Add a stream relay (TURN) to the proxy for browsers that cannot connect directly

Vanadium forbids direct UDP for WebRTC, and mobile and company networks often
block direct connections; the only route then is a relay reached over TCP.

- server/turn.ts: STUN and TURN on one port, over UDP and TCP, with
  short-lived credentials from /api/turn, quotas and a peer filter
- The browser build fetches credentials and offers the relay automatically
- Stats for nerds says when a stream is relayed and how the relay is reached
- Tests: a TURN client over UDP and TCP, and a browser limited to the relay
  over TCP in the web E2E

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-01 23:30:09 +02:00
co-authored by Claude Opus 5.5
parent 98e44d7082
commit 08aa5268d0
13 changed files with 720 additions and 85 deletions
+5 -1
View File
@@ -7,7 +7,8 @@ services:
restart: unless-stopped
# Host networking, so STUN sees each visitor's real address (through Docker's port
# forwarding it would often see Docker's own) and a Mumble server on this machine is
# reachable as localhost. The proxy listens on 127.0.0.1:8080 for nginx and on UDP 3478.
# reachable as localhost. The proxy listens on 127.0.0.1:8080 for nginx, on port 3478 (UDP and
# TCP) for STUN and the relay, and relays streams on UDP 49160-49359.
network_mode: host
# Passed on from .env (or the shell); empty means the proxy's default. Written out one by
# one because older docker-compose versions cannot mark an env_file as optional.
@@ -22,5 +23,8 @@ services:
MUMH5_SEND_PROXY: ${MUMH5_SEND_PROXY:-}
MUMH5_STUN_PORT: ${MUMH5_STUN_PORT:-3478}
MUMH5_STUN_BIND: ${MUMH5_STUN_BIND:-}
MUMH5_TURN: ${MUMH5_TURN:-}
MUMH5_TURN_IP: ${MUMH5_TURN_IP:-}
MUMH5_TURN_PORTS: ${MUMH5_TURN_PORTS:-}
MUMH5_MAX_CONNECTIONS: ${MUMH5_MAX_CONNECTIONS:-}
MUMH5_MAX_PER_ADDRESS: ${MUMH5_MAX_PER_ADDRESS:-}