2026-07-06 13:11:37 +05:30
|
|
|
# LiveKit SFU config (non-secret — the API key/secret are injected via the LIVEKIT_KEYS env var
|
|
|
|
|
# in docker-compose, sourced from .env, so nothing secret lives in git).
|
|
|
|
|
#
|
|
|
|
|
# Media plane: LiveKit needs UDP reachable from clients (NPM only proxies the HTTP/WS signaling on
|
|
|
|
|
# 7880). The UDP range + TCP fallback below are published as HOST ports in docker-compose. On the
|
|
|
|
|
# VPS, if the server sits behind NAT and can't auto-detect its public IP, set rtc.node_ip to it.
|
|
|
|
|
port: 7880 # signaling (HTTP/WS) — NPM proxies wss://livekit.bizgaze.com -> here
|
|
|
|
|
rtc:
|
|
|
|
|
tcp_port: 7881 # WebRTC-over-TCP fallback (restrictive networks)
|
2026-07-06 13:50:24 +05:30
|
|
|
udp_port: 50000 # SINGLE UDP media port (all participants mux over it) — minimizes
|
|
|
|
|
# the NAT port-forward to one UDP + one TCP port.
|
|
|
|
|
# This box sits behind NAT (private 192.168.88.61 behind public 118.95.33.89). Auto-detection
|
|
|
|
|
# would find the wrong (outbound) IP, so pin the inbound public IP clients actually reach.
|
|
|
|
|
use_external_ip: false
|
|
|
|
|
node_ip: 118.95.33.89
|
2026-07-06 13:11:37 +05:30
|
|
|
|
|
|
|
|
# Embedded TURN over TLS on 443 helps clients on locked-down networks. Left off by default because
|
|
|
|
|
# NPM already owns 443; enable via a dedicated hostname + NPM stream if you need it (see DEPLOY.md).
|
|
|
|
|
turn:
|
|
|
|
|
enabled: false
|
|
|
|
|
|
|
|
|
|
logging:
|
|
|
|
|
level: info
|