Eigenen TURN-Server bereitstellen und absichern
Lernen Sie, mit coturn einen eigenen TURN-Server zu betreiben, Zugangsdaten mit zeitlich begrenzten Tokens sicher zu konfigurieren und zwischen Self-Hosting und verwalteten TURN-Services zu entscheiden
Eigenen TURN-Server bereitstellen und absichern ist eine kostenlose Real-Time Streaming Systems (WebRTC + Live Data)-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Real-Time Streaming Systems (WebRTC + Live Data)-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Real-Time Streaming Systems (WebRTC + Live Data)-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
From Theory to Operation
You understand NAT challenges, STUN, and what TURN does. Now you will actually run a TURN server, secure it, and connect WebRTC to it. The most common open-source choice is coturn.
Why Self-Host TURN
Public STUN is free, but TURN relays media and consumes bandwidth, so it is rarely free. Running your own TURN server gives you control over capacity, cost, and privacy.
Installing coturn
On a Linux server you install coturn from the package manager. It runs as a background service.
sudo apt-get update
sudo apt-get install -y coturn
sudo systemctl enable coturnBasic Configuration
coturn reads /etc/turnserver.conf. A minimal config sets the realm and listening ports.
listening-port=3478
tls-listening-port=5349
realm=turn.example.com
fingerprintThe Credential Problem
TURN requires authentication or anyone could relay traffic through your server at your expense. Hardcoding a static username and password is risky because clients can leak them.
Time-Limited Credentials
The secure approach is the REST/ephemeral credential mechanism. Your server generates short-lived usernames and passwords derived from a shared secret, so leaked credentials expire quickly.
use-auth-secret
static-auth-secret=your_long_shared_secretGenerating a Credential
Your backend creates a username as an expiry timestamp and signs it with HMAC-SHA1 using the shared secret. The signature becomes the password.
const crypto = require('crypto');
function turnCredential(secret, ttl) {
const username = String(Math.floor(Date.now() / 1000) + ttl);
const hmac = crypto.createHmac('sha1', secret);
hmac.update(username);
const password = hmac.digest('base64');
return { username, password };
}Wiring It Into WebRTC
Pass the TURN URL and ephemeral credentials into the peer connection's ICE server list. WebRTC uses them when direct paths fail.
const pc = new RTCPeerConnection({
iceServers: [{
urls: 'turn:turn.example.com:3478',
username: cred.username,
credential: cred.password
}]
});Use TLS and TCP Fallback
Some restrictive networks block UDP entirely. Offer turns: over TCP on port 443 so media can tunnel through firewalls that only allow HTTPS traffic.
// add a TLS/TCP TURN entry alongside the UDP one
urls: 'turns:turn.example.com:443?transport=tcp'Self-Host vs Managed
Self-hosting coturn is cheaper at scale but means you handle uptime, bandwidth, and security. Managed TURN providers cost more per GB but remove operational burden. Pick based on your team and traffic.
Operating Responsibly
Monitor bandwidth, rotate the shared secret periodically, restrict relay to authenticated users, and place the server geographically near your users to minimize latency. A well-run TURN server is the safety net that makes calls connect everywhere.
Quick Check
Test your understanding of TURN deployment.
Recap
You learned to deploy and secure TURN:
- Install and configure coturn with a realm and ports
- Use
use-auth-secretwith HMAC-based ephemeral credentials - Wire credentials into the ICE server list
- Offer TLS/TCP on 443 for restrictive networks
- Weigh self-hosting against managed services
A secure TURN server ensures calls connect even behind tough NATs.
Häufig gestellte Fragen
Ist die Lektion „Eigenen TURN-Server bereitstellen und absichern“ kostenlos?
Ja — der vollständige Text von „Eigenen TURN-Server bereitstellen und absichern“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Real-Time Streaming Systems (WebRTC + Live Data)-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Real-Time Streaming Systems (WebRTC + Live Data)-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Eigenen TURN-Server bereitstellen und absichern“?
Lernen Sie, mit coturn einen eigenen TURN-Server zu betreiben, Zugangsdaten mit zeitlich begrenzten Tokens sicher zu konfigurieren und zwischen Self-Hosting und verwalteten TURN-Services zu entscheid… Du übst Real-Time Streaming Systems (WebRTC + Live Data) mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Real-Time Streaming Systems (WebRTC + Live Data) zu starten?
Keine Vorkenntnisse erforderlich. Real-Time Streaming Systems (WebRTC + Live Data) auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Eigenen TURN-Server bereitstellen und absichern“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Real-Time Streaming Systems (WebRTC + Live Data)-Lektion Code schreiben und ausführen?
Ja. Jede Real-Time Streaming Systems (WebRTC + Live Data)-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Herausforderungen durch NAT und Firewalls
- Funktionsweise von STUN-Servern
- TURN-Server für weitergeleitete Verbindungen
- Eigenen TURN-Server bereitstellen und absichern