Is there a workaround getting static IPs to whitel...
# ask-ai
m
Is there a workaround getting static IPs to whitelist for calling various APIs?
t
Thanks for reaching out, Varun. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
LiveKit Cloud doesn’t offer static outbound IPs for API calls, so traditional IP whitelisting isn’t something we can do in managed environments. But don’t worry! You can still control access using authentication credentials like user/password. If your provider needs IP ranges, you might consider using broad ranges such as 0.0.0.0/0 or splitting them into 0.0.0.0/1 and 128.0.0.0/1 to cover all IPv4 addresses. Now, if you need stricter egress filtering, a great option is to deploy a self-hosted LiveKit instance with static outbound IPs through NAT 1:1 mappings. This means reserving a static public IP in your cloud environment and setting the nat1to1_ip field in LiveKit’s YAML configuration. This way, your outbound IPs become predictable and can be whitelisted easily. Would you like me to walk you through setting up a self-hosted instance or help with configuring NAT 1:1 mappings? I’m here to assist! Sources: SIP outbound trunk | LiveKit Docs | pkg/sip/config.go | pkg/rtc/transport.go | pkg/rtcconfig/webrtc_config.go | Firewall Tips
m
Why is dynamic IPs not feasible?
t
Dynamic IPs can be a bit tricky when it comes to API whitelisting in LiveKit because the LiveKit Cloud nodes don’t have static IP address ranges. Since the infrastructure is dynamic, IPs can change, which might cause some connectivity hiccups or even potential unauthorized access when those IPs shift. To keep things secure and smooth, LiveKit suggests using user/password authentication instead. However, if IP-based authentication is really important for your setup, the only option would be to allow all IPs using broad CIDR ranges like 0.0.0.0/0, but please keep in mind this does lower security quite a bit. For tighter control, running a self-hosted LiveKit instance with static IPs is definitely the way to go. I’m here to help if you want some guidance on setting that up! Sources: SIP outbound trunk | LiveKit Docs | cmd/server/main.go | pkg/rtcconfig/webrtc_config_test.go