Skip to content

Run a TURN/STUN relay for DUB - #38

Merged
mordamax merged 10 commits into
mainfrom
turn-relay
Sep 28, 2026
Merged

mordamax merged 10 commits into
mainfrom
turn-relay

Conversation

@mordamax

Copy link
Copy Markdown
Collaborator

DUB's turn-api minted TURN credentials with nothing to relay them and an empty server list. This runs eturnal next to DUB and wires the two together, so p2p clients get working STUN/TURN servers from POST /api/v1/turn/issue.

  • New turn process: eturnal from eturnal.net on Linux, from the processone Homebrew tap on macOS
  • DUB gets TURN_SECRET and ICE_SERVERS from the same code that configures eturnal. A deployment must set its own TURN_SECRET (base64 of a printable string)
  • /api/network and the dashboard list the ICE servers, with a STUN health probe
  • ppn nginx-conf emits a TLS stream for turns: at a new {{GENERATED_STREAMS}} marker, so the deploy template needs that marker in its stream {} block
  • 11-turn.zndsl checks STUN, credential issuance and an authenticated Allocate against the relay

Details in docs/TURN.md

@mordamax
mordamax marked this pull request as ready for review September 24, 2026 22:56

@bee344 bee344 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mordamax
mordamax merged commit 79bf6a7 into main Sep 28, 2026
15 checks passed
@mordamax
mordamax deleted the turn-relay branch September 28, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants