Skip to content

Production Hardening & Deployment Checklist ​

Before taking RUSEON Core into high-throughput production environments (handling dozens or hundreds of concurrent RTSP camera streams and WebRTC viewers), apply the following operating system, network, and runtime optimizations.


1. Linux Kernel Network & System Tuning ​

Create /etc/sysctl.d/99-ruseon.conf to optimize socket buffers and file descriptor ceilings for massive video streaming:

ini
# Maximum socket receive and send buffer sizes for high-bitrate RTSP/WebRTC
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.core.rmem_default = 262144
net.core.wmem_default = 262144

# UDP buffer minimums for Pion WebRTC packet processing
net.ipv4.udp_rmem_min = 16384
net.ipv4.udp_wmem_min = 16384

# Increase backlog queue for incoming connections
net.core.netdev_max_backlog = 10000
net.core.somaxconn = 4096

# Global file descriptor limits
fs.file-max = 2097152

# Virtual memory settings for BadgerDB memory-mapped operations
vm.max_map_count = 262144

Apply the changes immediately:

bash
sudo sysctl --system

2. File Descriptor Limits (ulimit) ​

Video streaming servers maintain numerous concurrent TCP and UDP connections alongside open fMP4 segment files.

Create /etc/security/limits.d/99-ruseon.conf:

text
ruseon    soft    nofile    65535
ruseon    hard    nofile    65535
ruseon    soft    nproc     32768
ruseon    hard    nproc     32768

3. Go Runtime Memory & Thread Tuning ​

Configure standard Go runtime environment variables in your systemd service or Docker compose file:

VariableRecommended ValuePurpose
GOMEMLIMIT80% of container/host RAM (e.g. 6GiB on 8GB host)Guides the Go Garbage Collector to prevent kernel OOM killer eviction
GOMAXPROCSSet to physical core countPrevents CPU throttling under virtualized hypervisors
GODEBUGmadvdontneed=1Instructs the Go runtime to return freed memory to the OS immediately

4. Production Security Checklist ​

  • [ ] Change Default Admin Password: Update default credentials upon initial login.
  • [ ] Rotate JWT Secret: Set a cryptographically strong auth.jwt_secret (at least 32 random characters).
  • [ ] Enable TLS / HTTPS: Use a reverse proxy (Caddy / Nginx) or direct certificate binding for WHEP / WebRTC security (browsers require HTTPS for WebRTC).
  • [ ] Restrict WebRTC UDP Ports: Open only the allocated UDP range (50000-50100) on external firewalls.
  • [ ] Dedicated Storage Volume: Ensure the video archive (storage_path) is mounted on a separate partition from the root OS disk.

Released under the MIT License.