diff --git a/deploy/self-hosting/.env.example b/deploy/self-hosting/.env.example index 4a3348121..8df8559f9 100644 --- a/deploy/self-hosting/.env.example +++ b/deploy/self-hosting/.env.example @@ -263,7 +263,7 @@ FLUXER_VAPID_PRIVATE_KEY=CHANGE_ME # only when a browser must reach an origin the defaults do not cover. Separate # several with spaces or commas. The three values below are illustrations. #FLUXER_CSP_EXTRA_DEFAULT_SRC= -#FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com:7881 +#FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com #FLUXER_CSP_EXTRA_IMG_SRC=https://cdn.example.com #FLUXER_CSP_EXTRA_MEDIA_SRC= #FLUXER_CSP_EXTRA_FONT_SRC= diff --git a/fluxer_docs/src/content/docs/operator/configuration.mdx b/fluxer_docs/src/content/docs/operator/configuration.mdx index 1df64841f..d94658230 100644 --- a/fluxer_docs/src/content/docs/operator/configuration.mdx +++ b/fluxer_docs/src/content/docs/operator/configuration.mdx @@ -2165,13 +2165,15 @@ CORS origins are exactly the app endpoint, the `FLUXER_APP_ORIGIN_ALIASES` origi | --- | --- | --- | | postgres-data | Every account, message, and configuration row | Yes | | seaweedfs-data | Every uploaded file | Yes | -| valkey-data | Deletion queues and shared cache | Yes | +| valkey-data | Pending file deletions, other queues and shared cache | Yes | | nats-data | Pending and failed background jobs | Yes | | edge-data | Issued TLS certificates | Optional, a loss only costs a re-issue | | edge-config | The edge's own state | No | -| meilisearch-data | The search index, rebuildable | No | +| meilisearch-data | The search index, rebuildable from Postgres | Optional | -Losing `valkey-data` can delay scheduled account and bulk-message deletions while their queues are rebuilt. Pending asset deletions and cache purges can be lost, so do not treat this volume as disposable cache. +Losing `valkey-data` can delay scheduled account and bulk-message deletions while their queues are rebuilt. Pending asset deletions and cache purges exist only here and are lost with it, so do not treat this volume as disposable cache. + +Losing `meilisearch-data` leaves search empty until it is rebuilt. Nothing rebuilds it automatically, because Postgres still records every channel as indexed. Rebuild each index with [`POST /admin/search/indexes/{index_name}/refreshes`](/admin-api/search-indexes/). The `channel_messages` and `guild_members` indexes rebuild one community at a time and need a `guild_id` for each. A backup of the volume avoids those calls on a large instance. `nats-data` retains pending jobs in `JOBS` for up to 7 days and failed jobs in `JOBS_DLQ` for up to 30 days. A full jobs stream rejects new work. A full dead-letter stream drops its oldest entries, so investigate failures promptly. If dead-letter storage is unavailable, failed jobs remain in `JOBS` only until they expire. Losing this volume loses queued work, which is not automatically recovered from the database. diff --git a/fluxer_docs/src/content/docs/operator/reverse-proxy.mdx b/fluxer_docs/src/content/docs/operator/reverse-proxy.mdx index 5009c965d..6f08f1dad 100644 --- a/fluxer_docs/src/content/docs/operator/reverse-proxy.mdx +++ b/fluxer_docs/src/content/docs/operator/reverse-proxy.mdx @@ -522,10 +522,13 @@ LiveKit signalling goes through `/livekit/*` like everything else. WebRTC media Both ports are published directly by the stack and must reach the host. A proxy or tunnel in front of `443` does nothing for them. -Hosting LiveKit on a hostname other than `FLUXER_DOMAIN` means widening the Content-Security-Policy the web app runs under. The line goes in `.env`, beside `FLUXER_DOMAIN`: +Signalling can use a hostname other than `FLUXER_DOMAIN`. Two lines go in `.env`, beside `FLUXER_DOMAIN`. The first points clients at the new hostname, and the second lets the web app's Content-Security-Policy connect to it: ```ini -FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com:7881 +FLUXER_LIVEKIT_URL=wss://livekit.example.com/livekit +FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com ``` -`app-proxy` builds the policy and reads its environment at container start, so apply the change with `docker compose up -d app-proxy`. `docker compose restart app-proxy` reuses the existing container with its old environment. [Content Security Policy](/operator/configuration/#content-security-policy) has the other variables. +The policy entry is the origin alone, with no port or path. The hostname needs a valid TLS certificate and must reach the `/livekit` route on the edge with WebSocket upgrades. The media ports above never belong in the policy, because WebRTC media is not governed by `connect-src`. A separate hostname is rarely needed, since media goes to the address LiveKit advertises, not to a hostname. + +`api` writes `FLUXER_LIVEKIT_URL` into the default voice server at start, and `app-proxy` builds the policy at container start, so apply the change with `docker compose up -d api app-proxy`. `docker compose restart` reuses the existing containers with their old environment. [Content Security Policy](/operator/configuration/#content-security-policy) has the other variables.