User Tools

Site Tools


computing:hpb-talk

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
computing:hpb-talk [2026/10/10 01:11] – oemb1905computing:hpb-talk [2026/10/10 05:21] (current) – oemb1905
Line 8: Line 8:
 ------------------------------------------- -------------------------------------------
  
-//Nextcloud Talk HPB//+//Talk HPB//
  
 ------------------------------------------- -------------------------------------------
Line 14: Line 14:
  
 ==== Introduction ==== ==== Introduction ====
-Rootless Podman as user ''worker'' on host ''support''. Apache + Let's Encrypt run as ''root''. Signaling is bound to localhost only. TURN is public.+ 
 +This tutorial is for Debian users who want or need to spin up a high performance back-end for Nextcloud Talk. This helps with multi-user calls and/or nasty NAT situations. Here's the layout:
  
 ^ Role ^ Bind ^ Public ^ ^ Role ^ Bind ^ Public ^
Line 20: Line 21:
 | TURN | ''0.0.0.0:3478/tcp'' + ''3478/udp'' | ''talk.haacksnetworking.org:3478'' | | TURN | ''0.0.0.0:3478/tcp'' + ''3478/udp'' | ''talk.haacksnetworking.org:3478'' |
  
-Image: ''ghcr.io/nextcloud-releases/aio-talk:latest''   +We will use the following image:
-One container: signaling + NATS + Janus + eturnal.   +
-The image rewrites ''/conf/signaling.conf'' on every start from ''NC_DOMAIN'' only. Extra Nextcloud backends must be re-added after every start. Do not mount ''/conf''.+
  
-Do not use ''podman generate systemd''. Units come from Quadlet files in ''~/.config/containers/systemd/''.+  * Image: ''ghcr.io/nextcloud-releases/aio-talk:latest''   
 + 
 +This image is basically signaling, NATS, Janus, and eturnal. Let's make sure the host is setup properly.
  
 ==== 0. Host firewall (root) ==== ==== 0. Host firewall (root) ====
-''3478/tcp'' and ''3478/udp'' must be reachable from clients. Signaling stays on localhost.+ 
 +We need to open turn on udp 3478 and its fallback, tcp 3478. This helps clients behind nasty NAT. The signaling stays on localhost. Let's open the ports:
  
 <code> <code>
Line 33: Line 35:
 ufw allow 3478/udp ufw allow 3478/udp
 </code> </code>
- 
-DNS: ''talk.haacksnetworking.org'' A/AAAA → this host. 
  
 ==== 1. Directories and secrets (worker) ==== ==== 1. Directories and secrets (worker) ====
Line 45: Line 45:
 </code> </code>
  
-Do not rotate these after Nextcloud has them. Update every Nextcloud that uses them if you do.+Keep these stable for yearly or longer rotations. No need to rotate if no compromise is suspected, etc., and usage is tightly monitored and restricted.
  
-Placeholders used below:+==== 2. Quadlet ====
  
-<code> +Create the quadlet for monitoring and starting/stopping the service as the ''worker'' user ''nano ~/.config/containers/systemd/container-talk-hpb.container''
-SIGNALING_SECRET=replace-with-your-signaling-secret +
-TURN_SECRET=replace-with-your-turn-secret +
-INTERNAL_SECRET=replace-with-your-internal-secret +
-</code> +
- +
-==== 2. Quadlet ==== +
-File: ''~/.config/containers/systemd/container-talk-hpb.container''+
  
 <code> <code>
-systemctl --user disable --now container-talk-hpb.service 2>/dev/null || true 
-rm -f ~/.config/systemd/user/container-talk-hpb.service 
-podman rm -f talk-hpb 
- 
 mkdir -p ~/.config/containers/systemd mkdir -p ~/.config/containers/systemd
 cat > ~/.config/containers/systemd/container-talk-hpb.container << 'EOF' cat > ~/.config/containers/systemd/container-talk-hpb.container << 'EOF'
Line 92: Line 81:
 sleep 25 sleep 25
 </code> </code>
- 
-''WantedBy=default.target'' starts it. Do not ''systemctl enable'' a Quadlet unit. Do not ''podman generate systemd''. 
  
 ==== 3. Extra Nextcloud backends (after every start) ==== ==== 3. Extra Nextcloud backends (after every start) ====
-''start.sh'' writes only ''backend-1'' = ''NC_DOMAIN''. For the other three hosts, patch the running file and reload signaling. Do not ''podman restart'' after the patch. A restart rewrites the file and drops the extra backends.+ 
 +The HPB container can only be built with one endpoint when it is updated, so the following is needed to add xx amount of endpoints to use the HPB with:
  
 <code> <code>
Line 109: Line 97:
 </code> </code>
  
-Expected:+When you run this, you get something like:
  
 <code> <code>
Line 129: Line 117:
  
 ==== 4. Verify ==== ==== 4. Verify ====
 +
 +Once your back-ends are all specified, let's verify the service is healthy and the api endpoint is reachable:
 +
 <code> <code>
 systemctl --user is-active container-talk-hpb.service systemctl --user is-active container-talk-hpb.service
Line 135: Line 126:
 </code> </code>
  
-Expect ''active'', ''cpus=2000000000'', ''memory=4294967296'', and an HTTP response from the welcome endpoint. The image has its own ''HEALTHCHECK''. Podman Desktop shows that status. The other containers do not, because their images do not define one.+We should see something like ''active'', ''cpus=2000000000'', ''memory=4294967296'', and an HTTP response from the welcome endpoint. 
  
 ==== 5. Upgrade script ==== ==== 5. Upgrade script ====
-''/usr/local/bin/upgrade-high-performance.sh''. A tag change is an edit to ''Image='' in the ''.container'' file before ''daemon-reload''. The script does not recreate the unit.+ 
 +Let's create an upgrade script at ''nano /usr/local/bin/upgrade-high-performance.sh''. Inside it, let's put something like this:
  
 <code> <code>
 #!/bin/bash #!/bin/bash
 set -euo pipefail set -euo pipefail
 +export XDG_RUNTIME_DIR=/run/user/$(id -u)
 +export DBUS_SESSION_BUS_ADDRESS=unix:path=${XDG_RUNTIME_DIR}/bus
  
 podman pull ghcr.io/nextcloud-releases/aio-talk:latest podman pull ghcr.io/nextcloud-releases/aio-talk:latest
Line 164: Line 158:
 </code> </code>
  
-Run it as ''worker'':+If your curl output is unhealthy, stop and debug before proceeding.
  
-<code> +==== 6. Apache reverse proxy (root) ====
-su - worker -c '/bin/bash /usr/local/bin/upgrade-high-performance.sh' +
-</code>+
  
-Do not ''sudo -u worker''. That drops the session bus.+We can now setup our reverse proxy and associated virtual hosts and Let's Encrypt cert:
  
-==== 6. Apache reverse proxy (root) ==== 
 <code> <code>
-a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl+sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host 
 +sudo certbot certonly --apache -d talk.haacksnetworking.org
 </code> </code>
  
-''/etc/apache2/sites-available/talk.haacksnetworking.org.conf'':+Inside ''nano /etc/apache2/sites-available/talk.haacksnetworking.org.conf'' let's put something like:
  
 <code> <code>
Line 185: Line 177:
     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
 </VirtualHost> </VirtualHost>
 +</code>
  
 +And, inside the TLS virtual host, ''nano /etc/apache2/sites-available/talk.haacksnetworking.org-ssl.conf'' let's drop something like:
 +
 +<code>
 <VirtualHost *:443> <VirtualHost *:443>
     ServerName talk.haacksnetworking.org     ServerName talk.haacksnetworking.org
Line 206: Line 202:
 </VirtualHost> </VirtualHost>
 </code> </code>
 +
 +Once the virtual hosts are built, let's enable it, check the config, and then check the endpoint. 
  
 <code> <code>
Line 214: Line 212:
 </code> </code>
  
-Clients use ''wss://talk.haacksnetworking.org/spreed''.+Check your output and make sure everything is accessible and running. If not, debug until it works. FYI, the endpoint for clients is ''wss://talk.haacksnetworking.org/spreed''. More updates if/when rebuilds are done will be posted. Reach out on Matrix if you have questions. 
  
-==== Facts ==== 
-  *  
  
- --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 01:10//+ --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 05:16//
computing/hpb-talk.1791594714.txt.gz · Last modified: by oemb1905