Skip to content
supernetsPublic

About

🟦🟧 SuperNETs XMPP Service

Topics

Resources

Stars

2 stars

Watchers

2 watching

Forks

Latest commit

 

History

11 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Prosody

SuperNETs XMPP server. Prosody 13 from Debian trixie-backports, running in Docker with host networking so mod_limits sees real client IPs.

Host Purpose
xmpp.supernets.org Accounts (user@xmpp.supernets.org)
supernets.org Separate accounts (user@supernets.org)
muc.supernets.org Chatrooms, shared by both hosts
upload.xmpp.supernets.org File sharing on port 5281, 10MB per file, 7 day expiry

Layout

Path Description
Dockerfile Debian trixie with prosody 13 (backports), prosody-modules and lua-unbound
docker-compose.yml Mounts ./etc to /etc/prosody and ./data to /var/lib/prosody
entrypoint.sh Fixes ownership of data and certs, runs Prosody in the foreground
etc/prosody.cfg.lua Prosody config
etc/plugins/ Custom modules: mod_superbowl bookmarks superbowl@muc.supernets.org for new accounts
etc/turn.cfg.lua TURN/STUN for calls (hardchats coturn login), included by the config; not tracked
certbot-deploy.sh certbot deploy hook, copies renewed certs into etc/certs and restarts the container

data/, etc/certs/ and etc/turn.cfg.lua are not tracked.

Deploy

docker compose up -d --build

Ports 5222 (c2s), 5269 (s2s) and 5281 (file share over HTTPS) must be open.

Certificates

Certs are issued on the host with certbot and copied into etc/certs/<domain>/{fullchain,privkey}.pem by certbot-deploy.sh. nginx holds port 80, so the standalone authenticator needs it stopped:

certbot certonly --standalone --cert-name xmpp.supernets.org \
    -d xmpp.supernets.org -d muc.supernets.org -d upload.xmpp.supernets.org \
    --pre-hook "systemctl stop nginx" --post-hook "systemctl start nginx" \
    --deploy-hook /home/supernets/xmpp/certbot-deploy.sh

The supernets.org cert uses the same deploy hook.

Client Setup

We use the Profanity XMPP client for communication.

Commands

/register acidvegas@xmpp.supernets.org
/account add acidvegas
/account default set acidvegas
/account set acidvegas clientid ""
/account set acidvegas jid acidvegas@xmpp.supernets.org
/account set acidvegas muc muc.supernets.org
/account set acidvegas nick acidvegas
/account set acidvegas port 5222
/account set acidvegas resource ""
/account set acidvegas server xmpp.supernets.org
/account set acidvegas session_alarm 2
/account set acidvegas status online
/account set acidvegas tls force
/autoconnect set acidvegas
/color on
/color own on
/connect acidvegas
/occupants color on
/omemo char 🔑
/omemo gen
/omemo log off
/omemo policy always
/omemo trustmode blind
/omemo trustmode manual
/outtype off
/privacy logging off
/privacy os off
/receipts send off
/states off

About

🟦🟧 SuperNETs XMPP Service

Topics

Resources

Stars

2 stars

Watchers

2 watching

Forks

Contributors

Languages