Files
prosody/docker-compose.yml
mguschin c11f05481c Fix coturn TLS listeners and pin relay to public IP.
Two problems found once coturn was running:

TLS listeners never started. The live/ certificate files are relative
symlinks into ../../archive/, so mounting live/ alone left them dangling
and coturn silently fell back to no TLS, disabling turns: on 5349.
Prosody's identical mount works only because its entrypoint copies the
files; coturn reads them in place. Mount both trees at their real paths
and reference the cert through live/.

Relay used every interface. Without explicit addresses coturn discovered
all of them and offered relay candidates on the Docker bridges and
loopback -- unreachable for remote peers, and needless exposure of the
internal networks. Pin listening-ip and relay-ip to the public address.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 22:20:37 +03:00

85 lines
2.9 KiB
YAML

services:
prosody:
build:
context: .
dockerfile: Dockerfile
container_name: prosody-xmpp
environment:
XMPP_DOMAIN: ${XMPP_DOMAIN}
XMPP_USER: ${XMPP_USER}
XMPP_PASSWORD: ${XMPP_PASSWORD}
MYSQL_HOST: ${MYSQL_HOST:-host.docker.internal}
MYSQL_USER: ${MYSQL_USER}
MYSQL_PASSWORD: ${MYSQL_PASSWORD}
MYSQL_DATABASE: ${MYSQL_DATABASE}
SLIDGRAM_COMPONENT_SECRET: ${SLIDGRAM_COMPONENT_SECRET}
TURN_HOST: ${TURN_HOST}
TURN_SECRET: ${TURN_SECRET}
extra_hosts:
- "host.docker.internal:172.17.0.1"
ports:
- "5222:5222"
- "5269:5269"
- "5280:5280"
- "5281:5281"
volumes:
- ./data/prosody:/var/lib/prosody
- ./logs/prosody:/var/log/prosody
- ./data/prosody/configuration:/etc/prosody/conf.d
- /etc/letsencrypt/live/xmpp.guschin.info:/etc/prosody/certs/letsencrypt/live/xmpp.guschin.info:ro
- /etc/letsencrypt/archive/xmpp.guschin.info:/etc/prosody/certs/letsencrypt/archive/xmpp.guschin.info:ro
- /etc/letsencrypt/live/guschin.info:/etc/prosody/certs/letsencrypt/live/guschin.info:ro
- /etc/letsencrypt/archive/guschin.info:/etc/prosody/certs/letsencrypt/archive/guschin.info:ro
restart: unless-stopped
mem_limit: 200M
healthcheck:
test: ["CMD", "nc", "-z", "localhost", "5222"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
networks:
- prosody
slidgram:
image: codeberg.org/slidge/slidgram:latest
container_name: slidgram
user: "100:102"
environment:
SLIDGE_JID: telegram.guschin.info
SLIDGE_SECRET: ${SLIDGRAM_COMPONENT_SECRET}
SLIDGE_SERVER: prosody-xmpp
SLIDGE_PORT: 5347
SLIDGE_UPLOAD_SERVICE: upload.guschin.info
volumes:
- ./data/slidgram:/var/lib/slidge
restart: unless-stopped
depends_on:
prosody:
condition: service_healthy
networks:
- prosody
coturn:
image: coturn/coturn:4.6-alpine
container_name: coturn
# Host networking: a TURN relay needs its whole UDP port range reachable,
# and Docker's userland NAT both mangles the source addresses coturn needs
# to see and makes publishing the range impractical.
network_mode: host
volumes:
- ./coturn/turnserver.conf:/etc/coturn/turnserver.conf:ro
# The live/ files are relative symlinks into ../../archive/, so both
# trees must be mounted at their real paths for the links to resolve.
# coturn reads the certificate directly (unlike Prosody, whose
# entrypoint copies it), so a broken symlink silently disables TLS.
- /etc/letsencrypt/live/guschin.info:/etc/letsencrypt/live/guschin.info:ro
- /etc/letsencrypt/archive/guschin.info:/etc/letsencrypt/archive/guschin.info:ro
command: ["-c", "/etc/coturn/turnserver.conf"]
restart: unless-stopped
mem_limit: 128M
networks:
prosody:
driver: bridge