Vanadium forbids direct UDP for WebRTC, and mobile and company networks often block direct connections; the only route then is a relay reached over TCP. - server/turn.ts: STUN and TURN on one port, over UDP and TCP, with short-lived credentials from /api/turn, quotas and a peer filter - The browser build fetches credentials and offers the relay automatically - Stats for nerds says when a stream is relayed and how the relay is reached - Tests: a TURN client over UDP and TCP, and a browser limited to the relay over TCP in the web E2E Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
31 lines
1.4 KiB
YAML
31 lines
1.4 KiB
YAML
# The mumh5 web proxy. Settings come from a .env file next to this one, for example:
|
|
# MUMH5_SERVERS=mumble.example.com=My server
|
|
# MUMH5_TRUST_PROXY=1
|
|
services:
|
|
mumh5:
|
|
build: .
|
|
restart: unless-stopped
|
|
# Host networking, so STUN sees each visitor's real address (through Docker's port
|
|
# forwarding it would often see Docker's own) and a Mumble server on this machine is
|
|
# reachable as localhost. The proxy listens on 127.0.0.1:8080 for nginx, on port 3478 (UDP and
|
|
# TCP) for STUN and the relay, and relays streams on UDP 49160-49359.
|
|
network_mode: host
|
|
# Passed on from .env (or the shell); empty means the proxy's default. Written out one by
|
|
# one because older docker-compose versions cannot mark an env_file as optional.
|
|
environment:
|
|
MUMH5_SERVERS: ${MUMH5_SERVERS:-}
|
|
MUMH5_ALLOW_ANY: ${MUMH5_ALLOW_ANY:-}
|
|
MUMH5_ALLOW_PRIVATE: ${MUMH5_ALLOW_PRIVATE:-}
|
|
MUMH5_PORT: ${MUMH5_PORT:-8080}
|
|
MUMH5_BIND: ${MUMH5_BIND:-127.0.0.1}
|
|
MUMH5_ORIGINS: ${MUMH5_ORIGINS:-}
|
|
MUMH5_TRUST_PROXY: ${MUMH5_TRUST_PROXY:-}
|
|
MUMH5_SEND_PROXY: ${MUMH5_SEND_PROXY:-}
|
|
MUMH5_STUN_PORT: ${MUMH5_STUN_PORT:-3478}
|
|
MUMH5_STUN_BIND: ${MUMH5_STUN_BIND:-}
|
|
MUMH5_TURN: ${MUMH5_TURN:-}
|
|
MUMH5_TURN_IP: ${MUMH5_TURN_IP:-}
|
|
MUMH5_TURN_PORTS: ${MUMH5_TURN_PORTS:-}
|
|
MUMH5_MAX_CONNECTIONS: ${MUMH5_MAX_CONNECTIONS:-}
|
|
MUMH5_MAX_PER_ADDRESS: ${MUMH5_MAX_PER_ADDRESS:-}
|