Thanks for the link to go-sendxmpp. It's nice to have an xmpp-native way to send notifications
stratself
Yes and federation works. The caveat is that since Matrix s2s de facto mandates TLS certs, you'll need to use self-signed certs as well as accept them from other onion peers. I've been aware of some more involved setups where a server name on the clearnet can be manually mapped to its Tor onionsite as well.
Beyond that, c2s is just a simple HTTP service, and most clients should support it assuming they have a way to hop on Tor (Orbot, SOCKS5 proxy etc)
I think they encourage that increased frequency by offering shortlived certs to begin with...
Although do note that normal certificates will reduce its lifetime to 45 days over the next few years
If the rooms are public, consider adding a moderation bot to be better equiped against spam too. Selfhosting Draupnir or Meowlnir is doable, but you can also employ https://asgard.chat/
You can use caddy reload -c /path/to/Caddyfile to reload the config midway through
For TLS I am looking into using CertBot and it appears there's a module (https://github.com/desec-io/certbot-dns-desec) I can use that works for https://desec.io/ to handle my certs.
You can consider using lego-acme as well. It's not too different, just that it comes prepackaged with a bunch of DNS providers including desec, so you don't need to install an additional module.
Since Caddy is handling my certs automatically, how often would I want to renew my certs?
By default, certs are valid for 90 days so you'd wanna renew a bit earlier than that. There's also the option to use 45-day certs or 6-day certs, depending on the profile chosen.
Would I be required to run the same command periodically to renew my cert?
Yes, but it's better if you automate them, like Caddy did, and both Certbot and lego can do this well. I run lego via a cronjob which checks for the certs' expiry, and renew it when it passes a certain deadline.
I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI
Not sure I can recommend anything from that list because I'm not familiar with them, but I've heard haproxy to be very performant.
I wrote this by myself using anectodal sources from the community and experience hosting the thing, and no, it never passed through any LLMs. Perhaps I should approach things with a less upbeat and more cynically curt tone.
Hello,
I believe Matrix would be the most suitable candidate for your use case. The protocol supports both public and private (invite-only) rooms. It also has spaces, which are collections of rooms that helps with organisation (and yes they do exist in the sidebar). Voice/video calls can be done through Element Call which is integrated in many clients, and are usually quite performant. Pinned messages and polls are natively supported, and there exist various bots for reminders and other little neat features (see the Maubot plugins).
Matrix is also federatable like email, so you can extend your community to people on other servers in the network, too. Be sure to employ moderation tooling though, of which the ecosystem has plenty of and are improving every day. I also recommend testing out non-Element clients (such as Sable, Cinny, or SchildiNext) to see which one fits best with your organisation.
In another comment, you have mentioned the limit of 100 users. I believe this only applies for the Element Server Suite freemium solution, and so I ask, why not use another open source solution? My suggestion would be Continuwuity, a homeserver written in Rust with a very active community behind it. Continuwuity is generally considered much more lightweight than alternatives, and have been seen supporting sub-500 users just fine on a machine with 8 gigs of memory.
There's some other QoL features of Continuwuity you may be interested in, like auto-joining to a room after account creation, or registration via admin-issued tokens. It can also integrate with your favorite single-sign-on solution via OIDC as well. So yeah, feel free to ask more about it here, or take the next steps in the support room!
There exists other solutions as well, but I think they are not the best candidates for few reasons. XMPP (i.e. the protocol behind Snikket) is more lightweight, but its clients still generally lack support for group calls, pinned messages, and polls. Fluxer may have a better UI, but it is not federated from the ground up which can lead to problems. I don't think Nextcloud Talk offers federation either(?), but I believe Nextcloud to be a quite heavy, "bells and whistles included" software suite in general which may be too much for your use case.
When the author started using it didn't support edits yet
Again in the linked Server-Server API, I can only find mentions of device details here. The most that is required is an opaque device ID, which alone cannot infer more device details. device_display_name is fully optional and hasn't been sent by servers for ages.
These device updates are used for sending device keys, which is needed for establishing multi-device E2EE sessions. The same kind of ratchet-based E2EE that Signal utilizes. The paper you linked only investigated a single server, non-federated deployment, extrapolating every finding to federation just doesn't make any sense.
Hi, I've been running something similar with Tailscale. Instead of traefik, you can use any other TCP proxy like nginx or caddy-l4, or even use
tailscale serveon the edge VPS as well. Do note that all of your listed services except Zola will make outbound requests, so it could be better to also exit node through the VPS (like the article did), as to avoid exposing your residential IP.As for the linked personas, you may wanna use one domain instead of two. Matrix homeservers can be resource-heavy for example, so maybe consider
@persona1:example.comand@persona2:example.comon a single server instead of having two resource hubs that does essentially the same thing. The same applies to GotoSocial and Lemmy. By the way, I recommend Continuwuity for the Matrix server :)Static sites don't actively take up resources, so they can be on separate domains. But again you may wanna save some money, so maybe consider using
persona1/persona2.example.comsubdomains, or even pubnix-styleexample.com/~persona(1|2)paths!As for the Docker management frontend, I have no idea which one's the best right now ๐ but do make use of Tailscale SSH feature to troubleshoot other parts of your machines as well. And as for updates, I just subscribe to RSS feeds to keep the important software updated. Highly recommend you do that too to check out changelogs yourself.