This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computing:hpb-talk [2026/10/10 01:11] – oemb1905 | computing:hpb-talk [2026/10/10 05:21] (current) – oemb1905 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ------------------------------------------- | ------------------------------------------- | ||
| + | |||
| * **talk-hpb** | * **talk-hpb** | ||
| * **Jonathan Haack** | * **Jonathan Haack** | ||
| * **Haack' | * **Haack' | ||
| * **webmaster@haacksnetworking.org** | * **webmaster@haacksnetworking.org** | ||
| + | |||
| ------------------------------------------- | ------------------------------------------- | ||
| - | //Nextcloud | + | |
| + | //Talk HPB// | ||
| ------------------------------------------- | ------------------------------------------- | ||
| ~~NOTOC~~ | ~~NOTOC~~ | ||
| + | |||
| ==== Introduction ==== | ==== Introduction ==== | ||
| - | Rootless Podman as user '' | + | |
| + | This tutorial is for Debian users who want or need to spin up a high performance back-end for Nextcloud Talk. This helps with multi-user calls and/or nasty NAT situations. Here' | ||
| ^ Role ^ Bind ^ Public ^ | ^ Role ^ Bind ^ Public ^ | ||
| Line 15: | Line 21: | ||
| | TURN | '' | | TURN | '' | ||
| - | Image: '' | + | We will use the following image: |
| - | One container: signaling + NATS + Janus + eturnal. | + | |
| - | The image rewrites ''/ | + | |
| - | Do not use '' | + | * Image: |
| + | |||
| + | This image is basically signaling, NATS, Janus, and eturnal. Let's make sure the host is setup properly. | ||
| ==== 0. Host firewall (root) ==== | ==== 0. Host firewall (root) ==== | ||
| - | '' | + | |
| + | We need to open turn on udp 3478 and its fallback, | ||
| < | < | ||
| Line 28: | Line 35: | ||
| ufw allow 3478/udp | ufw allow 3478/udp | ||
| </ | </ | ||
| - | |||
| - | DNS: '' | ||
| ==== 1. Directories and secrets (worker) ==== | ==== 1. Directories and secrets (worker) ==== | ||
| Line 40: | Line 45: | ||
| </ | </ | ||
| - | Do not rotate | + | Keep these stable for yearly or longer rotations. No need to rotate |
| - | Placeholders used below: | + | ==== 2. Quadlet ==== |
| - | < | + | Create the quadlet for monitoring and starting/stopping the service as the '' |
| - | SIGNALING_SECRET=replace-with-your-signaling-secret | + | |
| - | TURN_SECRET=replace-with-your-turn-secret | + | |
| - | INTERNAL_SECRET=replace-with-your-internal-secret | + | |
| - | </code> | + | |
| - | + | ||
| - | ==== 2. Quadlet ==== | + | |
| - | File: '' | + | |
| < | < | ||
| - | systemctl --user disable --now container-talk-hpb.service 2>/ | ||
| - | rm -f ~/ | ||
| - | podman rm -f talk-hpb | ||
| - | |||
| mkdir -p ~/ | mkdir -p ~/ | ||
| cat > ~/ | cat > ~/ | ||
| Line 87: | Line 81: | ||
| sleep 25 | sleep 25 | ||
| </ | </ | ||
| - | |||
| - | '' | ||
| ==== 3. Extra Nextcloud backends (after every start) ==== | ==== 3. Extra Nextcloud backends (after every start) ==== | ||
| - | '' | + | |
| + | The HPB container can only be built with one endpoint when it is updated, so the following is needed to add xx amount of endpoints to use the HPB with: | ||
| < | < | ||
| Line 104: | Line 97: | ||
| </ | </ | ||
| - | Expected: | + | When you run this, you get something like: |
| < | < | ||
| Line 124: | Line 117: | ||
| ==== 4. Verify ==== | ==== 4. Verify ==== | ||
| + | |||
| + | Once your back-ends are all specified, let's verify the service is healthy and the api endpoint is reachable: | ||
| + | |||
| < | < | ||
| systemctl --user is-active container-talk-hpb.service | systemctl --user is-active container-talk-hpb.service | ||
| Line 130: | Line 126: | ||
| </ | </ | ||
| - | Expect | + | We should see something like '' |
| ==== 5. Upgrade script ==== | ==== 5. Upgrade script ==== | ||
| - | ''/ | + | |
| + | Let's create an upgrade script at '' | ||
| < | < | ||
| #!/bin/bash | #!/bin/bash | ||
| set -euo pipefail | set -euo pipefail | ||
| + | export XDG_RUNTIME_DIR=/ | ||
| + | export DBUS_SESSION_BUS_ADDRESS=unix: | ||
| podman pull ghcr.io/ | podman pull ghcr.io/ | ||
| Line 159: | Line 158: | ||
| </ | </ | ||
| - | Run it as '' | + | If your curl output is unhealthy, stop and debug before proceeding. |
| - | < | + | ==== 6. Apache reverse proxy (root) ==== |
| - | su - worker -c '/ | + | |
| - | </ | + | |
| - | Do not ''sudo -u worker'' | + | We can now setup our reverse proxy and associated virtual hosts and Let's Encrypt cert: |
| - | ==== 6. Apache reverse proxy (root) ==== | ||
| < | < | ||
| - | a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl | + | sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host |
| + | sudo certbot certonly --apache -d talk.haacksnetworking.org | ||
| </ | </ | ||
| - | ''/ | + | Inside |
| < | < | ||
| Line 180: | Line 177: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | And, inside the TLS virtual host, '' | ||
| + | |||
| + | < | ||
| < | < | ||
| ServerName talk.haacksnetworking.org | ServerName talk.haacksnetworking.org | ||
| Line 201: | Line 202: | ||
| </ | </ | ||
| </ | </ | ||
| + | |||
| + | Once the virtual hosts are built, let's enable it, check the config, and then check the endpoint. | ||
| < | < | ||
| Line 209: | Line 212: | ||
| </ | </ | ||
| - | Clients use '' | + | Check your output and make sure everything is accessible and running. If not, debug until it works. FYI, the endpoint for clients is '' |
| - | ==== Facts ==== | ||
| - | * | ||
| - | --- // | + | --- // |