Skip to content

Direct Public Exposure & Standalone TLS ​

RUSEON Core can be deployed directly on a public IP address without an intermediary reverse proxy. This architecture eliminates proxy latency, simplifies networking, and provides direct WebRTC ICE candidate negotiation.


1. Native TLS / HTTPS Configuration ​

RUSEON Core features a built-in HTTPS engine. Configure your TLS certificates in config.yaml:

yaml
server:
  host: "0.0.0.0"
  port: 8443
  
  # Native TLS termination
  tls:
    enabled: true
    cert_file: "/etc/letsencrypt/live/ruseon.example.com/fullchain.pem"
    key_file: "/etc/letsencrypt/live/ruseon.example.com/privkey.pem"
    min_version: "TLS1.3"

To automatically bind to standard privileged HTTPS port 443 without running as root, grant Linux capability:

bash
sudo setcap 'cap_net_bind_service=+ep' /opt/ruseon/bin/ruseon

2. Firewall Rules (UFW / iptables) ​

When exposing RUSEON directly to the internet, open only the strictly necessary ports:

bash
# Allow SSH management
sudo ufw allow 22/tcp

# Allow Web UI, REST API, WHEP signaling, and HLS
sudo ufw allow 8443/tcp

# Allow Inbound Camera RTSP (if cameras stream over public WAN)
sudo ufw allow 8554/tcp

# Allow WebRTC ICE Media Packet Range (UDP)
sudo ufw allow 50000:50100/udp

# Enable firewall
sudo ufw enable

3. WebRTC Public IP & ICE Candidate Binding ​

For WebRTC / WHEP clients to successfully establish peer-to-peer media streams over the internet, RUSEON must advertise its public IP address in SDP offer/answer exchanges:

yaml
webrtc:
  # Your public IPv4 or IPv6 address
  public_ip: "203.0.113.50"

  # Port range for UDP ICE media transport
  port_range_start: 50000
  port_range_end: 50100

  # Optional STUN servers for NAT discovery
  stun_servers:
    - "stun:stun.l.google.com:19302"

4. Security Precautions for Direct Exposure ​

  1. Rotate Default Credentials: Update admin password immediately upon first boot.
  2. Use Strong JWT Secrets: Configure auth.jwt_secret with a 32+ character entropy string.
  3. Restrict Camera Ingest: Where possible, restrict port 8554 to specific camera VPN subnets or static IP source ranges.

Released under the MIT License.