how to setup the built in turn server in gcp gke
# ask-ai
d
how to setup the built in turn server in gcp gke
t
Thanks for reaching out, Othmane. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
I'm here to help you set up the built-in TURN server in GCP GKE for LiveKit! Just follow these steps, and if you have any questions along the way, feel free to ask: 1. First, enable the TURN server in your Helm values by setting
livekit.turn.enabled
to
true
. 2. Next, set the TURN domain to match your TLS certificate (for example,
<http://turn.myhost.com|turn.myhost.com>
) using
livekit.turn.domain
. 3. Then, configure the TLS port for TURN—this is usually
3478
or
443
, depending on your load balancer setup. 4. Don’t forget to provide a TLS secret by specifying
livekit.turn.secretName
, which should point to a Kubernetes TLS secret containing your certificate and private key for the TURN domain. 5. Set the load balancer type to GKE with
loadBalancer.type: gke
in your values file. 6. Make sure your firewall rules allow ingress on the TURN/TLS port (like 3478) and the necessary WebRTC UDP/TCP ports. 7. Finally, import your SSL certificate into a Kubernetes Secret in the same namespace using the
kubectl create secret tls
command. Here’s a helpful example of the Helm values snippet for GKE:
Copy code
livekit:
  turn:
    enabled: true
    domain: <http://turn.myhost.com|turn.myhost.com>
    tls_port: 3478
    secretName: turn-tls-secret
loadBalancer:
  type: gke
Once you’ve deployed, point the TURN domain (like
<http://turn.myhost.com|turn.myhost.com>
) to the address of the TURN service load balancer. To find the TURN service address, just run:
Copy code
kubectl get --namespace <namespace> service <release-name>-turn
Also, double-check that your GKE cluster allows traffic on the required ports and that your DNS records for the TURN domain are set up correctly. I’m here if you need any more help or want to walk through any of these steps together! Sources: examples/server-eks.yaml | Deploy to Kubernetes | LiveKit Docs
d
what do you mean by configure TLS port for turn
t
Configuring the TLS port for TURN is a great step to ensure your media relay traffic is securely transmitted over TLS (Transport Layer Security). This really helps when you’re trying to get through restrictive firewalls, since TURN/TLS traffic looks just like regular HTTPS traffic. Here’s a simple breakdown of what you’ll need to do: 1. Set the
tls_port
in your configuration. The default is
5349
, but if you’re not using a load balancer, it’s best to set it to
443
for smoother firewall compatibility. 2. Specify a domain (like
<http://turn.myhost.com|turn.myhost.com>
) that matches the SSL certificate you’re using for TURN. 3. Provide the TLS certificate and private key files, unless TLS termination is already handled elsewhere (for example, by a load balancer). Here’s an example to guide you:
Copy code
turn:
  enabled: true
  tls_port: 5349
  domain: <http://turn.myhost.com|turn.myhost.com>
  cert_file: /path/to/turn.crt
  key_file: /path/to/turn.key
If you have a load balancer in place, you can actually terminate TLS there and just set
external_tls
to
true
. This way, unencrypted traffic can flow on the configured
tls_port
. Feel free to reach out if you want me to walk you through any part of this or if you have any other questions! Sources: Deploying LiveKit | LiveKit Docs | pkg/config/config.go