WebRTC deployment guides

Field notes from building and operating a Pion SFU, browser publisher and self-hosted TURN deployment. Each guide starts with the symptom and narrows the cause before proposing a fix.

Why ReplaceTrack succeeds but video never reaches the second SFU

Separate a successful local binding from a negotiated, decodable video path. Check SDP direction, codec compatibility and packet counters in that order.

Read the Pion guide ->

Coturn and Kurento in Docker Compose

A working split between host networking for coturn, Compose networking for Kurento and the Spring Boot service, plus the public-address settings that prevent private IPs in SDP.

Read the deployment guide ->

Coturn use-auth-secret and the missing realm

Diagnose repeated 401 responses, generate valid time-limited credentials and verify the relay without putting a browser in the loop.

Read the TURN authentication guide ->

Start with the failing layer

Most "WebRTC is broken" reports combine several unrelated failures. Signaling can be healthy while the media path is unreachable. ICE can connect while RTP never carries a decodable frame. A TURN allocation can succeed while media ports remain closed.

The guides are organized around that split: transport first, then negotiation, then media. That order is usually faster than changing application code and hoping the symptom changes.

If you want the working reference implementation rather than assembling the pieces yourself, the Low-Latency Kit source package includes the Pion signaling server and SFU, browser publisher and viewer, reconnect chain, diagnostics and deployment notes.

Product overview Source and pricing