dazzling-tailor-69241
09/25/2025, 12:04 PMtall-airline-16756
09/25/2025, 12:04 PMtall-airline-16756
09/25/2025, 12:04 PMlivekit.turn.enabled to true.
2. Next, set the TURN domain to match your TLS certificate (for example, <http://turn.myhost.com|turn.myhost.com>) using livekit.turn.domain.
3. Then, configure the TLS port for TURN—this is usually 3478 or 443, depending on your load balancer setup.
4. Don’t forget to provide a TLS secret by specifying livekit.turn.secretName, which should point to a Kubernetes TLS secret containing your certificate and private key for the TURN domain.
5. Set the load balancer type to GKE with loadBalancer.type: gke in your values file.
6. Make sure your firewall rules allow ingress on the TURN/TLS port (like 3478) and the necessary WebRTC UDP/TCP ports.
7. Finally, import your SSL certificate into a Kubernetes Secret in the same namespace using the kubectl create secret tls command.
Here’s a helpful example of the Helm values snippet for GKE:
livekit:
turn:
enabled: true
domain: <http://turn.myhost.com|turn.myhost.com>
tls_port: 3478
secretName: turn-tls-secret
loadBalancer:
type: gke
Once you’ve deployed, point the TURN domain (like <http://turn.myhost.com|turn.myhost.com>) to the address of the TURN service load balancer. To find the TURN service address, just run:
kubectl get --namespace <namespace> service <release-name>-turn
Also, double-check that your GKE cluster allows traffic on the required ports and that your DNS records for the TURN domain are set up correctly. I’m here if you need any more help or want to walk through any of these steps together!
Sources: examples/server-eks.yaml | Deploy to Kubernetes | LiveKit Docsdazzling-tailor-69241
09/25/2025, 12:11 PMtall-airline-16756
09/25/2025, 12:12 PMtls_port in your configuration. The default is 5349, but if you’re not using a load balancer, it’s best to set it to 443 for smoother firewall compatibility.
2. Specify a domain (like <http://turn.myhost.com|turn.myhost.com>) that matches the SSL certificate you’re using for TURN.
3. Provide the TLS certificate and private key files, unless TLS termination is already handled elsewhere (for example, by a load balancer).
Here’s an example to guide you:
turn:
enabled: true
tls_port: 5349
domain: <http://turn.myhost.com|turn.myhost.com>
cert_file: /path/to/turn.crt
key_file: /path/to/turn.key
If you have a load balancer in place, you can actually terminate TLS there and just set external_tls to true. This way, unencrypted traffic can flow on the configured tls_port.
Feel free to reach out if you want me to walk you through any part of this or if you have any other questions!
Sources: Deploying LiveKit | LiveKit Docs | pkg/config/config.go