6 ms·
Show HN: An Almost Free, Open Source TURN Server
Hi HN,
I have been messing around with WebRTC for a few years now but when it comes to the TURN server I never quite got to my gold standard of free, self-hosted and open source. I decided to give it a go using Oracle Cloud Infrastructure's free tier, meaning that my total spend got down to domain name hosting. I know plenty of people have been burnt by Oracle in the past, but I have had servers running on the free tier for 5 years now without so much as a hiccup. Regardless, the concepts will be the same using any cloud based server.
This is the first time I've written up an end-to-end technical how-to like this and the audience I am writing for is really myself - I know just enough about networks and web dev and Linux, etc to get all this running and there are plenty of snippets out there on the web that tell you how to do one thing or another, but nowhere that puts it all together in one place so if I'm explaining what is obvious to you, my apologies - like I say, I'm writing to myself here.
I don't know that this even is a Show HN - @dang, if it isn't, please feel free to recategorise/edit the title.
@Everybody else, I am happy to answer questions if I can but please bear in mind that I am not claiming to be an expert on any of the tech gathered together to make this work.
- ggm 2y ago99% of this does not depend on Oracle, you can do this on any vm hosting platform you can get. The only point of using Oracle is the price point which will vanish as soon as they can cease using it to build market share. Good to show btw. Nice instructions. They're mostly platform neutral. It might be a different interface to manage on another host of course but the outcome would be much the same.
- cookie_monsta 2y agoThanks, and you're exactly right - the Oracle bit is probably the most basic, interchangeable part of the whole stack. The tricky bit there for me was all the ports/firewall configuration which like you say will be the same/very similar anywhere. For hobby projects like this I have had no complaints with OCI but yeah, you would have to be crazy to use it in production.
- Uptrenda 2y agoRespect++ for what you said about Peerjs. I used those servers myself for testing when I wrote my own TURN client and always felt a little bad about it. But it saved me tons of time before setting up my own. Now I have my own server (though not as well setup as yours -- your guide is good.) This is a valuable contribution. IMO, the Internet needs more STUN, TURN, and MQTT servers. It's even more valuable if they support as many protocols as possible and have IPv4 / IPv6. For STUN -- running it with two IPs means it can support bind requests which is necessary for testing NAT types.
- cookie_monsta 2y agoOh, thanks that's very kind of you to say. PeerJS is great - it takes a lot of the complexity out of WebRTC and replaces it with a nice, clean API. I think it was an OK decision for them to use Google for their TURN server - really, the best use case for their cloud server is exactly as you described - get your PoC working, and then if you're serious, implement your own
- keepamovin 2y agoThis how to is extremely comprehensive and well written. You have a knack for writing technical tutorials and documentation that are accessible, clear and simple. Well done! Good prose, clearly not written by AI - respect!
- cookie_monsta 2y agoCheers :) I trained and worked as a writer in my previous career, so it's nice to know that at least some of those chops remain. Like every other writer on the planet, I've tried AI for generating some base text that I could then tweak, but I find myself spending so much time rewriting that it's quicker just to do it from scratch...
- Sean-Der 2y agoGreat write up! It isn’t free, but the price/what it offers is really great with Hetzner. I switched from digital ocean. Did you evaluate any other TURN servers? I’m curious about your thoughts of the Elixir and Go ones. Maybe even more exist, I haven’t looked recently
- cookie_monsta 2y agooh, no - I am far too lazy to "shop around" for TURN servers and coturn just works and ticks all the open source boxes for me - lots of contributors, recent commits, lots of stars and forks (although these last two aren't as important as the first)
- import 2y agoHow to doc recommends using Oracle Free Tier but they recently had a breach and leaked login server data https://www.bleepingcomputer.com/news/security/oracle-customers-confirm-data-stolen-in-alleged-cloud-breach-is-valid/ https://www.bleepingcomputer.com/news/security/oracle-custom...
- ranger_danger 2y agoThe problem I see with TURN is there's basically no way to prevent people from abusing it publicly for relaying any traffic they want, without any of your own web sites or WebRTC apps involved.
- cookie_monsta 2y agoBasic authentication is covered in Section 11[0] There are more thoughts on tightening up authentication in the last section "Tightening and tidying" Apologies if I have misunderstood your comment [0]https://github.com/lvidgen/WebRTC/blob/master/FOSS_TURN_Server/howto.md#11-add-some-authentication https://github.com/lvidgen/WebRTC/blob/master/FOSS_TURN_Serv...
- ranger_danger 2y agoAuthentication still requires the client to have access to the password, where you can just take it and use it for any other purpose. Unless you're asking every user to manually input a TURN password and they promise not to give it out, you're basically forced to reveal it to every visitor of your site.
- cookie_monsta 2y agoyes, but you can block cross origin requests to both the credentials server and the PeerJS server which I understand prevents this: "relaying any traffic they want, without any of your own web sites or WebRTC apps involved" Again, not an expert. This problem only really exists for "ad-hoc" connections where you don't want people to have to set up accounts. coturn has the ability to do standard authentication by checking credentials stored in databases
- mtud 2y agoYou can generate short-lived and single-use credentials for users.
- ranger_danger 2y ago
- markisus 2y agoThis has got me reading about TURN and it just seems like a huge ugly hack. Two computers want to send UDP to each other. They are electrically connected by sets of physical cables. They could even be down the street from each other. But they don’t know how to get their routers to set the right bits in their translation tables. Instead it’s just easier to send all their traffic through a third computer in another city thousands of miles away or maybe into outer space and back. Have I got it right?
- XorNot 2y agoYep. But this is what IPv6 was supposed to solve.
- markisus 2y agoI don’t know much about IPv6 but it seems like even if we are stuck with IPv4 we could still make some sort of protocol where my computer could manipulate the NAT table entries allocated to it. Maybe something like DHCP but it deals with ports.
- mindcrime 2y agoIsn't something like that what UPnP / zeroconf is supposed to do[1][2]? [1]: https://en.wikipedia.org/wiki/Universal_Plug_and_Play https://en.wikipedia.org/wiki/Universal_Plug_and_Play [2]: https://en.wikipedia.org/wiki/Zero-configuration_networking https://en.wikipedia.org/wiki/Zero-configuration_networking
- markisus 2y agoVery interesting. I even found some protocols that exactly implement the functionality I was thinking of! https://en.wikipedia.org/wiki/Internet_Gateway_Device_Protocol https://en.wikipedia.org/wiki/Internet_Gateway_Device_Protoc... https://en.wikipedia.org/wiki/Port_Control_Protocol https://en.wikipedia.org/wiki/Port_Control_Protocol
- alwayslikethis 2y ago
- BiteCode_dev 2y agoCan't we have TURN over something like bittorrent or ifps so that it's decentralized ?
- deeth_starr_v 2y agoDoesn't bittorrent have the tracker that is acting as the glue to connect to peers?
- nurettin 2y agoIf I was tasked to get this up and running, I would probably start with porting the entire thing to postgres.
- nubinetwork 2y agoI'm not paying oracle for cloud services, I learned my lesson the hard way, they're still emailing me about random cloud stuff despite me telling them to stop contacting me.
- miki123211 2y ago> Additionally, some people have privacy concerns about running their data through anything associated with the big G. It's important to point out that Web RTC is E2E encrypted, so Google never actually sees your data. As long as the server you use for signaling is secure, your TURN server may as well be run by the NSA. Since initial signaling is extremely low-bandwidth compared to the actual call, it's usually fine to handle it in your application directly. THe actual problem with WebRTC is that, in its default setup, every call participant leaks their IP address to everybody else, and you need to upload your data n-1 times for n call participants, making it almost unusable on slow connections. You can mitigate both of these problems with an SFU, essentially a central server that takes in streams from all clients and distributes them further, but then you lose the E2E.
- telesilla 2y agoLook at Stunner as a Kubernetes friendly alternative to coturn. https://github.com/l7mp/stunner https://github.com/l7mp/stunner For those of you needing turn services without wanting to host, I can highly recommended Xirsys. Excellent service and while pricing is more than Cloudflare you get better network quality. If you prefer Cloudflare, unless you are using GBs a day you'll most likely have a $0 monthly bill which makes it an excellent choice for small projects and testing.
- deleted 2y ago[deleted]
- j45 2y agoThis codebase seems to be a little old - does anyone have it running as is, or close to as is?