208 lines
6.8 KiB
Nix
208 lines
6.8 KiB
Nix
# docs:
|
|
# - <https://docs.ejabberd.im/admin/configuration/basic>
|
|
# example configs:
|
|
# - 2013: <https://github.com/processone/ejabberd/blob/master/ejabberd.yml.example>
|
|
{ lib, ... }:
|
|
|
|
# lib.mkIf false
|
|
{
|
|
sane.impermanence.service-dirs = [
|
|
{ user = "ejabberd"; group = "ejabberd"; directory = "/var/lib/ejabberd"; }
|
|
];
|
|
networking.firewall.allowedTCPPorts = [
|
|
5222 # XMPP client -> server
|
|
5269 # XMPP server -> server
|
|
5443 # web services (file uploads, websockets, admin)
|
|
];
|
|
|
|
# provide access to certs
|
|
users.users.ejabberd.extraGroups = [ "nginx" ];
|
|
|
|
security.acme.certs."uninsane.org".extraDomainNames = [
|
|
"conference.xmpp.uninsane.org"
|
|
"pubsub.xmpp.uninsane.org"
|
|
"upload.xmpp.uninsane.org"
|
|
"vjid.xmpp.uninsane.org"
|
|
];
|
|
|
|
# TODO: allocate UIDs/GIDs ?
|
|
services.ejabberd.enable = true;
|
|
services.ejabberd.configFile = builtins.toFile "ejabberd.yaml" ''
|
|
hosts:
|
|
- uninsane.org
|
|
|
|
# none | emergency | alert | critical | error | warning | notice | info | debug
|
|
loglevel: debug
|
|
|
|
acme:
|
|
auto: false
|
|
certfiles:
|
|
- /var/lib/acme/uninsane.org/fullchain.pem
|
|
- /var/lib/acme/uninsane.org/key.pem
|
|
|
|
pam_userinfotype: jid
|
|
|
|
acl:
|
|
local:
|
|
user_regexp: ""
|
|
|
|
access_rules:
|
|
local:
|
|
allow: local
|
|
pubsub_createnode_access:
|
|
allow: local
|
|
c2s_access:
|
|
allow: all
|
|
muc_create:
|
|
allow: local
|
|
|
|
# docs: <https://docs.ejabberd.im/admin/configuration/basic/#shaper-rules>
|
|
shaper_rules:
|
|
# setting this to above 1 may break outgoing messages
|
|
# - maybe some servers rate limit? or just don't understand simultaneous connections?
|
|
max_s2s_connections: 1
|
|
max_user_sessions: 10
|
|
max_user_offline_messages: 5000
|
|
c2s_shaper:
|
|
fast: all
|
|
s2s_shaper:
|
|
med: all
|
|
|
|
# docs: <https://docs.ejabberd.im/admin/configuration/basic/#shapers>
|
|
# this limits the bytes/sec.
|
|
# for example, burst: 3_000_000 and rate: 100_000 means:
|
|
# - each client has a BW budget that accumulates 100kB/sec and is capped at 3 MB
|
|
shaper:
|
|
fast: 1000000
|
|
med: 500000
|
|
# fast:
|
|
# - rate: 1000000
|
|
# - burst_size: 10000000
|
|
# med:
|
|
# - rate: 500000
|
|
# - burst_size: 5000000
|
|
|
|
# see: <https://docs.ejabberd.im/admin/configuration/listen/>
|
|
# s2s_use_starttls: true
|
|
s2s_use_starttls: optional
|
|
# lessens 504: remote-server-timeout errors
|
|
# see: <https://github.com/processone/ejabberd/issues/3105#issuecomment-562182967>
|
|
negotiation_timeout: 60
|
|
|
|
listen:
|
|
-
|
|
port: 5222
|
|
module: ejabberd_c2s
|
|
shaper: c2s_shaper
|
|
starttls: true
|
|
access: c2s_access
|
|
-
|
|
port: 5269
|
|
module: ejabberd_s2s_in
|
|
shaper: s2s_shaper
|
|
-
|
|
port: 5443
|
|
module: ejabberd_http
|
|
tls: true
|
|
request_handlers:
|
|
/admin: ejabberd_web_admin # TODO: ensure this actually works
|
|
/api: mod_http_api # ejabberd API endpoint (to control server)
|
|
/bosh: mod_bosh
|
|
/upload: mod_http_upload
|
|
/ws: ejabberd_http_ws
|
|
# /.well-known/host-meta: mod_host_meta
|
|
# /.well-known/host-meta.json: mod_host_meta
|
|
|
|
# TODO: enable mod_client_state for net optimization
|
|
# TODO: enable mod_fail2ban
|
|
# TODO(low): look into mod_http_fileserver for serving macros?
|
|
# TODO: enable mod_muc
|
|
modules:
|
|
# allows users to set avatars in vCard
|
|
# - <https://docs.ejabberd.im/admin/configuration/modules/#mod-avatar>
|
|
mod_avatar: {}
|
|
mod_caps: {} # for mod_pubsub
|
|
mod_carboncopy: {} # allows multiple clients to receive a user's message
|
|
# mod_conversejs: TODO: enable once on 21.12
|
|
# allows clients like Dino to discover where to upload files
|
|
mod_disco:
|
|
server_info:
|
|
-
|
|
modules: all
|
|
name: abuse-addresses
|
|
urls:
|
|
- "mailto:admin.xmpp@uninsane.org"
|
|
- "xmpp:colin@uninsane.org"
|
|
-
|
|
modules: all
|
|
name: admin-addresses
|
|
urls:
|
|
- "mailto:admin.xmpp@uninsane.org"
|
|
- "xmpp:colin@uninsane.org"
|
|
mod_http_upload:
|
|
host: upload.xmpp.uninsane.org
|
|
hosts:
|
|
- upload.xmpp.uninsane.org
|
|
put_url: "https://@HOST@:5443/upload"
|
|
dir_mode: "0750"
|
|
file_mode: "0750"
|
|
rm_on_unregister: false
|
|
# allow discoverability of BOSH and websocket endpoints
|
|
# TODO: enable once on ejabberd 22.05 (presently 21.04)
|
|
# mod_host_meta: {}
|
|
mod_jidprep: {} # probably not needed: lets clients normalize jids
|
|
mod_last: {} # allow other users to know when i was last online
|
|
mod_muc:
|
|
access:
|
|
- allow
|
|
access_admin:
|
|
- allow: admin
|
|
access_create: muc_create
|
|
access_persistent: muc_create
|
|
history_size: 100 # messages to show new participants
|
|
host: conference.xmpp.uninsane.org
|
|
hosts:
|
|
- conference.xmpp.uninsane.org
|
|
default_room_options:
|
|
anonymous: false
|
|
lang: en
|
|
persistent: true
|
|
mod_offline: # store messages for a user when they're offline (TODO: understand multi-client workflow?)
|
|
access_max_user_messages: max_user_offline_messages
|
|
store_groupchat: true
|
|
mod_ping: {}
|
|
mod_privacy: {} # deprecated, but required for `ejabberctl export_piefxis`
|
|
mod_private: {} # allow local clients to persist arbitrary data on my server
|
|
mod_roster:
|
|
versioning: true
|
|
# docs: <https://docs.ejabberd.im/admin/configuration/modules/#mod-s2s-dialback>
|
|
# mod_s2s_dialback: {} # XXX: MIGHT need to enable this to federate with some servers
|
|
mod_shared_roster: {} # creates groups for @all, @online, and anything manually administered?
|
|
mod_stream_mgmt:
|
|
resend_on_timeout: if_offline # resend undelivered messages if the origin client is offline
|
|
# docs: <https://docs.ejabberd.im/admin/configuration/modules/#mod-vcard>
|
|
mod_vcard:
|
|
allow_return_all: true # all users are discoverable (?)
|
|
host: vjid.xmpp.uninsane.org
|
|
hosts:
|
|
- vjid.xmpp.uninsane.org
|
|
search: true
|
|
mod_vcard_xupdate: {} # needed for avatars
|
|
# docs: <https://docs.ejabberd.im/admin/configuration/modules/#mod-pubsub>
|
|
mod_pubsub: # needed for avatars
|
|
access_createnode: pubsub_createnode_access
|
|
host: pubsub.xmpp.uninsane.org
|
|
hosts:
|
|
- pubsub.xmpp.uninsane.org
|
|
plugins:
|
|
- flat
|
|
- pep
|
|
force_node_config:
|
|
# avoid buggy clients to make their bookmarks public
|
|
# XXX: not sure if this is necessary: copying config from examples
|
|
storage:bookmarks:
|
|
access_model: whitelist
|
|
mod_version: {}
|
|
'';
|
|
}
|