summary refs log tree commit diff
path: root/host/Rory-nginx/services/matrix/synapse/workers/auth.nix
blob: 2313a4db81b8be1b40b5278140050b1080cce63f (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
{ config, lib, ... }:

let
  cfg = config.services.matrix-synapse;
  dbGroup = "solo";
  hasClientResource = false;
  hasFederationResource = false;
  workers = lib.range 0 (cfg.authWorkers - 1);
  workerName = "auth";
  workerRoutes = {
    client = [
      "~ ^/_matrix/client/(api/v1|r0|v3|unstable)/login$"
      "~ ^/_matrix/client/(api/v1|r0|v3|unstable)/account/3pid$"
      "~ ^/_matrix/client/(api/v1|r0|v3|unstable)/account/whoami$"
      "~ ^/_matrix/client/versions$"
      "~ ^/_matrix/client/(api/v1|r0|v3|unstable)/voip/turnServer$"
      "~ ^/_matrix/client/(r0|v3|unstable)/register$"
      "~ ^/_matrix/client/(r0|v3|unstable)/register/available$"
      "~ ^/_matrix/client/(r0|v3|unstable)/auth/.*/fallback/web$"
      "~ ^/_matrix/client/(r0|v3|unstable)/password_policy$"
      "~ ^/_matrix/client/(r0|v3|unstable)/capabilities$"
    ];
  };
in
{
  config = lib.mkIf (cfg.authWorkers > 0) {
    services.matrix-synapse = {
      settings = {
        instance_map = lib.listToAttrs (
          lib.map (index: {
            name = "${workerName}-${toString index}";
            value = {
              path = "/run/matrix-synapse/${workerName}-${toString index}.sock";
            };
          }) workers
        );
      };

      workers = lib.listToAttrs (
        lib.map (index: {
          name = "${workerName}-${toString index}";
          value = {
            worker_app = "synapse.app.generic_worker";
            worker_listeners = [
              {
                type = "http";
                path = "/run/matrix-synapse/${workerName}-${toString index}.sock";
                resources = [
                  {
                    names = [ "replication" ];
                    compress = false;
                  }
                ];
              }
              {
                type = "http";
                path = "/run/matrix-synapse/${workerName}-client-${toString index}.sock";
                mode = "666";
                resources = [
                  {
                    names = [ "client" ];
                    compress = false;
                  }
                ];
              }
            ];
            database = (
              import ../db.nix {
                inherit dbGroup;
                workerName = "${workerName}-${toString index}";
              }
            );
          };
        }) workers
      );
    };

    services.nginx.upstreams."${workerName}" = {
      extraConfig = ''
        keepalive 32;
      '';
      servers = lib.listToAttrs (
        lib.map (index: {
          name = "unix:/run/matrix-synapse/${workerName}-client-${toString index}.sock";
          value = {
            max_fails = 0;
          };
        }) workers
      );
    };

    services.nginx.virtualHosts."${cfg.nginxVirtualHostName}".locations = lib.listToAttrs (
      lib.map (route: {
        name = route;
        value = {
          proxyPass = "http://${workerName}";
        };
      }) workerRoutes
    );
  };
}