matrix: Conduit and Element, told their own name by the route #166

Open
mesh-admin wants to merge 1 commits from feat/matrix-for-ace into main
Contributor

New module: matrix — Conduit homeserver + Element Web (ace runs both under HAL).

  • server_name = ${bound:route:name-homeserver} in a mesh-rendered conduit.toml (CONDUIT_CONFIG), and the same name in Element's config.json. Depends on mesh-controller #149 — on main the render is refused (name-homeserver), never written empty.
  • Two routes (contributes.route.{homeserver,element}): matrix → 6167, element → 80. No 8448: Conduit's well-known says <name>:443, so federation goes through the route (verified live from outside).
  • allow_registration = false (HAL had it open to the internet with the dummy flow, on 0.10.13 — 0.10.14 fixes an account takeover by any local user). Operator decides whether to reopen it.
  • Element config.json is the one merge:json file; HAL's map_style_url (embedded a tile API key) not carried.
  • Images: the digests ace runs (Conduit 0.10.13, Element 1.12.28). Recommend moving to Conduit 0.10.15 after migration; not proven on ace's data here.

Verified: catalogue tests (MESH_CATALOGUE) on main and #149; #149 resolution renders both names into both files and contributions; throwaway containers of both digests with the rendered files: versions 200, well-known matrix.zurag.be:443, register → M_FORBIDDEN, Element 200 with the rendered config.

New module: **matrix** — Conduit homeserver + Element Web (ace runs both under HAL). - `server_name` = `${bound:route:name-homeserver}` in a mesh-rendered `conduit.toml` (`CONDUIT_CONFIG`), and the same name in Element's `config.json`. **Depends on mesh-controller #149** — on main the render is refused (`name-homeserver`), never written empty. - Two routes (`contributes.route.{homeserver,element}`): `matrix` → 6167, `element` → 80. No 8448: Conduit's well-known says `<name>:443`, so federation goes through the route (verified live from outside). - `allow_registration = false` (HAL had it open to the internet with the dummy flow, on 0.10.13 — 0.10.14 fixes an account takeover by any local user). Operator decides whether to reopen it. - Element `config.json` is the one `merge:json` file; HAL's `map_style_url` (embedded a tile API key) not carried. - Images: the digests ace runs (Conduit 0.10.13, Element 1.12.28). **Recommend moving to Conduit 0.10.15** after migration; not proven on ace's data here. Verified: catalogue tests (MESH_CATALOGUE) on main and #149; #149 resolution renders both names into both files and contributions; throwaway containers of both digests with the rendered files: versions 200, well-known `matrix.zurag.be:443`, register → M_FORBIDDEN, Element 200 with the rendered config.
mesh-admin added 1 commit 2026-09-30 09:59:58 +00:00
ace runs a Conduit homeserver (matrix.zurag.be, 5.4 GB of RocksDB, federating)
and Element Web under HAL, configured by environment with the domain
templated in, and Element's config.json carrying matrix.zurag.be literally.

A homeserver's server_name is its permanent identity - every user id, room id
and signature in the database carries it - and it is the name the module is
served under. So it comes from ${bound:route:name-homeserver} (mesh-controller
#149), rendered into a conduit.toml the container reads through CONDUIT_CONFIG,
and into Element's config.json (base_url, default_server_name, the room
directory). Without #149 the render is refused ("name-homeserver"), never
written empty. Two routes, one per endpoint: homeserver (label matrix, 6167)
and element (label element, 80).

Federation needs no 8448: Conduit answers /.well-known/matrix/server with
<name>:443, so peers federate through the route. HAL published 8448 on all
interfaces, but the router never forwarded it; checked from outside, the
well-known, federation version and client versions all answer on 443.

Registration defaults to off. HAL ran with CONDUIT_ALLOW_REGISTRATION=true,
which on ace means anyone on the internet can create an account with the
dummy flow (seen: /register offers m.login.dummy) - on 0.10.13, whose
successor 0.10.14 fixes an account-takeover by any local user. Existing
accounts are unaffected; the operator decides whether to reopen it.

Element's config.json is the one merge:json file (it tolerates `endpoints`),
so a machine can add keys. HAL's map_style_url is not carried: it embedded
a map-tile API key, which belongs in an assignment if wanted.

Images are the digests ace runs (Conduit 0.10.13, Element 1.12.28).

Verified: catalogue tests with MESH_CATALOGUE pointed here on mesh-controller
main and #149; a resolution on #149 renders both names (matrix.zurag.be,
element.zurag.be) into both files and both contributions; throwaway
containers of both pinned digests with the rendered files (root 0644, :ro):
client versions 200, well-known says matrix.zurag.be:443, register refused
M_FORBIDDEN, Element 200 serving the rendered config.json.
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/matrix-for-ace:feat/matrix-for-ace
git checkout feat/matrix-for-ace
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#166