{"id":10173,"date":"2020-03-20T21:27:14","date_gmt":"2020-03-20T21:27:14","guid":{"rendered":"https:\/\/merikebi.warrenmyers.com\/?p=10173"},"modified":"2020-03-20T21:27:14","modified_gmt":"2020-03-20T21:27:14","slug":"basic-dockerized-jitsi-deployment-with-an-apache-reverse-proxy-on-centos","status":"publish","type":"post","link":"https:\/\/merikebi.warrenmyers.com\/?p=10173","title":{"rendered":"basic dockerized jitsi deployment with an apache reverse proxy on centos"},"content":{"rendered":"<p>After a <a href=\"http:\/\/skhtec.cf\">friend<\/a> of mine told me he wanted to deploy <a href=\"\/\/jitsi.org\">Jitsi<\/a> on my main webserver, and me saying &#8220;sure&#8221;, I decided I wanted to get it up and running on a new server both so <em>I<\/em> knew how to do it, and to avoid the latency issues of videoconferencing from central North America to <a href=\"\/\/hetzner.com\">Germany<\/a> and back.<\/p>\n<p>Before I go into how I got it working, let me say that the official <a href=\"https:\/\/github.com\/jitsi\/docker-jitsi-meet#quick-start\">Quick Start guide<\/a> is good &#8211; but it doesn&#8217;t cover anything <em>but<\/em> itself.<\/p>\n<p>Here&#8217;s the basic setup:<\/p>\n<ul>\n<li><a href=\"https:\/\/antipaucity.com\/?s=centos&amp;submit.x=0&amp;submit.y=0#.XnUqEm4pChY\">CentOS<\/a> 7<\/li>\n<li><a href=\"http:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=Docker\">Docker<\/a><\/li>\n<li>Apache 2.4<\/li>\n<\/ul>\n<h4>What To Do:<\/h4>\n<p>Once you have your new CentOS instance up and running (I used <a href=\"http:\/\/www.vultr.com\/?ref=7190952\">Vultr<\/a>), here&#8217;s everything you need to install:<\/p>\n<p><code>yum -y install epel-release &amp;&amp; yum -y upgrade &amp;&amp; yum -y install httpd docker docker-compose screen bind-utils certbot git haveged net-tools mod_ssl <\/code><\/p>\n<p>I also installed a few other things, but that&#8217;s because I&#8217;m multi-purposing this server for <a href=\"https:\/\/antipaucity.com\/2018\/07\/18\/a-fairly-comprehensive-squid-configuration-for-proxying-all-the-http-things\/#.XnUnV24pChY\">Squid<\/a>, and other things, too.<\/p>\n<p>Enable Apache, firewalld, &amp; Docker:<\/p>\n<p><code>systemctl enable httpd &amp;&amp; systemctl enable docker &amp;&amp; systemctl enable firewalld<\/code><\/p>\n<p>Now get your swap space setup:<\/p>\n<p><code>fallocate -l 4G \/swapfile &amp;&amp; chmod 0600 \/swapfile &amp;&amp; mkswap \/swapfil &amp;&amp; swapon \/swapfile<\/code><\/p>\n<p>Add the following line to the bottom of your <code>\/etc\/fstab<\/code>:<\/p>\n<p><code>\/swapfile swap swap default 0 0<\/code><\/p>\n<p>Restart your VPS:<\/p>\n<p><code>shutdown -r now<\/code><\/p>\n<p>Get your cert from Let&#8217;s Encrypt (make sure you&#8217;ve already setup appropriate <a href=\"https:\/\/support.dnsimple.com\/articles\/caa-record\/\">CAA<\/a> &amp; A records for your domain and any subdomains you want to use):<\/p>\n<p><code>certbot -t -n --agree-tos --keep --expand --standalone certonly --must-staple --rsa-key-size 4096 --preferred-challenges dns-01,http-01 -m &lt;user&gt;@&lt;domain.tld&gt; -d &lt;jitsi.yourdomain.tld&gt;<\/code><\/p>\n<p>Create a root crontab entry to run <a href=\"https:\/\/antipaucity.com\/2020\/02\/18\/next-update-keeping-your-lets-encrypt-certs-up-to-date\/#.XnUqbm4pChY\">certbot<\/a> frequently (I do <code>@weekly ~\/renew-le.sh<\/code>)<\/p>\n<p>Go to the home directory of whatever user you plan to run Jitsi as:<\/p>\n<p><code>su - &lt;jitsi-user&gt;<\/code><\/p>\n<p>Begin the Quick Start directions:<\/p>\n<ul>\n<li><code>git clone https:\/\/github.com\/jitsi\/docker-jitsi-meet &amp;&amp; cd docker-jitsi-meet<\/code><\/li>\n<li><code>mv env.example .env<\/code><\/li>\n<li>Change the timezone in <code>.env<\/code> from <code>Europe\/Amsterdam<\/code> if you want it to show up in a sane timezone (like <code>Etc\/UTC<\/code>)<\/li>\n<li><code>mkdir -p ~\/.jitsi-meet-cfg\/{web\/letsencrypt,transcripts,prosody,jicofo,jvb}<\/code><\/li>\n<li><code>docker-compose up -d<\/code><\/li>\n<\/ul>\n<p>Now configure <a href=\"http:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=Apache\">Apache<\/a> for SSL. Start with this <a href=\"https:\/\/antipaucity.com\/2017\/07\/07\/ssl-configuration-for-apache-2-4-on-centos-7-with-lets-encrypt\/#.XnUrFG4pChY\">reference<\/a> I posted.<\/p>\n<p>But in the [sub]domain-specific conf file <code>z-[sub]domain-tld.conf<\/code>, add proxy and authentication lines (so that only people <em>you<\/em> allow to use your video conference can actually use it):<\/p>\n<pre class=\"wp-block-preformatted\">ProxyPreserveHost on\nProxyPass \/ http:\/\/localhost:8000\/ nocanon\nProxyPassReverse \/ http:\/\/localhost:8000\/\nProxyRequests       off\nServerAdmin warren@warrenmyers.com\nAllowEncodedSlashes NoDecode\n&lt;Proxy http:\/\/localhost:8000\/*&gt;\n    Order deny,allow\n    Allow from all\n    Authtype Basic\n    Authname \"Password Required\"\n    AuthUserFile \/etc\/httpd\/.htpasswd\n    Require valid-user\n&lt;\/Proxy&gt;\nRewriteEngine       on\nRewriteRule        ^\/meetwith\/(.*)$ http:\/\/%{HTTP_HOST}\/$1 [P]\nProxyPassReverseCookiePath \/meetwith \/<\/pre>\n<pre><p><\/p><\/pre>\n<p>Reload your configs, and make sure they&#8217;re happy, fixing any errors that may exist:<\/p>\n<p><code>apachectl graceful<\/code><\/p>\n<p>Setup at least one user who&#8217;ll be able to access the site:<\/p>\n<p><code>htpasswd -B -c \/etc\/httpd\/.htpasswd &lt;user><\/code><\/p>\n<p>You should also configure <a href=\"http:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=firewalld\">firewalld<\/a> to allow <em>only<\/em> what you want (http, https, ssh):<\/p>\n<p><code>firewall-cmd --zone=public --add-service=http &amp;&amp; firewall-cmd --zone=public --add-service=https &amp;&amp; firewall-cmd --zone=public --add-service=ssh<\/code><\/p>\n<p>With any luck, when you now navigate to https:\/\/[sub.]domain.tld in your web browser, and enter your username and password you created with <code>htpasswd<\/code>, you&#8217;ll get the Jitsi welcome page!<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-1024x602.png\" alt=\"\" class=\"wp-image-3484\" width=\"512\" height=\"301\" srcset=\"https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-1024x602.png 1024w, https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-300x176.png 300w, https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-768x451.png 768w, https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-1536x903.png 1536w, https:\/\/antipaucity.com\/wp-content\/uploads\/2020\/03\/Screen-Shot-2020-03-20-at-17.00.46-2048x1203.png 2048w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/figure>\n<h4>Other Resources:<\/h4>\n<ul>\n<li>Check out the Jitsi subreddit &#8211; <a href=\"\/\/reddit.com\/r\/jitsi\/new\">r\/jitsi<\/a><\/li>\n<li>Jitsi on Twitter: <a href=\"https:\/\/twitter.com\/jitsinews\">@jitsinews<\/a><\/li>\n<\/ul>\n<p>from antipaucity https:\/\/antipaucity.com\/2020\/03\/20\/basic-dockerized-jitsi-deployment-with-an-apache-reverse-proxy-on-centos\/<br \/>\nvia <a href=\"https:\/\/ifttt.com\/?ref=da&#038;site=wordpress\">IFTTT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After a friend of mine told me he wanted to deploy Jitsi on my main webserver, and me saying &#8220;sure&#8221;, I decided I wanted to get it up and running on a new server both so I knew how to do it, and to avoid the latency issues of videoconferencing from central North America to &hellip;<br \/><a href=\"https:\/\/merikebi.warrenmyers.com\/?p=10173\" class=\"more-link pen_button pen_element_default pen_icon_arrow_double\">Continue reading <span class=\"screen-reader-text\">basic dockerized jitsi deployment with an apache reverse proxy on centos<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[95],"keyring_services":[],"class_list":["post-10173","post","type-post","status-publish","format-standard","hentry","category-blih","tag-antipaucity"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10173"}],"version-history":[{"count":1,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10173\/revisions"}],"predecessor-version":[{"id":10174,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/10173\/revisions\/10174"}],"wp:attachment":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10173"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fkeyring_services&post=10173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}