookshot_container_labels_additional_labels: |
  244. # my.label=1
  245. # another.label="here"
  246. matrix_hookshot_container_labels_additional_labels: ''
  247. # List of systemd services that service depends on.
  248. matrix_hookshot_systemd_required_services_list: "{{ matrix_hookshot_systemd_required_services_list_default + matrix_hookshot_systemd_required_services_list_auto + matrix_hookshot_systemd_required_services_list_custom }}"
  249. matrix_hookshot_systemd_required_services_list_default: "{{ [devture_systemd_docker_base_docker_service_name] if devture_systemd_docker_base_docker_service_name else [] }}"
  250. matrix_hookshot_systemd_required_services_list_auto: []
  251. matrix_hookshot_systemd_required_services_list_custom: []
  252. # List of systemd services that service wants
  253. matrix_hookshot_systemd_wanted_services_list: []
  254. # List of ports to bind to the host to expose them directly.
  255. # Supply docker port bind arguments in a list like this:
  256. #
  257. # matrix_hookshot_container_http_host_bind_ports:
  258. # - "127.0.0.1:9999:{{ matrix_hookshot_metrics_port }}"
  259. #
  260. # Above example will bind the metrics port in the container to port 9999 on localhost.
  261. matrix_hookshot_container_http_host_bind_ports: []
  262. # These tokens will be set automatically
  263. matrix_hookshot_appservice_token: ''
  264. matrix_hookshot_homeserver_token: ''
  265. # Default configuration template which covers the generic use case.
  266. # You can customize it by controlling the various variables inside it.
  267. #
  268. # For a more advanced customization, you can extend the default (see `matrixhookshot_configuration_extension_yaml`)
  269. # or completely replace this variable with your own template.
  270. matrix_hookshot_configuration_yaml: "{{ lookup('template', 'templates/config.yml.j2') }}"
  271. matrix_hookshot_configuration_extension_yaml: |
  272. # Your custom YAML configuration goes here.
  273. # This configuration extends the default starting configuration (`matrix_hookshot_configuration_yaml`).
  274. #
  275. # You can override individual variables from the default configuration, or introduce new ones.
  276. #
  277. # If you need something more special, you can take full control by
  278. # completely redefining `matrix_hookshot_configuration_yaml`.
  279. matrix_hookshot_configuration_extension: "{{ matrix_hookshot_configuration_extension_yaml | from_yaml if matrix_hookshot_configuration_extension_yaml | from_yaml is mapping else {} }}"
  280. # Holds the final configuration (a combination of the default and its extension).
  281. # You most likely don't need to touch this variable. Instead, see `matrix_hookshot_configuration_yaml`.
  282. matrix_hookshot_configuration: "{{ matrix_hookshot_configuration_yaml | from_yaml | combine(matrix_hookshot_configuration_extension, recursive=True) }}"
  283. # Default registration template which covers the generic use case.
  284. # You can customize it by controlling the various variables inside it.
  285. #
  286. # For a more advanced customization, you can extend the default (see `matrixhookshot_registration_extension_yaml`)
  287. # or completely replace this variable with your own template.
  288. matrix_hookshot_registration_yaml: "{{ lookup('template', 'templates/registration.yml.j2') }}"
  289. matrix_hookshot_registration_extension_yaml: |
  290. # Your custom YAML registration goes here.
  291. # This registration extends the default starting registration (`matrix_hookshot_registration_yaml`).
  292. #
  293. # You can override individual variables from the default registration, or introduce new ones.
  294. #
  295. # If you need something more special, you can take full control by
  296. # completely redefining `matrix_hookshot_registration_yaml`.
  297. matrix_hookshot_registration_extension: "{{ matrix_hookshot_registration_extension_yaml | from_yaml if matrix_hookshot_registration_extension_yaml | from_yaml is mapping else {} }}"
  298. # Holds the final registration (a combination of the default and its extension).
  299. # You most likely don't need to touch this variable. Instead, see `matrix_hookshot_registration_yaml`.
  300. matrix_hookshot_registration: "{{ matrix_hookshot_registration_yaml | from_yaml | combine(matrix_hookshot_registration_extension, recursive=True) }}"