soli-sfu

Install

Use the installer, a release tarball, Docker, or build from source. Each tagged release ships binaries for Linux (amd64, arm64) and macOS (Apple Silicon), each with a SHA-256 checksum.

Installer script

The script detects your platform, downloads the latest release, checks it against the published SHA-256 and refuses to install if the checksum is missing or wrong. It installs to ~/.local/bin, or /usr/local/bin as root or with --system.

curl -sSL https://raw.githubusercontent.com/solisoft/sfu/main/install.sh | sh

# system-wide
curl -sSL https://raw.githubusercontent.com/solisoft/sfu/main/install.sh | sudo sh

Release tarballs

PlatformFile
Linux x86_64soli-sfu-linux-amd64.tar.gz
Linux ARM64soli-sfu-linux-arm64.tar.gz
macOS Apple Siliconsoli-sfu-darwin-arm64.tar.gz
curl -sSLO https://github.com/solisoft/sfu/releases/latest/download/soli-sfu-linux-amd64.tar.gz
curl -sSLO https://github.com/solisoft/sfu/releases/latest/download/soli-sfu-linux-amd64.tar.gz.sha256
echo "$(cat soli-sfu-linux-amd64.tar.gz.sha256)  soli-sfu-linux-amd64.tar.gz" | sha256sum -c
tar xzf soli-sfu-linux-amd64.tar.gz
sudo install -m 755 soli-sfu /usr/local/bin/

Docker

Tagged releases push an image to GHCR. Use host networking: the address in public_ip must really reach the media port, and a NATed bridge breaks ICE.

docker run -d --name soli-sfu \
  --network host \
  -e SOLI_SFU_SECRET=... \
  -e SOLI_SFU_PUBLIC_IP=203.0.113.10 \
  -v /etc/soli/sfu.toml:/etc/soli/sfu.toml:ro \
  ghcr.io/solisoft/sfu:latest

Build from source

A stable Rust toolchain, a C compiler and cmake. The crypto is aws-lc-rs, so there is no OpenSSL to install.

git clone https://github.com/solisoft/sfu
cd sfu
cargo build --release      # target/release/soli-sfu

First run

# 1. copy the example config and set public_ip to the machine's public address
cp config.example.toml sfu.toml

# 2. the same secret as the Soli app that mints tokens
export SOLI_SFU_SECRET=...

# 3. run it
soli-sfu sfu.toml
#   media:   udp 0.0.0.0:3478 (advertised as <public_ip>:3478, ice-lite)
#   control: http://127.0.0.1:9300
  • Open UDP 3478 in the firewall. Do not proxy it.
  • Put soli-proxy in front of :9300 for TLS (see Production).
  • Check it: curl http://127.0.0.1:9300/healthz, then open examples/client.html in two tabs.

Trying it locally

dev.toml binds to loopback and accepts unsigned dev.<user>.<room> tokens, so the test client works without a secret:

cargo run -- dev.toml
open examples/client.html   # in two tabs, same room

Releasing

Every push runs tests, clippy -D warnings, fmt --check and cargo audit. A v* tag that matches the Cargo.toml version drafts a release, builds the three binaries with checksums, publishes it and pushes the Docker image.

git tag v0.1.0 && git push origin v0.1.0