blob: 66be5ea32e1bb22a61423e033f55db19ba091206 [file] [log] [blame]
Piotr Dobrowolskia2226912019-05-14 18:49:29 +02001# matrix.hackerspace.pl, a matrix/synapse instance
2# This needs a secret provisioned, create with:
Piotr Dobrowolskieabbe8a2019-08-11 19:49:08 +02003# kubectl -n matrix create secret generic synapse --from-literal=postgres_password=$(pwgen 24 1) --from-literal=macaroon_secret_key=$(pwgen 32 1) --from-literal=registration_shared_secret=$(pwgen 32 1)
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +02004# kubectl -n matrix create secret generic oauth2-cas-proxy --from-literal=oauth2_secret=...
Serge Bazanskide627512020-08-24 21:17:55 +00005#
6# Sequencing appservices is fun. The appservice needs to run first (for
7# instance, via a bootstrap job), and on startup it will spit out a
8# registration file. This registration file then needs to be fed to synapse -
9# this is done via specialy named secrets (appservice-X-registration, for X key
10# in the appservices object).
11#
12# For appservice-irc instances, you can use this oneliner magic to get the
13# registration YAML from logs.
Piotr Dobrowolski3ea979d2019-05-23 16:11:52 +020014# kubectl -n matrix create secret generic appservice-irc-freenode-registration --from-file=registration.yaml=<(kubectl logs -n matrix $(kubectl get pods -n matrix --selector=job-name=appservice-irc-freenode-bootstrap --output=jsonpath='{.items[*].metadata.name}') | tail -n +4 | sed -r 's/(.*aliases:.*)/ group_id: "+freenode:hackerspace.pl"\n\1/')
Serge Bazanskide627512020-08-24 21:17:55 +000015#
16# For appservice-telegram instances, you can use this oneliner magic:
17# kubectl -n matrix create secret generic appservice-telegram-prod-registration --from-file=registration.yaml=<(kubectl -n matrix logs job/appservice-telegram-prod-bootstrap | grep -A 100 SNIPSNIP | grep -v SNIPSNIP)
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020018
19local kube = import "../../kube/kube.libsonnet";
20local postgres = import "../../kube/postgres.libsonnet";
21
Serge Bazanskicdba2912020-08-24 19:11:10 +000022local irc = import "appservice-irc.libsonnet";
Serge Bazanskide627512020-08-24 21:17:55 +000023local telegram = import "appservice-telegram.libsonnet";
Serge Bazanskicdba2912020-08-24 19:11:10 +000024
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020025{
26 local app = self,
27 local cfg = app.cfg,
28 cfg:: {
29 namespace: "matrix",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020030 domain: "matrix.hackerspace.pl",
31 serverName: "hackerspace.pl",
Serge Bazanskide627512020-08-24 21:17:55 +000032 storageClassName: "waw-hdd-redundant-3",
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +020033
Sergiusz Bazanskiec221a02020-07-17 12:50:18 +020034 synapseImage: "matrixdotorg/synapse:v1.17.0",
35 riotImage: "vectorim/riot-web:v1.7.1",
Sergiusz Bazanski735ac9c2020-07-17 12:10:42 +020036 casProxyImage: "registry.k0.hswaw.net/q3k/oauth2-cas-proxy:0.1.4",
37 appserviceIRCImage: "matrixdotorg/matrix-appservice-irc:release-0.17.1",
Serge Bazanskide627512020-08-24 21:17:55 +000038 # That's v0.8.2 - we just don't trust that host to not re-tag images.
39 appserviceTelegramImage: "dock.mau.dev/tulir/mautrix-telegram@sha256:9e68eaa80c9e4a75d9a09ec92dc4898b12d48390e01efa4de40ce882a6f7e330"
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020040 },
41
42 metadata(component):: {
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +020043 namespace: cfg.namespace,
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020044 labels: {
45 "app.kubernetes.io/name": "matrix",
46 "app.kubernetes.io/managed-by": "kubecfg",
47 "app.kubernetes.io/component": component,
48 },
49 },
50
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +020051 namespace: kube.Namespace(cfg.namespace),
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020052
Serge Bazanskic0c037a2020-08-23 01:24:03 +000053 postgres3: postgres {
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020054 cfg+: {
55 namespace: cfg.namespace,
56 appName: "synapse",
57 database: "synapse",
58 username: "synapse",
Serge Bazanskic0c037a2020-08-23 01:24:03 +000059 prefix: "waw3-",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020060 password: { secretKeyRef: { name: "synapse", key: "postgres_password" } },
Serge Bazanskide627512020-08-24 21:17:55 +000061 storageClassName: cfg.storageClassName,
Serge Bazanskic0c037a2020-08-23 01:24:03 +000062 storageSize: "100Gi",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020063 },
64 },
65
Serge Bazanskic0c037a2020-08-23 01:24:03 +000066 dataVolume: kube.PersistentVolumeClaim("synapse-data-waw3") {
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020067 metadata+: app.metadata("synapse-data"),
68 spec+: {
Serge Bazanskide627512020-08-24 21:17:55 +000069 storageClassName: cfg.storageClassName,
Piotr Dobrowolskia2226912019-05-14 18:49:29 +020070 accessModes: [ "ReadWriteOnce" ],
71 resources: {
72 requests: {
73 storage: "50Gi",
74 },
75 },
76 },
77 },
Piotr Dobrowolskiffbb47c2019-05-16 12:18:39 +020078
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +020079 synapseConfig: kube.ConfigMap("synapse") {
80 metadata+: app.metadata("synapse"),
81 data: {
Piotr Dobrowolskieabbe8a2019-08-11 19:49:08 +020082 "homeserver.yaml": importstr "homeserver.yaml",
83 "log.config": importstr "log.config",
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +020084 },
85 },
86
87 casDeployment: kube.Deployment("oauth2-cas-proxy") {
88 metadata+: app.metadata("oauth2-cas-proxy"),
89 spec+: {
90 replicas: 1,
91 template+: {
92 spec+: {
93 containers_: {
94 proxy: kube.Container("oauth2-cas-proxy") {
95 image: cfg.casProxyImage,
96 ports_: {
97 http: { containerPort: 5000 },
98 },
99 env_: {
100 BASE_URL: "https://matrix.hackerspace.pl",
Piotr Dobrowolskiaa0e7552019-05-17 12:55:48 +0200101 SERVICE_URL: "https://matrix.hackerspace.pl",
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +0200102 OAUTH2_CLIENT: "matrix",
103 OAUTH2_SECRET: { secretKeyRef: { name: "oauth2-cas-proxy", key: "oauth2_secret" } },
104 },
105 },
106 },
107 },
108 },
109 },
110 },
111
112 casSvc: kube.Service("oauth2-cas-proxy") {
113 metadata+: app.metadata("oauth2-cas-proxy"),
114 target_pod:: app.casDeployment.spec.template,
115 },
116
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200117 synapseDeployment: kube.Deployment("synapse") {
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200118 metadata+: app.metadata("synapse"),
119 spec+: {
120 replicas: 1,
121 template+: {
122 spec+: {
123 volumes_: {
124 data: kube.PersistentVolumeClaimVolume(app.dataVolume),
Piotr Dobrowolski8ebfc1d2020-03-03 21:01:18 +0100125 config_template: kube.ConfigMapVolume(app.synapseConfig),
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200126 } + {
127 [k]: { secret: { secretName: "appservice-%s-registration" % [k] } }
128 for k in std.objectFields(app.appservices)
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200129 },
130 containers_: {
131 web: kube.Container("synapse") {
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200132 image: cfg.synapseImage,
Piotr Dobrowolski8ebfc1d2020-03-03 21:01:18 +0100133 command: ["/bin/sh", "-c", "/start.py migrate_config && exec /start.py"],
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200134 ports_: {
135 http: { containerPort: 8008 },
136 },
137 env_: {
Piotr Dobrowolski8ebfc1d2020-03-03 21:01:18 +0100138 SYNAPSE_CONFIG_DIR: "/config",
Piotr Dobrowolskieabbe8a2019-08-11 19:49:08 +0200139 SYNAPSE_CONFIG_PATH: "/config/homeserver.yaml",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200140
Piotr Dobrowolski8ebfc1d2020-03-03 21:01:18 +0100141 # These values are not used in a template, but
142 # are required by /start.py migrate_config
143 SYNAPSE_SERVER_NAME: "hackerspace.pl",
144 SYNAPSE_REPORT_STATS: "no",
145
146 SYNAPSE_MACAROON_SECRET_KEY: { secretKeyRef: { name: "synapse", key: "macaroon_secret_key" } },
147 SYNAPSE_REGISTRATION_SHARED_SECRET: { secretKeyRef: { name: "synapse", key: "registration_shared_secret" } },
148 POSTGRES_PASSWORD: { secretKeyRef: { name: "synapse", key: "postgres_password" } },
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200149 },
150 volumeMounts_: {
151 data: { mountPath: "/data" },
Piotr Dobrowolski8ebfc1d2020-03-03 21:01:18 +0100152 config_template: {
153 mountPath: "/conf/homeserver.yaml",
154 subPath: "homeserver.yaml",
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +0200155 },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200156 } + {
157 [k]: { mountPath: "/appservices/%s" % [k] }
158 for k in std.objectFields(app.appservices)
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200159 },
160 },
161 },
162 },
163 },
164 },
165 },
166
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200167 synapseSvc: kube.Service("synapse") {
Piotr Dobrowolskiffbb47c2019-05-16 12:18:39 +0200168 metadata+: app.metadata("synapse"),
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200169 target_pod:: app.synapseDeployment.spec.template,
Piotr Dobrowolskiffbb47c2019-05-16 12:18:39 +0200170 },
171
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200172 riotConfig: kube.ConfigMap("riot-web-config") {
173 metadata+: app.metadata("riot-web-config"),
174 data: {
175 "config.json": std.manifestJsonEx({
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +0200176 "default_hs_url": "https://%s" % [cfg.domain],
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200177 "disable_custom_urls": false,
178 "disable_guests": false,
179 "disable_login_language_selector": false,
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +0200180 "disable_3pid_login": true,
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200181 "brand": "Riot",
182 "integrations_ui_url": "https://scalar.vector.im/",
183 "integrations_rest_url": "https://scalar.vector.im/api",
184 "integrations_jitsi_widget_url": "https://scalar.vector.im/api/widgets/jitsi.html",
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +0200185
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200186 "bug_report_endpoint_url": "https://riot.im/bugreports/submit",
187 "features": {
188 "feature_groups": "labs",
189 "feature_pinning": "labs",
190 "feature_reactions": "labs"
191 },
192 "default_federate": true,
193 "default_theme": "light",
194 "roomDirectory": {
195 "servers": [
Piotr Dobrowolski4b4231d2019-05-15 11:41:21 +0200196 "hackerspace.pl"
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200197 ]
198 },
199 "welcomeUserId": "@riot-bot:matrix.org",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200200 "enable_presence_by_hs_url": {
201 "https://matrix.org": false
202 }
203 }, ""),
204 },
205 },
206
207 riotDeployment: kube.Deployment("riot-web") {
208 metadata+: app.metadata("riot-web"),
209 spec+: {
210 replicas: 1,
211 template+: {
212 spec+: {
213 volumes_: {
214 config: kube.ConfigMapVolume(app.riotConfig),
215 },
216 containers_: {
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200217 web: kube.Container("riot-web") {
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200218 image: cfg.riotImage,
219 ports_: {
220 http: { containerPort: 80 },
221 },
222 volumeMounts_: {
223 config: {
Piotr Dobrowolskiaca7e282020-03-21 22:14:38 +0100224 mountPath: "/app/config.json",
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200225 subPath: "config.json",
226 },
227 },
228 },
229 },
230 },
231 },
232 },
233 },
234
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200235 riotSvc: kube.Service("riot-web") {
236 metadata+: app.metadata("riot-web"),
237 target_pod:: app.riotDeployment.spec.template,
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200238 },
239
Serge Bazanskide627512020-08-24 21:17:55 +0000240 // Any appservice you add here will require an appservice-X-registration
241 // secret containing a registration.yaml file. Adding something to this
242 // dictionary will cause Synapse to not start until that secret is
243 // available - so change things carefully!
244 // If bootstrapping a new appservice, just keep it out of this dictionary
245 // until it spits you a registration YAML and you feed that to a secret.
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200246 appservices: {
Serge Bazanskicdba2912020-08-24 19:11:10 +0000247 "irc-freenode": irc.AppServiceIrc("freenode") {
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200248 cfg+: {
Serge Bazanskicdba2912020-08-24 19:11:10 +0000249 image: cfg.appserviceIRCImage,
Serge Bazanskide627512020-08-24 21:17:55 +0000250 // TODO(q3k): move this appservice to waw-hdd-redundant-3
251 storageClassName: "waw-hdd-paranoid-2",
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200252 metadata: app.metadata("appservice-irc-freenode"),
Sergiusz Bazanski92b48d62020-01-08 13:59:04 +0100253 // TODO(q3k): add labels to blessed nodes
254 nodeSelector: {
Serge Bazanski1b15dc42020-08-23 01:01:28 +0200255 "kubernetes.io/hostname": "bc01n03.hswaw.net",
Sergiusz Bazanski92b48d62020-01-08 13:59:04 +0100256 },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200257 config+: {
258 homeserver+: {
259 url: "https://%s" % [cfg.domain],
260 domain: "%s" % [cfg.serverName],
261 },
Piotr Dobrowolskieabbe8a2019-08-11 19:49:08 +0200262 ircService+: {
263 servers+: {
264 "irc.freenode.net"+: {
265 ircClients+: {
266 maxClients: 150,
267 },
268 },
269 },
270 },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200271 },
272 },
273 },
Serge Bazanskide627512020-08-24 21:17:55 +0000274 "telegram-prod": telegram.AppServiceTelegram("prod") {
275 cfg+: {
276 image: cfg.appserviceTelegramImage,
277 storageClassName: cfg.storageClassName,
278 metadata: app.metadata("appservice-telegram-prod"),
279
280 config+: {
281 homeserver+: {
282 address: "https://%s" % [cfg.domain],
283 domain: cfg.serverName,
284 },
285 appservice+: {
286 id: "telegram",
287 },
288 telegram+: {
289 api_id: (std.split(importstr "secrets/plain/appservice-telegram-prod-api-id", "\n"))[0],
290 api_hash: (std.split(importstr "secrets/plain/appservice-telegram-prod-api-hash", "\n"))[0],
291 bot_token: (std.split(importstr "secrets/plain/appservice-telegram-prod-token", "\n"))[0],
292 },
293 bridge+: {
294 permissions+: {
295 "hackerspace.pl": "puppeting",
296 "@q3k:hackerspace.pl": "admin",
297 },
298 },
299 },
300 },
301 },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200302 },
303
304 ingress: kube.Ingress("matrix") {
305 metadata+: app.metadata("matrix") {
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200306 annotations+: {
307 "kubernetes.io/tls-acme": "true",
308 "certmanager.k8s.io/cluster-issuer": "letsencrypt-prod",
309 "nginx.ingress.kubernetes.io/proxy-body-size": "0",
310 },
311 },
312 spec+: {
313 tls: [
314 {
315 hosts: [cfg.domain],
316 secretName: "synapse-tls",
317 },
318 ],
319 rules: [
320 {
321 host: cfg.domain,
322 http: {
323 paths: [
324 { path: "/", backend: app.riotSvc.name_port },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200325 { path: "/_matrix", backend: app.synapseSvc.name_port },
Piotr Dobrowolskic39fb042019-05-17 09:13:56 +0200326 { path: "/_cas", backend: app.casSvc.name_port },
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200327 ]
328 },
329 }
330 ],
331 },
332 },
Piotr Dobrowolskifef4c122019-05-16 21:05:02 +0200333
Piotr Dobrowolskia2226912019-05-14 18:49:29 +0200334}