This is an adapted setup bundle. It has not been deployed on the recipient's server or domain.
Passed
- Read the source deployment's image metadata without changing the VPS. All
seven digest pins in
compose.ymlmatch those recorded inimages.json. - Ran
configure.pyagainst disposable settings in a private copy, producing fresh secrets and all five configuration files. - Parsed the generated YAML and JSON and verified that no template markers remained. PostgreSQL/Synapse, Coturn/Synapse and LiveKit/JWT secrets matched.
- Verified
.envmode0600and generated-directory mode0700. - Re-ran the initializer and confirmed that it refused to overwrite the installation; existing file contents remained unchanged.
- Docker Compose v5.5.1 validated the complete seven-service model, variable interpolation, dependencies, image pins, network names, source paths and the TCP 7881 / UDP 7882 mapping.
- Ran the documented signing-key generation command in a temporary local container using the pinned Synapse v1.159.0 image. The new signing key was written to the disposable data directory.
- Loaded the generated config through that image's
HomeServerConfigparser. Parsing succeeded; the MatrixRTC feature flags and transport URL were present in the effective Synapse configuration. - Checked the shareable files for the original credentials, server domain/IPs, VPS-specific paths and generated test secrets. None are included.
- Verified that the documented archive file list excludes generated config,
.env,settings.env, data and backups.
Local container checks used Docker Engine 29.8.1 on Linux/aarch64 through Docker Desktop. The source deployment uses Linux/amd64; the full seven-image stack and Coturn host networking have not been validated on other architectures.
Required on the new server
- DNS, provider/host firewall rules, certificate issuance and IPv4 reachability.
- First PostgreSQL initialization, complete service startup and resource sizing.
- Account creation, login, messaging, uploads and federation.
- MatrixRTC token issuance and client discovery, external encrypted audio/video calls, selected UDP candidate, TCP fallback and TURN allocation where used.
- A backup restore in isolation, preserving the signing key and server name.
The original deployment had working external calls; its corrected UDP 7882 path was also checked with two external synthetic LiveKit clients exchanging audio. That is source-deployment evidence, not a substitute for the new-server checks.
Inside the bundle
The complete setup lives in a folder you can keep, inspect and change. No generated credentials or runtime data are included.
compose.ymlThe seven-service stack ↗configure.pyGenerate your own config ↗settings.env.exampleDomain, IP and email ↗images.jsonImage origins and digests ↗Archive SHA-256dfdb0a203861f119a6b21d503041a792a111374742a1b3cd48b9dbc06dca085f