From 7c2675f0e9d94c13f8b1de9a7922d4a1ea4835c3 Mon Sep 17 00:00:00 2001 From: Daniel Bulant Date: Fri, 14 Aug 2026 23:13:33 +0200 Subject: [PATCH] matrix --- flake.nix | 7 +++ modules/tuwunel-admin.nix | 83 +++++++++++++++++++++++++++++++++ pkgs/tuwunel-admin/package.nix | 28 +++++++++++ servers/eisen/configuration.nix | 42 +++++++++++++---- 4 files changed, 152 insertions(+), 8 deletions(-) create mode 100644 modules/tuwunel-admin.nix create mode 100644 pkgs/tuwunel-admin/package.nix diff --git a/flake.nix b/flake.nix index 0e9d070..198f9b6 100644 --- a/flake.nix +++ b/flake.nix @@ -107,10 +107,17 @@ # Export sysbox package overlay for external use overlays.default = final: prev: { sysbox = final.callPackage ./pkgs/sysbox/package.nix { }; + tuwunel-admin = final.callPackage ./pkgs/tuwunel-admin/package.nix { }; }; # Export sysbox NixOS module for external use nixosModules.sysbox = import ./modules/sysbox.nix; + nixosModules.tuwunel-admin = import ./modules/tuwunel-admin.nix; + + packages.x86_64-linux = rec { + tuwunel-admin = nixpkgs.legacyPackages.x86_64-linux.callPackage ./pkgs/tuwunel-admin/package.nix { }; + default = tuwunel-admin; + }; nixosConfigurations.fern = nixpkgs.lib.nixosSystem { system = "x86_64-linux"; diff --git a/modules/tuwunel-admin.nix b/modules/tuwunel-admin.nix new file mode 100644 index 0000000..c4b56fa --- /dev/null +++ b/modules/tuwunel-admin.nix @@ -0,0 +1,83 @@ +{ + config, + lib, + pkgs, + ... +}: + +let + cfg = config.services.tuwunel-admin; + tomlFormat = pkgs.formats.toml { }; + configFile = tomlFormat.generate "tuwunel-admin.toml" cfg.settings; +in +{ + options.services.tuwunel-admin = { + enable = lib.mkEnableOption "tuwunel-admin web UI"; + + package = lib.mkOption { + type = lib.types.package; + default = pkgs.callPackage ../pkgs/tuwunel-admin/package.nix { }; + defaultText = lib.literalExpression "pkgs.callPackage ../pkgs/tuwunel-admin/package.nix { }"; + description = "The tuwunel-admin package to use."; + }; + + settings = lib.mkOption { + type = tomlFormat.type; + default = { }; + example = { + server.bind = "127.0.0.1:8009"; + matrix = { + homeservers = [ "https://matrix.example.com" ]; + allow_any_server = false; + admin_bot = "@tuwunel:matrix.example.com"; + admin_room_alias = "#admins:matrix.example.com"; + device_id = "tuwunel-admin"; + device_display_name = "tuwunel-admin"; + }; + }; + description = '' + Configuration written to tuwunel-admin's TOML configuration file. + See . + ''; + }; + }; + + config = lib.mkIf cfg.enable { + systemd.services.tuwunel-admin = { + description = "tuwunel Matrix administration UI"; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + + serviceConfig = { + Type = "simple"; + ExecStart = "${lib.getExe cfg.package} --config ${configFile}"; + Restart = "on-failure"; + RestartSec = "5s"; + + DynamicUser = true; + NoNewPrivileges = true; + PrivateDevices = true; + PrivateTmp = true; + ProtectClock = true; + ProtectControlGroups = true; + ProtectHome = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectSystem = "strict"; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictSUIDSGID = true; + SystemCallArchitectures = "native"; + SystemCallFilter = [ "@system-service" ]; + UMask = "0077"; + }; + }; + }; +} diff --git a/pkgs/tuwunel-admin/package.nix b/pkgs/tuwunel-admin/package.nix new file mode 100644 index 0000000..5a26d16 --- /dev/null +++ b/pkgs/tuwunel-admin/package.nix @@ -0,0 +1,28 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, +}: + +rustPlatform.buildRustPackage rec { + pname = "tuwunel-admin"; + version = "0.1.0"; + + src = fetchFromGitHub { + owner = "knadh"; + repo = "tuwunel-admin"; + tag = "v${version}"; + hash = "sha256-60yPa+B6PYzOoCjQyeqdy5vdF5BCFNVv2CTofPi6lRQ="; + }; + + cargoHash = "sha256-TpC+5/Ox04aQpUSssMnaVadq7+sroW9mJViVFGNsVIk="; + + env.VERSION = "v${version}"; + + meta = { + description = "Web admin UI for the tuwunel Matrix server"; + homepage = "https://github.com/knadh/tuwunel-admin"; + license = lib.licenses.asl20; + mainProgram = "tuwunel-admin"; + }; +} diff --git a/servers/eisen/configuration.nix b/servers/eisen/configuration.nix index cb2cedd..aeb9844 100644 --- a/servers/eisen/configuration.nix +++ b/servers/eisen/configuration.nix @@ -35,8 +35,10 @@ let prometheus-llama-swap = 9409; prometheus = 9090; livekit-jwt = 8080; + tuwunel-admin = 8009; }; - matrixServerName = "matrix.badapple.cz"; + matrixServerName = "badapple.cz"; + matrixHost = "matrix.badapple.cz"; livekitKeyFile = "/var/lib/livekit/keys"; in { @@ -53,6 +55,7 @@ in nix-index-database.nixosModules.nix-index ./hardware-configuration.nix ../../modules/llama-swap-exporter.nix + ../../modules/tuwunel-admin.nix ]; nix = { @@ -104,8 +107,23 @@ in registration_token_file = "/etc/secrets/matrix-registration-token"; well_known = { - client = "https://${matrixServerName}"; - livekit_url = "wss://${matrixServerName}/livekit/sfu"; + client = "https://${matrixHost}"; + livekit_url = "https://${matrixHost}/livekit/jwt"; + }; + }; + }; + + tuwunel-admin = { + enable = true; + settings = { + server.bind = "127.0.0.1:${toString internalPorts.tuwunel-admin}"; + matrix = { + homeservers = [ "https://${matrixHost}" ]; + allow_any_server = false; + admin_bot = "@tuwunel:${matrixServerName}"; + admin_room_alias = "#admins:${matrixServerName}"; + device_id = "tuwunel-admin"; + device_display_name = "tuwunel-admin"; }; }; }; @@ -120,6 +138,8 @@ in rtc = { tcp_port = 7881; use_external_ip = true; + port_range_start = 50100; + port_range_end = 50105; }; }; }; @@ -127,7 +147,7 @@ in lk-jwt-service = { enable = true; keyFile = livekitKeyFile; - livekitUrl = "wss://${matrixServerName}/livekit/sfu"; + livekitUrl = "wss://${matrixHost}/livekit/sfu"; port = internalPorts.livekit-jwt; }; @@ -343,23 +363,23 @@ in }) (builtins.attrNames ports) ) // { - "${matrixServerName}:80" = { + "${matrixHost}:80" = { extraConfig = '' @matrixClientWellKnown path /.well-known/matrix/client handle @matrixClientWellKnown { header Access-Control-Allow-Origin "*" header Content-Type application/json - respond `{\"m.homeserver\":{\"base_url\":\"https://${matrixServerName}\"},\"org.matrix.msc4143.rtc_foci\":[{\"type\":\"livekit\",\"livekit_service_url\":\"https://${matrixServerName}/livekit/jwt\"}]}` 200 + respond `{"m.homeserver":{"base_url":"https://${matrixHost}"},"org.matrix.msc4143.rtc_foci":[{"type":"livekit","livekit_service_url":"https://${matrixHost}/livekit/jwt"}]}` 200 } @matrixServerWellKnown path /.well-known/matrix/server handle @matrixServerWellKnown { header Access-Control-Allow-Origin "*" header Content-Type application/json - respond `{\"m.server\":\"${matrixServerName}:443\"}` 200 + respond `{"m.server":"${matrixHost}:443"}` 200 } - @jwtService path /livekit/jwt/sfu/get /livekit/jwt/healthz + @jwtService path /livekit/jwt/sfu/get* /livekit/jwt/healthz* /livekit/jwt/get_token* handle @jwtService { uri strip_prefix /livekit/jwt reverse_proxy http://localhost:${toString internalPorts.livekit-jwt} @@ -367,6 +387,7 @@ in @livekit path /livekit/sfu* handle @livekit { + uri strip_prefix /livekit/sfu reverse_proxy http://localhost:${toString ports.livekit} } @@ -375,6 +396,11 @@ in } ''; }; + "admin.${matrixHost}:80" = { + extraConfig = '' + reverse_proxy http://localhost:${toString internalPorts.tuwunel-admin} + ''; + }; "translations.danbulant.cloud:80, translations.rpi1.danbulant.cloud:80" = { extraConfig = '' reverse_proxy http://localhost:${toString ports.tolgee}