This a TURN server for WebRTC applications, built using the Pion TURN toolkit.
Repository: https://github.com/AgustinSRG/turn-server
You can configure the server using environment variables.
| Variable | Description |
|---|---|
REALM | Realm for the TURN server. Set your domain. Example: example.com |
PUBLIC_IP | External IP address of the server. If you leave it blank, it will try to auto detect it. |
| Variable | Description |
|---|---|
MIN_RELAY_PORT | Start of the RTP relay port range. Default: 50000 |
MAX_RELAY_PORT | End of the RTP relay port range. Default: 55000 |
Note: The ports must be opened through the firewall under the UDP protocol.
| Variable | Description |
|---|---|
USERS | List of users and passwords separated by commas. The user and the password must be separated by a colon (:). |
AUTH_SECRET | Secret to validate authentication tokens. Leave empty to disable auth tokens. Check the authentication tokens documentation. |
AUTH_CALLBACK_URL | URL of the authorization callback. Leave empty to disable it. Check the authentication callback documentation |
AUTH_CALLBACK_AUTHORIZATION | Value for the Authorization header when calling the authorization callback. |
| Variable | Description |
|---|---|
UDP_ENABLED | Can be YES or NO. Set it to YES in order to enable the UDP listener. |
UDP_PORT | The port number for the UDP listener (3478 by default) |
UDP_BIND_ADDRESS | The bind address UDP listener (Leave empty to listen on all network interfaces) |
| Variable | Description |
|---|---|
TCP_ENABLED | Can be YES or NO. Set it to YES in order to enable the TCP listener. |
TCP_PORT | The port number for the TCP listener (3478 by default) |
TCP_BIND_ADDRESS | The bind address TCP listener (Leave empty to listen on all network interfaces) |
| Variable | Description |
|---|---|
TLS_ENABLED | Can be YES or NO. Set it to YES in order to enable the TLS listener. |
TLS_PORT | The port number for the TLS listener (5349 by default) |
TLS_BIND_ADDRESS | The bind address TLS listener (Leave empty to listen on all network interfaces) |
TLS_CERTIFICATE | Path to the X.509 certificate for TLS |
TLS_PRIVATE_KEY | Path to the private key for TLS |
TLS_CHECK_RELOAD_SECONDS | Number of seconds to check for changes in the certificate or key (for auto renewal) |
| Variable | Description |
|---|---|
LOG_ERROR | Can be YES or NO. Default: YES. Set it to YES in order to enable logging ERROR messages |
LOG_WARNING | Can be YES or NO. Default: YES. Set it to YES in order to enable logging WARNING messages |
LOG_INFO | Can be YES or NO. Default: YES. Set it to YES in order to enable logging INFO messages |
LOG_DEBUG | Can be YES or NO. Default: NO. Set it to YES in order to enable logging DEBUG messages |
LOG_TRACE | Can be YES or NO. Default: NO. Set it to YES in order to enable logging TRACE messages |
In order to control the TURN server authentication with dynamic users, the following authentication token system is available:
username must follow the pattern: turn/{TIMESTAMP}/{EXPIRATION}/{UID}. The TIMESTAMP must be the token generation timestamp, in UNIX time (Seconds). The EXPIRATION must be the expiration timestamp, also in UNIX time (Seconds). The UID can be any string. It will be sent to the callback if configured.password must be the SHA-256 (SHA-2) of the UTF-8 bytes of the concatenation of the username and the secret (value of AUTH_SECRET), converted into hexadecimal and lowercased.The application using the TURN server can generate these tokens as credentials for their users, controlling the duration of such credentials.
Here is an example in Go of the procedure of generation of the password:
import (
"crypto/sha256"
"encoding/hex"
"strings"
)
// Generates an authentication token, to be used
// as the password for the given username
//
// Parameters:
// - username - The username
// - secret - The secret shared between the TURN server and the application server
//
// Returns the password as string
func GenerateAuthPassword(username string, secret string) string {
h := sha256.New()
h.Write([]byte(username))
h.Write([]byte(secret))
return strings.ToLower(hex.EncodeToString(h.Sum(nil)))
}
In order for your application to get a more fine-grained control of authentication, you can configure and URL for the TURN server in order to check for access.
Note: Authentication tokens must be used in order to also use the callback.
The procedure is the following:
GET request to the URL provided by AUTH_CALLBACK_URL.uid = The UID part of the usernameip = The client IP addressAUTH_CALLBACK_AUTHORIZATION will be sent as the Authorization header, in order for the application to restrict access to the callback, so only the TURN server can use it.200, the authentication request is considered as failed, and the user will be denied of access to the TURN server.200, the authentication process will continue, using a generated password as described in the authentication tokens section.In order to use the TURN server in the browser, you can use the server by setting the URL, username and credential in the iceServers section of the RTCPeerConnection constructor options.
const TURN_SERVER_HOST = "localhost";
const iceConfiguration = {
iceServers: [
{
urls: [
// Add the TURN server URLs for all the available transports
"turn:" + TURN_SERVER_HOST + ":3478", // UDP
"turn:" + TURN_SERVER_HOST + ":3478?transport=tcp", // TCP
"turns:" + TURN_SERVER_HOST + ":5349?transport=tcp", // TLS
],
// Use the credentials for the server
username: "user",
credential: "password",
},
],
};
Content type
Image
Digest
sha256:71a8db67d…
Size
8.7 MB
Last updated
over 1 year ago
docker pull asanrom/turn-server