| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150 |
- #!/bin/bash
- # This Source Code Form is subject to the terms of the Mozilla Public
- # License, v. 2.0. If a copy of the MPL was not distributed with this
- # file, You can obtain one at https://mozilla.org/MPL/2.0/.
- set -e
- # Set password for basic authentication
- if [ "$(echo ${SELKIES_ENABLE_BASIC_AUTH} | tr '[:upper:]' '[:lower:]')" = "true" ] && [ -z "${SELKIES_BASIC_AUTH_PASSWORD}" ]; then export SELKIES_BASIC_AUTH_PASSWORD="${PASSWD}"; fi
- # Set default display
- export DISPLAY="${DISPLAY:-:0}"
- # PipeWire-Pulse server socket path
- export PIPEWIRE_LATENCY="32/48000"
- export XDG_RUNTIME_DIR="${XDG_RUNTIME_DIR:-/tmp}"
- export PIPEWIRE_RUNTIME_DIR="${PIPEWIRE_RUNTIME_DIR:-${XDG_RUNTIME_DIR:-/tmp}}"
- export PULSE_RUNTIME_PATH="${PULSE_RUNTIME_PATH:-${XDG_RUNTIME_DIR:-/tmp}/pulse}"
- export PULSE_SERVER="${PULSE_SERVER:-unix:${PULSE_RUNTIME_PATH:-${XDG_RUNTIME_DIR:-/tmp}/pulse}/native}"
- # Configure NGINX
- if [ "$(echo ${SELKIES_ENABLE_BASIC_AUTH} | tr '[:upper:]' '[:lower:]')" != "false" ]; then htpasswd -bcm "${XDG_RUNTIME_DIR}/.htpasswd" "${SELKIES_BASIC_AUTH_USER:-${USER}}" "${SELKIES_BASIC_AUTH_PASSWORD:-${PASSWD}}"; fi
- echo "# Selkies-GStreamer NGINX Configuration
- access_log /dev/stdout;
- error_log /dev/stderr;
- server {
- listen 8080 $(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"ssl\"; fi);
- listen [::]:8080 $(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"ssl\"; fi);
- ssl_certificate ${SELKIES_HTTPS_CERT-/etc/ssl/certs/ssl-cert-snakeoil.pem};
- ssl_certificate_key ${SELKIES_HTTPS_KEY-/etc/ssl/private/ssl-cert-snakeoil.key};
- $(if [ \"$(echo ${SELKIES_ENABLE_BASIC_AUTH} | tr '[:upper:]' '[:lower:]')\" != \"false\" ]; then printf \"auth_basic_user_file ${XDG_RUNTIME_DIR}/.htpasswd\;\"; fi)
- location / {
- alias /opt/gst-web;
- index index.html index.htm;
- }
- location /health {
- proxy_http_version 1.1;
- proxy_read_timeout 1800s;
- proxy_send_timeout 1800s;
- proxy_connect_timeout 1800s;
- proxy_buffering off;
- client_max_body_size 10M;
- proxy_pass http$(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"s\"; fi)://localhost:8081;
- }
- location /turn {
- proxy_http_version 1.1;
- proxy_read_timeout 1800s;
- proxy_send_timeout 1800s;
- proxy_connect_timeout 1800s;
- proxy_buffering off;
- client_max_body_size 10M;
- proxy_pass http$(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"s\"; fi)://localhost:8081;
- }
- location /ws {
- proxy_set_header Upgrade \$http_upgrade;
- proxy_set_header Connection \"upgrade\";
- proxy_set_header Host \$host;
- proxy_set_header X-Real-IP \$remote_addr;
- proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto \$scheme;
- proxy_http_version 1.1;
- proxy_read_timeout 1800s;
- proxy_send_timeout 1800s;
- proxy_connect_timeout 1800s;
- proxy_buffering off;
- client_max_body_size 10M;
- proxy_pass http$(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"s\"; fi)://localhost:8081;
- }
- location /webrtc/signalling {
- proxy_set_header Upgrade \$http_upgrade;
- proxy_set_header Connection \"upgrade\";
- proxy_set_header Host \$host;
- proxy_set_header X-Real-IP \$remote_addr;
- proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto \$scheme;
- proxy_http_version 1.1;
- proxy_read_timeout 1800s;
- proxy_send_timeout 1800s;
- proxy_connect_timeout 1800s;
- proxy_buffering off;
- client_max_body_size 10M;
- proxy_pass http$(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"s\"; fi)://localhost:8081;
- }
- location /metrics {
- proxy_http_version 1.1;
- proxy_read_timeout 1800s;
- proxy_send_timeout 1800s;
- proxy_connect_timeout 1800s;
- proxy_buffering off;
- client_max_body_size 10M;
- proxy_pass http$(if [ \"$(echo ${SELKIES_ENABLE_HTTPS} | tr '[:upper:]' '[:lower:]')\" = \"true\" ]; then printf \"s\"; fi)://localhost:8081;
- }
- error_page 500 502 503 504 /50x.html;
- location = /50x.html {
- alias /opt/gst-web;
- }
- }" | tee /etc/nginx/sites-available/default > /dev/null
- # Export environment variables required for Selkies-GStreamer
- export GST_DEBUG="${GST_DEBUG:-*:2}"
- export GSTREAMER_PATH=/opt/gstreamer
- # Source environment for GStreamer
- . /opt/gstreamer/gst-env
- export SELKIES_ENCODER="${SELKIES_ENCODER:-x264enc}"
- export SELKIES_ENABLE_RESIZE="${SELKIES_ENABLE_RESIZE:-false}"
- if ( [ -z "${SELKIES_TURN_USERNAME}" ] || [ -z "${SELKIES_TURN_PASSWORD}" ] ) && [ -z "${SELKIES_TURN_SHARED_SECRET}" ] || [ -z "${SELKIES_TURN_HOST}" ] || [ -z "${SELKIES_TURN_PORT}" ]; then
- export TURN_RANDOM_PASSWORD="$(tr -dc 'A-Za-z0-9' < /dev/urandom 2>/dev/null | head -c 24)"
- export SELKIES_TURN_HOST="$(curl -fsSL checkip.amazonaws.com)"
- export SELKIES_TURN_PORT="3478"
- export SELKIES_TURN_USERNAME="selkies"
- export SELKIES_TURN_PASSWORD="${TURN_RANDOM_PASSWORD}"
- /etc/start-turnserver.sh &
- fi
- export SELKIES_TURN_PROTOCOL="${SELKIES_TURN_PROTOCOL:-tcp}"
- # Wait for X server to start
- echo 'Waiting for X Socket' && until [ -S "/tmp/.X11-unix/X${DISPLAY#*:}" ]; do sleep 0.5; done && echo 'X Server is ready'
- # Clear the cache registry
- rm -rf "${HOME}/.cache/gstreamer-1.0"
- # Start the Selkies-GStreamer WebRTC HTML5 remote desktop application
- selkies-gstreamer \
- --addr="0.0.0.0" \
- --port="8081" \
- --enable_basic_auth="false" \
- $@
|