matrix-docker-ansible-deploy/docs/configuring-playbook-synapse-admin.md
Suguru Hirahara 04b32af0c1
Update docs for DNS settings etc. (#3936)
* Update docs for DNS settings of the services which need its CNAME record by default

- Buscarron
- Go-NEB; fix a line on the instruction as well
- wsproxy
- Cinny
- Element Web
- Hydrogen
- SchildiChat Web
- Dimension
- Etherpad
- Jitsi
- ntfy
- Grafana
- rageshake
- Sygnal

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs for DNS settings of the services which do not need its CNAME record by default

- matrix-alertmanager-receiver
- Honoroit
- maubot
- Heisenbridge
- Cactus Comments
- Matrix Authentication Service
- matrix-registration
- Sliding Sync proxy
- Synapse Admin
- synapse-usage-exporter

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs for DNS settings: ma1sd

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs for DNS settings: Email2Matrix

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs for DNS settings: Postmoogle

Remove the table from configuring-dns.md altogether

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs for Cinny and Dimension: adopt the common note

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

* Update docs/configuring-dns.md: add "Note" to the line on using Cloudflare DNS

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>

---------

Signed-off-by: Suguru Hirahara <acioustick@noreply.codeberg.org>
Co-authored-by: Suguru Hirahara <acioustick@noreply.codeberg.org>
2025-01-15 09:22:00 +02:00

5.4 KiB

Setting up Synapse Admin (optional)

The playbook can install and configure etkecc/synapse-admin (a feature-rich fork of Awesome-Technologies/synapse-admin, community room: #synapse-admin:etke.cc) for you.

synapse-admin is a web UI tool you can use to administrate users, rooms, media, etc. on your Matrix server. It's designed to work with the Synapse homeserver implementation and WON'T work with Dendrite because Dendrite Admin API differs from Synapse Admin API.

💡 Note: the latest version of synapse-admin is hosted by etke.cc at admin.etke.cc. If you only need this service occasionally and trust giving your admin credentials to a 3rd party Single Page Application, you can consider using it from there and avoiding the (small) overhead of self-hosting.

Adjusting DNS records (optional)

By default, this playbook installs Synapse Admin on the matrix. subdomain, at the /synapse-admin path (https://matrix.example.com/synapse-admin). This makes it easy to install it, because it doesn't require additional DNS records to be set up. If that's okay, you can skip this section.

If you wish to adjust it, see the section below for details about DNS configuration.

Adjusting the playbook configuration

To enable Synapse Admin, add the following configuration to your inventory/host_vars/matrix.example.com/vars.yml file:

matrix_synapse_admin_enabled: true

Note: Synapse Admin requires Synapse's Admin APIs to function. Access to them is restricted with a valid access token, so exposing them publicly should not be a real security concern. Still, for additional security, we normally leave them unexposed, following official Synapse reverse-proxying recommendations. Because Synapse Admin needs these APIs to function, when installing Synapse Admin, the playbook automatically exposes the Synapse Admin API publicly for you. Depending on the homeserver implementation you're using (Synapse, Dendrite), this is equivalent to:

  • for Synapse (our default homeserver implementation): matrix_synapse_container_labels_public_client_synapse_admin_api_enabled: true
  • for Dendrite: matrix_dendrite_container_labels_public_client_synapse_admin_api_enabled: true

By default, synapse-admin installation will be restricted to only work with one homeserver - the one managed by the playbook. To adjust these restrictions, tweak the matrix_synapse_admin_config_restrictBaseUrl variable.

⚠️ Warning: If you're using Matrix Authentication Service (MAS) for authentication, you will be able to log into synapse-admin with an access token, but certain synapse-admin features (especially those around user management) will be limited or not work at all.

Adjusting the Synapse Admin URL (optional)

By tweaking the matrix_synapse_admin_hostname and matrix_synapse_admin_path_prefix variables, you can easily make the service available at a different hostname and/or path than the default one.

Example additional configuration for your vars.yml file:

# Change the default hostname and path prefix
matrix_synapse_admin_hostname: admin.example.com
matrix_synapse_admin_path_prefix: /

If you've changed the default hostname, you may need to create a CNAME record for the Synapse Admin domain (admin.example.com), which targets matrix.example.com.

When setting, replace example.com with your own.

Installing

After configuring the playbook and potentially adjusting your DNS records, run the playbook with playbook tags as below:

ansible-playbook -i inventory/hosts setup.yml --tags=setup-all,start

The shortcut commands with the just program are also available: just install-all or just setup-all

just install-all is useful for maintaining your setup quickly (2x-5x faster than just setup-all) when its components remain unchanged. If you adjust your vars.yml to remove other components, you'd need to run just setup-all, or these components will still remain installed. Note these shortcuts run the ensure-matrix-users-created tag too.

Usage

After installation, Synapse Admin will be accessible at: https://matrix.example.com/synapse-admin/

To use Synapse Admin, you need to have registered at least one administrator account on your server.