Production setup

1. Choose a cloud hosting provider:
Choose a host with enough CPU, memory, disk space, and bandwidth for the expected recording and playback load.

2. Set up a machine:
Set up a Linux machine or virtual machine, such as Ubuntu, with Docker Engine and Docker Compose installed.\

3. Configure the firewall to allow the required service ports from the intended client networks. See the Docker firewall notes below.

A deployment behind an HTTPS reverse proxy uses the following access ports:\

VOD

Port Description
443 HTTPS access to the server

Live

For direct udp streams ingress open the ports specified in the platforms configuration, for example:

Port Description
30120-30130 (udp) Stream channels udp ports - default platform configuration

For SRT ingress open the ports specified in the srt listener, for example:

Port Description
4200-4210 (udp) Stream channels srt listener ports

4. Create a local folder (for example, ~/stserver/).

Create a new folder for the server, change the ownership to your user and then enter the directory you created.

    sudo mkdir stserver
    sudo chown -R yourUser:yourGroup stserver
    cd stserver

5. Download the setup.

Download the stserver-install.tar.gz file from the STANAG On Demand Server github repository website or use the command:

    wget https://github.com/impleotv/stserver-release/releases/download/v3.6.8/stserver-install.tar.gz

Extract files:

    tar -xvf stserver-install.tar.gz

6. In a terminal, change the directory to the location of docker-compose-production.yml file.

Edit .env file.

Warning
In the .env file, there are some directories where the content will be stored, like ~/videos/. Create the directories and make sure the server (Docker) has the permission to write to these directories.

Configure the environment variables:

Enable reverse proxy in the .env file:

USING_REVERSE_PROXY=true

Uncomment the following line and set up the domain

SERVER_DOMAIN=mydomain.com  

If you want to use reverse proxy without domain, you can set the IP address of the host:

SERVER_DOMAIN=50.16.0.24 

7. Configure DNS:
Once your server backend is ready and Cloudflare or a reverse proxy is set up, configure your DNS records to point to your server's IP address or domain name.

8. Install the necessary software:

Once your VM is set up, you'll need to install the necessary software to run your backend application.

Configure SSL/TLS: To secure traffic between the client and the server, you should set up SSL/TLS encryption. You can obtain SSL/TLS certificates from a certificate authority (CA) like Let's Encrypt or purchase them from a commercial provider. Or you can use Cloudflare to provide additional security and performance benefits. Cloudflare offers DDoS protection, caching, and SSL/TLS encryption

9. Start all the services by running docker-compose:

You can use this file docker-compose-production.yml (with -f arg) or simply rename the file to docker-compose.yml, so docker compose can be used with defaults.

docker compose -f docker-compose-production.yml up -d

or, if you have an old version of Docker Compose, run

docker-compose -f docker-compose-production.yml up -d

If you renamed the file to docker-compose.yml, just use

docker compose up -d

When you run this for the first time, docker will download the required images and start containers.

When the docker finishes downloading and starts the containers, restart the server.

docker compose down
docker compose up -d

Test your setup: Finally, test your server backend by accessing it through a web browser or API client. Make sure that all functionality is working correctly and that SSL/TLS encryption is properly configured.

The services should now be running.\

Docker and host firewall rules

Docker-published ports on bridge networks can bypass UFW rules. Review the rules for the Docker firewall backend in use and test access from another host. For the iptables backend, Docker documents filtering forwarded container traffic through the DOCKER-USER chain. Host-network services need appropriate host firewall rules.

Do not disable Docker’s firewall rule management as a general UFW workaround: it can break container networking. See Docker’s packet filtering and firewall documentation.