Synapse on Postgres plus the Element web client, on two subdomains: the homeserver on matrix.<domain> (which becomes server_name, so IDs read @alice:matrix.<domain>) and Element on element.<domain>. Two hosts rather than one because server_name then matches the host Traefik already terminates TLS for, so 'serve_server_wellknown: true' is all the federation delegation needed and nothing has to be published at the apex domain — which this app has no way to configure. CFG_MATRIX_AUTHELIA is pinned false and documented: forward-auth in front of /_matrix locks out every client and every federating peer, since they carry Matrix access tokens and cannot follow a redirect. Real SSO goes through the OIDC block in resources/homeserver.yaml instead. The install hook generates the signing key once via upstream's own 'generate' command and refuses to regenerate it over an existing install — a new key would be rejected by every server that had cached the old one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2 lines
631 B
XML
2 lines
631 B
XML