If anyone is looking for a temp fix until CSP gets re-adjusted / fixed up and has similar setup as mine where LiveKit runs on VPS with a separate domain then here's what I've done with Caddy running on my VPS. It just makes same livekit instance be reverse proxied on both https://chat.mydomain.tld/livekit* and https://lk.mydomain.tld which solves the problem for the time being.
https://chat.mydomain.tld {
handle_path /livekit* {
# Change this to ip:port that LiveKit listens on internally, I run my caddy inside a container.
# This just means localhost pretty much in Podman lingo.
reverse_proxy host.containers.internal:7880 {
header_up Connection "upgrade"
header_up Upgrade {http.request.header.Upgrade}
header_up X-Real-IP {remote_host}
}
}
handle {
# WireGuard tunnel, change this to whatever ip:port you expose your internal HTTP Caddy instance with
reverse_proxy 10.100.1.3:8777
}
}
# ...and normal livekit domain just chilling here that Matrix uses.
https://lk.mydomain.tld {
@jwt_service {
path /sfu/get* /healthz* /get_token*
}
handle @jwt_service {
reverse_proxy lk-jwt-service:8081 {
header_up X-Real-IP {remote_host}
}
}
reverse_proxy host.containers.internal:7880 {
header_up Connection "upgrade"
header_up Upgrade {http.request.header.Upgrade}
header_up X-Real-IP {remote_host}
}
}
This way my single LiveKit instance is still available on lk.mydomain.tld while also being accessible to Fluxer from wss://chat.mydomain.tld/livekit <-- this is the one you add from admin panel after doing this. Hope it helps somebody out.
You can do simpler just force caddy to add csp.
# The beginning of your file...
handle {
reverse_proxy app-proxy:8080 {
# Here add CSP for Turnstile and external Livekit
header_down Content-Security-Policy "script-src " "script-src 'unsafe-eval' https://challenges.cloudflare.com "
header_down Content-Security-Policy "frame-src " "frame-src https://challenges.cloudflare.com "
header_down Content-Security-Policy "connect-src " "connect-src https://lk.domain.com wss://lk.domain.com "
}
}
}
:8088 {
handle_path /api/* {
reverse_proxy api:8080
}
Sorry for ident i'm on mobile. You should add those at the same level of staticAsset etc
Thread
Comment by @Buco7854