services: add tls for coturn

This commit is contained in:
Kabbone 2022-12-18 19:09:48 +01:00
parent 584bdd0df0
commit 46bb780395
Signed by: Kabbone
SSH Key Fingerprint: SHA256:A5zPB5I6u5V78V51c362BBdCwhDhfDUVbt7NfKdjWBY
2 changed files with 7 additions and 6 deletions

View File

@ -62,14 +62,14 @@
group = "turnserver"; group = "turnserver";
}; };
# configure synapse to point users to coturn # configure synapse to point users to coturn
services.matrix-synapse = with config.services.coturn; { # services.matrix-synapse = with config.services.coturn; {
turn_uris = ["turn:${realm}:3478?transport=udp" "turn:${realm}:3478?transport=tcp"]; # turn_uris = ["turn:${realm}:3478?transport=udp" "turn:${realm}:3478?transport=tcp"];
turn_shared_secret = static-auth-secret; # turn_shared_secret = static-auth-secret;
turn_user_lifetime = "1h"; # turn_user_lifetime = "1h";
}; # };
age.secrets."services/coturn/static-auth" = { age.secrets."services/coturn/static-auth" = {
file = ../../../secrets/services/coturn/static-auth.age; file = ../../../secrets/services/coturn/static-auth.age;
owner = "turnserver"; owner = "turnserver";
} };
} }

View File

@ -17,5 +17,6 @@
services.jitsi-videobridge.openFirewall = true; services.jitsi-videobridge.openFirewall = true;
security.acme.defaults.email = "webmaster@kabtop.de"; security.acme.defaults.email = "webmaster@kabtop.de";
security.acme.defaults.webroot = "/var/lib/acme/acme-challenge";
security.acme.acceptTerms = true; security.acme.acceptTerms = true;
} }