feat(jitsi-meet): optional public setup (FQDN, Let's Encrypt, NAT, secure domain) (#17132)

Adds five optional var_jitsi_* settings to the install script. All default
to empty, which keeps the previous LAN-only behaviour (container IP,
self-signed certificate):

- var_jitsi_domain     public hostname instead of the container IP
- var_jitsi_le_email   Let's Encrypt via the packaged debconf option
- var_jitsi_public_ip  static NAT mapping in jvb.conf (JVB 2.3+)
- var_jitsi_admin_user secure domain: only authenticated users create rooms
- var_jitsi_admin_pass password for that user (generated when empty)

Tested on Proxmox VE 9.2 as unprivileged Debian 13 LXC, both with all
variables set (self-signed) and with none set.

Co-authored-by: klanghans <13657862+klanghans@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Kevin Langhans
2026-09-12 14:25:09 +02:00
committed by GitHub
parent 9580c0f5bd
commit 02cf8a0a8f
2 changed files with 98 additions and 3 deletions

View File

@@ -17,6 +17,14 @@ var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
# Optional public setup, read by the install script (all empty = LAN-only install as before).
# Without the export they never reach the container.
export var_jitsi_domain="${var_jitsi_domain:-}"
export var_jitsi_le_email="${var_jitsi_le_email:-}"
export var_jitsi_public_ip="${var_jitsi_public_ip:-}"
export var_jitsi_admin_user="${var_jitsi_admin_user:-}"
export var_jitsi_admin_pass="${var_jitsi_admin_pass:-}"
header_info "$APP"
variables
color
@@ -50,4 +58,7 @@ description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}https://${IP}${CL}"
echo -e "${GATEWAY}${BGN}https://${var_jitsi_domain:-$IP}${CL}"
if [[ -n "${var_jitsi_domain}" ]]; then
echo -e "${INFO}${YW}Forward TCP 80/443 and UDP 10000 to the container. Secure-domain credentials (if enabled) are in ~/jitsi-meet.creds inside the container.${CL}"
fi