Deployment Overview of Jitsi on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Debian or Ubuntu.
-
Privileges: Root or sudo access is required for package installation and service management.
-
Domain Name: A valid FQDN configured to point to the server's IP address.
-
Ports: The following ports must be open in the firewall:
| Port | Protocol | Purpose |
|---|---|---|
| 80 | TCP | HTTP (Web traffic and Let's Encrypt validation) |
| 443 | TCP | HTTPS (Secure web traffic) |
| 10000 | UDP | Jitsi Video/Audio streaming |
FQDN of the final panel on the hostkey.in domain¶
The application uses a specific naming convention for its access URL based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | jitsi |
| Domain | hostkey.in |
| Full template | jitsi{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several directories for configuration, certificates, and proxy management:
-
/etc/nginx/sites-available/: Contains the Nginx virtual host configuration files. -
/etc/nginx/sites-enabled/: Contains symbolic links to active Nginx configurations. -
/usr/share/jitsi-meet/scripts/: Location of the Let's Encrypt installation script. -
/root/nginx/: Directory containing the Docker Compose file for the Certbot proxy. -
/data/nginx/user_conf.d/: Custom Nginx configuration directory used by the proxy container.
Application Installation Process¶
The application is installed using a combination of APT package management and automated configuration scripts:
-
Dependency Installation: The system installs base dependencies including
curl,gnuppg,apt-transport-https, andca-certificates. -
Repository Setup:
-
The Jitsi official repository is added to the system.
-
The Prosody repository is added to handle XMPP messaging components.
-
Package Installation: The following core packages are installed via
apt: -
jitsi-meet -
jicofo(Jitsi Conference Focus) -
jitsi-videobridge2(Video Bridge) -
jitsi-meet-prosody(XMPP Server) -
jitsi-meet-web(Web interface) -
jitsi-meet-turnserver(STUN/TURN server) -
Configuration: The installation uses a preseed mechanism to automatically configure the FQDN for both the web component and the Video Bridge.
-
SSL Provisioning: An automated script
/usr/share/jitsi-meet/scripts/install-letsencrypt-cert.shis executed to obtain SSL certificates via Let's Encrypt using a provided administrator email.
Access Rights and Security¶
Security is managed through the Uncomplicated Firewall (UFW):
-
The firewall is enabled with a default policy of
allow. -
Specific rules are applied to allow traffic on ports 80, 443 (TCP), and 10000 (UDP).
-
Nginx is configured to redirect all HTTP traffic to HTTPS.
Docker Containers and Their Deployment¶
The deployment includes a specialized container for managing SSL certificates via a proxy setup:
Nginx Certbot Proxy
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Environment Variables:
-
CERTBOT_EMAIL: Set to the administrator's email for renewal notifications. -
Volumes:
-
nginx_secrets:/etc/letsencrypt: Persists SSL certificates. -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d: Maps custom proxy configurations into the container.
Custom Scripts and Additional Setup¶
The deployment performs several non-standard configuration steps to ensure proper routing:
-
Nginx Vhost Configuration: The system automatically identifies or creates an Nginx virtual host file, removes the default site configuration, and ensures the
server_namematches the FQDN. -
Proxy Routing: A custom configuration is generated in
/data/nginx/user_conf.d/to proxy traffic from the external port 443 to the internal Jitsi service running on127.0.0.1:8443. This includes specific handling for: -
Standard web traffic (
/) -
XMPP WebSockets (
/xmpp-websocket) -
Colibri WebSockets (
/colibri-ws/) -
HTTP Bind (
/http-bind)
Application Update Instructions¶
To update the main Jitsi application, use the standard package manager:
Location of Configuration Files and Data¶
-
Nginx Vhost Configs:
/etc/nginx/sites-available/ -
Jitsi Web Config: Managed via
jitsi-meet-web-config. -
SSL Certificates: Managed by Certbot within the Docker volume
nginx_secrets.
Available Ports for Connection¶
| Port | Protocol | Access Type |
|---|---|---|
| 80 | TCP | Public (Redirect to HTTPS) |
| 443 | TCP | Public (Web Interface/Signaling) |
| 10000 | UDP | Public (Media Streams) |
Starting and Stopping the Application¶
The application consists of several systemd services. Use the following commands:
To restart all Jitsi components:
To manage individual services:
-
systemctl start/stop/status prosody -
systemctl start/stop/status jicofo -
systemctl start/stop/status jitsi-videobridge2 -
systemctl start/stop/status nginx