Dynamic IPs can be a bit tricky when it comes to API whitelisting in LiveKit because the LiveKit Cloud nodes don’t have static IP address ranges. Since the infrastructure is dynamic, IPs can change, which might cause some connectivity hiccups or even potential unauthorized access when those IPs shift.
To keep things secure and smooth, LiveKit suggests using user/password authentication instead. However, if IP-based authentication is really important for your setup, the only option would be to allow all IPs using broad CIDR ranges like 0.0.0.0/0, but please keep in mind this does lower security quite a bit. For tighter control, running a self-hosted LiveKit instance with static IPs is definitely the way to go. I’m here to help if you want some guidance on setting that up! Sources:
SIP outbound trunk | LiveKit Docs |
cmd/server/main.go |
pkg/rtcconfig/webrtc_config_test.go