You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Ubuntu 20.04上Docker-Jitsi的TURN服务器配置失败求助

Docker-Jitsi Meet + Nginx + Coturn TURN 服务器完整配置指南

环境与问题概述

在GCP Ubuntu 20.04实例上,通过Docker部署Jitsi Meet测试环境,搭配Nginx反向代理与容器化Coturn TURN服务器,当前存在以下问题:

  • Coturn容器启动报错(CLI密码缺失、TLS证书未配置、PID文件权限不足等)
  • turnserver.conf未同步至Jitsi其他容器(web、jibri等)的共享卷
  • TURN服务无法正常为Jitsi提供中继功能

现有配置信息

1. Nginx 配置片段

location /xmpp-websocket {
    proxy_pass https://myapp.one:443; # myapp.one为域名别名
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
}

location /colibri-ws {
    proxy_pass https://myapp.one:443;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
}

2. Coturn Docker Compose 配置

myapp_turnserver:
        container_name: myapp_turnserver
        image: coturn/coturn:4.5.2
        restart: ${RESTART_POLICY:-unless-stopped}
        volumes:
            - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z
        shm_size: '2gb'
        cap_add:
            - SYS_ADMIN
        networks:
            meet.myapp:
        # network_mode: "host"      
        # environment:

3. TURN 凭证信息

TURN_CREDENTIALS=secret
TURN_HOST=turnserver.myapp.one
TURNS_HOST=turnserver.myapp.one
TURN_PORT=443
TURNS_PORT=443

Coturn 容器启动错误日志

myapp_turnserver          | 0: : Config file found: //etc/coturn/turnserver.conf
myapp_turnserver          | 0: : Config file found: //etc/coturn/turnserver.conf
myapp_turnserver          | 0: : Config file found: //etc/coturn/turnserver.conf
myapp_turnserver          | 0: : Config file found: //etc/coturn/turnserver.conf
myapp_turnserver          | 0: : 
myapp_turnserver          | RFC 3489/5389/5766/5780/6062/6156 STUN/TURN Server
myapp_turnserver          | Version Coturn-4.5.2 'dan Eider'
myapp_turnserver          | 0: : 
myapp_turnserver          | RFC 3489/5389/5766/5780/6062/6156 STUN/TURN Server
myapp_turnserver          | Version Coturn-4.5.2 'dan Eider'
myapp_turnserver          | 0: : 
myapp_turnserver          | Max number of open files/sockets allowed for this process: 1048576
myapp_turnserver          | 0: : 
myapp_turnserver          | Max number of open files/sockets allowed for this process: 1048576
myapp_turnserver          | 0: : 
myapp_turnserver          | Due to the open files/sockets limitation,
myapp_turnserver          | max supported number of TURN Sessions possible is: 524000 (approximately)
myapp_turnserver          | 0: : 
myapp_turnserver          | Due to the open files/sockets limitation,
myapp_turnserver          | max supported number of TURN Sessions possible is: 524000 (approximately)
myapp_turnserver          | 0: : 
myapp_turnserver          | 
myapp_turnserver          | ==== Show him the instruments, Practical Frost: ====
myapp_turnserver          | 
myapp_turnserver          | 0: : 
myapp_turnserver          | 
myapp_turnserver          | ==== Show him the instruments, Practical Frost: ====
myapp_turnserver          | 
myapp_turnserver          | 0: : TLS supported
myapp_turnserver          | 0: : TLS supported
myapp_turnserver          | 0: : DTLS supported
myapp_turnserver          | 0: : DTLS supported
myapp_turnserver          | 0: : DTLS 1.2 supported
myapp_turnserver          | 0: : DTLS 1.2 supported
myapp_turnserver          | 0: : TURN/STUN ALPN supported
myapp_turnserver          | 0: : TURN/STUN ALPN supported
myapp_turnserver          | 0: : Third-party authorization (oAuth) supported
myapp_turnserver          | 0: : Third-party authorization (oAuth) supported
myapp_turnserver          | 0: : GCM (AEAD) supported
myapp_turnserver          | 0: : GCM (AEAD) supported
myapp_turnserver          | 0: : OpenSSL compile-time version: OpenSSL 1.1.1n  15 Mar 2022 (0x101010ef)
myapp_turnserver          | 0: : OpenSSL compile-time version: OpenSSL 1.1.1n  15 Mar 2022 (0x101010ef)
myapp_turnserver          | 0: : 
myapp_turnserver          | 0: : 
myapp_turnserver          | 0: : SQLite supported, default database location is /var/lib/coturn/turndb
myapp_turnserver          | 0: : SQLite supported, default database location is /var/lib/coturn/turndb
myapp_turnserver          | 0: : Redis supported
myapp_turnserver          | 0: : Redis supported
myapp_turnserver          | 0: : PostgreSQL supported
myapp_turnserver          | 0: : PostgreSQL supported
myapp_turnserver          | 0: : MySQL supported
myapp_turnserver          | 0: : MySQL supported
myapp_turnserver          | 0: : MongoDB supported
myapp_turnserver          | 0: : MongoDB supported
myapp_turnserver          | 0: : 
myapp_turnserver          | 0: : 
myapp_turnserver          | 0: : Default Net Engine version: 3 (UDP thread per CPU core)
myapp_turnserver          | 
myapp_turnserver          | =====================================================
myapp_turnserver          | 
myapp_turnserver          | 0: : Default Net Engine version: 3 (UDP thread per CPU core)
myapp_turnserver          | 
myapp_turnserver          | =====================================================
myapp_turnserver          | 
myapp_turnserver          | 0: : Domain name: 
myapp_turnserver          | 0: : Domain name: 
myapp_turnserver          | 0: : Default realm: 
myapp_turnserver          | 0: : Default realm: 
myapp_turnserver          | 0: : ERROR: 
myapp_turnserver          | CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password!
myapp_turnserver          | 0: : ERROR: 
myapp_turnserver          | CONFIG ERROR: Empty cli-password, and so telnet cli interface is disabled! Please set a non empty cli-password!
myapp_turnserver          | 0: : WARNING: cannot find certificate file: turn_server_cert.pem (1)
myapp_turnserver          | 0: : WARNING: cannot find certificate file: turn_server_cert.pem (1)
myapp_turnserver          | 0: : WARNING: cannot start TLS and DTLS listeners because certificate file is not set properly
myapp_turnserver          | 0: : WARNING: cannot start TLS and DTLS listeners because certificate file is not set properly
myapp_turnserver          | 0: : WARNING: cannot find private key file: turn_server_pkey.pem (1)
myapp_turnserver          | 0: : WARNING: cannot find private key file: turn_server_pkey.pem (1)
myapp_turnserver          | 0: : WARNING: cannot start TLS and DTLS listeners because private key file is not set properly
myapp_turnserver          | 0: : WARNING: cannot start TLS and DTLS listeners because private key file is not set properly
myapp_turnserver          | 0: : NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED
myapp_turnserver          | 0: : NO EXPLICIT LISTENER ADDRESS(ES) ARE CONFIGURED
myapp_turnserver          | 0: : ===========Discovering listener addresses: =========
myapp_turnserver          | 0: : ===========Discovering listener addresses: =========
myapp_turnserver          | 0: : Listener address to use: 127.0.0.1
myapp_turnserver          | 0: : Listener address to use: 127.0.0.1
myapp_turnserver          | 0: : Listener address to use: 172.21.0.4
myapp_turnserver          | 0: : Listener address to use: 172.21.0.4
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : Total: 1 'real' addresses discovered
myapp_turnserver          | 0: : Total: 1 'real' addresses discovered
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED
myapp_turnserver          | 0: : NO EXPLICIT RELAY ADDRESS(ES) ARE CONFIGURED
myapp_turnserver          | 0: : ===========Discovering relay addresses: =============
myapp_turnserver          | 0: : ===========Discovering relay addresses: =============
myapp_turnserver          | 0: : Relay address to use: 172.21.0.4
myapp_turnserver          | 0: : Relay address to use: 172.21.0.4
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : Total: 1 relay addresses discovered
myapp_turnserver          | 0: : Total: 1 relay addresses discovered
myapp_turnserver          | Cannot create pid file: /var/run/turnserver.pid: Permission denied
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : =====================================================
myapp_turnserver          | 0: : Cannot create pid file: /var/run/turnserver.pid
myapp_turnserver          | 0: : Cannot create pid file: /var/run/turnserver.pid
myapp_turnserver          | 0: : pid file created: /var/tmp/turnserver.pid
myapp_turnserver          | 0: : pid file created: /var/tmp/turnserver.pid
myapp_turnserver          | 0: : IO method (main listener thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (main listener thread): epoll (with changelist)
myapp_turnserver          | 0: : WARNING: I cannot support STUN CHANGE_REQUEST functionality because only one IP address is provided
myapp_turnserver          | 0: : WARNING: I cannot support STUN CHANGE_REQUEST functionality because only one IP address is provided
myapp_turnserver          | 0: : Wait for relay ports initialization...
myapp_turnserver          | 0: : Wait for relay ports initialization...
myapp_turnserver          | 0: :   relay 172.21.0.4 initialization...
myapp_turnserver          | 0: :   relay 172.21.0.4 initialization...
myapp_turnserver          | 0: :   relay 172.21.0.4 initialization done
myapp_turnserver          | 0: :   relay 172.21.0.4 initialization done
myapp_turnserver          | 0: : Relay ports initialization done
myapp_turnserver          | 0: : Relay ports initialization done
myapp_turnserver          | 0: : IO method (general relay thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (general relay thread): epoll (with changelist)
myapp_turnserver          | 0: : turn server id=1 created
myapp_turnserver          | 0: : turn server id=1 created
myapp_turnserver          | 0: : IO method (general relay thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (general relay thread): epoll (with changelist)
myapp_turnserver          | 0: : turn server id=0 created
myapp_turnserver          | 0: : turn server id=0 created
myapp_turnserver          | 0: : Total General servers: 2
myapp_turnserver          | 0: : Total General servers: 2
myapp_turnserver          | 0: : IO method (auth thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (auth thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (auth thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (auth thread): epoll (with changelist)
myapp_turnserver          | 0: : SQLite DB connection success: /var/lib/coturn/turndb
myapp_turnserver          | 0: : SQLite DB connection success: /var/lib/coturn/turndb
myapp_turnserver          | 0: : IO method (admin thread): epoll (with changelist)
myapp_turnserver          | 0: : IO method (admin thread): epoll (with changelist)
myapp_turnserver          | 0: : ERROR: 
myapp_turnserver          | Could not start Prometheus collector!
myapp_turnserver          | 0: : ERROR: 
myapp_turnserver          | Could not start Prometheus collector!

完整修复与配置步骤

1. 解决配置文件同步问题

将Coturn的配置目录挂载到Jitsi集群的共享卷,确保所有容器可访问:

  • 修改Docker Compose中Coturn的volumes配置,新增共享卷挂载:
volumes:
    - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z
    - jitsi_shared_config:/etc/coturn/shared:Z # 新增共享卷
  • 在Jitsi web容器的volumes中添加同一份共享卷:
volumes:
    - jitsi_shared_config:/config/shared:Z
  • 创建共享卷(如果不存在):
docker volume create jitsi_shared_config

2. 修正 Coturn 核心配置(turnserver.conf)

替换现有turnserver.conf为以下内容,根据实际域名/IP调整:

# 基础配置
listening-ip=0.0.0.0
relay-ip=172.21.0.4 # 替换为容器内网IP,可通过`docker inspect myapp_turnserver`获取
external-ip=GCP_INSTANCE_PUBLIC_IP/172.21.0.4 # 替换为GCP实例公网IP
realm=turnserver.myapp.one
server-name=turnserver.myapp.one

# CLI 密码(必填)
cli-password=your_secure_cli_pass_123

# TLS 配置(适配TURNS)
cert=/etc/coturn/cert.pem
pkey=/etc/coturn/privkey.pem
tls-listening-port=443

# 认证配置
lt-cred-mech
user=jitsi:secret # 对应TURN_CREDENTIALS=secret

# PID 文件路径(解决权限问题)
pidfile=/var/tmp/turnserver.pid

# 禁用Prometheus(可选,若不需要监控)
no-prometheus

3. 更新 Docker Compose Coturn 服务配置

调整端口映射、证书挂载与网络设置:

myapp_turnserver:
        container_name: myapp_turnserver
        image: coturn/coturn:4.5.2
        restart: ${RESTART_POLICY:-unless-stopped}
        volumes:
            - ${CONFIG}/coturn/turnserver.conf:/etc/coturn/turnserver.conf:Z
            - /etc/letsencrypt/live/turnserver.myapp.one/fullchain.pem:/etc/coturn/cert.pem:Z
            - /etc/letsencrypt/live
相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 04:45:41