SuperNETs XMPP server. Prosody 13 from Debian trixie-backports, running in Docker with host networking so mod_limits sees real client IPs.
| Host | Purpose |
|---|---|
xmpp.supernets.org |
Accounts (user@xmpp.supernets.org) |
supernets.org |
Separate accounts (user@supernets.org) |
muc.supernets.org |
Chatrooms, shared by both hosts |
upload.xmpp.supernets.org |
File sharing on port 5281, 10MB per file, 7 day expiry |
| Path | Description |
|---|---|
Dockerfile |
Debian trixie with prosody 13 (backports), prosody-modules and lua-unbound |
docker-compose.yml |
Mounts ./etc to /etc/prosody and ./data to /var/lib/prosody |
entrypoint.sh |
Fixes ownership of data and certs, runs Prosody in the foreground |
etc/prosody.cfg.lua |
Prosody config |
etc/plugins/ |
Custom modules: mod_superbowl bookmarks superbowl@muc.supernets.org for new accounts |
etc/turn.cfg.lua |
TURN/STUN for calls (hardchats coturn login), included by the config; not tracked |
certbot-deploy.sh |
certbot deploy hook, copies renewed certs into etc/certs and restarts the container |
data/, etc/certs/ and etc/turn.cfg.lua are not tracked.
docker compose up -d --buildPorts 5222 (c2s), 5269 (s2s) and 5281 (file share over HTTPS) must be open.
Certs are issued on the host with certbot and copied into etc/certs/<domain>/{fullchain,privkey}.pem by certbot-deploy.sh. nginx holds port 80, so the standalone authenticator needs it stopped:
certbot certonly --standalone --cert-name xmpp.supernets.org \
-d xmpp.supernets.org -d muc.supernets.org -d upload.xmpp.supernets.org \
--pre-hook "systemctl stop nginx" --post-hook "systemctl start nginx" \
--deploy-hook /home/supernets/xmpp/certbot-deploy.shThe supernets.org cert uses the same deploy hook.
We use the Profanity XMPP client for communication.
/register acidvegas@xmpp.supernets.org
/account add acidvegas
/account default set acidvegas
/account set acidvegas clientid ""
/account set acidvegas jid acidvegas@xmpp.supernets.org
/account set acidvegas muc muc.supernets.org
/account set acidvegas nick acidvegas
/account set acidvegas port 5222
/account set acidvegas resource ""
/account set acidvegas server xmpp.supernets.org
/account set acidvegas session_alarm 2
/account set acidvegas status online
/account set acidvegas tls force
/autoconnect set acidvegas
/color on
/color own on
/connect acidvegas
/occupants color on
/omemo char 🔑
/omemo gen
/omemo log off
/omemo policy always
/omemo trustmode blind
/omemo trustmode manual
/outtype off
/privacy logging off
/privacy os off
/receipts send off
/states off