A production-grade, containerized Matrix stack with automated SSL (Let's Encrypt), PostgreSQL performance tuning, and the Element web client.
- Domain: You must own a domain (e.g.,
example.com). - DNS: Create A/AAAA records for:
matrix.yourdomain.comchat.yourdomain.com
- Network: Ensure your router/firewall forwards:
- Public
80-> Host8080 - Public
443-> Host8443
- Public
Run the following command to replace the placeholder domain with your actual domain:
# Replace 'yourdomain.com' with your real domain
grep -rli 'YOUR_DOMAIN' * | xargs -i@ sed -i 's/YOUR_DOMAIN/yourdomain.com/g' @# 1. Set permissions and generate signing keys
./setup.sh
# 2. Update passwords (CRITICAL)
# Edit docker-compose.yml and config/synapse/homeserver.yaml
# to change 'synapse_password_change_me' to a strong password.
# 3. Launch the stack
docker-compose up -d- Traefik v3: Entry point for all traffic. Handles SSL termination and routing.
- Synapse: The core Matrix Homeserver.
- PostgreSQL 16: High-performance database.
- Element Web: The browser-based client.
docker-compose logs -f synapse
docker-compose logs -f traefikTo create an admin user via the command line:
docker exec -it synapse register_new_matrix_user -c /data/homeserver.yaml http://localhost:8008Certificates are managed automatically by Traefik and stored in ./letsencrypt/acme.json. The setup.sh script ensures this file has the correct 600 permissions.
This stack is optimized for a host with 8GB RAM:
- Postgres: Uses custom
shared_buffersandeffective_cache_size. - Synapse: Configured with a
global_factorof2.0for enhanced caching.
config/synapse: Configuration and data for the Synapse homeserver.config/element: Configuration for the Element web client.letsencrypt: Let's Encrypt SSL storage.setup.sh: Initialization script.
