Maintenance
Upgrading
In order to upgrade your deployment, you should:
- Read the release notes of the new version and check if there are any breaking changes. The changelog is available on element matrix-stack chart page on the right panel.
- Adjust your values if necessary.
- Re-run the install command. It will upgrade your installation to the latest version of the chart.
Fixing CVE-2026-24044/ELEMENTSEC-2025-1670 manually
If you initially deployed ESS Community with the chart secrets initialization hook enabled (initSecrets.enabled not set to false), your Synapse signing key will be vulnerable if it was not set explicitly in synapse.signingKey. If you later specified its content in synapse.signingKey in the values files, the chart will not be able to generate a new key automatically. You will be using the vulnerable signing key until you change it manually.
- Install
signedjsonandpyyamlusingpip:pip install signedjson pyyaml -
Generate your new signing key with the key id
ed25519:1using the following command: -
Specify this value as the new secret content under
synapse.signingKey: -
To invalidate the old signing key, you will have to construct Synapse
old_signing_keyconfiguration. Generate a throwaway verifying key using the key ided25519:0with the following command:$ python3 -c "import yaml; import time; import signedjson.key; signing_key = signedjson.key.generate_signing_key(0); revoke_time = int(time.time()*1000); result = {\"old_signing_keys\": {\"ed25519:0\": {\"key\": signedjson.key.encode_verify_key_base64(signing_key), \"expired_ts\": revoke_time}}}; print(f\"{yaml.dump(result)}\")" old_signing_keys: ed25519:0: expired_ts: 1770625043432 key: x1YFkPUwoKBnS69Yfxhpjc5Y8cd2nLPElJFdqCcJk4E -
Inject this in synapse additional settings in your values, under a new
synapse.additionalsection:synapse: additional: revoke_bad_signing_key.yml: config: | old_signing_keys: ed25519:0: key: <throwaway verifying key> expired_ts: <current ts>This will make sure that:
- The old key id ed25519:0 is not accepted any more by the federation, and because the verifying key has been randomly generated during revocation, the old key signatures are all invalid.
- The new key ed25519:1 is accepted by the federation
-
Apply the new values using
helmand wait for Synapse to be restarted. Run the following command to check that the new signing keyed25519:1is now advertised properly by Synapse, and the old key ided25519:0is marked as revoked:curl -s https://<your synapse host>/_matrix/key/v2/server | jq { "old_verify_keys": { "ed25519:0": { "expired_ts": 1769001790846, "key": "tt+JkcqGzTxt..." } }, "server_name": "<your server name>", "signatures": { "<your server name>": { "ed25519:1": "gahd4eeGh..." } }, "valid_until_ts": ..., "verify_keys": { "ed25519:1": { "key": "BUIaPW..." } } }