Skip to content

Deployment Overview of Jitsi on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the server must meet the following requirements:

  • Operating System: Debian or Ubuntu.

  • Privileges: Root or sudo access is required for package installation and service management.

  • Domain Name: A valid FQDN configured to point to the server's IP address.

  • Ports: The following ports must be open in the firewall:

Port Protocol Purpose
80 TCP HTTP (Web traffic and Let's Encrypt validation)
443 TCP HTTPS (Secure web traffic)
10000 UDP Jitsi Video/Audio streaming

FQDN of the final panel on the hostkey.in domain

The application uses a specific naming convention for its access URL based on the server ID.

Parameter Value
Prefix jitsi
Domain hostkey.in
Full template jitsi{Server_ID}.hostkey.in

File and Directory Structure

The deployment utilizes several directories for configuration, certificates, and proxy management:

  • /etc/nginx/sites-available/: Contains the Nginx virtual host configuration files.

  • /etc/nginx/sites-enabled/: Contains symbolic links to active Nginx configurations.

  • /usr/share/jitsi-meet/scripts/: Location of the Let's Encrypt installation script.

  • /root/nginx/: Directory containing the Docker Compose file for the Certbot proxy.

  • /data/nginx/user_conf.d/: Custom Nginx configuration directory used by the proxy container.

Application Installation Process

The application is installed using a combination of APT package management and automated configuration scripts:

  1. Dependency Installation: The system installs base dependencies including curl, gnuppg, apt-transport-https, and ca-certificates.

  2. Repository Setup:

  3. The Jitsi official repository is added to the system.

  4. The Prosody repository is added to handle XMPP messaging components.

  5. Package Installation: The following core packages are installed via apt:

  6. jitsi-meet

  7. jicofo (Jitsi Conference Focus)

  8. jitsi-videobridge2 (Video Bridge)

  9. jitsi-meet-prosody (XMPP Server)

  10. jitsi-meet-web (Web interface)

  11. jitsi-meet-turnserver (STUN/TURN server)

  12. Configuration: The installation uses a preseed mechanism to automatically configure the FQDN for both the web component and the Video Bridge.

  13. SSL Provisioning: An automated script /usr/share/jitsi-meet/scripts/install-letsencrypt-cert.sh is executed to obtain SSL certificates via Let's Encrypt using a provided administrator email.

Access Rights and Security

Security is managed through the Uncomplicated Firewall (UFW):

  • The firewall is enabled with a default policy of allow.

  • Specific rules are applied to allow traffic on ports 80, 443 (TCP), and 10000 (UDP).

  • Nginx is configured to redirect all HTTP traffic to HTTPS.

Docker Containers and Their Deployment

The deployment includes a specialized container for managing SSL certificates via a proxy setup:

Nginx Certbot Proxy

  • Image: jonasal/nginx-certbot:latest

  • Network Mode: host

  • Environment Variables:

  • CERTBOT_EMAIL: Set to the administrator's email for renewal notifications.

  • Volumes:

  • nginx_secrets:/etc/letsencrypt: Persists SSL certificates.

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d: Maps custom proxy configurations into the container.

Custom Scripts and Additional Setup

The deployment performs several non-standard configuration steps to ensure proper routing:

  • Nginx Vhost Configuration: The system automatically identifies or creates an Nginx virtual host file, removes the default site configuration, and ensures the server_name matches the FQDN.

  • Proxy Routing: A custom configuration is generated in /data/nginx/user_conf.d/ to proxy traffic from the external port 443 to the internal Jitsi service running on 127.0.0.1:8443. This includes specific handling for:

  • Standard web traffic (/)

  • XMPP WebSockets (/xmpp-websocket)

  • Colibri WebSockets (/colibri-ws/)

  • HTTP Bind (/http-bind)

Application Update Instructions

To update the main Jitsi application, use the standard package manager:

sudo apt update
sudo apt upgrade jitsi-meet jicofo jitsi-videobridge2 prosody nginx

Location of Configuration Files and Data

  • Nginx Vhost Configs: /etc/nginx/sites-available/

  • Jitsi Web Config: Managed via jitsi-meet-web-config.

  • SSL Certificates: Managed by Certbot within the Docker volume nginx_secrets.

Available Ports for Connection

Port Protocol Access Type
80 TCP Public (Redirect to HTTPS)
443 TCP Public (Web Interface/Signaling)
10000 UDP Public (Media Streams)

Starting and Stopping the Application

The application consists of several systemd services. Use the following commands:

To restart all Jitsi components:

sudo systemctl restart prosody jicofo jitsi-videobridge2 nginx

To manage individual services:

  • systemctl start/stop/status prosody

  • systemctl start/stop/status jicofo

  • systemctl start/stop/status jitsi-videobridge2

  • systemctl start/stop/status nginx

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×