Production Hardening & Deployment Checklist
Before taking RUSEON Core into high-throughput production environments (handling dozens or hundreds of concurrent RTSP camera streams and WebRTC viewers), apply the following operating system, network, and runtime optimizations.
1. Linux Kernel Network & System Tuning
Create /etc/sysctl.d/99-ruseon.conf to optimize socket buffers and file descriptor ceilings for massive video streaming:
ini
# Maximum socket receive and send buffer sizes for high-bitrate RTSP/WebRTC
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.core.rmem_default = 262144
net.core.wmem_default = 262144
# UDP buffer minimums for Pion WebRTC packet processing
net.ipv4.udp_rmem_min = 16384
net.ipv4.udp_wmem_min = 16384
# Increase backlog queue for incoming connections
net.core.netdev_max_backlog = 10000
net.core.somaxconn = 4096
# Global file descriptor limits
fs.file-max = 2097152
# Virtual memory settings for BadgerDB memory-mapped operations
vm.max_map_count = 262144Apply the changes immediately:
bash
sudo sysctl --system2. File Descriptor Limits (ulimit)
Video streaming servers maintain numerous concurrent TCP and UDP connections alongside open fMP4 segment files.
Create /etc/security/limits.d/99-ruseon.conf:
text
ruseon soft nofile 65535
ruseon hard nofile 65535
ruseon soft nproc 32768
ruseon hard nproc 327683. Go Runtime Memory & Thread Tuning
Configure standard Go runtime environment variables in your systemd service or Docker compose file:
| Variable | Recommended Value | Purpose |
|---|---|---|
GOMEMLIMIT | 80% of container/host RAM (e.g. 6GiB on 8GB host) | Guides the Go Garbage Collector to prevent kernel OOM killer eviction |
GOMAXPROCS | Set to physical core count | Prevents CPU throttling under virtualized hypervisors |
GODEBUG | madvdontneed=1 | Instructs the Go runtime to return freed memory to the OS immediately |
4. Production Security Checklist
- [ ] Change Default Admin Password: Update default credentials upon initial login.
- [ ] Rotate JWT Secret: Set a cryptographically strong
auth.jwt_secret(at least 32 random characters). - [ ] Enable TLS / HTTPS: Use a reverse proxy (Caddy / Nginx) or direct certificate binding for WHEP / WebRTC security (browsers require HTTPS for WebRTC).
- [ ] Restrict WebRTC UDP Ports: Open only the allocated UDP range (
50000-50100) on external firewalls. - [ ] Dedicated Storage Volume: Ensure the video archive (
storage_path) is mounted on a separate partition from the root OS disk.