Summary
In my setup i have Fluxer installed on a local server and I forward traffic using netbird to my VPS and expose it using Netbirds reverse proxy feature to the internet.
When trying to connect to a voice chat the console throws the error:
`
Content-Security-Policy: The page’s settings blocked the loading of a resource (connect-src) at wss://livekit-tcp.mydomain.com:7881/rtc/v1 because it violates the following directive: “connect-src 'self' data:
https://*.fluxer.app/ wss://
.fluxer.app https://.fluxer.media wss://
.fluxer.media https://fluxer-uploads.ewr1.vultrobjects.com/ https://hcaptcha.com/ https://.hcaptcha.com
https://fluxerstatus.com/ https://fluxer.media/ http://127.0.0.1:21863/ http://127.0.0.1:21864/ https://chat.mydomain.com/ https://chat.mydomain.com/media%E2%80%9D
`
The reason for this issue is that Netbird doesnt allow multiple services of different type (TCP, UDP, HTTPS) exposed on the same subdomain, thus I am forced to put LiveKit's TCP and UDP ports on different subdomains.
From my understanding, the fluxer code hardcodes the allowed address for connections to be only the FLUXER_DOMAIN. This is obviously also a Netbird issue but nontheless could be fixed by allowing extra domains via a new environment variable.
Steps to reproduce
- Default installation of selfhosted Fluxer
- .env with changes:
FLUXER_PUBLIC_SCHEME=httpsFLUXER_PUBLIC_PORT=443FLUXER_CADDY_SITE_ADDRESS=:80 - livekit.yaml changes:
use_external_ip: falsenode_ip: ip_of_netbird_vps - Configured Voice region and voice server in admin panel. Endpoint was set to:
wss://livekit-tcp.proxy.mydomain.com:7881. Other domain combinations (with and without port, direct ip adress of vps, just mydomain.com etc.) were all tried with no success. - Netbird reverse proxy exposes fluxer http service under subdomain chat.mydomain.com and 7881/tcp and 7882/udp are exposed under livekit-tcp.mydomain.com and livekit-udp.mydomain.com respectivly
Environment
OS: Ubuntu 26.04 LXC on Proxmox
Browser: Zen Browser (Firefox)
Device: Windows 11
Logs or screenshots
`{"level":"info","time":"2026-06-16T11:09:29.811Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":14,"msg":"Request completed"}
{"level":"info","time":"2026-06-16T11:09:59.869Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}
{"level":"error","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","error":{"type":"TypeError","message":"fetch failed: connect ECONNREFUSED vps_ip_address:7881","stack":"TypeError: fetch failed\ncaused by: Error: connect ECONNREFUSED vps_ip_address:7881\n at TCPConnectWrap.afterConnect [as oncomplete] (node:net:1705:16)"},"msg":"Error disconnecting LiveKit participant"}
{"level":"info","time":"2026-06-16T11:10:00.413Z","service":"fluxer-api","env":"production","method":"POST","path":"/internal/rpc","status":200,"durationMs":39,"msg":"Request completed"}`
8 comments
Comment by @Buco7854
Comment by @shleeable
Comment by @SleazeStiKs
wss://fluxer_domain/livekitseems to mitigate this issue. Atleast as long as both the FLUXER_DOMAIN and the subdomain used for exposing 7881/tcp & 7882/udp in Netbird, both resolve to the same IP adress.Comment by @kerichdev
Comment by @SleazeStiKs
livekit-tcp.mydomain.comandlivekit-udp.mydomain.com. In the admin panel I set the endpoint towss://livekit-tcp.mydomain.com:7881. After some trial and error i ended up setting the endpoint tochat.mydomain.comas that resolves to the same IP aslivekit-tcp.mydomain.com. This seems to fix this particular error.Comment by @kerichdev
Comment by @MrRubberDucky
https://chat.mydomain.tld/livekit*andhttps://lk.mydomain.tldwhich solves the problem for the time being.lk.mydomain.tldwhile also being accessible to Fluxer fromwss://chat.mydomain.tld/livekit<-- this is the one you add from admin panel after doing this. Hope it helps somebody out.Comment by @Buco7854