LibrePortal/containers/matrix/matrix.config
librelad a96a3a69a1 fix(linkding): declare the admin keys its auth adapter writes
linkding_auth.sh persists ADMIN_USER and ADMIN_PASSWORD when the first admin is
created, and keeps the password in step on later resets of that account, but
linkding.config declared neither — so both writes were no-ops and the WebUI
credentials card never had anything to show. Predates the slot work; it only
became visible once authPersistCfg started warning instead of failing silently.

Added empty rather than RANDOMIZED*, because unlike bookstack or nextcloud
nothing seeds a linkding account at install — the first user is created from the
WebUI. A generated password would name an account that does not exist, and the
card would display a password that cannot log in. Unslotted for the same reason:
the slot number marks a value the installer generates, and this one is written at
runtime by the tool.

No AUTH_PROFILE key: nothing reads it (it exists only in a comment in
auth_adapter.sh), and adding an unread key is what was just cleaned up elsewhere.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 21:24:28 +01:00

120 lines
6.9 KiB
Plaintext

#
# =============================================================================
# GENERAL CONFIGURATION
# =============================================================================
# APP_NAME = name of application for use in scripts
# REQUIRES = comma-separated install prerequisites (see scripts/checks/requirements/check_app_install.sh)
# COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is
# BACKUP = if true, include this application in backup operations
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
# HEALTHCHECK = if true, default docker health checks for that container will be enabled
# AUTHELIA = if true, use Authelia authentication, if false turned off.
# HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote
# ENABLE_REGISTRATION = if true, anyone who can reach the homeserver can create an account on it
# ADMIN_USERNAME = localpart of the first admin account created at install (the full ID becomes @<name>:<server_name>)
# ADMIN_PASSWORD = password for that first admin account
# SERVER_NAME = permanent identity of this homeserver — the half of a user ID after the colon
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed)
#
CFG_MATRIX_APP_NAME=matrix
# No prerequisites. Synapse runs perfectly well on a plain HTTP listener reached
# by IP over the LAN or a WireGuard tunnel — that is the same setup as sitting
# behind a reverse proxy, minus the proxy. Only *federation* needs a real domain
# with public DNS and TLS, and federation is optional.
CFG_MATRIX_REQUIRES=""
CFG_MATRIX_BACKUP=true
CFG_MATRIX_BACKUP_STRATEGY=auto
CFG_MATRIX_UPDATE_TYPE=auto
CFG_MATRIX_COMPOSE_FILE=default
CFG_MATRIX_HEALTHCHECK=true
# Must stay false. Authelia's forward-auth would sit in front of /_matrix, which
# is the API every Matrix client and every federating server speaks — they
# authenticate with Matrix access tokens and cannot follow an Authelia redirect,
# so turning this on breaks all clients and federation at once. Synapse can do
# real SSO against Authelia instead, via the OIDC block in
# resources/homeserver.yaml.
CFG_MATRIX_AUTHELIA=false
CFG_MATRIX_HEADSCALE=false
CFG_MATRIX_ENABLE_REGISTRATION=false
CFG_MATRIX_ADMIN_USERNAME=admin
CFG_MATRIX_ADMIN_PASSWORD_1=RANDOMIZEDPASSWORD1
# Set this if you ever intend to federate — it is the single most consequential
# value here and the ONLY one that cannot be changed later. It is signed into
# every event this server sends and forms the half of a user ID after the colon
# (@alice:example.com), so changing it orphans the database.
#
# Crucially it is independent of how clients reach the server: you can set it to
# a domain you own that has no DNS pointing anywhere yet, run today on
# http://<lan-ip>:<port>, and switch federation on later by adding DNS, Traefik
# and a certificate — with no rebuild and no lost history.
#
# Left empty it is derived: <subdomain>.<domain> when a domain is configured,
# otherwise this machine's LAN address. The LAN address works fine for local and
# WireGuard use but can never federate, and every user ID breaks if the IP
# changes — so if in doubt, put a domain here even if you do not use it yet.
CFG_MATRIX_SERVER_NAME=
CFG_MATRIX_MONITORING=false
# Postgres password for the `synapse` role, fed to the compose via
# #LIBREPORTAL|MATRIX_DB_PASSWORD_1_TAG| and written into homeserver.yaml by the
# install hook. Generated on first install and preserved across reinstalls —
# initdb sets it once when the volume is created, so a regenerated value would
# leave Synapse unable to open its own database.
CFG_MATRIX_DB_PASSWORD_1=RANDOMIZEDPASSWORD2
#
# =============================================================================
# METADATA
# =============================================================================
# CATEGORY = application category for grouping
# TITLE = display name for the application
# DESCRIPTION = short description of the application
# LONG_DESCRIPTION = detailed description of the application
# URL = source repository or documentation URL
# ACTIONS = available actions for this application
# REQUIRES_SERVICE = name of another LibrePortal app that must be installed before this one can be configured
#
CFG_MATRIX_CATEGORY="communication"
CFG_MATRIX_TITLE="Matrix"
CFG_MATRIX_DESCRIPTION="Federated Chat"
CFG_MATRIX_LONG_DESCRIPTION="The open federated chat protocol — rooms, end-to-end encryption and bridges to Discord and Slack. Installs Synapse plus the Element web client"
CFG_MATRIX_URL="https://github.com/element-hq/synapse"
CFG_MATRIX_ACTIONS="configure|install|restart|shutdown|uninstall"
#
# =============================================================================
# NETWORK CONFIGURATION
# =============================================================================
# DOMAIN = number of domain from the general config, useful when using multiple domains
# WHITELIST = if true only allow whitelisted ips (see general config), if false allow all
#
CFG_MATRIX_DOMAIN=1
CFG_MATRIX_WHITELIST=false
CFG_MATRIX_NETWORK=default
#
# =============================================================================
# PORT CONFIGURATION
# =============================================================================
# PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description
# - app: application name
# - name: service identifier (webui, dns, ssh, etc.)
# - external:internal: port mapping (external can be 'random' for auto-allocation)
# - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running)
# - protocol: 'tcp' or 'udp'
# - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true)
# - traefik: if true, Traefik handles this port (reverse proxy)
# - webui: if true, this port serves the main web interface
# - description: human-readable description of the service
#
# Two hosts, on purpose. Port 1 is the homeserver API on matrix.<domain>, which
# becomes server_name — so user IDs read @alice:matrix.<domain>. Port 2 is the
# Element web client on element.<domain>. Keeping them apart means Synapse can
# answer /.well-known/matrix/server for itself and federation needs no
# delegation from the apex domain, which this app has no way to configure.
#
# Port 1 must NOT be marked login=true: /_matrix is the client and federation
# API and basic-auth in front of it locks out every client and every peer.
#
CFG_MATRIX_PORT_1="matrix-synapse|homeserver|random:8008|public|tcp|false|true|false|Matrix Homeserver (client + federation API)||matrix"
CFG_MATRIX_PORT_2="matrix-element|webui|random:80|public|tcp|false|true|true|Element Web Interface||element"
# AUTH_PROFILE = capability tier for the WebUI auth tools (single_password | user_password | multi_user)
CFG_MATRIX_AUTH_PROFILE=multi_user