hosts: - yegunity.org loglevel: info #ca_file: /etc/letsencrypt/live/social.yegunity.org/*.pem certfiles: # - /opt/ejabberd/certs/*.pem # - /opt/ejabberd/certs/*.pem - /opt/ejabberd/certs/server.pem default_db: sql sql_type: pgsql sql_server: "localhost" sql_database: "ejabberd" sql_username: "user" sql_password: "password" listen: - port: 5222 ip: "::" module: ejabberd_c2s max_stanza_size: 262144 shaper: c2s_shaper access: c2s starttls_required: true - port: 5223 ip: "::" tls: true module: ejabberd_c2s max_stanza_size: 262144 shaper: c2s_shaper access: c2s starttls_required: true - port: 5269 ip: "::" module: ejabberd_s2s_in max_stanza_size: 524288 - port: 5443 ip: "::" module: ejabberd_http tls: true request_handlers: /admin: ejabberd_web_admin /api: mod_http_api /bosh: mod_bosh /captcha: ejabberd_captcha /upload: mod_http_upload "": mod_http_fileserver - port: 5280 ip: "::" module: ejabberd_http request_handlers: /admin: ejabberd_web_admin /.well-known/acme-challenge: ejabberd_acme /api: mod_http_api /bosh: mod_bosh /captcha: ejabberd_captcha /upload: mod_http_upload /ws: ejabberd_http_ws /conversejs: mod_conversejs - port: 3478 ip: "::" transport: udp module: ejabberd_stun use_turn: true - port: 1883 ip: "::" module: mod_mqtt backlog: 1000 - port: 8443 ip: "::" module: ejabberd_http tls: true request_handlers: "upload": mod_http_upload s2s_use_starttls: optional acl: local: user_regexp: "" loopback: ip: - 127.0.0.0/8 - ::1/128 admin: - user: "admin@yegunity.org" access_rules: local: allow: local c2s: deny: blocked allow: all announce: allow: admin configure: allow: admin muc_create: allow: local pubsub_createnode: allow: local trusted_network: allow: all api_permissions: "console commands": from: - ejabberd_ctl who: all what: "*" "admin access": who: access: allow: - acl: loopback - acl: admin oauth: scope: "ejabberd:admin" access: allow: - acl: loopback - acl: admin what: - "*" - "!stop" - "!start" "public commands": who: ip: 127.0.0.1/8 what: - status - connected_users_number shaper: normal: rate: 3000 burst_size: 20000 fast: 100000 shaper_rules: max_user_sessions: 10 max_user_offline_messages: 5000: admin 100: all c2s_shaper: none: admin normal: all s2s_shaper: fast modules: mod_adhoc: {} mod_admin_extra: {} mod_announce: access: announce mod_avatar: {} mod_blocking: {} mod_bosh: {} mod_caps: {} mod_carboncopy: {} mod_client_state: {} mod_configure: {} mod_conversejs: websocket_url: "ws://@HOST@:5280/ws" mod_disco: {} mod_fail2ban: {} mod_http_api: {} mod_http_upload: put_url: "https://upload.@HOST@" docroot: "/var/www/ejabberdupload/@HOST@" external_secret: "xxxxxxx" # file_mode: "0640" # dir_mode: "2750" # name: "HTTP File Upload" # access: local # max_size: 104857600 # 100 MiB. # thumbnail: false # custom_headers: # "Access-Control-Allow-Origin": "*" # "Access-Control-Allow-Methods": "GET, POST, PUT, OPTIONS, DELETE" # "Access-Control-Allow-Headers": "Content-Type, Origin, X-Requested-With" # "Content-Security-Policy": "default-src 'none'; frame-ancestors 'none'; " # "X-Content-Type-Options": "nosniff" # "X-Frame-Options": "deny" mod_last: {} mod_mam: assume_mam_usage: true default: always mod_mqtt: {} mod_muc: access: - allow access_admin: - allow: admin access_create: muc_create access_persistent: muc_create access_mam: - allow default_room_options: mam: true # allow_subscription: true # persistent: true mod_muc_admin: {} mod_offline: access_max_user_messages: max_user_offline_messages mod_ping: {} mod_privacy: {} mod_private: {} mod_proxy65: access: local max_connections: 5 mod_pubsub: access_createnode: pubsub_createnode plugins: - flat - pep force_node_config: ## Avoid buggy clients to make their bookmarks public storage:bookmarks: access_model: whitelist mod_push: {} mod_push_keepalive: {} mod_register: ip_access: trusted_network mod_roster: versioning: true mod_s2s_dialback: {} mod_shared_roster: {} mod_stream_mgmt: resend_on_timeout: if_offline mod_stun_disco: {} mod_vcard: {} mod_vcard_xupdate: {} mod_version: show_os: false mod_http_fileserver: docroot: "/var/www/ejabberdupload/yegunity.org" accesslog: "/opt/ejabberd/logs/web.log" directory_indices: - "index.html" custom_headers: "Access-Control-Allow-Origin": "*" "Access-Control-Allow-Methods": "GET,HEAD,PUT,OPTIONS" "Strict-Transport-Security": "max-age=31536000; includeSubDomains; preload" "Content-Security-Policy": "default-src 'self' yegunity.org; connect-src 'self' https://yegunity.org wss://yegunity.org:5280/ws https://upload.yegunity.org; img-src * 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; font-src 'self' data:; upgrade-insecure-requests; " "X-Frame-Options": "sameorigin" "X-Xss-Protection": "1; mode=block" "X-Content-Type-Options": "nosniff" "Referrer-Policy": "strict-origin" content_types: ".ogg": "audio/ogg" ".png": "image/png" ".jpg": "image/jpg" ".css": "text/css" ".js": "text/javascript" default_content_type: "text/html"