setup proxy for federation
This commit is contained in:
parent
9391a79415
commit
45805e1ed0
2 changed files with 10 additions and 6 deletions
|
@ -4,19 +4,21 @@ server {
|
||||||
listen 443 ssl http2;
|
listen 443 ssl http2;
|
||||||
listen [::]:443 ssl http2;
|
listen [::]:443 ssl http2;
|
||||||
|
|
||||||
# For the federation port
|
|
||||||
listen 8448 ssl http2 default_server;
|
|
||||||
listen [::]:8448 ssl http2 default_server;
|
|
||||||
|
|
||||||
server_name {{ matrix_server_name }};
|
server_name {{ matrix_server_name }};
|
||||||
|
|
||||||
ssl_certificate /etc/nginx/certs/{{ matrix_server_name }}.crt;
|
ssl_certificate /etc/nginx/certs/{{ matrix_server_name }}.crt;
|
||||||
ssl_certificate_key /etc/nginx/certs/{{ matrix_server_name }}.key;
|
ssl_certificate_key /etc/nginx/certs/{{ matrix_server_name }}.key;
|
||||||
|
|
||||||
# Logs
|
# Logs
|
||||||
access_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}.log;
|
access_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}.log;
|
||||||
error_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}_error.log;
|
error_log /var/log/nginx/synapse_rp_{{ matrix_server_name }}_error.log;
|
||||||
|
|
||||||
|
location /.well-known/matrix/server {
|
||||||
|
return 200 '{"m.server": "deso-palaiseau.fr:443"}';
|
||||||
|
default_type application/json;
|
||||||
|
add_header Access-Control-Allow-Origin *;
|
||||||
|
}
|
||||||
|
|
||||||
location ~* ^(\/_matrix|\/_synapse\/client) {
|
location ~* ^(\/_matrix|\/_synapse\/client) {
|
||||||
proxy_pass https://{{ matrix_local_server_name }};
|
proxy_pass https://{{ matrix_local_server_name }};
|
||||||
proxy_set_header X-Forwarded-For $remote_addr;
|
proxy_set_header X-Forwarded-For $remote_addr;
|
||||||
|
|
|
@ -371,6 +371,8 @@ retention:
|
||||||
|
|
||||||
## TLS ##
|
## TLS ##
|
||||||
|
|
||||||
|
no_tls: True
|
||||||
|
|
||||||
# PEM-encoded X509 certificate for TLS.
|
# PEM-encoded X509 certificate for TLS.
|
||||||
# This certificate, as of Synapse 1.0, will need to be a valid and verifiable
|
# This certificate, as of Synapse 1.0, will need to be a valid and verifiable
|
||||||
# certificate, signed by a recognised Certificate Authority.
|
# certificate, signed by a recognised Certificate Authority.
|
||||||
|
|
Loading…
Reference in a new issue