mirror of
				https://github.com/spantaleev/matrix-docker-ansible-deploy.git
				synced 2025-10-31 07:17:57 +01:00 
			
		
		
		
	Merge pull request #454 from Jozian/add-mx-puppet-slack-role
Initial mx-puppet-slack bridge role
This commit is contained in:
		
							
								
								
									
										34
									
								
								docs/configuring-playbook-bridge-mx-puppet-slack.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										34
									
								
								docs/configuring-playbook-bridge-mx-puppet-slack.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,34 @@ | ||||
| # Setting up MX Puppet Slack (optional) | ||||
|  | ||||
| The playbook can install and configure | ||||
| [mx-puppet-slack](https://github.com/Sorunome/mx-puppet-slack) for you. | ||||
|  | ||||
| See the project page to learn what it does and why it might be useful to you. | ||||
|  | ||||
| To enable the [Slack](https://www.slack.com/) bridge just use the following | ||||
| playbook configuration: | ||||
|  | ||||
|  | ||||
| ```yaml | ||||
| matrix_mx_puppet_slack_enabled: true | ||||
| matrix_mx_puppet_slack_client_id: "" | ||||
| matrix_mx_puppet_slack_client_secret: "" | ||||
| ``` | ||||
|  | ||||
|  | ||||
| ## Usage | ||||
|  | ||||
| Once the bot is enabled you need to start a chat with `Slack Puppet Bridge` with | ||||
| the handle `@_slackpuppet_bot:YOUR_DOMAIN` (where `YOUR_DOMAIN` is your base | ||||
| domain, not the `matrix.` domain). | ||||
|  | ||||
| Three authentication methods are available, Legacy Token, OAuth and xoxc token. | ||||
| See mx-puppet-slack [documentation](https://github.com/Sorunome/mx-puppet-slack) | ||||
| for more information about how to configure the bridge. | ||||
|  | ||||
| Once logged in, send `list` to the bot user to list the available rooms. | ||||
|  | ||||
| Clicking rooms in the list will result in you receiving an invitation to the | ||||
| bridged room. | ||||
|  | ||||
| Also send `help` to the bot to see the commands available. | ||||
| @@ -337,6 +337,37 @@ matrix_mx_puppet_skype_login_shared_secret: "{{ matrix_synapse_ext_password_prov | ||||
| ###################################################################### | ||||
|  | ||||
|  | ||||
| ###################################################################### | ||||
| # | ||||
| # matrix-bridge-mx-puppet-slack | ||||
| # | ||||
| ###################################################################### | ||||
|  | ||||
| # We don't enable bridges by default. | ||||
| matrix_mx_puppet_slack_enabled: false | ||||
|  | ||||
| matrix_mx_puppet_skype_container_image_self_build: "{{ matrix_architecture != 'amd64'}}" | ||||
|  | ||||
| matrix_mx_puppet_slack_systemd_required_services_list: | | ||||
|   {{ | ||||
|     ['docker.service'] | ||||
|     + | ||||
|     (['matrix-synapse.service'] if matrix_synapse_enabled else []) | ||||
|   }} | ||||
|  | ||||
| matrix_mx_puppet_slack_appservice_token: "{{ matrix_synapse_macaroon_secret_key | password_hash('sha512', 'mxslk.as.tok') | to_uuid }}" | ||||
|  | ||||
| matrix_mx_puppet_slack_homeserver_token: "{{ matrix_synapse_macaroon_secret_key | password_hash('sha512', 'mxslk.hs.tok') | to_uuid }}" | ||||
|  | ||||
| matrix_mx_puppet_slack_login_shared_secret: "{{ matrix_synapse_ext_password_provider_shared_secret_auth_shared_secret if matrix_synapse_ext_password_provider_shared_secret_auth_enabled else '' }}" | ||||
|  | ||||
| ###################################################################### | ||||
| # | ||||
| # /matrix-bridge-mx-puppet-slack | ||||
| # | ||||
| ###################################################################### | ||||
|  | ||||
|  | ||||
| ###################################################################### | ||||
| # | ||||
| # matrix-corporal | ||||
|   | ||||
| @@ -139,7 +139,6 @@ matrix_mx_puppet_skype_configuration_yaml: | | ||||
|  | ||||
|   provisioning: | ||||
|     # Regex of Matrix IDs allowed to use the puppet bridge | ||||
|     whitelist: | ||||
|     whitelist: {{ matrix_mx_puppet_skype_provisioning_whitelist|to_json }} | ||||
|       # Allow a specific user | ||||
|       #- "@user:server\\.com" | ||||
|   | ||||
							
								
								
									
										181
									
								
								roles/matrix-bridge-mx-puppet-slack/defaults/main.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										181
									
								
								roles/matrix-bridge-mx-puppet-slack/defaults/main.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,181 @@ | ||||
| # Mx Puppet Slack is a Matrix <-> Slack bridge | ||||
| # See: https://github.com/Sorunome/mx-puppet-slack | ||||
|  | ||||
| matrix_mx_puppet_slack_enabled: true | ||||
|  | ||||
| matrix_mx_puppet_slack_container_image_self_build: false | ||||
|  | ||||
| matrix_mx_puppet_slack_docker_image: "sorunome/mx-puppet-slack:latest" | ||||
| matrix_mx_puppet_slack_docker_image_force_pull: "{{ matrix_mx_puppet_slack_docker_image.endswith(':latest') }}" | ||||
|  | ||||
| matrix_mx_puppet_slack_base_path: "{{ matrix_base_data_path }}/mx-puppet-slack" | ||||
| matrix_mx_puppet_slack_config_path: "{{ matrix_mx_puppet_slack_base_path }}/config" | ||||
| matrix_mx_puppet_slack_data_path: "{{ matrix_mx_puppet_slack_base_path }}/data" | ||||
| matrix_mx_puppet_slack_docker_src_files_path: "{{ matrix_mx_puppet_slack_base_path }}/docker-src" | ||||
|  | ||||
| matrix_mx_puppet_slack_appservice_port: "8432" | ||||
|  | ||||
| matrix_mx_puppet_slack_homeserver_address: 'http://matrix-synapse:8008' | ||||
| matrix_mx_puppet_slack_homeserver_domain: '{{ matrix_domain }}' | ||||
| matrix_mx_puppet_slack_appservice_address: 'http://matrix-mx-puppet-slack:{{ matrix_mx_puppet_slack_appservice_port }}' | ||||
|  | ||||
| matrix_mx_puppet_slack_client_id: '' | ||||
| matrix_mx_puppet_slack_client_secret: '' | ||||
| matrix_mx_puppet_slack_redirect_path: '/slack/oauth' | ||||
| matrix_mx_puppet_slack_redirect_uri: 'https://{{ matrix_server_fqn_matrix }}{{ matrix_mx_puppet_slack_redirect_path }}' | ||||
|  | ||||
| # "@user:server.com" to allow specific user | ||||
| # "@.*:yourserver.com" to allow users on a specific homeserver | ||||
| # "@.*" to allow anyone | ||||
| matrix_mx_puppet_slack_provisioning_whitelist: | ||||
|   - "@.*:{{ matrix_domain|regex_escape }}" | ||||
|  | ||||
| # Leave empty to disable blacklist | ||||
| # "@user:server.com" disallow a specific user | ||||
| # "@.*:yourserver.com" disallow users on a specific homeserver | ||||
| matrix_mx_puppet_slack_provisioning_blacklist: [] | ||||
|  | ||||
| # A list of extra arguments to pass to the container | ||||
| matrix_mx_puppet_slack_container_extra_arguments: [] | ||||
|  | ||||
| # List of systemd services that matrix-puppet-slack.service depends on. | ||||
| matrix_mx_puppet_slack_systemd_required_services_list: ['docker.service'] | ||||
|  | ||||
| # List of systemd services that matrix-puppet-slack.service wants | ||||
| matrix_mx_puppet_slack_systemd_wanted_services_list: [] | ||||
|  | ||||
| matrix_mx_puppet_slack_appservice_token: '' | ||||
| matrix_mx_puppet_slack_homeserver_token: '' | ||||
|  | ||||
| # Default configuration template which covers the generic use case. | ||||
| # You can customize it by controlling the various variables inside it. | ||||
| # | ||||
| # For a more advanced customization, you can extend the default (see `matrix_mx_puppet_slack_configuration_extension_yaml`) | ||||
| # or completely replace this variable with your own template. | ||||
| matrix_mx_puppet_slack_configuration_yaml: | | ||||
|   #jinja2: lstrip_blocks: "True" | ||||
|   bridge: | ||||
|     # Port to host the bridge on | ||||
|     # Used for communication between the homeserver and the bridge | ||||
|     port: {{ matrix_mx_puppet_slack_appservice_port }} | ||||
|     # The host connections to the bridge's webserver are allowed from | ||||
|     bindAddress: 0.0.0.0 | ||||
|     # Public domain of the homeserver | ||||
|     domain: {{ matrix_mx_puppet_slack_homeserver_domain }} | ||||
|     # Reachable URL of the Matrix homeserver | ||||
|     homeserverUrl: {{ matrix_mx_puppet_slack_homeserver_address }} | ||||
|  | ||||
|  | ||||
|   # Slack OAuth settings. Create a slack app at https://api.slack.com/apps | ||||
|   oauth: | ||||
|     enabled: false | ||||
|     # Slack app credentials. | ||||
|     # N.B. This must be quoted so YAML wouldn't parse it as a float. | ||||
|     clientId: "{{ matrix_mx_puppet_slack_client_id }}" | ||||
|     clientSecret: {{ matrix_mx_puppet_slack_client_secret }} | ||||
|     # Path where to listen for OAuth redirect callbacks. | ||||
|     redirectPath: {{ matrix_mx_puppet_slack_redirect_path }} | ||||
|     # Set up proxying from https://your.domain/redirect_path to http://bindAddress:port/redirect_path, | ||||
|     # then set this field and the Slack app redirect URI field to the former. | ||||
|     redirectUri: {{ matrix_mx_puppet_slack_redirect_uri }} | ||||
|  | ||||
|   presence: | ||||
|     # Bridge Discord online/offline status | ||||
|     enabled: true | ||||
|     # How often to send status to the homeserver in milliseconds | ||||
|     interval: 500 | ||||
|  | ||||
|   provisioning: | ||||
|     # Regex of Matrix IDs allowed to use the puppet bridge | ||||
|     whitelist: {{ matrix_mx_puppet_slack_provisioning_whitelist|to_json }} | ||||
|       # Allow a specific user | ||||
|       #- "@user:server\\.com" | ||||
|       # Allow users on a specific homeserver | ||||
|       #- "@.*:yourserver\\.com" | ||||
|       # Allow anyone | ||||
|       #- ".*" | ||||
|     # Regex of Matrix IDs forbidden from using the puppet bridge | ||||
|     #blacklist: | ||||
|       # Disallow a specific user | ||||
|       #- "@user:server\\.com" | ||||
|       # Disallow users on a specific homeserver | ||||
|       #- "@.*:yourserver\\.com" | ||||
|     blacklist: {{ matrix_mx_puppet_slack_provisioning_blacklist|to_json }} | ||||
|  | ||||
|     # Shared secret for the provisioning API for use by integration managers. | ||||
|     # If this is not set, the provisioning API will not be enabled. | ||||
|     #sharedSecret: random string | ||||
|     # Path prefix for the provisioning API. /v1 will be appended to the prefix automatically. | ||||
|     apiPrefix: /_matrix/provision | ||||
|  | ||||
|   database: | ||||
|     # Use Postgres as a database backend | ||||
|     # If set, will be used instead of SQLite3 | ||||
|     # Connection string to connect to the Postgres instance | ||||
|     # with username "user", password "pass", host "localhost" and database name "dbname". | ||||
|     # Modify each value as necessary | ||||
|     #connString: "postgres://user:pass@localhost/dbname?sslmode=disable" | ||||
|     # Use SQLite3 as a database backend | ||||
|     # The name of the database file | ||||
|     filename: /data/database.db | ||||
|  | ||||
|   logging: | ||||
|     # Log level of console output | ||||
|     # Allowed values starting with most verbose: | ||||
|     # silly, debug, verbose, info, warn, error | ||||
|     console: info | ||||
|     # Date and time formatting | ||||
|     lineDateFormat: MMM-D HH:mm:ss.SSS | ||||
|     # Logging files | ||||
|     # Log files are rotated daily by default | ||||
|     files: | ||||
|       # Log file path | ||||
|       - file: "/data/bridge.log" | ||||
|         # Log level for this file | ||||
|         # Allowed values starting with most verbose: | ||||
|         # silly, debug, verbose, info, warn, error | ||||
|         level: info | ||||
|         # Date and time formatting | ||||
|         datePattern: YYYY-MM-DD | ||||
|         # Maximum number of logs to keep. | ||||
|         # This can be a number of files or number of days. | ||||
|         # If using days, add 'd' as a suffix | ||||
|         maxFiles: 14d | ||||
|         # Maximum size of the file after which it will rotate. This can be a | ||||
|         # number of bytes, or units of kb, mb, and gb. If using the units, add | ||||
|         # 'k', 'm', or 'g' as the suffix | ||||
|         maxSize: 50m | ||||
|  | ||||
| matrix_mx_puppet_slack_configuration_extension_yaml: | | ||||
|   # Your custom YAML configuration goes here. | ||||
|   # This configuration extends the default starting configuration (`matrix_mx_puppet_slack_configuration_yaml`). | ||||
|   # | ||||
|   # You can override individual variables from the default configuration, or introduce new ones. | ||||
|   # | ||||
|   # If you need something more special, you can take full control by | ||||
|   # completely redefining `matrix_mx_puppet_slack_configuration_yaml`. | ||||
|  | ||||
| matrix_mx_puppet_slack_configuration_extension: "{{ matrix_mx_puppet_slack_configuration_extension_yaml|from_yaml if matrix_mx_puppet_slack_configuration_extension_yaml|from_yaml is mapping else {} }}" | ||||
|  | ||||
| # Holds the final configuration (a combination of the default and its extension). | ||||
| # You most likely don't need to touch this variable. Instead, see `matrix_mx_puppet_slack_configuration_yaml`. | ||||
| matrix_mx_puppet_slack_configuration: "{{ matrix_mx_puppet_slack_configuration_yaml|from_yaml|combine(matrix_mx_puppet_slack_configuration_extension, recursive=True) }}" | ||||
|  | ||||
| matrix_mx_puppet_slack_registration_yaml: | | ||||
|   as_token: "{{ matrix_mx_puppet_slack_appservice_token }}" | ||||
|   hs_token: "{{ matrix_mx_puppet_slack_homeserver_token }}" | ||||
|   id: slack-puppet | ||||
|   namespaces: | ||||
|     users: | ||||
|       - exclusive: true | ||||
|         regex: '@_slackpuppet_.*:{{ matrix_mx_puppet_slack_homeserver_domain|regex_escape }}' | ||||
|     rooms: [] | ||||
|     aliases: | ||||
|       - exclusive: true | ||||
|         regex: '#_slackpuppet_.*:{{ matrix_mx_puppet_slack_homeserver_domain|regex_escape }}' | ||||
|   protocols: [] | ||||
|   rate_limited: false | ||||
|   sender_localpart: _slackpuppet_bot | ||||
|   url: {{ matrix_mx_puppet_slack_appservice_address }} | ||||
|  | ||||
| matrix_mx_puppet_slack_registration: "{{ matrix_mx_puppet_slack_registration_yaml|from_yaml }}" | ||||
							
								
								
									
										70
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/init.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										70
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/init.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,70 @@ | ||||
| - set_fact: | ||||
|     matrix_systemd_services_list: "{{ matrix_systemd_services_list + ['matrix-mx-puppet-slack'] }}" | ||||
|   when: matrix_mx_puppet_slack_enabled|bool | ||||
|  | ||||
| # If the matrix-synapse role is not used, these variables may not exist. | ||||
| - set_fact: | ||||
|     matrix_synapse_container_extra_arguments: > | ||||
|       {{ matrix_synapse_container_extra_arguments|default([]) }} | ||||
|       + | ||||
|       ["--mount type=bind,src={{ matrix_mx_puppet_slack_config_path }}/registration.yaml,dst=/matrix-mx-puppet-slack-registration.yaml,ro"] | ||||
|  | ||||
|     matrix_synapse_app_service_config_files: > | ||||
|       {{ matrix_synapse_app_service_config_files|default([]) }} | ||||
|       + | ||||
|       {{ ["/matrix-mx-puppet-slack-registration.yaml"] }} | ||||
|   when: matrix_mx_puppet_slack_enabled|bool | ||||
|  | ||||
| - block: | ||||
|   - name: Fail if matrix-nginx-proxy role already executed | ||||
|     fail: | ||||
|       msg: >- | ||||
|         Trying to append Slack Appservice's reverse-proxying configuration to matrix-nginx-proxy, | ||||
|         but it's pointless since the matrix-nginx-proxy role had already executed. | ||||
|         To fix this, please change the order of roles in your plabook, | ||||
|         so that the matrix-nginx-proxy role would run after the matrix-mx-puppet-slack role. | ||||
|     when: matrix_nginx_proxy_role_executed|default(False)|bool | ||||
|  | ||||
|   - name: Generate Matrix MX Puppet Slack proxying configuration for matrix-nginx-proxy | ||||
|     set_fact: | ||||
|       matrix_mx_puppet_slack_matrix_nginx_proxy_configuration: | | ||||
|         location {{ matrix_mx_puppet_slack_redirect_path }} { | ||||
|         {% if matrix_nginx_proxy_enabled|default(False) %} | ||||
|         	{# Use the embedded DNS resolver in Docker containers to discover the service #} | ||||
|         	resolver 127.0.0.11 valid=5s; | ||||
|         	set $backend "{{ matrix_mx_puppet_slack_appservice_address }}"; | ||||
|         	proxy_pass $backend; | ||||
|         {% else %} | ||||
|         	{# Generic configuration for use outside of our container setup #} | ||||
|         	proxy_pass http://127.0.0.1:{{ matrix_mx_puppet_slack_appservice_port }}; | ||||
|         {% endif %} | ||||
|         } | ||||
|  | ||||
|   - name: Register Slack Appservice proxying configuration with matrix-nginx-proxy | ||||
|     set_fact: | ||||
|       matrix_nginx_proxy_proxy_matrix_additional_server_configuration_blocks: | | ||||
|         {{ | ||||
|           matrix_nginx_proxy_proxy_matrix_additional_server_configuration_blocks|default([]) | ||||
|           + | ||||
|           [matrix_mx_puppet_slack_matrix_nginx_proxy_configuration] | ||||
|         }} | ||||
|   tags: | ||||
|    - always | ||||
|   when: matrix_appservice_slack_enabled|bool | ||||
|  | ||||
| - name: Warn about reverse-proxying if matrix-nginx-proxy not used | ||||
|   debug: | ||||
|     msg: >- | ||||
|       NOTE: You've enabled the Matrix Slack bridge but are not using the matrix-nginx-proxy | ||||
|       reverse proxy. | ||||
|       Please make sure that you're proxying the `{{ something }}` | ||||
|       URL endpoint to the matrix-appservice-slack container. | ||||
|       You can expose the container's port using the `matrix_appservice_slack_container_http_host_bind_port` variable. | ||||
|   when: "matrix_appservice_slack_enabled|bool and matrix_nginx_proxy_enabled is not defined" | ||||
|  | ||||
| # ansible lower than 2.8, does not support docker_image build parameters | ||||
| # for self buildig it is explicitly needed, so we rather fail here | ||||
| - name: Fail if running on Ansible lower than 2.8 and trying self building | ||||
|   fail: | ||||
|     msg: "To self build Puppet Slack image, you should usa ansible 2.8 or higher. E.g. pip contains such packages." | ||||
|   when: "ansible_version.major == 2 and ansible_version.minor < 8 and matrix_mx_puppet_slack_container_image_self_build" | ||||
							
								
								
									
										21
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/main.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										21
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/main.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,21 @@ | ||||
| - import_tasks: "{{ role_path }}/tasks/init.yml" | ||||
|   tags: | ||||
|     - always | ||||
|  | ||||
| - import_tasks: "{{ role_path }}/tasks/validate_config.yml" | ||||
|   when: "run_setup|bool and matrix_mx_puppet_slack_enabled|bool" | ||||
|   tags: | ||||
|     - setup-all | ||||
|     - setup-mx-puppet-slack | ||||
|  | ||||
| - import_tasks: "{{ role_path }}/tasks/setup_install.yml" | ||||
|   when: "run_setup|bool and matrix_mx_puppet_slack_enabled|bool" | ||||
|   tags: | ||||
|     - setup-all | ||||
|     - setup-mx-puppet-slack | ||||
|  | ||||
| - import_tasks: "{{ role_path }}/tasks/setup_uninstall.yml" | ||||
|   when: "run_setup|bool and not matrix_mx_puppet_slack_enabled|bool" | ||||
|   tags: | ||||
|     - setup-all | ||||
|     - setup-mx-puppet-slack | ||||
							
								
								
									
										93
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/setup_install.yml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										93
									
								
								roles/matrix-bridge-mx-puppet-slack/tasks/setup_install.yml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,93 @@ | ||||
| --- | ||||
|  | ||||
| # If the matrix-synapse role is not used, `matrix_synapse_role_executed` won't exist. | ||||
| # We don't want to fail in such cases. | ||||
| - name: Fail if matrix-synapse role already executed | ||||
|   fail: | ||||
|     msg: >- | ||||
|       The matrix-bridge-mx-puppet-slack role needs to execute before the matrix-synapse role. | ||||
|   when: "matrix_synapse_role_executed|default(False)" | ||||
|  | ||||
| - name: Ensure MX Puppet Slack image is pulled | ||||
|   docker_image: | ||||
|     name: "{{ matrix_mx_puppet_slack_docker_image }}" | ||||
|     source: "{{ 'pull' if ansible_version.major > 2 or ansible_version.minor > 7 else omit }}" | ||||
|     force_source: "{{ matrix_mx_puppet_slack_docker_image_force_pull if ansible_version.major > 2 or ansible_version.minor >= 8 else omit }}" | ||||
|     force: "{{ omit if ansible_version.major > 2 or ansible_version.minor >= 8 else matrix_mx_puppet_slack_docker_image_force_pull }}" | ||||
|   when: matrix_mx_puppet_slack_enabled|bool and not matrix_mx_puppet_slack_container_image_self_build | ||||
|  | ||||
| - name: Ensure MX Puppet Slack paths exist | ||||
|   file: | ||||
|     path: "{{ item.path }}" | ||||
|     state: directory | ||||
|     mode: 0750 | ||||
|     owner: "{{ matrix_user_username }}" | ||||
|     group: "{{ matrix_user_username }}" | ||||
|   with_items: | ||||
|     - { path: "{{ matrix_mx_puppet_slack_base_path }}", when: true } | ||||
|     - { path: "{{ matrix_mx_puppet_slack_config_path }}", when: true } | ||||
|     - { path: "{{ matrix_mx_puppet_slack_data_path }}", when: true } | ||||
|     - { path: "{{ matrix_mx_puppet_slack_docker_src_files_path }}", when: "{{ matrix_mx_puppet_slack_container_image_self_build }}" } | ||||
|   when: matrix_mx_puppet_slack_enabled|bool and item.when|bool | ||||
|  | ||||
| - name: Ensure MX Puppet Slack repository is present on self build | ||||
|   git: | ||||
|     repo: https://github.com/Sorunome/mx-puppet-slack.git | ||||
|     dest: "{{ matrix_mx_puppet_slack_docker_src_files_path }}" | ||||
|     force: "yes" | ||||
|   when: "matrix_mx_puppet_slack_enabled|bool and matrix_mx_puppet_slack_container_image_self_build" | ||||
|  | ||||
| - name: Ensure MX Puppet Slack Docker image is built | ||||
|   docker_image: | ||||
|     name: "{{ matrix_mx_puppet_slack_docker_image }}" | ||||
|     source: build | ||||
|     build: | ||||
|       dockerfile: Dockerfile | ||||
|       path: "{{ matrix_mx_puppet_slack_docker_src_files_path }}" | ||||
|       pull: yes | ||||
|   when: "matrix_mx_puppet_slack_enabled|bool and matrix_mx_puppet_slack_container_image_self_build" | ||||
|  | ||||
| - name: Check if an old database file already exists | ||||
|   stat: | ||||
|     path: "{{ matrix_mx_puppet_slack_base_path }}/database.db" | ||||
|   register: matrix_mx_puppet_slack_stat_database | ||||
|  | ||||
| - name: (Data relocation) Ensure matrix-mx-puppet-slack.service is stopped | ||||
|   service: | ||||
|     name: matrix-mx-puppet-slack | ||||
|     state: stopped | ||||
|     daemon_reload: yes | ||||
|   failed_when: false | ||||
|   when: "matrix_mx_puppet_slack_stat_database.stat.exists" | ||||
|  | ||||
| - name: (Data relocation) Move mx-puppet-slack database file to ./data directory | ||||
|   command: "mv {{ matrix_mx_puppet_slack_base_path }}/database.db {{ matrix_mx_puppet_slack_data_path }}/database.db" | ||||
|   when: "matrix_mx_puppet_slack_stat_database.stat.exists" | ||||
|  | ||||
| - name: Ensure mx-puppet-slack config.yaml installed | ||||
|   copy: | ||||
|     content: "{{ matrix_mx_puppet_slack_configuration|to_nice_yaml }}" | ||||
|     dest: "{{ matrix_mx_puppet_slack_config_path }}/config.yaml" | ||||
|     mode: 0644 | ||||
|     owner: "{{ matrix_user_username }}" | ||||
|     group: "{{ matrix_user_username }}" | ||||
|  | ||||
| - name: Ensure mx-puppet-slack slack-registration.yaml installed | ||||
|   copy: | ||||
|     content: "{{ matrix_mx_puppet_slack_registration|to_nice_yaml }}" | ||||
|     dest: "{{ matrix_mx_puppet_slack_config_path }}/registration.yaml" | ||||
|     mode: 0644 | ||||
|     owner: "{{ matrix_user_username }}" | ||||
|     group: "{{ matrix_user_username }}" | ||||
|  | ||||
| - name: Ensure matrix-mx-puppet-slack.service installed | ||||
|   template: | ||||
|     src: "{{ role_path }}/templates/systemd/matrix-mx-puppet-slack.service.j2" | ||||
|     dest: "/etc/systemd/system/matrix-mx-puppet-slack.service" | ||||
|     mode: 0644 | ||||
|   register: matrix_mx_puppet_slack_systemd_service_result | ||||
|  | ||||
| - name: Ensure systemd reloaded after matrix-mx-puppet-slack.service installation | ||||
|   service: | ||||
|     daemon_reload: yes | ||||
|   when: "matrix_mx_puppet_slack_systemd_service_result.changed" | ||||
| @@ -0,0 +1,24 @@ | ||||
| --- | ||||
|  | ||||
| - name: Check existence of matrix-mx-puppet-slack service | ||||
|   stat: | ||||
|     path: "/etc/systemd/system/matrix-mx-puppet-slack.service" | ||||
|   register: matrix_mx_puppet_slack_service_stat | ||||
|  | ||||
| - name: Ensure matrix-mx-puppet-slack is stopped | ||||
|   service: | ||||
|     name: matrix-mx-puppet-slack | ||||
|     state: stopped | ||||
|     daemon_reload: yes | ||||
|   when: "matrix_mx_puppet_slack_service_stat.stat.exists" | ||||
|  | ||||
| - name: Ensure matrix-mx-puppet-slack.service doesn't exist | ||||
|   file: | ||||
|     path: "/etc/systemd/system/matrix-mx-puppet-slack.service" | ||||
|     state: absent | ||||
|   when: "matrix_mx_puppet_slack_service_stat.stat.exists" | ||||
|  | ||||
| - name: Ensure systemd reloaded after matrix-mx-puppet-slack.service removal | ||||
|   service: | ||||
|     daemon_reload: yes | ||||
|   when: "matrix_mx_puppet_slack_service_stat.stat.exists" | ||||
| @@ -0,0 +1,10 @@ | ||||
| --- | ||||
|  | ||||
| - name: Fail if required settings not defined | ||||
|   fail: | ||||
|     msg: >- | ||||
|       You need to define a required configuration setting (`{{ item }}`). | ||||
|   when: "vars[item] == ''" | ||||
|   with_items: | ||||
|     - "matrix_mx_puppet_slack_appservice_token" | ||||
|     - "matrix_mx_puppet_slack_homeserver_token" | ||||
| @@ -0,0 +1,41 @@ | ||||
| #jinja2: lstrip_blocks: "True" | ||||
| [Unit] | ||||
| Description=Matrix Mx Puppet Slack server | ||||
| {% for service in matrix_mx_puppet_slack_systemd_required_services_list %} | ||||
| Requires={{ service }} | ||||
| After={{ service }} | ||||
| {% endfor %} | ||||
| {% for service in matrix_mx_puppet_slack_systemd_wanted_services_list %} | ||||
| Wants={{ service }} | ||||
| {% endfor %} | ||||
|  | ||||
| [Service] | ||||
| Type=simple | ||||
| ExecStartPre=-/usr/bin/docker kill matrix-mx-puppet-slack | ||||
| ExecStartPre=-/usr/bin/docker rm matrix-mx-puppet-slack | ||||
|  | ||||
| # Intentional delay, so that the homeserver (we likely depend on) can manage to start. | ||||
| ExecStartPre=/bin/sleep 5 | ||||
|  | ||||
| ExecStart=/usr/bin/docker run --rm --name matrix-mx-puppet-slack \ | ||||
| 			--log-driver=none \ | ||||
| 			--user={{ matrix_user_uid }}:{{ matrix_user_gid }} \ | ||||
| 			--cap-drop=ALL \ | ||||
| 			--network={{ matrix_docker_network }} \ | ||||
| 			-e CONFIG_PATH=/config/config.yaml \ | ||||
| 			-e REGISTRATION_PATH=/config/registration.yaml \ | ||||
| 			-v {{ matrix_mx_puppet_slack_config_path }}:/config:z \ | ||||
| 			-v {{ matrix_mx_puppet_slack_data_path }}:/data:z \ | ||||
| 			{% for arg in matrix_mx_puppet_slack_container_extra_arguments %} | ||||
| 			{{ arg }} \ | ||||
| 			{% endfor %} | ||||
| 			{{ matrix_mx_puppet_slack_docker_image }} | ||||
|  | ||||
| ExecStop=-/usr/bin/docker kill matrix-mx-puppet-slack | ||||
| ExecStop=-/usr/bin/docker rm matrix-mx-puppet-slack | ||||
| Restart=always | ||||
| RestartSec=30 | ||||
| SyslogIdentifier=matrix-mx-puppet-slack | ||||
|  | ||||
| [Install] | ||||
| WantedBy=multi-user.target | ||||
		Reference in New Issue
	
	Block a user