MATRIX HAS YOU FIELD MANUAL

SELF-HOSTING / DOCKER COMPOSE / EDITION 2026.10

Trust.
Then verify.

Here is what was actually checked—and what you still need to prove on your own server. A green config check is only the beginning.

12 files · fresh secrets on your server · no account needed

Linux · public IPv47 services · digest-pinned images4.75 GiB · combined memory capsWhat has been checked

This is an adapted setup bundle. It has not been deployed on the recipient's server or domain.

Passed

  • Read the source deployment's image metadata without changing the VPS. All seven digest pins in compose.yml match those recorded in images.json.
  • Ran configure.py against disposable settings in a private copy, producing fresh secrets and all five configuration files.
  • Parsed the generated YAML and JSON and verified that no template markers remained. PostgreSQL/Synapse, Coturn/Synapse and LiveKit/JWT secrets matched.
  • Verified .env mode 0600 and generated-directory mode 0700.
  • Re-ran the initializer and confirmed that it refused to overwrite the installation; existing file contents remained unchanged.
  • Docker Compose v5.5.1 validated the complete seven-service model, variable interpolation, dependencies, image pins, network names, source paths and the TCP 7881 / UDP 7882 mapping.
  • Ran the documented signing-key generation command in a temporary local container using the pinned Synapse v1.159.0 image. The new signing key was written to the disposable data directory.
  • Loaded the generated config through that image's HomeServerConfig parser. Parsing succeeded; the MatrixRTC feature flags and transport URL were present in the effective Synapse configuration.
  • Checked the shareable files for the original credentials, server domain/IPs, VPS-specific paths and generated test secrets. None are included.
  • Verified that the documented archive file list excludes generated config, .env, settings.env, data and backups.

Local container checks used Docker Engine 29.8.1 on Linux/aarch64 through Docker Desktop. The source deployment uses Linux/amd64; the full seven-image stack and Coturn host networking have not been validated on other architectures.

Required on the new server

  • DNS, provider/host firewall rules, certificate issuance and IPv4 reachability.
  • First PostgreSQL initialization, complete service startup and resource sizing.
  • Account creation, login, messaging, uploads and federation.
  • MatrixRTC token issuance and client discovery, external encrypted audio/video calls, selected UDP candidate, TCP fallback and TURN allocation where used.
  • A backup restore in isolation, preserving the signing key and server name.

The original deployment had working external calls; its corrected UDP 7882 path was also checked with two external synthetic LiveKit clients exchanging audio. That is source-deployment evidence, not a substitute for the new-server checks.

Inside the bundle

The complete setup lives in a folder you can keep, inspect and change. No generated credentials or runtime data are included.

Archive SHA-256dfdb0a203861f119a6b21d503041a792a111374742a1b3cd48b9dbc06dca085f