Add a stream relay (TURN) to the proxy for browsers that cannot connect directly

Vanadium forbids direct UDP for WebRTC, and mobile and company networks often
block direct connections; the only route then is a relay reached over TCP.

- server/turn.ts: STUN and TURN on one port, over UDP and TCP, with
  short-lived credentials from /api/turn, quotas and a peer filter
- The browser build fetches credentials and offers the relay automatically
- Stats for nerds says when a stream is relayed and how the relay is reached
- Tests: a TURN client over UDP and TCP, and a browser limited to the relay
  over TCP in the web E2E

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-01 23:30:09 +02:00
co-authored by Claude Opus 5.5
parent 98e44d7082
commit 08aa5268d0
13 changed files with 720 additions and 85 deletions
+1 -1
View File
@@ -14,5 +14,5 @@ COPY --from=build /src/dist-web ./dist-web
COPY --from=build /src/dist-proxy ./dist-proxy
USER node
ENV MUMH5_PORT=8080
EXPOSE 8080/tcp 3478/udp
EXPOSE 8080/tcp 3478/udp 3478/tcp 49160-49359/udp
CMD ["node", "dist-proxy/proxy.mjs"]