4d62a75f6f
We do this by creating one more layer of indirection. First we reach some generic vhost handling matrix.DOMAIN. A bunch of override rules are added there (capturing traffic to send to ma1sd, etc). nginx-status and similar generic things also live there. We then proxy to the homeserver on some other vhost (only Synapse being available right now, but repointing this to Dendrite or other will be possible in the future). Then that homeserver-specific vhost does its thing to proxy to the homeserver. It may or may not use workers, etc. Without matrix-corporal, the flow is now: 1. matrix.DOMAIN (matrix-nginx-proxy/matrix-domain.conf) 2. matrix-nginx-proxy/matrix-synapse.conf 3. matrix-synapse With matrix-corporal enabled, it becomes: 1. matrix.DOMAIN (matrix-nginx-proxy/matrix-domain.conf) 2. matrix-corporal 3. matrix-nginx-proxy/matrix-synapse.conf 4. matrix-synapse (matrix-corporal gets injected at step 2).
226 lines
7.7 KiB
Django/Jinja
226 lines
7.7 KiB
Django/Jinja
#jinja2: lstrip_blocks: "True"
|
|
|
|
{% set generic_workers = matrix_nginx_proxy_synapse_workers_list|selectattr('type', 'equalto', 'generic_worker')|list %}
|
|
{% set media_repository_workers = matrix_nginx_proxy_synapse_workers_list|selectattr('type', 'equalto', 'media_repository')|list %}
|
|
{% set user_dir_workers = matrix_nginx_proxy_synapse_workers_list|selectattr('type', 'equalto', 'user_dir')|list %}
|
|
{% set frontend_proxy_workers = matrix_nginx_proxy_synapse_workers_list|selectattr('type', 'equalto', 'frontend_proxy')|list %}
|
|
{% if matrix_nginx_proxy_synapse_workers_enabled %}
|
|
# Round Robin "upstream" pools for workers
|
|
|
|
{% if generic_workers %}
|
|
upstream generic_worker_upstream {
|
|
# ensures that requests from the same client will always be passed
|
|
# to the same server (except when this server is unavailable)
|
|
ip_hash;
|
|
|
|
{% for worker in generic_workers %}
|
|
server "matrix-synapse:{{ worker.port }}";
|
|
{% endfor %}
|
|
}
|
|
{% endif %}
|
|
|
|
{% if frontend_proxy_workers %}
|
|
upstream frontend_proxy_upstream {
|
|
{% for worker in frontend_proxy_workers %}
|
|
server "matrix-synapse:{{ worker.port }}";
|
|
{% endfor %}
|
|
}
|
|
{% endif %}
|
|
|
|
{% if media_repository_workers %}
|
|
upstream media_repository_upstream {
|
|
{% for worker in media_repository_workers %}
|
|
server "matrix-synapse:{{ worker.port }}";
|
|
{% endfor %}
|
|
}
|
|
{% endif %}
|
|
|
|
{% if user_dir_workers %}
|
|
upstream user_dir_upstream {
|
|
{% for worker in user_dir_workers %}
|
|
server "matrix-synapse:{{ worker.port }}";
|
|
{% endfor %}
|
|
}
|
|
{% endif %}
|
|
{% endif %}
|
|
|
|
server {
|
|
listen 12080;
|
|
server_name {{ matrix_nginx_proxy_proxy_synapse_hostname }};
|
|
|
|
server_tokens off;
|
|
root /dev/null;
|
|
|
|
gzip on;
|
|
gzip_types text/plain application/json;
|
|
|
|
{% if matrix_nginx_proxy_synapse_workers_enabled %}
|
|
{# Workers redirects BEGIN #}
|
|
|
|
{% if generic_workers %}
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappgeneric_worker
|
|
{% for location in matrix_nginx_proxy_synapse_generic_worker_client_server_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://generic_worker_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
{% endfor %}
|
|
{% endif %}
|
|
|
|
{% if media_repository_workers %}
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappmedia_repository
|
|
{% for location in matrix_nginx_proxy_synapse_media_repository_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://media_repository_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
|
|
client_body_buffer_size 25M;
|
|
client_max_body_size {{ matrix_nginx_proxy_proxy_matrix_client_api_client_max_body_size_mb }}M;
|
|
proxy_max_temp_file_size 0;
|
|
}
|
|
{% endfor %}
|
|
{% endif %}
|
|
|
|
{% if user_dir_workers %}
|
|
# FIXME: obsolete if matrix_nginx_proxy_proxy_matrix_user_directory_search_enabled is set
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappuser_dir
|
|
{% for location in matrix_nginx_proxy_synapse_user_dir_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://user_dir_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
{% endfor %}
|
|
{% endif %}
|
|
|
|
{% if frontend_proxy_workers %}
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappfrontend_proxy
|
|
{% for location in matrix_nginx_proxy_synapse_frontend_proxy_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://frontend_proxy_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
{% endfor %}
|
|
{% if matrix_nginx_proxy_synapse_presence_disabled %}
|
|
# FIXME: keep in sync with synapse workers documentation manually
|
|
location ~ ^/_matrix/client/(api/v1|r0|unstable)/presence/[^/]+/status {
|
|
proxy_pass http://frontend_proxy_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
{% endif %}
|
|
{% endif %}
|
|
{# Workers redirects END #}
|
|
{% endif %}
|
|
|
|
|
|
{% for configuration_block in matrix_nginx_proxy_proxy_synapse_additional_server_configuration_blocks %}
|
|
{{- configuration_block }}
|
|
{% endfor %}
|
|
|
|
{% if matrix_nginx_proxy_proxy_synapse_metrics %}
|
|
location /_synapse/metrics {
|
|
{% if matrix_nginx_proxy_enabled %}
|
|
{# Use the embedded DNS resolver in Docker containers to discover the service #}
|
|
resolver 127.0.0.11 valid=5s;
|
|
set $backend "{{ matrix_nginx_proxy_proxy_synapse_metrics_addr_with_container }}";
|
|
proxy_pass http://$backend;
|
|
{% else %}
|
|
{# Generic configuration for use outside of our container setup #}
|
|
proxy_pass http://{{ matrix_nginx_proxy_proxy_synapse_metrics_addr_sans_container }};
|
|
{% endif %}
|
|
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
|
|
{% if matrix_nginx_proxy_proxy_synapse_metrics_basic_auth_enabled %}
|
|
auth_basic "protected";
|
|
auth_basic_user_file /nginx-data/matrix-synapse-metrics-htpasswd;
|
|
{% endif %}
|
|
}
|
|
{% endif %}
|
|
|
|
{# Everything else just goes to the API server ##}
|
|
location / {
|
|
{% if matrix_nginx_proxy_enabled %}
|
|
{# Use the embedded DNS resolver in Docker containers to discover the service #}
|
|
resolver 127.0.0.11 valid=5s;
|
|
set $backend "{{ matrix_nginx_proxy_proxy_synapse_client_api_addr_with_container }}";
|
|
proxy_pass http://$backend;
|
|
{% else %}
|
|
{# Generic configuration for use outside of our container setup #}
|
|
proxy_pass http://{{ matrix_nginx_proxy_proxy_synapse_client_api_addr_sans_container }};
|
|
{% endif %}
|
|
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
|
|
client_body_buffer_size 25M;
|
|
client_max_body_size {{ matrix_nginx_proxy_proxy_matrix_client_api_client_max_body_size_mb }}M;
|
|
proxy_max_temp_file_size 0;
|
|
}
|
|
}
|
|
|
|
{% if matrix_nginx_proxy_proxy_synapse_federation_api_enabled %}
|
|
server {
|
|
listen 12088;
|
|
|
|
server_name {{ matrix_nginx_proxy_proxy_synapse_hostname }};
|
|
server_tokens off;
|
|
|
|
root /dev/null;
|
|
|
|
gzip on;
|
|
gzip_types text/plain application/json;
|
|
|
|
{% if matrix_nginx_proxy_synapse_workers_enabled %}
|
|
{% if generic_workers %}
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappgeneric_worker
|
|
{% for location in matrix_nginx_proxy_synapse_generic_worker_federation_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://generic_worker_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
{% endfor %}
|
|
{% endif %}
|
|
{% if media_repository_workers %}
|
|
# https://github.com/matrix-org/synapse/blob/master/docs/workers.md#synapseappmedia_repository
|
|
{% for location in matrix_nginx_proxy_synapse_media_repository_locations %}
|
|
location ~ {{ location }} {
|
|
proxy_pass http://media_repository_upstream$request_uri;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
|
|
client_body_buffer_size 25M;
|
|
client_max_body_size {{ matrix_nginx_proxy_proxy_matrix_federation_api_client_max_body_size_mb }}M;
|
|
proxy_max_temp_file_size 0;
|
|
}
|
|
{% endfor %}
|
|
{% endif %}
|
|
{% endif %}
|
|
|
|
location / {
|
|
{% if matrix_nginx_proxy_enabled %}
|
|
{# Use the embedded DNS resolver in Docker containers to discover the service #}
|
|
resolver 127.0.0.11 valid=5s;
|
|
set $backend "{{ matrix_nginx_proxy_proxy_synapse_federation_api_addr_with_container }}";
|
|
proxy_pass http://$backend;
|
|
{% else %}
|
|
{# Generic configuration for use outside of our container setup #}
|
|
proxy_pass http://{{ matrix_nginx_proxy_proxy_synapse_federation_api_addr_sans_container }};
|
|
{% endif %}
|
|
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
|
|
client_body_buffer_size 25M;
|
|
client_max_body_size {{ matrix_nginx_proxy_proxy_matrix_federation_api_client_max_body_size_mb }}M;
|
|
proxy_max_temp_file_size 0;
|
|
}
|
|
}
|
|
{% endif %}
|