System Gen171 @ 2026-07-17-23:59:59 by jonas@monolith
This commit is contained in:
@@ -0,0 +1,113 @@
|
||||
{
|
||||
flake.nixosModules.matrix = {
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}: let
|
||||
cfg = config.hive.matrix;
|
||||
in {
|
||||
options.hive.matrix = {
|
||||
enable = lib.mkEnableOption "Enable matrix server (synapse)";
|
||||
|
||||
localPort = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
default = 8474;
|
||||
description = "The internal port of the synapse server";
|
||||
};
|
||||
|
||||
registrationSecretSopsKey = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = "The sops key of the secret containing the registration secret";
|
||||
};
|
||||
|
||||
hiddenServiceHostnameSopsKey = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
description = "The sops key of the secret containing the hostname of the hidden service";
|
||||
};
|
||||
hiddenServiceSecret = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "The file containing the hidden service's secret";
|
||||
};
|
||||
instanceFQDN = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
example = "nextcloud.example.com";
|
||||
description = "Fully qualified domain name of the Nextcloud instance";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
# Database setup
|
||||
services.postgresql = {
|
||||
enable = true;
|
||||
initialScript = pkgs.writeText "matrix-synapse-initScript" ''
|
||||
CREATE ROLE "matrix-synapse";
|
||||
CREATE DATABASE "matrix-synapse" WITH OWNER "matrix-synapse"
|
||||
TEMPLATE template0
|
||||
LC_COLLATE = "C"
|
||||
LC_CTYPE = "C";
|
||||
'';
|
||||
};
|
||||
|
||||
# Hidden service
|
||||
services.tor = {
|
||||
enable = true;
|
||||
enableGeoIP = false;
|
||||
relay.onionServices.matrix = {
|
||||
secretKey = cfg.hiddenServiceSecret;
|
||||
version = 3;
|
||||
map = [
|
||||
{
|
||||
port = 80;
|
||||
target = {
|
||||
addr = "[::1]";
|
||||
port = cfg.localPort;
|
||||
};
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
# Secret hostname for matrix-synapse
|
||||
sops.templates."hidden-matrix-synapse".owner = "matrix-synapse";
|
||||
sops.templates."hidden-matrix-synapse".content = ''
|
||||
server_name: "${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}"
|
||||
public_baseurl: "http://${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}"
|
||||
registration_shared_secret: "${config.sops.placeholder.${cfg.registrationSecretSopsKey}}"
|
||||
'';
|
||||
|
||||
# Synapse
|
||||
services.matrix-synapse = {
|
||||
enable = true;
|
||||
settings.listeners = [
|
||||
{
|
||||
port = cfg.localPort;
|
||||
bind_addresses = ["::1"];
|
||||
type = "http";
|
||||
tls = false;
|
||||
x_forwarded = false;
|
||||
resources = [
|
||||
{
|
||||
names = [
|
||||
"client"
|
||||
];
|
||||
compress = false;
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
settings = {
|
||||
enable_registration = false;
|
||||
registration_requires_token = true;
|
||||
report_stats = false;
|
||||
federation_domain_whitelist = [];
|
||||
federation_ip_range_blacklist = ["0.0.0.0/0"];
|
||||
};
|
||||
|
||||
extraConfigFiles = [
|
||||
config.sops.templates."hidden-matrix-synapse".path
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user