Two problems found once coturn was running: TLS listeners never started. The live/ certificate files are relative symlinks into ../../archive/, so mounting live/ alone left them dangling and coturn silently fell back to no TLS, disabling turns: on 5349. Prosody's identical mount works only because its entrypoint copies the files; coturn reads them in place. Mount both trees at their real paths and reference the cert through live/. Relay used every interface. Without explicit addresses coturn discovered all of them and offered relay candidates on the Docker bridges and loopback -- unreachable for remote peers, and needless exposure of the internal networks. Pin listening-ip and relay-ip to the public address. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
85 lines
2.9 KiB
YAML
85 lines
2.9 KiB
YAML
services:
|
|
prosody:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
container_name: prosody-xmpp
|
|
environment:
|
|
XMPP_DOMAIN: ${XMPP_DOMAIN}
|
|
XMPP_USER: ${XMPP_USER}
|
|
XMPP_PASSWORD: ${XMPP_PASSWORD}
|
|
MYSQL_HOST: ${MYSQL_HOST:-host.docker.internal}
|
|
MYSQL_USER: ${MYSQL_USER}
|
|
MYSQL_PASSWORD: ${MYSQL_PASSWORD}
|
|
MYSQL_DATABASE: ${MYSQL_DATABASE}
|
|
SLIDGRAM_COMPONENT_SECRET: ${SLIDGRAM_COMPONENT_SECRET}
|
|
TURN_HOST: ${TURN_HOST}
|
|
TURN_SECRET: ${TURN_SECRET}
|
|
extra_hosts:
|
|
- "host.docker.internal:172.17.0.1"
|
|
ports:
|
|
- "5222:5222"
|
|
- "5269:5269"
|
|
- "5280:5280"
|
|
- "5281:5281"
|
|
volumes:
|
|
- ./data/prosody:/var/lib/prosody
|
|
- ./logs/prosody:/var/log/prosody
|
|
- ./data/prosody/configuration:/etc/prosody/conf.d
|
|
- /etc/letsencrypt/live/xmpp.guschin.info:/etc/prosody/certs/letsencrypt/live/xmpp.guschin.info:ro
|
|
- /etc/letsencrypt/archive/xmpp.guschin.info:/etc/prosody/certs/letsencrypt/archive/xmpp.guschin.info:ro
|
|
- /etc/letsencrypt/live/guschin.info:/etc/prosody/certs/letsencrypt/live/guschin.info:ro
|
|
- /etc/letsencrypt/archive/guschin.info:/etc/prosody/certs/letsencrypt/archive/guschin.info:ro
|
|
restart: unless-stopped
|
|
mem_limit: 200M
|
|
healthcheck:
|
|
test: ["CMD", "nc", "-z", "localhost", "5222"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 40s
|
|
networks:
|
|
- prosody
|
|
|
|
slidgram:
|
|
image: codeberg.org/slidge/slidgram:latest
|
|
container_name: slidgram
|
|
user: "100:102"
|
|
environment:
|
|
SLIDGE_JID: telegram.guschin.info
|
|
SLIDGE_SECRET: ${SLIDGRAM_COMPONENT_SECRET}
|
|
SLIDGE_SERVER: prosody-xmpp
|
|
SLIDGE_PORT: 5347
|
|
SLIDGE_UPLOAD_SERVICE: upload.guschin.info
|
|
volumes:
|
|
- ./data/slidgram:/var/lib/slidge
|
|
restart: unless-stopped
|
|
depends_on:
|
|
prosody:
|
|
condition: service_healthy
|
|
networks:
|
|
- prosody
|
|
|
|
coturn:
|
|
image: coturn/coturn:4.6-alpine
|
|
container_name: coturn
|
|
# Host networking: a TURN relay needs its whole UDP port range reachable,
|
|
# and Docker's userland NAT both mangles the source addresses coturn needs
|
|
# to see and makes publishing the range impractical.
|
|
network_mode: host
|
|
volumes:
|
|
- ./coturn/turnserver.conf:/etc/coturn/turnserver.conf:ro
|
|
# The live/ files are relative symlinks into ../../archive/, so both
|
|
# trees must be mounted at their real paths for the links to resolve.
|
|
# coturn reads the certificate directly (unlike Prosody, whose
|
|
# entrypoint copies it), so a broken symlink silently disables TLS.
|
|
- /etc/letsencrypt/live/guschin.info:/etc/letsencrypt/live/guschin.info:ro
|
|
- /etc/letsencrypt/archive/guschin.info:/etc/letsencrypt/archive/guschin.info:ro
|
|
command: ["-c", "/etc/coturn/turnserver.conf"]
|
|
restart: unless-stopped
|
|
mem_limit: 128M
|
|
|
|
networks:
|
|
prosody:
|
|
driver: bridge
|