diff --git a/Makefile b/Makefile index 030d154a..e7101259 100644 --- a/Makefile +++ b/Makefile @@ -833,16 +833,7 @@ deb-pkg: --deb-systemd-restart-after-upgrade \ --after-install=util/systemd/after-install.sh \ --description="Live video for the AT Protocol. Solving video for everybody forever." \ - build-linux-$(SP_ARCH_NAME)/streamplace=/usr/bin/streamplace \ - && fpm $(FPM_BASE_OPTS) \ - -n streamplace-default-http \ - -a $(SP_ARCH_NAME) \ - -d streamplace \ - --deb-systemd-restart-after-upgrade \ - -p bin/streamplace-default-http-$(VERSION)-linux-$(SP_ARCH_NAME).deb \ - --description="Installing this package will install Streamplace as the default HTTP server on ports 80 and 443." \ - util/systemd/streamplace-http.socket=/lib/systemd/system/streamplace-http.socket \ - util/systemd/streamplace-https.socket=/lib/systemd/system/streamplace-https.socket + build-linux-$(SP_ARCH_NAME)/streamplace=/usr/bin/streamplace .PHONY: pkg-linux-amd64 pkg-linux-amd64: @@ -869,20 +860,16 @@ deb-release: aptly repo create -distribution=all -component=main streamplace-releases aptly mirror create old-version $$S3_PUBLIC_URL/debian all aptly mirror update old-version - aptly repo import old-version streamplace-releases streamplace streamplace-default-http + aptly repo import old-version streamplace-releases streamplace aptly repo add streamplace-releases \ - bin/streamplace-default-http-$(VERSION)-linux-arm64.deb \ bin/streamplace-$(VERSION)-linux-arm64.deb \ - bin/streamplace-default-http-$(VERSION)-linux-amd64.deb \ bin/streamplace-$(VERSION)-linux-amd64.deb aptly snapshot create streamplace-$(VERSION) from repo streamplace-releases aptly publish snapshot -distribution=all streamplace-$(VERSION) s3:streamplace-releases: .PHONY: ci-deb-release ci-deb-release: - $(MAKE) ci-download-file download_file=streamplace-default-http-$(VERSION)-linux-amd64.deb $(MAKE) ci-download-file download_file=streamplace-$(VERSION)-linux-amd64.deb - $(MAKE) ci-download-file download_file=streamplace-default-http-$(VERSION)-linux-arm64.deb $(MAKE) ci-download-file download_file=streamplace-$(VERSION)-linux-arm64.deb echo $$CI_SIGNING_KEY_BASE64 | base64 -d | gpg --import gpg --armor --export | gpg --no-default-keyring --keyring trustedkeys.gpg --import @@ -905,14 +892,12 @@ ci-upload: ci-upload-node ci-upload-android ci-upload-node-linux-amd64: $(MAKE) ci-upload-file upload_file=streamplace-$(VERSION)-linux-amd64.tar.gz \ && $(MAKE) ci-upload-file upload_file=streamplace-desktop-$(VERSION)-linux-amd64.AppImage \ - && $(MAKE) ci-upload-file upload_file=streamplace-default-http-$(VERSION)-linux-amd64.deb \ && $(MAKE) ci-upload-file upload_file=streamplace-$(VERSION)-linux-amd64.deb .PHONY: ci-upload-node-linux-arm64 ci-upload-node-linux-arm64: $(MAKE) ci-upload-file upload_file=streamplace-$(VERSION)-linux-arm64.tar.gz \ && $(MAKE) ci-upload-file upload_file=streamplace-desktop-$(VERSION)-linux-arm64.AppImage \ - && $(MAKE) ci-upload-file upload_file=streamplace-default-http-$(VERSION)-linux-arm64.deb \ && $(MAKE) ci-upload-file upload_file=streamplace-$(VERSION)-linux-arm64.deb .PHONY: ci-upload-node-darwin-arm64 diff --git a/js/docs/src/content/docs/guides/installing/downloading-streamplace.md b/js/docs/src/content/docs/guides/installing/downloading-streamplace.md index 52998e20..0d2a1d9c 100644 --- a/js/docs/src/content/docs/guides/installing/downloading-streamplace.md +++ b/js/docs/src/content/docs/guides/installing/downloading-streamplace.md @@ -13,19 +13,6 @@ brew install streamplace/streamplace/streamplace ## Linux -We distribute two Linux packages for Streamplace: - -- `streamplace`, which is the main Streamplace binary. -- `streamplace-default-http`, which includes some additional systemd - configuration to make Streamplace your default HTTP server on ports 80 - and 443. - -If you're looking to set up a Streamplace node on a server that isn't hosting -any other services, we'd recommend e.g. -`apt install streamplace streamplace-default-http`. If your server is hosting -other HTTP servers and you'll handle the proxying yourself, you can simply -`apt install streamplace`. - ### Debian/Ubuntu ```shell @@ -37,6 +24,26 @@ sudo apt update sudo apt install streamplace ``` +This will install the `streamplace` systemd service. To configure it, you will +want to edit the environment variables at `/etc/streamplace/streamplace.env`. An +example production env file might look something like this: + +```ini +# Handle default HTTP and HTTPS traffic for the server +SP_HTTP_ADDR=:80 +SP_HTTPS_ADDR=:443 +SP_SECURE=true + +# Necessary to advertise a public Streamplace broadcaster +SP_BROADCASTER_HOST=example.com +# If you have a multi-node cluster, they'll each need different public DNS names: +SP_SERVER_HOST=prod-nyc0.example.com + +# Useful if your TLS cert and key aren't in the default +SP_TLS_CERT=/tls/tls.crt +SP_TLS_KEY=/tls/tls.key +``` + ## Download a binary Binaries for all platforms are available to download from diff --git a/util/systemd/after-install.sh b/util/systemd/after-install.sh index 7beba2f1..18ed92d4 100755 --- a/util/systemd/after-install.sh +++ b/util/systemd/after-install.sh @@ -18,6 +18,23 @@ chown -R streamplace:streamplace /var/lib/streamplace # Create default environment file if it doesn't exist if [ ! -f /etc/streamplace/streamplace.env ]; then - echo "# Configure your Streamplace instance by creating lines such as:" > /etc/streamplace/streamplace.env - echo "# SP_PUBLIC_HOST=example.com" >> /etc/streamplace/streamplace.env + cat < /etc/streamplace/streamplace.env +# Configure your Streamplace instance by creating lines such as: +# +# SP_BROADCASTER_HOST=example.com +# +# If you have a multi-node cluster, they'll each need different public DNS names: +# +# SP_SERVER_HOST=prod-nyc0.example.com +# +# If you want your Streamplace node handle default HTTP and HTTPS traffic for the server, uncomment these: +# +# SP_HTTP_ADDR=:80 +# SP_HTTPS_ADDR=:443 +# SP_SECURE=true +# Useful if your TLS cert and key aren't in the default: +# +# SP_TLS_CERT=/tls/tls.crt +# SP_TLS_KEY=/tls/tls.key +EOF fi diff --git a/util/systemd/streamplace-http.socket b/util/systemd/streamplace-http.socket deleted file mode 100644 index 811d5423..00000000 --- a/util/systemd/streamplace-http.socket +++ /dev/null @@ -1,10 +0,0 @@ -[Unit] -Description=streamplace http socket - -[Socket] -ListenStream=80 -FileDescriptorName=http -Service=streamplace.service - -[Install] -WantedBy=sockets.target diff --git a/util/systemd/streamplace-https.socket b/util/systemd/streamplace-https.socket deleted file mode 100644 index 55ce377a..00000000 --- a/util/systemd/streamplace-https.socket +++ /dev/null @@ -1,10 +0,0 @@ -[Unit] -Description=streamplace https socket - -[Socket] -ListenStream=443 -FileDescriptorName=https -Service=streamplace.service - -[Install] -WantedBy=sockets.target diff --git a/util/systemd/streamplace.service b/util/systemd/streamplace.service index df752373..ce9a8a43 100644 --- a/util/systemd/streamplace.service +++ b/util/systemd/streamplace.service @@ -3,7 +3,6 @@ Description=Live video for the AT Protocol. Solving video for everybody forever. Documentation=https://stream.place/docs After=network-online.target Wants=network-online.target -Wants=streamplace-http.socket streamplace-https.socket Requires=network.target [Service] @@ -23,9 +22,12 @@ Environment=SP_DATA_DIR=/var/lib/streamplace # Additional environment file for user customization EnvironmentFile=-/etc/streamplace/streamplace.env +# Grant capability to bind to privileged ports +AmbientCapabilities=CAP_NET_BIND_SERVICE +CapabilityBoundingSet=CAP_NET_BIND_SERVICE + # Security hardening NoNewPrivileges=yes -ProtectSystem=strict ProtectHome=yes ProtectKernelTunables=yes ProtectKernelModules=yes @@ -35,10 +37,6 @@ RestrictSUIDSGID=yes RemoveIPC=yes PrivateTmp=yes -# Allow access to necessary directories -ReadWritePaths=/var/lib/streamplace -ReadOnlyPaths=/etc/streamplace - # Resource limits LimitNOFILE=65536 LimitNPROC=4096 @@ -52,4 +50,4 @@ SyslogIdentifier=streamplace WorkingDirectory=/var/lib/streamplace [Install] -WantedBy=multi-user.target \ No newline at end of file +WantedBy=multi-user.target