GCP Ubuntu 20.04上Docker-Jitsi的TURN服务器配置失败求助
Docker-Jitsi Meet + Nginx + Coturn TURN 服务器完整配置指南
环境与问题概述
在GCP Ubuntu 20.04实例上,通过Docker部署Jitsi Meet测试环境,搭配Nginx反向代理与容器化Coturn TURN服务器,当前存在以下问题:
- Coturn容器启动报错(CLI密码缺失、TLS证书未配置、PID文件权限不足等)
turnserver.conf未同步至Jitsi其他容器(web、jibri等)的共享卷- TURN服务无法正常为Jitsi提供中继功能
现有配置信息
1. Nginx 配置片段
location /xmpp-websocket { proxy_pass https://myapp.one:443; # myapp.one为域名别名 proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } location /colibri-ws { proxy_pass https://myapp.one:443; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; }
2. Coturn Docker Compose 配置
myapp_turnserver: container_name: myapp_turnserver image: coturn/coturn:4.5.2 restart: ${RESTART_POLICY:-unless-stopped} volumes: - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z shm_size: '2gb' cap_add: - SYS_ADMIN networks: meet.myapp: # network_mode: "host" # environment:
3. TURN 凭证信息
TURN_CREDENTIALS=secret TURN_HOST=turnserver.myapp.one TURNS_HOST=turnserver.myapp.one TURN_PORT=443 TURNS_PORT=443
Coturn 容器启动错误日志
myapp_turnserver | 0: : Config file found: //etc/coturn/turnserver.conf myapp_turnserver | 0: : Config file found: //etc/coturn/turnserver.conf myapp_turnserver | 0: : Config file found: //etc/coturn/turnserver.conf myapp_turnserver | 0: : Config file found: //etc/coturn/turnserver.conf myapp_turnserver | 0: : myapp_turnserver | RFC 3489/5389/5766/5780/6062/6156 STUN/TURN Server myapp_turnserver | Version Coturn-4.5.2 'dan Eider' myapp_turnserver | 0: : myapp_turnserver | RFC 3489/5389/5766/5780/6062/6156 STUN/TURN Server myapp_turnserver | Version Coturn-4.5.2 'dan Eider' myapp_turnserver | 0: : myapp_turnserver | Max number of open files/sockets allowed for this process: 1048576 myapp_turnserver | 0: : myapp_turnserver | Max number of open files/sockets allowed for this process: 1048576 myapp_turnserver | 0: : myapp_turnserver | Due to the open files/sockets limitation, myapp_turnserver | max supported number of TURN Sessions possible is: 524000 (approximately) myapp_turnserver | 0: : myapp_turnserver | Due to the open files/sockets limitation, myapp_turnserver | max supported number of TURN Sessions possible is: 524000 (approximately) myapp_turnserver | 0: : myapp_turnserver | myapp_turnserver | ==== Show him the instruments, Practical Frost: ==== myapp_turnserver | myapp_turnserver | 0: : myapp_turnserver | myapp_turnserver | ==== Show him the instruments, Practical Frost: ==== myapp_turnserver | myapp_turnserver | 0: : TLS supported myapp_turnserver | 0: : TLS supported myapp_turnserver | 0: : DTLS supported myapp_turnserver | 0: : DTLS supported myapp_turnserver | 0: : DTLS 1.2 supported myapp_turnserver | 0: : DTLS 1.2 supported myapp_turnserver | 0: : TURN/STUN ALPN supported myapp_turnserver | 0: : TURN/STUN ALPN supported myapp_turnserver | 0: : Third-party authorization (oAuth) supported myapp_turnserver | 0: : Third-party authorization (oAuth) supported myapp_turnserver | 0: : GCM (AEAD) supported myapp_turnserver | 0: : GCM (AEAD) supported myapp_turnserver | 0: : OpenSSL compile-time version: OpenSSL 1.1.1n 15 Mar 2022 (0x101010ef) myapp_turnserver | 0: : OpenSSL compile-time version: OpenSSL 1.1.1n 15 Mar 2022 (0x101010ef) myapp_turnserver | 0: : myapp_turnserver | 0: : myapp_turnserver | 0: : SQLite supported, default database location is /var/lib/coturn/turndb myapp_turnserver | 0: : SQLite supported, default database location is /var/lib/coturn/turndb myapp_turnserver | 0: : Redis supported myapp_turnserver | 0: : Redis supported myapp_turnserver | 0: : PostgreSQL supported myapp_turnserver | 0: : PostgreSQL supported myapp_turnserver | 0: : MySQL supported myapp_turnserver | 0: : MySQL supported myapp_turnserver | 0: : MongoDB supported myapp_turnserver | 0: : MongoDB supported myapp_turnserver | 0: : myapp_turnserver | 0: : myapp_turnserver | 0: : Default Net Engine version: 3 (UDP thread per CPU core) myapp_turnserver | myapp_turnserver | ===================================================== myapp_turnserver | myapp_turnserver | 0: : Default Net Engine version: 3 (UDP thread per CPU core) myapp_turnserver | myapp_turnserver | ===================================================== myapp_turnserver | myapp_turnserver | 0: : Domain name: myapp_turnserver | 0: : Domain name: myapp_turnserver | 0: : Default realm: myapp_turnserver | 0: : Default realm: myapp_turnserver | 0: : ERROR: myapp_turnserver | CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password! myapp_turnserver | 0: : ERROR: myapp_turnserver | CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password! myapp_turnserver | 0: : WARNING: cannot find certificate file: turn_server_cert.pem (1) myapp_turnserver | 0: : WARNING: cannot find certificate file: turn_server_cert.pem (1) myapp_turnserver | 0: : WARNING: cannot start TLS and DTLS listeners because certificate file is not set properly myapp_turnserver | 0: : WARNING: cannot start TLS and DTLS listeners because certificate file is not set properly myapp_turnserver | 0: : WARNING: cannot find private key file: turn_server_pkey.pem (1) myapp_turnserver | 0: : WARNING: cannot find private key file: turn_server_pkey.pem (1) myapp_turnserver | 0: : WARNING: cannot start TLS and DTLS listeners because private key file is not set properly myapp_turnserver | 0: : WARNING: cannot start TLS and DTLS listeners because private key file is not set properly myapp_turnserver | 0: : NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED myapp_turnserver | 0: : NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED myapp_turnserver | 0: : ===========Discovering listener addresses: ========= myapp_turnserver | 0: : ===========Discovering listener addresses: ========= myapp_turnserver | 0: : Listener address to use: 127.0.0.1 myapp_turnserver | 0: : Listener address to use: 127.0.0.1 myapp_turnserver | 0: : Listener address to use: 172.21.0.4 myapp_turnserver | 0: : Listener address to use: 172.21.0.4 myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : Total: 1 'real' addresses discovered myapp_turnserver | 0: : Total: 1 'real' addresses discovered myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED myapp_turnserver | 0: : NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED myapp_turnserver | 0: : ===========Discovering relay addresses: ============= myapp_turnserver | 0: : ===========Discovering relay addresses: ============= myapp_turnserver | 0: : Relay address to use: 172.21.0.4 myapp_turnserver | 0: : Relay address to use: 172.21.0.4 myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : Total: 1 relay addresses discovered myapp_turnserver | 0: : Total: 1 relay addresses discovered myapp_turnserver | Cannot create pid file: /var/run/turnserver.pid: Permission denied myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : ===================================================== myapp_turnserver | 0: : Cannot create pid file: /var/run/turnserver.pid myapp_turnserver | 0: : Cannot create pid file: /var/run/turnserver.pid myapp_turnserver | 0: : pid file created: /var/tmp/turnserver.pid myapp_turnserver | 0: : pid file created: /var/tmp/turnserver.pid myapp_turnserver | 0: : IO method (main listener thread): epoll (with changelist) myapp_turnserver | 0: : IO method (main listener thread): epoll (with changelist) myapp_turnserver | 0: : WARNING: I cannot support STUN CHANGE_REQUEST functionality because only one IP address is provided myapp_turnserver | 0: : WARNING: I cannot support STUN CHANGE_REQUEST functionality because only one IP address is provided myapp_turnserver | 0: : Wait for relay ports initialization... myapp_turnserver | 0: : Wait for relay ports initialization... myapp_turnserver | 0: : relay 172.21.0.4 initialization... myapp_turnserver | 0: : relay 172.21.0.4 initialization... myapp_turnserver | 0: : relay 172.21.0.4 initialization done myapp_turnserver | 0: : relay 172.21.0.4 initialization done myapp_turnserver | 0: : Relay ports initialization done myapp_turnserver | 0: : Relay ports initialization done myapp_turnserver | 0: : IO method (general relay thread): epoll (with changelist) myapp_turnserver | 0: : IO method (general relay thread): epoll (with changelist) myapp_turnserver | 0: : turn server id=1 created myapp_turnserver | 0: : turn server id=1 created myapp_turnserver | 0: : IO method (general relay thread): epoll (with changelist) myapp_turnserver | 0: : IO method (general relay thread): epoll (with changelist) myapp_turnserver | 0: : turn server id=0 created myapp_turnserver | 0: : turn server id=0 created myapp_turnserver | 0: : Total General servers: 2 myapp_turnserver | 0: : Total General servers: 2 myapp_turnserver | 0: : IO method (auth thread): epoll (with changelist) myapp_turnserver | 0: : IO method (auth thread): epoll (with changelist) myapp_turnserver | 0: : IO method (auth thread): epoll (with changelist) myapp_turnserver | 0: : IO method (auth thread): epoll (with changelist) myapp_turnserver | 0: : SQLite DB connection success: /var/lib/coturn/turndb myapp_turnserver | 0: : SQLite DB connection success: /var/lib/coturn/turndb myapp_turnserver | 0: : IO method (admin thread): epoll (with changelist) myapp_turnserver | 0: : IO method (admin thread): epoll (with changelist) myapp_turnserver | 0: : ERROR: myapp_turnserver | Could not start Prometheus collector! myapp_turnserver | 0: : ERROR: myapp_turnserver | Could not start Prometheus collector!
完整修复与配置步骤
1. 解决配置文件同步问题
将Coturn的配置目录挂载到Jitsi集群的共享卷,确保所有容器可访问:
- 修改Docker Compose中Coturn的
volumes配置,新增共享卷挂载:
volumes: - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z - jitsi_shared_config:/etc/coturn/shared:Z # 新增共享卷
- 在Jitsi web容器的
volumes中添加同一份共享卷:
volumes: - jitsi_shared_config:/config/shared:Z
- 创建共享卷(如果不存在):
docker volume create jitsi_shared_config
2. 修正 Coturn 核心配置(turnserver.conf)
替换现有turnserver.conf为以下内容,根据实际域名/IP调整:
# 基础配置 listening-ip=0.0.0.0 relay-ip=172.21.0.4 # 替换为容器内网IP,可通过`docker inspect myapp_turnserver`获取 external-ip=GCP_INSTANCE_PUBLIC_IP/172.21.0.4 # 替换为GCP实例公网IP realm=turnserver.myapp.one server-name=turnserver.myapp.one # CLI 密码(必填) cli-password=your_secure_cli_pass_123 # TLS 配置(适配TURNS) cert=/etc/coturn/cert.pem pkey=/etc/coturn/privkey.pem tls-listening-port=443 # 认证配置 lt-cred-mech user=jitsi:secret # 对应TURN_CREDENTIALS=secret # PID 文件路径(解决权限问题) pidfile=/var/tmp/turnserver.pid # 禁用Prometheus(可选,若不需要监控) no-prometheus
3. 更新 Docker Compose Coturn 服务配置
调整端口映射、证书挂载与网络设置:
myapp_turnserver: container_name: myapp_turnserver image: coturn/coturn:4.5.2 restart: ${RESTART_POLICY:-unless-stopped} volumes: - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z - /etc/letsencrypt/live/turnserver.myapp.one/fullchain.pem:/etc/coturn/cert.pem:Z - /etc/letsencrypt/live
相关产品推荐
相关产品推荐

