diff options
author | Quentin Dufour <quentin@deuxfleurs.fr> | 2022-08-25 01:02:16 +0200 |
---|---|---|
committer | Quentin Dufour <quentin@deuxfleurs.fr> | 2022-08-25 01:02:16 +0200 |
commit | e37c1f9057ed986ac50b86463a4dbe6bf5d77f02 (patch) | |
tree | 5f5757bde3cf8a694a70bd11afdcdf9b87806db8 /cluster/prod/app/matrix/config/coturn | |
parent | 3be2659aa19abfb7e676d33e9e7e1357c790a383 (diff) | |
download | nixcfg-e37c1f9057ed986ac50b86463a4dbe6bf5d77f02.tar.gz nixcfg-e37c1f9057ed986ac50b86463a4dbe6bf5d77f02.zip |
Deploy Matrix
Diffstat (limited to 'cluster/prod/app/matrix/config/coturn')
-rw-r--r-- | cluster/prod/app/matrix/config/coturn/turnserver.conf.tpl | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/cluster/prod/app/matrix/config/coturn/turnserver.conf.tpl b/cluster/prod/app/matrix/config/coturn/turnserver.conf.tpl new file mode 100644 index 0000000..f867ac0 --- /dev/null +++ b/cluster/prod/app/matrix/config/coturn/turnserver.conf.tpl @@ -0,0 +1,19 @@ +use-auth-secret +static-auth-secret={{ key "secrets/chat/coturn/static-auth" | trimSpace }} +realm=turn.deuxfleurs.fr + +# VoIP traffic is all UDP. There is no reason to let users connect to arbitrary TCP endpoints via the relay. +#no-tcp-relay + +# don't let the relay ever try to connect to private IP address ranges within your network (if any) +# given the turn server is likely behind your firewall, remember to include any privileged public IPs too. +#denied-peer-ip=10.0.0.0-10.255.255.255 +#denied-peer-ip=192.168.0.0-192.168.255.255 +#denied-peer-ip=172.16.0.0-172.31.255.255 + +# consider whether you want to limit the quota of relayed streams per user (or total) to avoid risk of DoS. +user-quota=12 # 4 streams per video call, so 12 streams = 3 simultaneous relayed calls per user. +total-quota=1200 + +min-port=49152 +max-port=49252 |