|
| 1 | +#!/bin/ash |
| 2 | + |
| 3 | +# make certs if not exist |
| 4 | +if [[ ! -f /config/cert.crt || ! -f /config/cert.key ]]; then |
| 5 | + openssl req -newkey rsa:2048 -nodes -keyout /config/cert.key -x509 -days 3650 -out /config/cert.crt -subj "/C=US/ST=NY/L=NY/O=IT/CN=${TURN_HOST}" |
| 6 | +fi |
| 7 | + |
| 8 | +# use non empty TURN_PUBLIC_IP variable, othervise set it dynamically. |
| 9 | +[ -z "${TURN_PUBLIC_IP}" ] && export TURN_PUBLIC_IP=$(curl -4ks https://icanhazip.com) |
| 10 | +[ -z "${TURN_PUBLIC_IP}" ] && echo "ERROR: variable TURN_PUBLIC_IP is not set and can not be set dynamically!" && kill 1 |
| 11 | + |
| 12 | +# set coturn web-admin access |
| 13 | +if [[ "${TURN_ADMIN_ENABLE}" == "1" || "${TURN_ADMIN_ENABLE}" == "true" ]]; then |
| 14 | + turnadmin -A -u ${TURN_ADMIN_USER:-admin} -p ${TURN_ADMIN_SECRET:-changeme} |
| 15 | + export TURN_ADMIN_OPTIONS="--web-admin --web-admin-ip=$(hostname -i) --web-admin-port=${TURN_ADMIN_PORT:-8443}" |
| 16 | +fi |
| 17 | + |
| 18 | +# run coturn server with API auth method enabled. |
| 19 | +turnserver -n ${TURN_ADMIN_OPTIONS} \ |
| 20 | +--verbose \ |
| 21 | +--prod \ |
| 22 | +--no-tlsv1 \ |
| 23 | +--no-tlsv1_1 \ |
| 24 | +--log-file=stdout \ |
| 25 | +--listening-port=${TURN_PORT:-5349} \ |
| 26 | +--tls-listening-port=${TURN_PORT:-5349} \ |
| 27 | +--alt-listening-port=${TURN_PORT:-5349} \ |
| 28 | +--alt-tls-listening-port=${TURN_PORT:-5349} \ |
| 29 | +--cert=/config/cert.crt \ |
| 30 | +--pkey=/config/cert.key \ |
| 31 | +--min-port=${TURN_RTP_MIN:-10000} \ |
| 32 | +--max-port=${TURN_RTP_MAX:-11000} \ |
| 33 | +--no-stun \ |
| 34 | +--use-auth-secret \ |
| 35 | +--static-auth-secret=${TURN_SECRET:-keepthissecret} \ |
| 36 | +--no-multicast-peers \ |
| 37 | +--realm=${TURN_REALM:-realm} \ |
| 38 | +--listening-ip=$(hostname -i) \ |
| 39 | +--external-ip=${TURN_PUBLIC_IP} \ |
| 40 | +--cli-password=NotReallyCliUs3d \ |
| 41 | +--no-cli |
| 42 | + |
0 commit comments