Matrix Docker Ansible eploy
Não pode escolher mais do que 25 tópicos Os tópicos devem começar com uma letra ou um número, podem incluir traços ('-') e podem ter até 35 caracteres.
 
 

198 linhas
17 KiB

  1. # SPDX-FileCopyrightText: 2019 - 2024 Slavi Pantaleev
  2. # SPDX-FileCopyrightText: 2024 Charles Wright
  3. # SPDX-FileCopyrightText: 2024 MDAD project contributors
  4. #
  5. # SPDX-License-Identifier: AGPL-3.0-or-later
  6. ---
  7. - name: Fail if required Synapse settings not defined
  8. ansible.builtin.fail:
  9. msg: >-
  10. You need to define a required configuration setting (`{{ item.name }}`).
  11. when: "item.when | bool and vars[item.name] | string | length == 0"
  12. with_items:
  13. - {'name': 'matrix_synapse_username', when: true}
  14. - {'name': 'matrix_synapse_uid', when: true}
  15. - {'name': 'matrix_synapse_gid', when: true}
  16. - {'name': 'matrix_synapse_container_network', when: true}
  17. - {'name': 'matrix_synapse_macaroon_secret_key', when: true}
  18. - {'name': 'matrix_synapse_database_host', when: true}
  19. - {'name': 'matrix_synapse_database_user', when: true}
  20. - {'name': 'matrix_synapse_database_password', when: true}
  21. - {'name': 'matrix_synapse_database_database', when: true}
  22. - {'name': 'matrix_synapse_container_labels_public_client_root_traefik_hostname', when: "{{ matrix_synapse_container_labels_public_client_root_enabled }}"}
  23. - {'name': 'matrix_synapse_container_labels_public_client_root_redirection_url', when: "{{ matrix_synapse_container_labels_public_client_root_redirection_enabled }}"}
  24. - {'name': 'matrix_synapse_container_labels_public_client_api_traefik_hostname', when: "{{ matrix_synapse_container_labels_public_client_api_enabled }}"}
  25. - {'name': 'matrix_synapse_container_labels_internal_client_api_traefik_entrypoints', when: "{{ matrix_synapse_container_labels_internal_client_api_enabled }}"}
  26. - {'name': 'matrix_synapse_container_labels_internal_client_synapse_admin_api_traefik_entrypoints', when: "{{ matrix_synapse_container_labels_internal_client_synapse_admin_api_enabled }}"}
  27. - {'name': 'matrix_synapse_container_labels_public_client_synapse_client_api_traefik_hostname', when: "{{ matrix_synapse_container_labels_public_client_synapse_client_api_enabled }}"}
  28. - {'name': 'matrix_synapse_container_labels_public_client_synapse_admin_api_traefik_hostname', when: "{{ matrix_synapse_container_labels_public_client_synapse_admin_api_enabled }}"}
  29. - {'name': 'matrix_synapse_container_labels_public_federation_api_traefik_hostname', when: "{{ matrix_synapse_container_labels_public_federation_api_enabled }}"}
  30. - {'name': 'matrix_synapse_container_labels_public_federation_api_traefik_entrypoints', when: "{{ matrix_synapse_container_labels_public_federation_api_enabled }}"}
  31. - {'name': 'matrix_synapse_metrics_proxying_hostname', when: "{{ matrix_synapse_metrics_proxying_enabled }}"}
  32. - {'name': 'matrix_synapse_metrics_proxying_path_prefix', when: "{{ matrix_synapse_metrics_proxying_enabled }}"}
  33. - {'name': 'matrix_synapse_matrix_authentication_service_endpoint', when: "{{ matrix_synapse_matrix_authentication_service_enabled }}"}
  34. - {'name': 'matrix_synapse_matrix_authentication_service_secret', when: "{{ matrix_synapse_matrix_authentication_service_enabled }}"}
  35. - {'name': 'matrix_synapse_container_labels_traefik_compression_middleware_name', when: "{{ matrix_synapse_container_labels_traefik_compression_middleware_enabled }}"}
  36. - name: Fail if asking for more than 1 instance of single-instance workers
  37. ansible.builtin.fail:
  38. msg: >-
  39. `{{ item }}` cannot be more than 1. This is a single-instance worker.
  40. when: "vars[item] | int > 1"
  41. with_items:
  42. - "matrix_synapse_workers_appservice_workers_count"
  43. - "matrix_synapse_workers_user_dir_workers_count"
  44. - "matrix_synapse_workers_background_workers_count"
  45. - "matrix_synapse_workers_stream_writer_typing_stream_workers_count"
  46. - "matrix_synapse_workers_stream_writer_to_device_stream_workers_count"
  47. - "matrix_synapse_workers_stream_writer_account_data_stream_workers_count"
  48. - "matrix_synapse_workers_stream_writer_receipts_stream_workers_count"
  49. - "matrix_synapse_workers_stream_writer_presence_stream_workers_count"
  50. - name: Fail when mixing generic workers with new specialized workers
  51. ansible.builtin.fail:
  52. msg: >-
  53. Generic workers should not be mixed with the new specialized worker types (room workers, sync workers, client readers, and federation readers)
  54. when: matrix_synapse_workers_generic_workers_count | int > 0 and ((matrix_synapse_workers_room_workers_count | int + matrix_synapse_workers_sync_workers_count | int + matrix_synapse_workers_client_reader_workers_count | int + matrix_synapse_workers_federation_reader_workers_count | int) > 0)
  55. - name: (Deprecation) Catch and report renamed settings
  56. ansible.builtin.fail:
  57. msg: >-
  58. Your configuration contains a variable, which now has a different name.
  59. Please rename the variable (`{{ item.old }}` -> `{{ item.new }}`) on your configuration file (vars.yml).
  60. when: "lookup('ansible.builtin.varnames', ('^' + item.old + '$'), wantlist=True) | length > 0"
  61. with_items:
  62. - {'old': 'matrix_synapse_email_riot_base_url', 'new': '<superseded by client_base_url>'}
  63. - {'old': 'matrix_synapse_container_expose_api_port', 'new': '<superseded by matrix_synapse_container_federation_api_plain_host_bind_port>'}
  64. - {'old': 'matrix_synapse_no_tls', 'new': '<removed>'}
  65. - {'old': 'matrix_enable_room_list_search', 'new': 'matrix_synapse_enable_room_list_search'}
  66. - {'old': 'matrix_alias_creation_rules', 'new': 'matrix_synapse_alias_creation_rules'}
  67. - {'old': 'matrix_room_list_publication_rules', 'new': 'matrix_synapse_room_list_publication_rules'}
  68. - {'old': 'matrix_synapse_rc_messages_per_second', 'new': '<per_second subkey of matrix_synapse_rc_message>'}
  69. - {'old': 'matrix_synapse_rc_message_burst_count', 'new': '<burst_count subkey of matrix_synapse_rc_message>'}
  70. - {'old': 'matrix_synapse_federation_rc_window_size', 'new': '<window_size subkey of matrix_synapse_rc_federation>'}
  71. - {'old': 'matrix_synapse_federation_rc_sleep_limit', 'new': '<sleep_limit subkey of matrix_synapse_rc_federation>'}
  72. - {'old': 'matrix_synapse_federation_rc_sleep_delay', 'new': '<sleep_delay subkey of matrix_synapse_rc_federation>'}
  73. - {'old': 'matrix_synapse_federation_rc_reject_limit', 'new': '<reject_limit subkey of matrix_synapse_rc_federation>'}
  74. - {'old': 'matrix_synapse_federation_rc_concurrent', 'new': '<concurrent subkey of matrix_synapse_rc_federation>'}
  75. - {'old': 'matrix_synapse_container_expose_client_api_port', 'new': '<superseded by matrix_synapse_container_client_api_host_bind_port>'}
  76. - {'old': 'matrix_synapse_container_expose_federation_api_port', 'new': '<superseded by matrix_synapse_container_federation_api_plain_host_bind_port>'}
  77. - {'old': 'matrix_synapse_container_expose_metrics_port', 'new': '<superseded by matrix_synapse_container_metrics_api_host_bind_port>'}
  78. - {'old': 'matrix_synapse_cache_factor', 'new': 'matrix_synapse_caches_global_factor'}
  79. - {'old': 'matrix_synapse_trusted_third_party_id_servers', 'new': '<deprecated in Synapse v0.99.4 and removed in Synapse v1.19.0>'}
  80. - {'old': 'matrix_synapse_use_presence', 'new': 'matrix_synapse_presence_enabled'}
  81. - {'old': 'matrix_synapse_version_arm64', 'new': '<superseded by matrix_synapse_version - see https://github.com/matrix-org/synapse/pull/11810>'}
  82. - {'old': 'matrix_synapse_enable_group_creation', 'new': '<removed in Synapse v1.61.0 - use the new Spaces feature instead>'}
  83. - {'old': 'matrix_synapse_account_threepid_delegates_email', 'new': '<removed in Synapse v1.66.0 - make sure to configure email settings for Synapse - see https://matrix-org.github.io/synapse/v1.66/upgrade.html#delegation-of-email-validation-no-longer-supported>'}
  84. - {'old': 'matrix_synapse_workers_frontend_proxy_workers_count', 'new': '<removed in favor of generic workers - see https://github.com/matrix-org/synapse/pull/13645>'}
  85. - {'old': 'matrix_synapse_workers_frontend_proxy_workers_port_range_start', 'new': '<removed in favor of generic workers - see https://github.com/matrix-org/synapse/pull/13645>'}
  86. - {'old': 'matrix_synapse_workers_frontend_proxy_workers_metrics_range_start', 'new': '<removed in favor of generic workers - see https://github.com/matrix-org/synapse/pull/13645>'}
  87. - {'old': 'matrix_synapse_ext_s3_storage_provider_path', 'new': 'matrix_synapse_ext_s3_storage_provider_base_path'}
  88. - {'old': 'matrix_synapse_send_federation', 'new': '<unnecessary - Synapse relies on federation_sender_instances now>'}
  89. - {'old': 'matrix_synapse_start_pushers', 'new': '<unnecessary - Synapse relies on pusher_instances now>'}
  90. - {'old': 'matrix_synapse_spam_checker', 'new': '<superseded by matrix_synapse_modules>'}
  91. - {'old': 'matrix_synapse_caches_autotuning_max_cache_memory_usage', 'new': 'matrix_synapse_cache_autotuning_max_cache_memory_usage'}
  92. - {'old': 'matrix_synapse_caches_autotuning_target_cache_memory_usage', 'new': 'matrix_synapse_cache_autotuning_target_cache_memory_usage'}
  93. - {'old': 'matrix_synapse_caches_autotuning_min_cache_ttl', 'new': 'matrix_synapse_cache_autotuning_min_cache_ttl'}
  94. - {'old': 'matrix_synapse_memtotal_kb', 'new': '<superseded by matrix_synapse_cache_size_calculations_memtotal_bytes>'}
  95. - {'old': 'matrix_synapse_docker_image_name_prefix', 'new': 'matrix_synapse_docker_image_registry_prefix'}
  96. - {'old': 'matrix_s3_goofys_docker_image_name_prefix', 'new': 'matrix_s3_goofys_docker_image_registry_prefix'}
  97. - {'old': 'matrix_synapse_rust_synapse_compress_state_docker_image_name_prefix', 'new': 'matrix_synapse_rust_synapse_compress_state_docker_image_registry_prefix'}
  98. - {'old': 'matrix_synapse_experimental_features_msc3861_enabled', 'new': 'matrix_synapse_matrix_authentication_service_enabled'}
  99. - {'old': 'matrix_synapse_experimental_features_msc3861_issuer', 'new': '<superseded by matrix_synapse_matrix_authentication_service_endpoint>'}
  100. - {'old': 'matrix_synapse_experimental_features_msc3861_client_id', 'new': '<removed>'}
  101. - {'old': 'matrix_synapse_experimental_features_msc3861_client_auth_method', 'new': '<removed>'}
  102. - {'old': 'matrix_synapse_experimental_features_msc3861_client_secret', 'new': '<removed>'}
  103. - {'old': 'matrix_synapse_experimental_features_msc3861_admin_token', 'new': '<removed>'}
  104. - {'old': 'matrix_synapse_experimental_features_msc3861_account_management_url', 'new': '<removed>'}
  105. - name: (Deprecation) Catch and report renamed settings in matrix_synapse_configuration_extension_yaml
  106. ansible.builtin.fail:
  107. msg: >-
  108. Your matrix_synapse_configuration_extension_yaml configuration contains a variable, which now has a different name.
  109. Please rename the variable (`{{ item.old }}` -> `{{ item.new }}`) on your configuration file (vars.yml).
  110. when: "item.old in matrix_synapse_configuration_extension"
  111. with_items:
  112. - {'old': 'federation_ip_range_blacklist', 'new': 'ip_range_blacklist'}
  113. - when: matrix_synapse_container_image_customizations_templates_enabled | bool
  114. block:
  115. - name: Fail if required `matrix_synapse_container_image_customizations_templates_*` settings not defined
  116. ansible.builtin.fail:
  117. msg: >-
  118. You need to define a required configuration setting (`{{ item }}`) when enabling `matrix_synapse_container_image_customizations_templates_enabled`.
  119. when: "vars[item] == ''"
  120. with_items:
  121. - matrix_synapse_container_image_customizations_templates_git_repository_url
  122. - matrix_synapse_container_image_customizations_templates_git_repository_branch
  123. - name: Fail if required `matrix_synapse_container_image_customizations_templates_git_repository_keyscan_*` settings not defined
  124. ansible.builtin.fail:
  125. msg: >-
  126. You need to define a required configuration setting (`{{ item }}`) when enabling `matrix_synapse_container_image_customizations_templates_git_repository_keyscan`.
  127. when: "matrix_synapse_container_image_customizations_templates_git_repository_keyscan_enabled | bool and vars[item] == ''"
  128. with_items:
  129. - matrix_synapse_container_image_customizations_templates_git_repository_keyscan_hostname
  130. - name: Fail when auto-accept-invite enabled as a native feature and a module at the same time
  131. ansible.builtin.fail:
  132. msg: >-
  133. Your configuration enables the auto-accept invites feature both as a native Synapse feature (`matrix_synapse_auto_accept_invites_enabled`) and a 3rd party module (`matrix_synapse_ext_synapse_auto_accept_invite_enabled`).
  134. This is unnecessary, since they both do the same and the native feature is built on top of the 3rd party module anyway.
  135. Enabling both at the same time will lead to issues.
  136. We recommend leaving `matrix_synapse_auto_accept_invites_enabled` in your configuration and removing `matrix_synapse_ext_synapse_auto_accept_invite_enabled`.
  137. when:
  138. - matrix_synapse_auto_accept_invites_enabled
  139. - matrix_synapse_ext_synapse_auto_accept_invite_enabled
  140. - name: Fail if known Synapse password provider modules are enabled when auth is delegated to Matrix Authentication Service
  141. ansible.builtin.fail:
  142. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it does not make sense to enable password provider modules, because it is not Synapse that is handling authentication. Please disable {{ item }} before enabling Matrix Authentication Service integration for Synapse. Synapse will refuse to start otherwise."
  143. when: matrix_synapse_matrix_authentication_service_enabled and vars[item] | bool
  144. with_items:
  145. - matrix_synapse_ext_password_provider_rest_auth_enabled
  146. - matrix_synapse_ext_password_provider_shared_secret_auth_enabled
  147. - matrix_synapse_ext_password_provider_ldap_enabled
  148. - name: Fail if password config is enabled for Synapse when auth is delegated to Matrix Authentication Service
  149. ansible.builtin.fail:
  150. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it doesn't make sense to enable the password config (`matrix_synapse_password_config_enabled: true`), because it is not Synapse that is handling authentication. Please remove your `matrix_synapse_password_config_enabled: true` setting before enabling Matrix Authentication Service integration for Synapse. Synapse will refuse to start otherwise."
  151. when: matrix_synapse_matrix_authentication_service_enabled and matrix_synapse_password_config_enabled
  152. - name: Fail if registration is enabled for Synapse when auth is delegated to Matrix Authentication Service
  153. ansible.builtin.fail:
  154. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it doesn't make sense to enable registration (`matrix_synapse_enable_registration: true`), because it is not Synapse that is handling authentication. Synapse will refuse to start otherwise."
  155. when: matrix_synapse_matrix_authentication_service_enabled and matrix_synapse_enable_registration
  156. - name: Fail if registration CAPTCHA is enabled for Synapse when auth is delegated to Matrix Authentication Service
  157. ansible.builtin.fail:
  158. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it doesn't make sense to enable registration CAPTCHA (`matrix_synapse_enable_registration_captcha: true`), because it is not Synapse that is handling authentication. Synapse will refuse to start otherwise."
  159. when: matrix_synapse_matrix_authentication_service_enabled and matrix_synapse_enable_registration_captcha
  160. - name: Fail if OpenID Connect is enabled for Synapse when auth is delegated to Matrix Authentication Service
  161. ansible.builtin.fail:
  162. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it doesn't make sense to enable OpenID Connect (`matrix_synapse_oidc_enabled: true`), because it is not Synapse that is handling authentication. Synapse will refuse to start otherwise."
  163. when: matrix_synapse_matrix_authentication_service_enabled and matrix_synapse_oidc_enabled
  164. - name: Fail if CAS config is enabled for Synapse when auth is delegated to Matrix Authentication Service
  165. ansible.builtin.fail:
  166. msg: "When Synapse is delegating authentication to Matrix Authentication Service (`matrix_synapse_matrix_authentication_service_enabled: true`), it doesn't make sense to enable CAS config (`matrix_synapse_cas_config_enabled: true`), because it is not Synapse that is handling authentication. Synapse will refuse to start otherwise."
  167. when: matrix_synapse_matrix_authentication_service_enabled and matrix_synapse_cas_config_enabled
  168. - name: Fail if QR code login (MSC4108) is enabled while Matrix Authentication Service is not
  169. ansible.builtin.fail:
  170. msg: "When Synapse QR code login is enabled (MSC4108 via `matrix_synapse_experimental_features_msc4108_enabled`), Matrix Authentication Service integration (`matrix_synapse_matrix_authentication_service_enabled`) must also be enabled."
  171. when: matrix_synapse_experimental_features_msc4108_enabled and not matrix_synapse_matrix_authentication_service_enabled