Matrix Docker Ansible eploy
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

84 lines
4.0 KiB

  1. ---
  2. matrix_coturn_enabled: true
  3. matrix_coturn_container_image_self_build: false
  4. matrix_coturn_container_image_self_build_repo: "https://github.com/coturn/coturn"
  5. matrix_coturn_container_image_self_build_repo_version: "docker/{{ matrix_coturn_version }}"
  6. matrix_coturn_container_image_self_build_repo_dockerfile_path: "docker/coturn/alpine/Dockerfile"
  7. matrix_coturn_version: 4.5.2-r11
  8. matrix_coturn_docker_image: "{{ matrix_coturn_docker_image_name_prefix }}coturn/coturn:{{ matrix_coturn_version }}-alpine"
  9. matrix_coturn_docker_image_name_prefix: "{{ 'localhost/' if matrix_coturn_container_image_self_build else matrix_container_global_registry_prefix }}"
  10. matrix_coturn_docker_image_force_pull: "{{ matrix_coturn_docker_image.endswith(':latest') }}"
  11. # The Docker network that Coturn would be put into.
  12. #
  13. # Because Coturn relays traffic to unvalidated IP addresses,
  14. # using a dedicated network, isolated from other Docker (and local) services is preferrable.
  15. #
  16. # Setting up deny/allow rules with `matrix_coturn_allowed_peer_ips`/`matrix_coturn_denied_peer_ips` is also
  17. # possible for achieving such isolation, but is more complicated due to the dynamic nature of Docker networking.
  18. matrix_coturn_docker_network: "matrix-coturn"
  19. matrix_coturn_base_path: "{{ matrix_base_data_path }}/coturn"
  20. matrix_coturn_docker_src_files_path: "{{ matrix_coturn_base_path }}/docker-src"
  21. matrix_coturn_config_path: "{{ matrix_coturn_base_path }}/turnserver.conf"
  22. # List of systemd services that matrix-coturn.service depends on
  23. matrix_coturn_systemd_required_services_list: ['docker.service']
  24. # A list of additional "volumes" to mount in the container.
  25. # This list gets populated dynamically at runtime. You can provide a different default value,
  26. # if you wish to mount your own files into the container.
  27. # Contains definition objects like this: `{"src": "/outside", "dst": "/inside", "options": "rw|ro|slave|.."}
  28. matrix_coturn_container_additional_volumes: []
  29. # A list of extra arguments to pass to the container
  30. matrix_coturn_container_extra_arguments: []
  31. # Controls whether the Coturn container exposes its plain STUN port (tcp/3478 and udp/3478 in the container).
  32. #
  33. # Takes an "<ip>:<port>" or "<port>" value (e.g. "127.0.0.1:3478"), or empty string to not expose.
  34. matrix_coturn_container_stun_plain_host_bind_port: '3478'
  35. # Controls whether the Coturn container exposes its TLS STUN port (tcp/5349 and udp/5349 in the container).
  36. #
  37. # Takes an "<ip>:<port>" or "<port>" value (e.g. "127.0.0.1:5349"), or empty string to not expose.
  38. matrix_coturn_container_stun_tls_host_bind_port: '5349'
  39. # Controls whether the Coturn container exposes its TURN UDP port range and which interface to do it on.
  40. #
  41. # Takes an interface "<ip address>" (e.g. "127.0.0.1"), or empty string to listen on all interfaces.
  42. # Takes a null/none value (`~`) to prevent listening.
  43. #
  44. # The UDP port-range itself is specified using `matrix_coturn_turn_udp_min_port` and `matrix_coturn_turn_udp_max_port`.
  45. matrix_coturn_container_turn_range_listen_interface: ''
  46. # UDP port-range to use for TURN
  47. matrix_coturn_turn_udp_min_port: 49152
  48. matrix_coturn_turn_udp_max_port: 49172
  49. # A shared secret (between Synapse and Coturn) used for authentication.
  50. # You can put any string here, but generating a strong one is preferred (e.g. `pwgen -s 64 1`).
  51. matrix_coturn_turn_static_auth_secret: ""
  52. # The external IP address of the machine where Coturn is.
  53. matrix_coturn_turn_external_ip_address: ''
  54. matrix_coturn_turn_external_ip_addresses: ["{{ matrix_coturn_turn_external_ip_address }}"]
  55. matrix_coturn_allowed_peer_ips: []
  56. matrix_coturn_denied_peer_ips: []
  57. matrix_coturn_user_quota: null
  58. matrix_coturn_total_quota: null
  59. # To enable TLS, you need to provide paths to certificates.
  60. # Paths defined in `matrix_coturn_tls_cert_path` and `matrix_coturn_tls_key_path` are in-container paths.
  61. # Files on the host can be mounted into the container using `matrix_coturn_container_additional_volumes`.
  62. matrix_coturn_tls_enabled: false
  63. matrix_coturn_tls_cert_path: ~
  64. matrix_coturn_tls_key_path: ~
  65. matrix_coturn_tls_v1_enabled: false
  66. matrix_coturn_tls_v1_1_enabled: false