Content-Security-Policy when hosting livekit on a different domain than FLUXER_DOMAIN

(#586) Bug Fixed self-hosting voice

Thread

Comment by @Buco7854
RexSystem 1 vote originally by @Buco7854 on GitHub
If anyone is looking for a temp fix until CSP gets re-adjusted / fixed up and has similar setup as mine where LiveKit runs on VPS with a separate domain then here's what I've done with Caddy running on my VPS. It just makes same livekit instance be reverse proxied on both https://chat.mydomain.tld/livekit* and https://lk.mydomain.tld which solves the problem for the time being.
https://chat.mydomain.tld {
  handle_path /livekit* {
    # Change this to ip:port that LiveKit listens on internally, I run my caddy inside a container.
    # This just means localhost pretty much in Podman lingo.
    reverse_proxy host.containers.internal:7880 {
      header_up Connection "upgrade"
      header_up Upgrade {http.request.header.Upgrade}
      header_up X-Real-IP {remote_host}
    }
  }
  handle {
    # WireGuard tunnel, change this to whatever ip:port you expose your internal HTTP Caddy instance with
    reverse_proxy 10.100.1.3:8777
  }
}
# ...and normal livekit domain just chilling here that Matrix uses.
https://lk.mydomain.tld {
  @jwt_service {
    path /sfu/get* /healthz* /get_token*
  }
  handle @jwt_service {
    reverse_proxy lk-jwt-service:8081 {
      header_up X-Real-IP {remote_host}
    }
  }
  reverse_proxy host.containers.internal:7880 {
    header_up Connection "upgrade"
    header_up Upgrade {http.request.header.Upgrade}
    header_up X-Real-IP {remote_host}
  }
}
This way my single LiveKit instance is still available on lk.mydomain.tld while also being accessible to Fluxer from wss://chat.mydomain.tld/livekit <-- this is the one you add from admin panel after doing this. Hope it helps somebody out.
You can do simpler just force caddy to add csp.
# The beginning of your file...
        handle {
                reverse_proxy app-proxy:8080 {
                        # Here add CSP for Turnstile and external Livekit
                        header_down Content-Security-Policy "script-src "  "script-src 'unsafe-eval' https://challenges.cloudflare.com "
                        header_down Content-Security-Policy "frame-src "   "frame-src https://challenges.cloudflare.com "
                        header_down Content-Security-Policy "connect-src " "connect-src https://lk.domain.com wss://lk.domain.com "
                }
        }
}
:8088 {
        handle_path /api/* {
                reverse_proxy api:8080
        }
Sorry for ident i'm on mobile. You should add those at the same level of staticAsset etc