coturn TURN Server That Will Not Relay Into Your Private Network

coturn from EPEL as a TURN server for WebRTC: credentials from a shared secret the role makes, TURN over TLS, and the relay kept out of private and special-purpose ranges, where by default a valid credential reached 10.x and 192.168.x peers. The live test relays to a public peer and is refused for private ones and the metadata address. Original role, live-tested on Rocky Linux 10.

ansibleNetworking & VPC

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-coturn/badge)](https://www.iac-bazaar.com/catalog/ansible-coturn?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [coturn TURN Server That Will Not Relay Into Your Private Network](https://www.iac-bazaar.com/catalog/ansible-coturn?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# coturn TURN Server That Will Not Relay Into Your Private Network: https://www.iac-bazaar.com/catalog/ansible-coturn (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

coturn

coturn from EPEL as a TURN server for WebRTC: time-limited credentials from a shared secret the role makes, the relay kept out of every private and special-purpose range so a valid credential is not a way into your network, TURN over TLS on its own port, and each file checked by running it before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages coturn in EPEL, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs coturn from EPEL, writes /etc/coturn/turnserver.conf (root:coturn 0640: it holds the secret) and enables the package's coturn.service, which runs as the coturn user. The listener is 127.0.0.1:3478 by default (and 127.0.0.1:5349 for TLS); a public TURN server listens on the host's public address, so set coturn_listen_address (and coturn_external_ip behind NAT). The live test reads the TCP and UDP sockets and expects loopback only.

A TURN credential reached the private network. With the shared-secret auth every guide shows and nothing else, the relay carried a client's packets to peers on 10.99.0.1 and 192.168.77.1 and brought the answers back (measured): a TURN server on a host with private interfaces is, by default, a way in. coturn 4.18 refuses loopback and link-local peers by itself; the role adds denied-peer-ip for the private, shared (100.64/10) and special-purpose ranges, and the live test is refused (403) by each one while a public peer relays over UDP and over TLS.

A file is never refused, so the role runs it. coturn 4.18 starts on a file with an unknown option ("Bad configuration format": no-tlsv1, no-tlsv1_1 and no-dtls are among the ones it no longer knows) or a bad value (an ERROR line), and no-cli itself is now an ERROR ("deprecated"; the CLI is off by default). The role's checker runs each candidate as the coturn user on spare ports for three seconds and refuses it on either kind of line; a clean file prints neither.

Credentials your application makes. With a shared secret coturn keeps no user list: your application turns the secret (/etc/coturn/iacbazaar-secret, root 0600) into a short-lived username and password per session, the TURN REST API form every WebRTC stack supports. The live test does exactly that, and is refused with a wrong secret. (The file says use-auth-secret as well; in 4.18 static-auth-secret alone already turns this on - measured.)

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-squid

The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-server

HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-frr

FRR from AppStream: BGP that announces only your prefixes, accepts from each neighbour only what you list for it, signs sessions with TCP MD5, and applies a change without dropping them. The live test peers with a real BGP speaker in its own namespace; a filtered prefix stays out of the kernel and a wrong password keeps the session down. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-headscale

Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-kea-dhcp4

Kea DHCPv4 from AppStream: your subnets, pools, options and reservations in Kea's own keys, checked with kea-dhcp4 -t and applied by reload, leases on disk. The live test runs a raw-socket DHCP client in a namespace: an address with router, DNS and lease time, the reserved address for its MAC, and nothing on a segment no subnet covers. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-libreswan

Libreswan from AppStream: IPsec connections authenticated by a pre-shared key made on the host, negotiated with IKEv2 under the system crypto policy, IKE kept to one address, each connection checked by its keywords and again by pluto. The live test brings a peer in a namespace up, sees the ping cross as ESP only, and is refused with a different key. Original role, live-tested on Rocky Linux 10.

View module