From 804c218236680ea82d84443b959c35b063fe1a2d Mon Sep 17 00:00:00 2001 From: sravan Date: Mon, 20 Jul 2026 17:55:30 +0530 Subject: [PATCH] docs: preserve coturn/TURN setup notes (rescued from the removed prod-fix worktree) --- docs/coturn-and-env.md | 87 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 docs/coturn-and-env.md diff --git a/docs/coturn-and-env.md b/docs/coturn-and-env.md new file mode 100644 index 0000000..b597d5e --- /dev/null +++ b/docs/coturn-and-env.md @@ -0,0 +1,87 @@ +# coturn + app config for TURN (remote.bizgaze.com) + +Status: self-hosted **coturn** is working on **UDP 3478** (verified — a `relay` +candidate was returned by the Trickle ICE test). This doc adds **TCP 3478** and +optional **TLS 5349** for wider firewall coverage, and points the BizGaze Connect +app at coturn. + +TURN makes the WebRTC *connection* work across cellular / strict NATs. It does NOT +let a phone share its screen in a browser — that is a separate platform limitation. + +--- + +## 1. coturn — turnserver.conf + +Verify the first block (already working) and ADD the TLS block. + +```conf +# --- core (already working on UDP 3478) --- +listening-port=3478 # serves BOTH UDP and TCP on 3478 +fingerprint +lt-cred-mech +realm=remote.bizgaze.com +external-ip=118.95.33.89 # coturn server's PUBLIC ip (from the relay result) +user=USERNAME:PASSWORD # the TURN username:password + +# --- ADD: TLS on 5349 (turns:) --- +tls-listening-port=5349 +cert=/etc/letsencrypt/live/remote.bizgaze.com/fullchain.pem +pkey=/etc/letsencrypt/live/remote.bizgaze.com/privkey.pem + +# --- relay media port range (must be open in the firewall) --- +min-port=49152 +max-port=65535 +``` + +Notes: +- TLS needs a cert for `remote.bizgaze.com`. Nginx Proxy Manager already issues a + Let's Encrypt cert for that host — point coturn at those `fullchain.pem` / + `privkey.pem` (copy or mount them so coturn can read them). +- TCP 3478 alone already widens coverage a lot; TLS/5349 can be added later. + +Restart coturn after editing: +``` +systemctl restart coturn # or: restart the coturn container +``` + +--- + +## 2. Firewall / cloud security group — open these ports +- UDP 3478 (already open — relay works) +- TCP 3478 <- add +- TCP 5349 <- add (only if doing TLS) +- UDP 49152-65535 (relay media range; should already be open) + +--- + +## 3. App .env (next to docker-compose.yml) + +Point BizGaze Connect at coturn. Without TLS yet: +```env +TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp +TURN_USERNAME=your-coturn-username +TURN_CREDENTIAL=your-coturn-password +``` + +After TLS (5349) is confirmed working, use: +```env +TURN_URLS=turn:remote.bizgaze.com:3478,turn:remote.bizgaze.com:3478?transport=tcp,turns:remote.bizgaze.com:5349?transport=tcp +TURN_USERNAME=your-coturn-username +TURN_CREDENTIAL=your-coturn-password +``` + +Reload the app: +``` +docker compose up -d +``` + +--- + +## 4. Verify +1. Open `https://remote.bizgaze.com/api/ice` — should show the + `remote.bizgaze.com` TURN entry with the username. + (The app only *sends* TURN to mobile clients by design, but /api/ice still lists it.) +2. Trickle ICE test (https://webrtc.github.io/samples/src/content/peerconnection/trickle-ice/): + - Add `turn:remote.bizgaze.com:3478?transport=tcp` + username + credential → expect a `relay` row. + - If TLS is set up, also test `turns:remote.bizgaze.com:5349?transport=tcp`. + A `relay` candidate = success. No relay row = TURN not reachable on that transport.