setup proxy for federation

This commit is contained in:
histausse 2021-08-03 03:44:37 +02:00
parent 9391a79415
commit 45805e1ed0
Signed by: histausse
GPG key ID: 67486F107F62E9E9
2 changed files with 10 additions and 6 deletions

View file

@ -4,19 +4,21 @@ server {
listen 443 ssl http2; listen 443 ssl http2;
listen [::]:443 ssl http2; listen [::]:443 ssl http2;
# For the federation port
listen 8448 ssl http2 default_server;
listen [::]:8448 ssl http2 default_server;
server_name {{ matrix_server_name }}; server_name {{ matrix_server_name }};
ssl_certificate /etc/nginx/certs/{{ matrix_server_name }}.crt; ssl_certificate /etc/nginx/certs/{{ matrix_server_name }}.crt;
ssl_certificate_key /etc/nginx/certs/{{ matrix_server_name }}.key; ssl_certificate_key /etc/nginx/certs/{{ matrix_server_name }}.key;
# Logs # Logs
access_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}.log; access_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}.log;
error_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}_error.log; error_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}_error.log;
location /.well-known/matrix/server {
return 200 '{"m.server": "deso-palaiseau.fr:443"}';
default_type application/json;
add_header Access-Control-Allow-Origin *;
}
location ~* ^(\/_matrix|\/_synapse\/client) { location ~* ^(\/_matrix|\/_synapse\/client) {
proxy_pass https://{{ matrix_local_server_name }}; proxy_pass https://{{ matrix_local_server_name }};
proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-For $remote_addr;

View file

@ -371,6 +371,8 @@ retention:
## TLS ## ## TLS ##
no_tls: True
# PEM-encoded X509 certificate for TLS. # PEM-encoded X509 certificate for TLS.
# This certificate, as of Synapse 1.0, will need to be a valid and verifiable # This certificate, as of Synapse 1.0, will need to be a valid and verifiable
# certificate, signed by a recognised Certificate Authority. # certificate, signed by a recognised Certificate Authority.