User Tools

Site Tools


computing:hpb-talk

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
computing:hpb-talk [2026/10/10 00:53] – oemb1905computing:hpb-talk [2026/10/10 05:21] (current) – oemb1905
Line 1: Line 1:
 +-------------------------------------------
  
 +  * **talk-hpb**
 +  * **Jonathan Haack**
 +  * **Haack's Networking**
 +  * **webmaster@haacksnetworking.org**
  
 +-------------------------------------------
  
 +//Talk HPB//
  
-# Nextcloud Talk HPB (aio-talk) — Rootless Podman Quadlet+------------------------------------------- 
 +~~NOTOC~~
  
-Rootless Podman as user `worker` on host `support`. Apache + Let's Encrypt run as `root`. Signaling is bound to localhost only. TURN is public.+==== Introduction ====
  
-| Role | Bind | Public | +This tutorial is for Debian users who want or need to spin up a high performance back-end for Nextcloud Talk. This helps with multi-user calls and/or nasty NAT situations. Here's the layout:
-| --- | --- | --- | +
-| Signaling | `127.0.0.1:8088` → container `8081` | `https://talk.haacksnetworking.org` (Apache) | +
-| TURN | `0.0.0.0:3478/tcp` + `3478/udp` | `talk.haacksnetworking.org:3478` |+
  
-Image: `ghcr.io/nextcloud-releases/aio-talk:latest`   +^ Role ^ Bind ^ Public ^ 
-One container: signaling + NATS + Janus + eturnal.   +| Signaling | ''127.0.0.1:8088'' → container ''8081'' | ''https://talk.haacksnetworking.org'' (Apache) | 
-The image rewrites `/conf/signaling.conf` on every start from `NC_DOMAIN` only. Extra Nextcloud backends must be re-added after every start. Do not mount `/conf`.+| TURN | ''0.0.0.0:3478/tcp'' + ''3478/udp'' | ''talk.haacksnetworking.org:3478'' |
  
-Do not use `podman generate systemd`. Units come from Quadlet files in `~/.config/containers/systemd/`.+We will use the following image:
  
----+  * Image: ''ghcr.io/nextcloud-releases/aio-talk:latest''  
  
-## 0. Host firewall (root)+This image is basically signaling, NATS, Janus, and eturnal. Let's make sure the host is setup properly.
  
-`3478/tcp` and `3478/udp` must be reachable from clients. Signaling stays on localhost.+==== 0. Host firewall (root) ====
  
-```bash+We need to open turn on udp 3478 and its fallback, tcp 3478. This helps clients behind nasty NAT. The signaling stays on localhost. Let's open the ports: 
 + 
 +<code>
 ufw allow 3478/tcp ufw allow 3478/tcp
 ufw allow 3478/udp ufw allow 3478/udp
-```+</code>
  
-DNS: `talk.haacksnetworking.org` A/AAAA → this host. +==== 1. Directories and secrets (worker) ==== 
- +<code>
---- +
- +
-## 1. Directories and secrets (worker) +
- +
-```bash+
 mkdir -p ~/talk-hpb mkdir -p ~/talk-hpb
 umask 077 umask 077
Line 41: Line 43:
 openssl rand -hex 32 > ~/talk-hpb/turn.secret openssl rand -hex 32 > ~/talk-hpb/turn.secret
 openssl rand -hex 32 > ~/talk-hpb/internal.secret openssl rand -hex 32 > ~/talk-hpb/internal.secret
-``` +</code>
- +
-Do not rotate these after Nextcloud has them. Update every Nextcloud that uses them if you do. +
- +
-Placeholders used below: +
- +
-``` +
-SIGNALING_SECRET=replace-with-your-signaling-secret +
-TURN_SECRET=replace-with-your-turn-secret +
-INTERNAL_SECRET=replace-with-your-internal-secret +
-``` +
- +
----+
  
-## 2. Quadlet+Keep these stable for yearly or longer rotations. No need to rotate if no compromise is suspected, etc., and usage is tightly monitored and restricted.
  
-File: `~/.config/containers/systemd/container-talk-hpb.container`+==== 2. Quadlet ====
  
-```bash +Create the quadlet for monitoring and starting/stopping the service as the ''worker'' user ''nano ~/.config/containers/systemd/container-talk-hpb.container''
-systemctl --user disable --now container-talk-hpb.service 2>/dev/null || true +
-rm -f ~/.config/systemd/user/container-talk-hpb.service +
-podman rm -f talk-hpb+
  
 +<code>
 mkdir -p ~/.config/containers/systemd mkdir -p ~/.config/containers/systemd
 cat > ~/.config/containers/systemd/container-talk-hpb.container << 'EOF' cat > ~/.config/containers/systemd/container-talk-hpb.container << 'EOF'
Line 92: Line 80:
 systemctl --user start container-talk-hpb.service systemctl --user start container-talk-hpb.service
 sleep 25 sleep 25
-```+</code>
  
-`WantedBy=default.target` starts it. Do not `systemctl enable` a Quadlet unit. Do not `podman generate systemd`.+==== 3. Extra Nextcloud backends (after every start) ====
  
----+The HPB container can only be built with one endpoint when it is updated, so the following is needed to add xx amount of endpoints to use the HPB with:
  
-## 3. Extra Nextcloud backends (after every start) +<code>
- +
-`start.sh` writes only `backend-1` = `NC_DOMAIN`. For the other three hosts, patch the running file and reload signaling. Do not `podman restart` after the patch. A restart rewrites the file and drops the extra backends. +
- +
-```bash+
 podman exec talk-hpb sh -c ' podman exec talk-hpb sh -c '
 printf "\n[backend-2]\nurls = https://cloud.gnulinux.vip\nsecret = replace-with-your-signaling-secret\nmaxstreambitrate = 1048576\nmaxscreenbitrate = 2097152\n" >> /conf/signaling.conf printf "\n[backend-2]\nurls = https://cloud.gnulinux.vip\nsecret = replace-with-your-signaling-secret\nmaxstreambitrate = 1048576\nmaxscreenbitrate = 2097152\n" >> /conf/signaling.conf
Line 111: Line 95:
 podman exec talk-hpb sh -c 'kill $(ps | awk "/nextcloud-spreed-signaling|[s]ignaling/{print \$1; exit}")' podman exec talk-hpb sh -c 'kill $(ps | awk "/nextcloud-spreed-signaling|[s]ignaling/{print \$1; exit}")'
 podman exec talk-hpb grep -A5 '^\[backend' /conf/signaling.conf podman exec talk-hpb grep -A5 '^\[backend' /conf/signaling.conf
-```+</code>
  
-Expected:+When you run this, you get something like:
  
-```+<code>
 [backend] [backend]
 backends = backend-1, backend-2, backend-3, backend-4 backends = backend-1, backend-2, backend-3, backend-4
Line 130: Line 114:
 [backend-4] [backend-4]
 urls = https://cloud.friend.info urls = https://cloud.friend.info
-```+</code>
  
----+==== 4. Verify ====
  
-## 4. Verify+Once your back-ends are all specified, let's verify the service is healthy and the api endpoint is reachable:
  
-```bash+<code>
 systemctl --user is-active container-talk-hpb.service systemctl --user is-active container-talk-hpb.service
 podman inspect talk-hpb --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}' podman inspect talk-hpb --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
 curl -sI http://127.0.0.1:8088/standalone-signaling/api/v1/welcome curl -sI http://127.0.0.1:8088/standalone-signaling/api/v1/welcome
-```+</code>
  
-Expect `active`, `cpus=2000000000`, `memory=4294967296`, and an HTTP response from the welcome endpoint. The image has its own `HEALTHCHECK`. Podman Desktop shows that status. The other containers do not, because their images do not define one.+We should see something like ''active'', ''cpus=2000000000'', ''memory=4294967296'', and an HTTP response from the welcome endpoint. 
  
----+==== 5. Upgrade script ====
  
-## 5. Upgrade script+Let's create an upgrade script at ''nano /usr/local/bin/upgrade-high-performance.sh''. Inside it, let's put something like this:
  
-`/usr/local/bin/upgrade-high-performance.sh`. A tag change is an edit to `Image=` in the `.container` file before `daemon-reload`. The script does not recreate the unit. +<code>
- +
-```bash+
 #!/bin/bash #!/bin/bash
 set -euo pipefail set -euo pipefail
 +export XDG_RUNTIME_DIR=/run/user/$(id -u)
 +export DBUS_SESSION_BUS_ADDRESS=unix:path=${XDG_RUNTIME_DIR}/bus
  
 podman pull ghcr.io/nextcloud-releases/aio-talk:latest podman pull ghcr.io/nextcloud-releases/aio-talk:latest
Line 172: Line 156:
  
 curl -sI http://127.0.0.1:8088/standalone-signaling/api/v1/welcome curl -sI http://127.0.0.1:8088/standalone-signaling/api/v1/welcome
-```+</code>
  
-Run it as `worker`:+If your curl output is unhealthy, stop and debug before proceeding.
  
-```bash +==== 6. Apache reverse proxy (root) ====
-su - worker -c '/bin/bash /usr/local/bin/upgrade-high-performance.sh' +
-```+
  
-Do not `sudo -u worker`. That drops the session bus.+We can now setup our reverse proxy and associated virtual hosts and Let's Encrypt cert:
  
----+<code> 
 +sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host 
 +sudo certbot certonly --apache -d talk.haacksnetworking.org 
 +</code>
  
-## 6. Apache reverse proxy (root)+Inside ''nano /etc/apache2/sites-available/talk.haacksnetworking.org.conf'' let's put something like:
  
-```bash +<code>
-a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl +
-``` +
- +
-`/etc/apache2/sites-available/talk.haacksnetworking.org.conf`: +
- +
-```apache+
 <VirtualHost *:80> <VirtualHost *:80>
     ServerName talk.haacksnetworking.org     ServerName talk.haacksnetworking.org
Line 198: Line 177:
     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
 </VirtualHost> </VirtualHost>
 +</code>
 +
 +And, inside the TLS virtual host, ''nano /etc/apache2/sites-available/talk.haacksnetworking.org-ssl.conf'' let's drop something like:
  
 +<code>
 <VirtualHost *:443> <VirtualHost *:443>
     ServerName talk.haacksnetworking.org     ServerName talk.haacksnetworking.org
     ServerAdmin support@haacksnetworking.org     ServerAdmin support@haacksnetworking.org
     SSLEngine on     SSLEngine on
-    SSLCertificateFile      /etc/letsencrypt/live/talk.haacksnetworking.org/fullchain.pem +    SSLCertificateFile /etc/letsencrypt/live/talk.haacksnetworking.org/fullchain.pem 
-    SSLCertificateKeyFile   /etc/letsencrypt/live/talk.haacksnetworking.org/privkey.pem+    SSLCertificateKeyFile /etc/letsencrypt/live/talk.haacksnetworking.org/privkey.pem
     Include /etc/letsencrypt/options-ssl-apache.conf     Include /etc/letsencrypt/options-ssl-apache.conf
     ProxyPreserveHost On     ProxyPreserveHost On
Line 213: Line 196:
     RewriteCond %{HTTP:Connection} upgrade [NC]     RewriteCond %{HTTP:Connection} upgrade [NC]
     RewriteRule ^/?(.*) ws://127.0.0.1:8088/$1 [P,L]     RewriteRule ^/?(.*) ws://127.0.0.1:8088/$1 [P,L]
-    ProxyPass        / http://127.0.0.1:8088/+    ProxyPass / http://127.0.0.1:8088/
     ProxyPassReverse / http://127.0.0.1:8088/     ProxyPassReverse / http://127.0.0.1:8088/
-    ErrorLog  ${APACHE_LOG_DIR}/talk.haacksnetworking.org-error.log+    ErrorLog ${APACHE_LOG_DIR}/talk.haacksnetworking.org-error.log
     CustomLog ${APACHE_LOG_DIR}/talk.haacksnetworking.org-access.log combined     CustomLog ${APACHE_LOG_DIR}/talk.haacksnetworking.org-access.log combined
 </VirtualHost> </VirtualHost>
-```+</code>
  
-```bash+Once the virtual hosts are built, let's enable it, check the config, and then check the endpoint.  
 + 
 +<code>
 a2ensite talk.haacksnetworking.org.conf a2ensite talk.haacksnetworking.org.conf
 apache2ctl configtest && systemctl reload apache2 apache2ctl configtest && systemctl reload apache2
 curl -sI http://talk.haacksnetworking.org/ curl -sI http://talk.haacksnetworking.org/
 curl -sI https://talk.haacksnetworking.org/ curl -sI https://talk.haacksnetworking.org/
-``` +</code>
- +
-Clients use `wss://talk.haacksnetworking.org/spreed`.+
  
----+Check your output and make sure everything is accessible and running. If not, debug until it works. FYI, the endpoint for clients is ''wss://talk.haacksnetworking.org/spreed''. More updates if/when rebuilds are done will be posted. Reach out on Matrix if you have questions. 
  
  
 + --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 05:16//
computing/hpb-talk.1791593594.txt.gz · Last modified: by oemb1905