- setup.sh: interactive/non-interactive one-shot installer (build, DB healthcheck, migrate, seed, start), idempotent secret generation, NPM reverse-proxy network auto-detection and optional join, optional AUTO_UPDATE cron install. - update.sh: release-tag-gated updates only (never bare main), DB backup with retention before every update, lock file against concurrent runs, automatic code rollback on failed post-update healthcheck. - Dockerfile: multi-stage build, non-root user, built-in HEALTHCHECK against the new /api/health route, wholesale COPY so new source dirs (e.g. scripts/) never silently go missing at runtime. - docker-compose.yml: internal anouma-network (configurable), named volume for Postgres, app depends_on postgres healthy, no unnecessary published ports; docker-compose.override.yml.example documents joining an existing NPM network without ever touching NPM itself. - Fix host-detection: isHost was Boolean(user), wrongly granting host privileges to logged-in customers; now checks user.collection === "users". - Wire configurable STUN/TURN servers through to the WebRTC client (lib/meeting/iceServers.ts) so a TURN server can be added later via env vars only, no code changes. - DEPLOYMENT.md, updated README.md and .env.example documenting the whole flow: NPM integration, env vars, WebRTC, updates, backups, rollback. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
23 lines
691 B
TypeScript
23 lines
691 B
TypeScript
/**
|
|
* Builds the WebRTC ICE server list from environment variables so a TURN
|
|
* server can be added later without any code changes (see DEPLOYMENT.md).
|
|
* P2P works fine with just STUN for most networks; TURN becomes necessary
|
|
* behind restrictive NATs/firewalls.
|
|
*/
|
|
export function getIceServers(): RTCIceServer[] {
|
|
const servers: RTCIceServer[] = [
|
|
{ urls: process.env.STUN_SERVER || "stun:stun.l.google.com:19302" },
|
|
];
|
|
|
|
const turnServer = process.env.TURN_SERVER;
|
|
if (turnServer) {
|
|
servers.push({
|
|
urls: turnServer,
|
|
username: process.env.TURN_USERNAME || undefined,
|
|
credential: process.env.TURN_PASSWORD || undefined,
|
|
});
|
|
}
|
|
|
|
return servers;
|
|
}
|