Direct Public Exposure & Standalone TLS
RUSEON Core can be deployed directly on a public IP address without an intermediary reverse proxy. This architecture eliminates proxy latency, simplifies networking, and provides direct WebRTC ICE candidate negotiation.
1. Native TLS / HTTPS Configuration
RUSEON Core features a built-in HTTPS engine. Configure your TLS certificates in config.yaml:
yaml
server:
host: "0.0.0.0"
port: 8443
# Native TLS termination
tls:
enabled: true
cert_file: "/etc/letsencrypt/live/ruseon.example.com/fullchain.pem"
key_file: "/etc/letsencrypt/live/ruseon.example.com/privkey.pem"
min_version: "TLS1.3"To automatically bind to standard privileged HTTPS port 443 without running as root, grant Linux capability:
bash
sudo setcap 'cap_net_bind_service=+ep' /opt/ruseon/bin/ruseon2. Firewall Rules (UFW / iptables)
When exposing RUSEON directly to the internet, open only the strictly necessary ports:
bash
# Allow SSH management
sudo ufw allow 22/tcp
# Allow Web UI, REST API, WHEP signaling, and HLS
sudo ufw allow 8443/tcp
# Allow Inbound Camera RTSP (if cameras stream over public WAN)
sudo ufw allow 8554/tcp
# Allow WebRTC ICE Media Packet Range (UDP)
sudo ufw allow 50000:50100/udp
# Enable firewall
sudo ufw enable3. WebRTC Public IP & ICE Candidate Binding
For WebRTC / WHEP clients to successfully establish peer-to-peer media streams over the internet, RUSEON must advertise its public IP address in SDP offer/answer exchanges:
yaml
webrtc:
# Your public IPv4 or IPv6 address
public_ip: "203.0.113.50"
# Port range for UDP ICE media transport
port_range_start: 50000
port_range_end: 50100
# Optional STUN servers for NAT discovery
stun_servers:
- "stun:stun.l.google.com:19302"4. Security Precautions for Direct Exposure
- Rotate Default Credentials: Update admin password immediately upon first boot.
- Use Strong JWT Secrets: Configure
auth.jwt_secretwith a 32+ character entropy string. - Restrict Camera Ingest: Where possible, restrict port
8554to specific camera VPN subnets or static IP source ranges.