feat(element-calling): fix Element X discovery and harden federated calling
The element-calling feature only advertised the LiveKit focus via the well-known org.matrix.msc4143.rtc_foci file, and relied on STUN auto-detection for the public IP. Element X queries the MatrixRTC transports registry endpoint and fails with MISSING_MATRIX_RTC_TRANSPORT when it is absent, and blocked STUN egress silently left LiveKit advertising a private IP (call connects but no video across servers). - synapse: enable msc4143_enabled and advertise matrix_rtc.transports (MSC4519) with the site's element-calling URL, so Element X can discover the LiveKit focus instead of erroring out - livekit: determine the public IP to advertise at runtime — explicit pin, then HTTPS egress detection (api.ipify.org / checkip.amazonaws.com / ifconfig.me), then STUN fallback with a warning; reject non-routable results (private/loopback/CGNAT) - lk-jwt-service: append optional extra homeservers to LIVEKIT_FULL_ACCESS_HOMESERVERS via the new sovran_systemsOS.elementCalling.fullAccessHomeservers option - add sovran_systemsOS.elementCalling.externalIP option to pin the advertised public IP for multi-WAN/VPN setups - add element-calling-public-check.service: boot-time diagnostics for public DNS (via 1.1.1.1, bypassing local loopback overrides), JWT healthz through Caddy and via the public IP, and the transports endpoint — turns the silent -no media- failure into a visible error - add restartTriggers so livekit/lk-jwt-service pick up regenerated runtime configs on rebuild
This commit is contained in:
@@ -79,6 +79,41 @@
|
||||
};
|
||||
};
|
||||
|
||||
# ── Element Calling (video/audio) tuning ──────────────────
|
||||
elementCalling = {
|
||||
fullAccessHomeservers = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
example = [ "matrix.peer.example.com" ];
|
||||
description = ''
|
||||
Additional Matrix server_names (beyond this server itself) that may
|
||||
trigger LiveKit room creation on this server's SFU via lk-jwt-service.
|
||||
|
||||
Not needed for the common federated setup: each participant's client
|
||||
always obtains its token from its own homeserver's JWT service and
|
||||
publishes to its own SFU, and the participant who starts a call
|
||||
creates the room on their own SFU — the remote user merely joins
|
||||
(joining does not require full access).
|
||||
|
||||
Only set this for asymmetric cases: e.g. a peer homeserver that has
|
||||
no focus of its own, or calls whose first participant lands on this
|
||||
server's SFU but belongs to the peer.
|
||||
'';
|
||||
};
|
||||
externalIP = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
example = "203.0.113.10";
|
||||
description = ''
|
||||
Optional pin: force LiveKit to advertise this public IPv4 in its
|
||||
host/TURN ICE candidates. Not required in normal operation — the
|
||||
module auto-detects the public IP at runtime (HTTPS egress
|
||||
detection, falling back to STUN). Set it only to override a
|
||||
mis-detected address (e.g. multi-WAN/VPN setups).
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
# ── Domain setup registry ─────────────────────────────────
|
||||
domainRequirements = lib.mkOption {
|
||||
type = lib.types.listOf (lib.types.submodule {
|
||||
|
||||
Reference in New Issue
Block a user