reverse_proxy.html 34 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426
  1. <!DOCTYPE HTML>
  2. <html lang="en" class="sidebar-visible no-js light">
  3. <head>
  4. <!-- Book generated using mdBook -->
  5. <meta charset="UTF-8">
  6. <title>Configuring a Reverse Proxy - Synapse</title>
  7. <!-- Custom HTML head -->
  8. <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  9. <meta name="description" content="">
  10. <meta name="viewport" content="width=device-width, initial-scale=1">
  11. <meta name="theme-color" content="#ffffff" />
  12. <link rel="icon" href="favicon.svg">
  13. <link rel="shortcut icon" href="favicon.png">
  14. <link rel="stylesheet" href="css/variables.css">
  15. <link rel="stylesheet" href="css/general.css">
  16. <link rel="stylesheet" href="css/chrome.css">
  17. <link rel="stylesheet" href="css/print.css" media="print">
  18. <!-- Fonts -->
  19. <link rel="stylesheet" href="FontAwesome/css/font-awesome.css">
  20. <link rel="stylesheet" href="fonts/fonts.css">
  21. <!-- Highlight.js Stylesheets -->
  22. <link rel="stylesheet" href="highlight.css">
  23. <link rel="stylesheet" href="tomorrow-night.css">
  24. <link rel="stylesheet" href="ayu-highlight.css">
  25. <!-- Custom theme stylesheets -->
  26. <link rel="stylesheet" href="docs/website_files/table-of-contents.css">
  27. <link rel="stylesheet" href="docs/website_files/remove-nav-buttons.css">
  28. <link rel="stylesheet" href="docs/website_files/indent-section-headers.css">
  29. <link rel="stylesheet" href="docs/website_files/version-picker.css">
  30. </head>
  31. <body>
  32. <!-- Provide site root to javascript -->
  33. <script type="text/javascript">
  34. var path_to_root = "";
  35. var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light";
  36. </script>
  37. <!-- Work around some values being stored in localStorage wrapped in quotes -->
  38. <script type="text/javascript">
  39. try {
  40. var theme = localStorage.getItem('mdbook-theme');
  41. var sidebar = localStorage.getItem('mdbook-sidebar');
  42. if (theme.startsWith('"') && theme.endsWith('"')) {
  43. localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1));
  44. }
  45. if (sidebar.startsWith('"') && sidebar.endsWith('"')) {
  46. localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1));
  47. }
  48. } catch (e) { }
  49. </script>
  50. <!-- Set the theme before any content is loaded, prevents flash -->
  51. <script type="text/javascript">
  52. var theme;
  53. try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { }
  54. if (theme === null || theme === undefined) { theme = default_theme; }
  55. var html = document.querySelector('html');
  56. html.classList.remove('no-js')
  57. html.classList.remove('light')
  58. html.classList.add(theme);
  59. html.classList.add('js');
  60. </script>
  61. <!-- Hide / unhide sidebar before it is displayed -->
  62. <script type="text/javascript">
  63. var html = document.querySelector('html');
  64. var sidebar = 'hidden';
  65. if (document.body.clientWidth >= 1080) {
  66. try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { }
  67. sidebar = sidebar || 'visible';
  68. }
  69. html.classList.remove('sidebar-visible');
  70. html.classList.add("sidebar-" + sidebar);
  71. </script>
  72. <nav id="sidebar" class="sidebar" aria-label="Table of contents">
  73. <div class="sidebar-scrollbox">
  74. <ol class="chapter"><li class="chapter-item expanded affix "><li class="part-title">Introduction</li><li class="chapter-item expanded "><a href="welcome_and_overview.html">Welcome and Overview</a></li><li class="chapter-item expanded affix "><li class="part-title">Setup</li><li class="chapter-item expanded "><a href="setup/installation.html">Installation</a></li><li class="chapter-item expanded "><a href="postgres.html">Using Postgres</a></li><li class="chapter-item expanded "><a href="reverse_proxy.html" class="active">Configuring a Reverse Proxy</a></li><li class="chapter-item expanded "><a href="setup/forward_proxy.html">Configuring a Forward/Outbound Proxy</a></li><li class="chapter-item expanded "><a href="turn-howto.html">Configuring a Turn Server</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="setup/turn/coturn.html">coturn TURN server</a></li><li class="chapter-item expanded "><a href="setup/turn/eturnal.html">eturnal TURN server</a></li></ol></li><li class="chapter-item expanded "><a href="delegate.html">Delegation</a></li><li class="chapter-item expanded affix "><li class="part-title">Upgrading</li><li class="chapter-item expanded "><a href="upgrade.html">Upgrading between Synapse Versions</a></li><li class="chapter-item expanded affix "><li class="part-title">Usage</li><li class="chapter-item expanded "><a href="federate.html">Federation</a></li><li class="chapter-item expanded "><a href="usage/configuration/index.html">Configuration</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="usage/configuration/config_documentation.html">Configuration Manual</a></li><li class="chapter-item expanded "><a href="usage/configuration/homeserver_sample_config.html">Homeserver Sample Config File</a></li><li class="chapter-item expanded "><a href="usage/configuration/logging_sample_config.html">Logging Sample Config File</a></li><li class="chapter-item expanded "><a href="structured_logging.html">Structured Logging</a></li><li class="chapter-item expanded "><a href="templates.html">Templates</a></li><li class="chapter-item expanded "><a href="usage/configuration/user_authentication/index.html">User Authentication</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="usage/configuration/user_authentication/single_sign_on/index.html">Single-Sign On</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="openid.html">OpenID Connect</a></li><li class="chapter-item expanded "><a href="usage/configuration/user_authentication/single_sign_on/saml.html">SAML</a></li><li class="chapter-item expanded "><a href="usage/configuration/user_authentication/single_sign_on/cas.html">CAS</a></li><li class="chapter-item expanded "><a href="sso_mapping_providers.html">SSO Mapping Providers</a></li></ol></li><li class="chapter-item expanded "><a href="password_auth_providers.html">Password Auth Providers</a></li><li class="chapter-item expanded "><a href="jwt.html">JSON Web Tokens</a></li><li class="chapter-item expanded "><a href="usage/configuration/user_authentication/refresh_tokens.html">Refresh Tokens</a></li></ol></li><li class="chapter-item expanded "><a href="CAPTCHA_SETUP.html">Registration Captcha</a></li><li class="chapter-item expanded "><a href="application_services.html">Application Services</a></li><li class="chapter-item expanded "><a href="server_notices.html">Server Notices</a></li><li class="chapter-item expanded "><a href="consent_tracking.html">Consent Tracking</a></li><li class="chapter-item expanded "><a href="user_directory.html">User Directory</a></li><li class="chapter-item expanded "><a href="message_retention_policies.html">Message Retention Policies</a></li><li class="chapter-item expanded "><a href="modules/index.html">Pluggable Modules</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="modules/writing_a_module.html">Writing a module</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="modules/spam_checker_callbacks.html">Spam checker callbacks</a></li><li class="chapter-item expanded "><a href="modules/third_party_rules_callbacks.html">Third-party rules callbacks</a></li><li class="chapter-item expanded "><a href="modules/presence_router_callbacks.html">Presence router callbacks</a></li><li class="chapter-item expanded "><a href="modules/account_validity_callbacks.html">Account validity callbacks</a></li><li class="chapter-item expanded "><a href="modules/password_auth_provider_callbacks.html">Password auth provider callbacks</a></li><li class="chapter-item expanded "><a href="modules/background_update_controller_callbacks.html">Background update controller callbacks</a></li><li class="chapter-item expanded "><a href="modules/account_data_callbacks.html">Account data callbacks</a></li><li class="chapter-item expanded "><a href="modules/add_extra_fields_to_client_events_unsigned.html">Add extra fields to client events unsigned section callbacks</a></li><li class="chapter-item expanded "><a href="modules/porting_legacy_module.html">Porting a legacy module to the new interface</a></li></ol></li></ol></li><li class="chapter-item expanded "><a href="workers.html">Workers</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="synctl_workers.html">Using synctl with Workers</a></li><li class="chapter-item expanded "><a href="systemd-with-workers/index.html">Systemd</a></li></ol></li></ol></li><li class="chapter-item expanded "><a href="usage/administration/index.html">Administration</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="usage/administration/admin_api/index.html">Admin API</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="admin_api/account_validity.html">Account Validity</a></li><li class="chapter-item expanded "><a href="usage/administration/admin_api/background_updates.html">Background Updates</a></li><li class="chapter-item expanded "><a href="admin_api/event_reports.html">Event Reports</a></li><li class="chapter-item expanded "><a href="admin_api/experimental_features.html">Experimental Features</a></li><li class="chapter-item expanded "><a href="admin_api/media_admin_api.html">Media</a></li><li class="chapter-item expanded "><a href="admin_api/purge_history_api.html">Purge History</a></li><li class="chapter-item expanded "><a href="admin_api/register_api.html">Register Users</a></li><li class="chapter-item expanded "><a href="usage/administration/admin_api/registration_tokens.html">Registration Tokens</a></li><li class="chapter-item expanded "><a href="admin_api/room_membership.html">Manipulate Room Membership</a></li><li class="chapter-item expanded "><a href="admin_api/rooms.html">Rooms</a></li><li class="chapter-item expanded "><a href="admin_api/server_notices.html">Server Notices</a></li><li class="chapter-item expanded "><a href="admin_api/statistics.html">Statistics</a></li><li class="chapter-item expanded "><a href="admin_api/user_admin_api.html">Users</a></li><li class="chapter-item expanded "><a href="admin_api/version_api.html">Server Version</a></li><li class="chapter-item expanded "><a href="usage/administration/admin_api/federation.html">Federation</a></li></ol></li><li class="chapter-item expanded "><a href="manhole.html">Manhole</a></li><li class="chapter-item expanded "><a href="metrics-howto.html">Monitoring</a></li><li><ol class="section"><li class="chapter-item expanded "><a href="usage/administration/monitoring/reporting_homeserver_usage_statistics.html">Reporting Homeserver Usage Statistics</a></li></ol></li><li class="chapter-item expanded "><a href="usage/administration/monthly_active_users.html">Monthly Active Users</a></li><li class="chapter-item expanded "><a href="usage/administration/understanding_synapse_through_grafana_graphs.html">Understanding Synapse Through Grafana Graphs</a></li><li class="chapter-item expanded "><a href="usage/administration/useful_sql_for_admins.html">Useful SQL for Admins</a></li><li class="chapter-item expanded "><a href="usage/administration/database_maintenance_tools.html">Database Maintenance Tools</a></li><li class="chapter-item expanded "><a href="usage/administration/state_groups.html">State Groups</a></li><li class="chapter-item expanded "><a href="usage/administration/request_log.html">Request log format</a></li><li class="chapter-item expanded "><a href="usage/administration/admin_faq.html">Admin FAQ</a></li><li class="chapter-item expanded "><div>Scripts</div></li></ol></li><li class="chapter-item expanded "><li class="part-title">Development</li><li class="chapter-item expanded "><a href="development/contributing_guide.html">Contributing Guide</a></li><li class="chapter-item expanded "><a href="code_style.html">Code Style</a></li><li class="chapter-item expanded "><a href="development/reviews.html">Reviewing Code</a></li><li class="chapter-item expanded "><a href="development/releases.html">Release Cycle</a></li><li class="chapter-item expanded "><a href="development/git.html">Git Usage</a></li><li class="chapter-item expanded "><div>Testing</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="development/demo.html">Demo scripts</a></li></ol></li><li class="chapter-item expanded "><a href="opentracing.html">OpenTracing</a></li><li class="chapter-item expanded "><a href="development/database_schema.html">Database Schemas</a></li><li class="chapter-item expanded "><a href="development/experimental_features.html">Experimental features</a></li><li class="chapter-item expanded "><a href="development/dependencies.html">Dependency management</a></li><li class="chapter-item expanded "><div>Synapse Architecture</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="development/synapse_architecture/cancellation.html">Cancellation</a></li><li class="chapter-item expanded "><a href="log_contexts.html">Log Contexts</a></li><li class="chapter-item expanded "><a href="replication.html">Replication</a></li><li class="chapter-item expanded "><a href="development/synapse_architecture/streams.html">Streams</a></li><li class="chapter-item expanded "><a href="tcp_replication.html">TCP Replication</a></li><li class="chapter-item expanded "><a href="development/synapse_architecture/faster_joins.html">Faster remote joins</a></li></ol></li><li class="chapter-item expanded "><a href="development/internal_documentation/index.html">Internal Documentation</a></li><li><ol class="section"><li class="chapter-item expanded "><div>Single Sign-On</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="development/saml.html">SAML</a></li><li class="chapter-item expanded "><a href="development/cas.html">CAS</a></li></ol></li><li class="chapter-item expanded "><a href="development/room-dag-concepts.html">Room DAG concepts</a></li><li class="chapter-item expanded "><div>State Resolution</div></li><li><ol class="section"><li class="chapter-item expanded "><a href="auth_chain_difference_algorithm.html">The Auth Chain Difference Algorithm</a></li></ol></li><li class="chapter-item expanded "><a href="media_repository.html">Media Repository</a></li><li class="chapter-item expanded "><a href="room_and_user_statistics.html">Room and User Statistics</a></li></ol></li><li class="chapter-item expanded "><div>Scripts</div></li><li class="chapter-item expanded affix "><li class="part-title">Other</li><li class="chapter-item expanded "><a href="deprecation_policy.html">Dependency Deprecation Policy</a></li><li class="chapter-item expanded "><a href="other/running_synapse_on_single_board_computers.html">Running Synapse on a Single-Board Computer</a></li></ol>
  75. </div>
  76. <div id="sidebar-resize-handle" class="sidebar-resize-handle"></div>
  77. </nav>
  78. <div id="page-wrapper" class="page-wrapper">
  79. <div class="page">
  80. <div id="menu-bar-hover-placeholder"></div>
  81. <div id="menu-bar" class="menu-bar sticky bordered">
  82. <div class="left-buttons">
  83. <button id="sidebar-toggle" class="icon-button" type="button" title="Toggle Table of Contents" aria-label="Toggle Table of Contents" aria-controls="sidebar">
  84. <i class="fa fa-bars"></i>
  85. </button>
  86. <button id="theme-toggle" class="icon-button" type="button" title="Change theme" aria-label="Change theme" aria-haspopup="true" aria-expanded="false" aria-controls="theme-list">
  87. <i class="fa fa-paint-brush"></i>
  88. </button>
  89. <ul id="theme-list" class="theme-popup" aria-label="Themes" role="menu">
  90. <li role="none"><button role="menuitem" class="theme" id="light">Light (default)</button></li>
  91. <li role="none"><button role="menuitem" class="theme" id="rust">Rust</button></li>
  92. <li role="none"><button role="menuitem" class="theme" id="coal">Coal</button></li>
  93. <li role="none"><button role="menuitem" class="theme" id="navy">Navy</button></li>
  94. <li role="none"><button role="menuitem" class="theme" id="ayu">Ayu</button></li>
  95. </ul>
  96. <button id="search-toggle" class="icon-button" type="button" title="Search. (Shortkey: s)" aria-label="Toggle Searchbar" aria-expanded="false" aria-keyshortcuts="S" aria-controls="searchbar">
  97. <i class="fa fa-search"></i>
  98. </button>
  99. <div class="version-picker">
  100. <div class="dropdown">
  101. <div class="select">
  102. <span></span>
  103. <i class="fa fa-chevron-down"></i>
  104. </div>
  105. <input type="hidden" name="version">
  106. <ul class="dropdown-menu">
  107. <!-- Versions will be added dynamically in version-picker.js -->
  108. </ul>
  109. </div>
  110. </div>
  111. </div>
  112. <h1 class="menu-title">Synapse</h1>
  113. <div class="right-buttons">
  114. <a href="print.html" title="Print this book" aria-label="Print this book">
  115. <i id="print-button" class="fa fa-print"></i>
  116. </a>
  117. <a href="https://github.com/matrix-org/synapse" title="Git repository" aria-label="Git repository">
  118. <i id="git-repository-button" class="fa fa-github"></i>
  119. </a>
  120. <a href="https://github.com/matrix-org/synapse/edit/develop/docs/reverse_proxy.md" title="Suggest an edit" aria-label="Suggest an edit">
  121. <i id="git-edit-button" class="fa fa-edit"></i>
  122. </a>
  123. </div>
  124. </div>
  125. <div id="search-wrapper" class="hidden">
  126. <form id="searchbar-outer" class="searchbar-outer">
  127. <input type="search" id="searchbar" name="searchbar" placeholder="Search this book ..." aria-controls="searchresults-outer" aria-describedby="searchresults-header">
  128. </form>
  129. <div id="searchresults-outer" class="searchresults-outer hidden">
  130. <div id="searchresults-header" class="searchresults-header"></div>
  131. <ul id="searchresults">
  132. </ul>
  133. </div>
  134. </div>
  135. <!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM -->
  136. <script type="text/javascript">
  137. document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible');
  138. document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible');
  139. Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) {
  140. link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1);
  141. });
  142. </script>
  143. <div id="content" class="content">
  144. <main>
  145. <!-- Page table of contents -->
  146. <div class="sidetoc">
  147. <nav class="pagetoc"></nav>
  148. </div>
  149. <h1 id="using-a-reverse-proxy-with-synapse"><a class="header" href="#using-a-reverse-proxy-with-synapse">Using a reverse proxy with Synapse</a></h1>
  150. <p>It is recommended to put a reverse proxy such as
  151. <a href="https://nginx.org/en/docs/http/ngx_http_proxy_module.html">nginx</a>,
  152. <a href="https://httpd.apache.org/docs/current/mod/mod_proxy_http.html">Apache</a>,
  153. <a href="https://caddyserver.com/docs/quick-starts/reverse-proxy">Caddy</a>,
  154. <a href="https://www.haproxy.org/">HAProxy</a> or
  155. <a href="https://man.openbsd.org/relayd.8">relayd</a> in front of Synapse. One advantage
  156. of doing so is that it means that you can expose the default https port
  157. (443) to Matrix clients without needing to run Synapse with root
  158. privileges.</p>
  159. <p>You should configure your reverse proxy to forward requests to <code>/_matrix</code> or
  160. <code>/_synapse/client</code> to Synapse, and have it set the <code>X-Forwarded-For</code> and
  161. <code>X-Forwarded-Proto</code> request headers.</p>
  162. <p>You should remember that Matrix clients and other Matrix servers do not
  163. necessarily need to connect to your server via the same server name or
  164. port. Indeed, clients will use port 443 by default, whereas servers default to
  165. port 8448. Where these are different, we refer to the 'client port' and the
  166. 'federation port'. See <a href="https://matrix.org/docs/spec/server_server/latest#resolving-server-names">the Matrix
  167. specification</a>
  168. for more details of the algorithm used for federation connections, and
  169. <a href="delegate.html">Delegation</a> for instructions on setting up delegation.</p>
  170. <p><strong>NOTE</strong>: Your reverse proxy must not <code>canonicalise</code> or <code>normalise</code>
  171. the requested URI in any way (for example, by decoding <code>%xx</code> escapes).
  172. Beware that Apache <em>will</em> canonicalise URIs unless you specify
  173. <code>nocanon</code>.</p>
  174. <p>Let's assume that we expect clients to connect to our server at
  175. <code>https://matrix.example.com</code>, and other servers to connect at
  176. <code>https://example.com:8448</code>. The following sections detail the configuration of
  177. the reverse proxy and the homeserver.</p>
  178. <h2 id="homeserver-configuration"><a class="header" href="#homeserver-configuration">Homeserver Configuration</a></h2>
  179. <p>The HTTP configuration will need to be updated for Synapse to correctly record
  180. client IP addresses and generate redirect URLs while behind a reverse proxy. </p>
  181. <p>In <code>homeserver.yaml</code> set <code>x_forwarded: true</code> in the port 8008 section and
  182. consider setting <code>bind_addresses: ['127.0.0.1']</code> so that the server only
  183. listens to traffic on localhost. (Do not change <code>bind_addresses</code> to <code>127.0.0.1</code>
  184. when using a containerized Synapse, as that will prevent it from responding
  185. to proxied traffic.)</p>
  186. <p>Optionally, you can also set
  187. <a href="./usage/configuration/config_documentation.html#listeners"><code>request_id_header</code></a>
  188. so that the server extracts and re-uses the same request ID format that the
  189. reverse proxy is using.</p>
  190. <h2 id="reverse-proxy-configuration-examples"><a class="header" href="#reverse-proxy-configuration-examples">Reverse-proxy configuration examples</a></h2>
  191. <p><strong>NOTE</strong>: You only need one of these.</p>
  192. <h3 id="nginx"><a class="header" href="#nginx">nginx</a></h3>
  193. <pre><code class="language-nginx">server {
  194. listen 443 ssl http2;
  195. listen [::]:443 ssl http2;
  196. # For the federation port
  197. listen 8448 ssl http2 default_server;
  198. listen [::]:8448 ssl http2 default_server;
  199. server_name matrix.example.com;
  200. location ~ ^(/_matrix|/_synapse/client) {
  201. # note: do not add a path (even a single /) after the port in `proxy_pass`,
  202. # otherwise nginx will canonicalise the URI and cause signature verification
  203. # errors.
  204. proxy_pass http://localhost:8008;
  205. proxy_set_header X-Forwarded-For $remote_addr;
  206. proxy_set_header X-Forwarded-Proto $scheme;
  207. proxy_set_header Host $host;
  208. # Nginx by default only allows file uploads up to 1M in size
  209. # Increase client_max_body_size to match max_upload_size defined in homeserver.yaml
  210. client_max_body_size 50M;
  211. # Synapse responses may be chunked, which is an HTTP/1.1 feature.
  212. proxy_http_version 1.1;
  213. }
  214. }
  215. </code></pre>
  216. <h3 id="caddy-v2"><a class="header" href="#caddy-v2">Caddy v2</a></h3>
  217. <pre><code>matrix.example.com {
  218. reverse_proxy /_matrix/* localhost:8008
  219. reverse_proxy /_synapse/client/* localhost:8008
  220. }
  221. example.com:8448 {
  222. reverse_proxy /_matrix/* localhost:8008
  223. }
  224. </code></pre>
  225. <p><a href="delegate.html">Delegation</a> example:</p>
  226. <pre><code>example.com {
  227. header /.well-known/matrix/* Content-Type application/json
  228. header /.well-known/matrix/* Access-Control-Allow-Origin *
  229. respond /.well-known/matrix/server `{&quot;m.server&quot;: &quot;matrix.example.com:443&quot;}`
  230. respond /.well-known/matrix/client `{&quot;m.homeserver&quot;:{&quot;base_url&quot;:&quot;https://matrix.example.com&quot;},&quot;m.identity_server&quot;:{&quot;base_url&quot;:&quot;https://identity.example.com&quot;}}`
  231. }
  232. matrix.example.com {
  233. reverse_proxy /_matrix/* localhost:8008
  234. reverse_proxy /_synapse/client/* localhost:8008
  235. }
  236. </code></pre>
  237. <h3 id="apache"><a class="header" href="#apache">Apache</a></h3>
  238. <pre><code class="language-apache">&lt;VirtualHost *:443&gt;
  239. SSLEngine on
  240. ServerName matrix.example.com
  241. RequestHeader set &quot;X-Forwarded-Proto&quot; expr=%{REQUEST_SCHEME}
  242. AllowEncodedSlashes NoDecode
  243. ProxyPreserveHost on
  244. ProxyPass /_matrix http://127.0.0.1:8008/_matrix nocanon
  245. ProxyPassReverse /_matrix http://127.0.0.1:8008/_matrix
  246. ProxyPass /_synapse/client http://127.0.0.1:8008/_synapse/client nocanon
  247. ProxyPassReverse /_synapse/client http://127.0.0.1:8008/_synapse/client
  248. &lt;/VirtualHost&gt;
  249. &lt;VirtualHost *:8448&gt;
  250. SSLEngine on
  251. ServerName example.com
  252. RequestHeader set &quot;X-Forwarded-Proto&quot; expr=%{REQUEST_SCHEME}
  253. AllowEncodedSlashes NoDecode
  254. ProxyPass /_matrix http://127.0.0.1:8008/_matrix nocanon
  255. ProxyPassReverse /_matrix http://127.0.0.1:8008/_matrix
  256. &lt;/VirtualHost&gt;
  257. </code></pre>
  258. <p><strong>NOTE</strong>: ensure the <code>nocanon</code> options are included.</p>
  259. <p><strong>NOTE 2</strong>: It appears that Synapse is currently incompatible with the ModSecurity module for Apache (<code>mod_security2</code>). If you need it enabled for other services on your web server, you can disable it for Synapse's two VirtualHosts by including the following lines before each of the two <code>&lt;/VirtualHost&gt;</code> above:</p>
  260. <pre><code class="language-apache">&lt;IfModule security2_module&gt;
  261. SecRuleEngine off
  262. &lt;/IfModule&gt;
  263. </code></pre>
  264. <p><strong>NOTE 3</strong>: Missing <code>ProxyPreserveHost on</code> can lead to a redirect loop.</p>
  265. <h3 id="haproxy"><a class="header" href="#haproxy">HAProxy</a></h3>
  266. <pre><code>frontend https
  267. bind *:443,[::]:443 ssl crt /etc/ssl/haproxy/ strict-sni alpn h2,http/1.1
  268. http-request set-header X-Forwarded-Proto https if { ssl_fc }
  269. http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
  270. http-request set-header X-Forwarded-For %[src]
  271. # Matrix client traffic
  272. acl matrix-host hdr(host) -i matrix.example.com matrix.example.com:443
  273. acl matrix-path path_beg /_matrix
  274. acl matrix-path path_beg /_synapse/client
  275. use_backend matrix if matrix-host matrix-path
  276. frontend matrix-federation
  277. bind *:8448,[::]:8448 ssl crt /etc/ssl/haproxy/synapse.pem alpn h2,http/1.1
  278. http-request set-header X-Forwarded-Proto https if { ssl_fc }
  279. http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
  280. http-request set-header X-Forwarded-For %[src]
  281. default_backend matrix
  282. backend matrix
  283. server matrix 127.0.0.1:8008
  284. </code></pre>
  285. <p><a href="delegate.html">Delegation</a> example:</p>
  286. <pre><code>frontend https
  287. acl matrix-well-known-client-path path /.well-known/matrix/client
  288. acl matrix-well-known-server-path path /.well-known/matrix/server
  289. use_backend matrix-well-known-client if matrix-well-known-client-path
  290. use_backend matrix-well-known-server if matrix-well-known-server-path
  291. backend matrix-well-known-client
  292. http-after-response set-header Access-Control-Allow-Origin &quot;*&quot;
  293. http-after-response set-header Access-Control-Allow-Methods &quot;GET, POST, PUT, DELETE, OPTIONS&quot;
  294. http-after-response set-header Access-Control-Allow-Headers &quot;Origin, X-Requested-With, Content-Type, Accept, Authorization&quot;
  295. http-request return status 200 content-type application/json string '{&quot;m.homeserver&quot;:{&quot;base_url&quot;:&quot;https://matrix.example.com&quot;},&quot;m.identity_server&quot;:{&quot;base_url&quot;:&quot;https://identity.example.com&quot;}}'
  296. backend matrix-well-known-server
  297. http-after-response set-header Access-Control-Allow-Origin &quot;*&quot;
  298. http-after-response set-header Access-Control-Allow-Methods &quot;GET, POST, PUT, DELETE, OPTIONS&quot;
  299. http-after-response set-header Access-Control-Allow-Headers &quot;Origin, X-Requested-With, Content-Type, Accept, Authorization&quot;
  300. http-request return status 200 content-type application/json string '{&quot;m.server&quot;:&quot;matrix.example.com:443&quot;}'
  301. </code></pre>
  302. <h3 id="relayd"><a class="header" href="#relayd">Relayd</a></h3>
  303. <pre><code>table &lt;webserver&gt; { 127.0.0.1 }
  304. table &lt;matrixserver&gt; { 127.0.0.1 }
  305. http protocol &quot;https&quot; {
  306. tls { no tlsv1.0, ciphers &quot;HIGH&quot; }
  307. tls keypair &quot;example.com&quot;
  308. match header set &quot;X-Forwarded-For&quot; value &quot;$REMOTE_ADDR&quot;
  309. match header set &quot;X-Forwarded-Proto&quot; value &quot;https&quot;
  310. # set CORS header for .well-known/matrix/server, .well-known/matrix/client
  311. # httpd does not support setting headers, so do it here
  312. match request path &quot;/.well-known/matrix/*&quot; tag &quot;matrix-cors&quot;
  313. match response tagged &quot;matrix-cors&quot; header set &quot;Access-Control-Allow-Origin&quot; value &quot;*&quot;
  314. pass quick path &quot;/_matrix/*&quot; forward to &lt;matrixserver&gt;
  315. pass quick path &quot;/_synapse/client/*&quot; forward to &lt;matrixserver&gt;
  316. # pass on non-matrix traffic to webserver
  317. pass forward to &lt;webserver&gt;
  318. }
  319. relay &quot;https_traffic&quot; {
  320. listen on egress port 443 tls
  321. protocol &quot;https&quot;
  322. forward to &lt;matrixserver&gt; port 8008 check tcp
  323. forward to &lt;webserver&gt; port 8080 check tcp
  324. }
  325. http protocol &quot;matrix&quot; {
  326. tls { no tlsv1.0, ciphers &quot;HIGH&quot; }
  327. tls keypair &quot;example.com&quot;
  328. block
  329. pass quick path &quot;/_matrix/*&quot; forward to &lt;matrixserver&gt;
  330. pass quick path &quot;/_synapse/client/*&quot; forward to &lt;matrixserver&gt;
  331. }
  332. relay &quot;matrix_federation&quot; {
  333. listen on egress port 8448 tls
  334. protocol &quot;matrix&quot;
  335. forward to &lt;matrixserver&gt; port 8008 check tcp
  336. }
  337. </code></pre>
  338. <h2 id="health-check-endpoint"><a class="header" href="#health-check-endpoint">Health check endpoint</a></h2>
  339. <p>Synapse exposes a health check endpoint for use by reverse proxies.
  340. Each configured HTTP listener has a <code>/health</code> endpoint which always returns
  341. 200 OK (and doesn't get logged).</p>
  342. <h2 id="synapse-administration-endpoints"><a class="header" href="#synapse-administration-endpoints">Synapse administration endpoints</a></h2>
  343. <p>Endpoints for administering your Synapse instance are placed under
  344. <code>/_synapse/admin</code>. These require authentication through an access token of an
  345. admin user. However as access to these endpoints grants the caller a lot of power,
  346. we do not recommend exposing them to the public internet without good reason.</p>
  347. </main>
  348. <nav class="nav-wrapper" aria-label="Page navigation">
  349. <!-- Mobile navigation buttons -->
  350. <a rel="prev" href="postgres.html" class="mobile-nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left">
  351. <i class="fa fa-angle-left"></i>
  352. </a>
  353. <a rel="next" href="setup/forward_proxy.html" class="mobile-nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right">
  354. <i class="fa fa-angle-right"></i>
  355. </a>
  356. <div style="clear: both"></div>
  357. </nav>
  358. </div>
  359. </div>
  360. <nav class="nav-wide-wrapper" aria-label="Page navigation">
  361. <a rel="prev" href="postgres.html" class="nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left">
  362. <i class="fa fa-angle-left"></i>
  363. </a>
  364. <a rel="next" href="setup/forward_proxy.html" class="nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right">
  365. <i class="fa fa-angle-right"></i>
  366. </a>
  367. </nav>
  368. </div>
  369. <script type="text/javascript">
  370. window.playground_copyable = true;
  371. </script>
  372. <script src="elasticlunr.min.js" type="text/javascript" charset="utf-8"></script>
  373. <script src="mark.min.js" type="text/javascript" charset="utf-8"></script>
  374. <script src="searcher.js" type="text/javascript" charset="utf-8"></script>
  375. <script src="clipboard.min.js" type="text/javascript" charset="utf-8"></script>
  376. <script src="highlight.js" type="text/javascript" charset="utf-8"></script>
  377. <script src="book.js" type="text/javascript" charset="utf-8"></script>
  378. <!-- Custom JS scripts -->
  379. <script type="text/javascript" src="docs/website_files/table-of-contents.js"></script>
  380. <script type="text/javascript" src="docs/website_files/version-picker.js"></script>
  381. <script type="text/javascript" src="docs/website_files/version.js"></script>
  382. </body>
  383. </html>