Matrix/Riot
-
I am having the issue that federation does not work if the root domain (example.com) is not used at all.
Then I am getting:curl https://example.com/.well-known/matrix/server curl: (60) SSL certificate problem: self signed certificate More details here: https://curl.haxx.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.
Once I set-up example.com as a redirect to matrix.example.com (where matrix synapse is installed) it works.
curl https://example.com/.well-known/matrix/server { "m.server": "matrix.example.com:443" }
-
@stantropics Thanks, now I understand.
Basically, the well-known file is served up Cloudron's reverse proxy/nginx. nginx is only configured to serve all the installed apps domains and redirects. If a domain is not used by an app and not a redirect, nginx will not process the request.
So, this is why it started working after a redirect. It could have been a redirect to any app and not just matrix (i.e you could have redirected to a random app). You could also have installed a random app at
example.com
and it would have worked. -
@girish Okay, thanks for explaining this. Now I know how to handle it and will make sure I have the domain (example.com) assigned to an app.
-
For those using my version and want to migrate to the official cloudron version, this is how you get there (it is a bit hacky, but worked out better in the end than exporting/importing the db and files) - BE CAREFUL WITH THE CLOUDRON CMDS, I DON'T WANT YOU TO MESS UP YOUR SETUPS:
-
backup!
-
grab the latest version from here
-
get the app-id from resources tab/cli/terminal and ssh into your cloudron to update the appstore-id via:
mysql -uroot -ppassword
use box
UPDATE apps SET appStoreId='org.matrix.synapse' WHERE id='your-current-synapse-matrix-app-id';
-
go to Updates, check for a new version and update (do that 3 times and you should be on 0.7.0 which is the latest one)
-
if you had external users like I did, you might need to adjust the following config items in the new homeserver.yaml
enable_registration: true allow_guest_access: true password_config: enabled: true localdb_enabled: true
- move your media_store files from
/app/data/synapse/media_store
to/app/data/data/media_store
or adjust the path in homeserver.yaml - restart and test if everything is working, also check https://federationtester.matrix.org/
Depending on your setup, you might also want to check the new config if the server_name is the same as before - else it won't start I think (I was using a subdomain and the main domain is not on cloudron, so I had to rename it to matrix.mydomain.com and also added echo
'{ "m.server": "matrix.mydomain.com:443" }' > server
to well-known as described above.I also had to re-verify the devices to read the encrypted history, but that worked out fine and it seems to be all there. To finish up, you can rm -rf the old dirs and files, best to compare with a fresh installation to be on the safe side.
-
-
@yusf that is a good question, I moved the app to a different subdomain to test around, but that's probably not it. I'm guessing it is because of new keys and everything, haven't tried to re-use any of the existing ones.
Oh yea, atm there is no default channel, you might want to remove the comment on those lines as well to get new users in there automatically
-
@stantropics already askes this question in the closed matrix thread:
First of all, thanks to everyone who has been working on the matrix app. I'm very happy to be able to run it on cloudron!
Making a user an administrator.
Referring to the documentation (https://github.com/matrix-org/synapse/wiki) one command needs to be executed to make a user an admin - it manipulates the data in the postgresdb:
UPDATE users SET admin = 1 WHERE name = '@foo:bar.com'
What is the recommended way to perform this on Cloudron?Thanks a lot in advance.
Stay healthy everyone!Is there any recommended way to set a user as an admin in the app store released version of matrix?
Thanks!
-
@NCKNE The sql command is probably the way to go for the app store version as well. I will put it in the docs. That said, I am yet to figure what an admin can do that a normal user cannot. Do special controls appear in the riot ui for admins?
-
OK, I found https://github.com/vector-im/riot-web/issues/4125 which is an open issue for implementing admin functions in Riot. I also found https://github.com/Awesome-Technologies/synapse-admin which can probably be run locally.
-
@girish Getting an error on verifying:
$ curl https://example.com/.well-known/matrix/server
curl: (6) Could not resolve host: example.com (I used my own domain)I chowned the matrix folder and server file to be owned by yellowtent. I had to use sudo to get the mkdir command to work.
I set permissions of 0600 on the server file.
There is no app at example.com.
Matrix is installed at matrix.example.com.
Do I need to manually add a DNS entry for example.com? -
@will Only requirement is that it should be used by some app on Cloudron. You don't need to redirect it to matrix specifically.
example.com
can either be any app or it can redirect to any app. (At a technical level, all this means is that the Cloudron's reverse proxy is prepared & ready to answer requests for that domain). -
@will there is no way around this requirement. the matrix protocol requires the apex domain to serve up those documents. is your concern that the domain
example.com
can be used to host a site somewhere else? If so, all you have to do is to move the.well-known
setup to that server/new location.