Run a TURN/STUN relay for DUB - #38
Merged
Merged
Conversation
mordamax
marked this pull request as ready for review
September 24, 2026 22:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DUB's turn-api minted TURN credentials with nothing to relay them and an empty server list. This runs eturnal next to DUB and wires the two together, so p2p clients get working STUN/TURN servers from
POST /api/v1/turn/issue.turnprocess: eturnal from eturnal.net on Linux, from the processone Homebrew tap on macOSTURN_SECRETandICE_SERVERSfrom the same code that configures eturnal. A deployment must set its ownTURN_SECRET(base64 of a printable string)/api/networkand the dashboard list the ICE servers, with a STUN health probeppn nginx-confemits a TLS stream forturns:at a new{{GENERATED_STREAMS}}marker, so the deploy template needs that marker in itsstream {}block11-turn.zndslchecks STUN, credential issuance and an authenticated Allocate against the relayDetails in
docs/TURN.md