110021726b978b53e1598bd479ce4e88c91f01cf
WebRTC Outpost
Configuration repository for a Coturn relay that supports a Stoat deployment on GCP. The stack provisions a relay-main Ubuntu 24.04 instance, hardens the host with nftables, fail2ban, and unattended-upgrades, then deploys Coturn plus a Coraza-enabled Caddy reverse proxy with Podman Compose.
Repository Layout
tofu/: OpenTofu infrastructure for the static IP, VM, and GCP firewall rule.ansible/: Host preparation and hardening for Ubuntu 24.04.compose/: Runtime configuration for Coturn and Caddy.docker/: Custom images for Coturn and Caddy..github/workflows/: CI workflows for building images and deploying the stack.
Required GitHub Secrets
R2_ACCESS_KEY_IDR2_SECRET_ACCESS_KEYCLOUDFLARE_ACCOUNT_IDGCP_SA_KEYSSH_PRIVATE_KEYTURN_SHARED_SECRET
Recommended GitHub Variables
GCP_PROJECTGCP_REGIONGCP_ZONETURN_REALMCADDY_DOMAINCADDY_EMAILSTOAT_UPSTREAMTURN_TLS_CERT_FILETURN_TLS_KEY_FILE
Notes
- The OpenTofu S3 backend is configured at deploy time so the Cloudflare R2 endpoint does not need to be committed to the repository.
- The Google provider reads service account credentials from the standard
GOOGLE_APPLICATION_CREDENTIALSshell environment variable. Set it to the JSON key file path for localtofuruns. - The custom Coturn image renders runtime settings from environment variables before starting
turnserver. TURN_TLS_CERT_FILEandTURN_TLS_KEY_FILEare optional. If they are omitted, Coturn starts on3478only and skips the5349TLS listener.- The Ansible playbook lowers
net.ipv4.ip_unprivileged_port_startto80so a rootless Podman-managed Caddy container can bind to80and443.
Local OpenTofu Usage
Export the Google credentials path and required OpenTofu variables before running tofu locally:
export GOOGLE_APPLICATION_CREDENTIALS="secret-path"
export TF_VAR_gcp_project="your-gcp-project"
export TF_VAR_gcp_region="us-west1"
export TF_VAR_gcp_zone="us-west1-b"
cd tofu
tofu init
tofu apply
network_name defaults to default, instance_name defaults to relay-main, and admin_ssh_public_key is optional unless you want SSH access provisioned on the VM.
Languages
HCL
46.2%
Shell
34%
Jinja
13.9%
Dockerfile
5.9%