Turns guest onboarding from an admin-only click in the Authentik UI into a traceable command a defined circle can run: !einladen creates a single-use invitation valid for three days, !verlaengern extends it twice at most, !freischalten makes it permanent, and expired accounts are deactivated automatically. Authorisation is deliberately twofold - the Authentik group decides, the invite room makes it visible. A group alone leaves no trace of who invited whom; a room alone would authorise anyone who gets in. Two deployment details matter: exactly one replica with Recreate, because a second instance would execute every command twice; and the script ConfigMap keeps its name hash so a change actually restarts the pod, avoiding the trap described in #50. Endpoints and field names were taken from the running Authentik OpenAPI schema, not guessed. Refs axion1337.chat/axion1337.chat-gitops#48
aXion1337.Chat – Deployment & Konfiguration Dokumentation
Diese Dokumentation beschreibt die Einrichtung und Konfiguration des Matrix-Homeservers für axion1337.chat mit Element Server Suite (ESS) v26.4.0 auf K3S mit Flux CD GitOps.
📋 Übersicht Deployment-Reihenfolge
Die Implementierungen wurden in dieser Reihenfolge durchgeführt. Für neue Setups sollten Sie dieser Abfolge folgen:
| # | Titel | Datei | Status | Zieldomäne |
|---|---|---|---|---|
| 1 | TURN Server für WebRTC Video-Calls | 01-turn-server-setup.md |
✅ Deployed | turn.axion1337.chat |
| 2 | Authentik als Identity Provider | 02-authentik-identity-provider.md |
✅ Deployed | auth.axion1337.chat |
| 3 | Monitoring mit Alloy/Prometheus/Loki | 03-monitoring-integration.md |
✅ Deployed | lokal (10.0.0.3) |
| 4 | Element Web Anpassung & Desktop-Apps | 04-element-customization.md |
✅ Deployed | axion1337.chat |
| 5 | Room Policies (Retention, Publication, Auto-Join) | 05-room-policies.md |
✅ Deployed | Matrix Synapse |
| 6 | Moderationsbot (Draupnir) & Content Scanning | 06-moderation-content-scanning.md |
✅ Deployed | Matrix Synapse |
| 7 | Host-Wartungsbenachrichtigungen (unattended-upgrades) | 07-host-maintenance-notifications.md |
✅ Deployed | Host-Ebene (kein K8s) |
🚀 Quick Start für neue Deployment
Siehe die einzelnen Dokumentationen für detaillierte Anleitung.
🏗️ Architektur-Übersicht
┌─────────────────────────────────────────────────────────────┐
│ Element Web (Apex) │
│ axion1337.chat (HTTP/TLS) │
└──────────────────────┬──────────────────────────────────────┘
│
┌─────────────┼─────────────┐
│ │ │
┌────▼────┐ ┌─────▼──────┐ ┌──▼────────┐
│ MAS │ │ Well-Known │ │Docs/Setup │
│account. │ │matrix/* │ │/setup │
│axion1337 │ │ │ │ │
└────┬────┘ └────────────┘ └───────────┘
│
┌────▼────────────────┐
│ Authentik OIDC │
│ auth.axion1337.chat │
│ (Identity Provider) │
└─────────────────────┘
│
┌────▼────────────────┐
│ Synapse Matrix │
│ matrix.axion1337.chat│
│ (Homeserver) │
└──────────────────────┘
🔑 Kritische Werte & Konfigurationen
Domains
- Apex:
axion1337.chat(Element Web) - Matrix Synapse:
matrix.axion1337.chat - MAS:
account.axion1337.chat - Authentik:
auth.axion1337.chat - TURN Server:
turn.axion1337.chat
Externe Services
- K3S Host IP:
49.13.132.245 - Monitoring Host:
10.0.0.3(Selendis)
📚 Dokumente im Detail
01-turn-server-setup.md
STUN/TURN Server für WebRTC Media Relay (Video-Calls).
02-authentik-identity-provider.md
Authentik als OIDC Provider für Matrix. Registrierung via Einladungs-Links.
03-monitoring-integration.md
Alloy → Prometheus/Loki Monitoring Integration.
04-element-customization.md
Custom Themes, Desktop-Setup-Scripts, Element Admin.
05-room-policies.md
Message Retention, Room Publication, Auto-Join Policies.
06-moderation-content-scanning.md
Draupnir Moderationsbot (Bans, Policy-Listen), Content Scanner via eigenes Synapse-Modul für unverschlüsselte Räume UND client-seitiges Scanning für verschlüsselte Räume/DMs (Issue #19 + Erweiterung) - inkl. Electron/Desktop-Deckungslücke (Issue #44). Beide live getestet.
07-host-maintenance-notifications.md
Erster nicht-GitOps-verwalteter Mechanismus im Repo: systemd-Timer auf dem nackten Host meldet
per Mail + Matrix-Thread-Reply anstehende unattended-upgrades, bevor sie laufen (Issue #24).
🛠️ Wartung & Troubleshooting
Alle Dokumentationen enthalten Troubleshooting-Sektionen für häufige Probleme.