This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computing:element-call [2026/10/10 05:43] – oemb1905 | computing:element-call [2026/10/10 06:03] (current) – oemb1905 | ||
|---|---|---|---|
| Line 204: | Line 204: | ||
| systemctl --user start container-element-call.service | systemctl --user start container-element-call.service | ||
| </ | </ | ||
| - | |||
| - | '' | ||
| ==== 8. Verify ==== | ==== 8. Verify ==== | ||
| + | |||
| + | Let's make sure those quadlets all function: | ||
| + | |||
| < | < | ||
| systemctl --user is-active container-livekit.service container-lk-jwt.service container-element-call.service | systemctl --user is-active container-livekit.service container-lk-jwt.service container-element-call.service | ||
| Line 216: | Line 217: | ||
| </ | </ | ||
| - | Expect | + | Here, we are looking for '' |
| ==== 9. Upgrade script ==== | ==== 9. Upgrade script ==== | ||
| - | ''/ | + | |
| + | Here's a simple upgrade script for the OCI container. Create | ||
| < | < | ||
| #!/bin/bash | #!/bin/bash | ||
| set -euo pipefail | set -euo pipefail | ||
| + | export XDG_RUNTIME_DIR=/ | ||
| + | export DBUS_SESSION_BUS_ADDRESS=unix: | ||
| podman pull docker.io/ | podman pull docker.io/ | ||
| Line 245: | Line 249: | ||
| </ | </ | ||
| - | Run it as '' | + | ==== 10. Apache (root) ==== |
| - | < | + | Now that the service is created and running, make sure dns for a/aaaa is ready and then let's cut the cert. |
| - | su - worker -c '/bin/bash / | + | |
| - | </ | + | |
| - | Do not '' | + | |
| + | sudo certbot certonly --apache -d webrtc.gnulinux.club | ||
| - | ==== 10. Apache | + | We also need to create the reverse proxy so we can forward external requests upstream to the local listening services we just created. For the cert(s) '' |
| - | ''/ | + | |
| < | < | ||
| Line 262: | Line 264: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | Inside '' | ||
| + | |||
| + | < | ||
| < | < | ||
| ServerName call.gnulinux.club | ServerName call.gnulinux.club | ||
| Line 276: | Line 282: | ||
| </ | </ | ||
| - | ''/ | + | Inside |
| < | < | ||
| Line 284: | Line 290: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | Inside '' | ||
| + | |||
| + | < | ||
| < | < | ||
| ServerName webrtc.gnulinux.club | ServerName webrtc.gnulinux.club | ||
| Line 304: | Line 314: | ||
| </ | </ | ||
| </ | </ | ||
| + | |||
| + | Once that's done, let's enable them and check the endpoints: | ||
| < | < | ||
| Line 316: | Line 328: | ||
| ==== 11. Synapse (Matrix VM) ==== | ==== 11. Synapse (Matrix VM) ==== | ||
| - | No new ports. Existing HTTPS is enough. Append this at the bottom of ''/ | + | |
| + | On the Matrix VM, we need to edit '' | ||
| < | < | ||
| Line 339: | Line 352: | ||
| livekit_service_url: | livekit_service_url: | ||
| </ | </ | ||
| + | |||
| + | Then, restart the service: | ||
| < | < | ||
| Line 344: | Line 359: | ||
| </ | </ | ||
| - | Wait until it is active. A curl during those few seconds returns nginx 502. The LiveKit secret is not added here. Synapse only advertises the JWT URL. '' | + | You can test with: |
| - | + | ||
| - | This Synapse serves the unstable route only. ''/ | + | |
| - | + | ||
| - | With a real Element access token: | + | |
| < | < | ||
| Line 355: | Line 366: | ||
| </ | </ | ||
| - | The body must contain '' | + | The body of the output should |
| ==== 12. Well-known (Matrix VM) ==== | ==== 12. Well-known (Matrix VM) ==== | ||
| - | ''/ | + | |
| + | In an initial build, I left old comments/ | ||
| < | < | ||
| Line 387: | Line 399: | ||
| } | } | ||
| </ | </ | ||
| + | |||
| + | Reload service and check API endpoint: | ||
| < | < | ||
| Line 394: | Line 408: | ||
| ==== 13. Element Web ==== | ==== 13. Element Web ==== | ||
| - | In '' | + | |
| + | In '' | ||
| < | < | ||
| Line 405: | Line 420: | ||
| </ | </ | ||
| - | '' | + | That should be it. Debug and review line by line if stuff is failing. Reach out on Matrix if needed. |
| - | + | ||
| - | ==== Facts ==== | + | |
| - | * UD | + | |
| - | --- // | + | --- // |