4. Restrict Who Can Publish and Watch
The relay controls who can publish (send a stream to it) with PUBLISH_IP_RANGE. It does not control who can watch: any machine that can reach port 1935 can play the stream. This page limits both.
4.1 Before You Begin
- The relay is set up as in Quick Start, and runs with
docker compose. - You know the IP address of the machine that runs your streaming software, and the relay host's address on the network your streaming software uses.
- For the confirm steps:
ffprobe(part of FFmpeg) on a second machine.
4.2 Limit Who Can Publish
-
In
env/relay.env, setPUBLISH_IP_RANGEto the networks or addresses allowed to publish, separated by commas. Every entry needs a prefix: use/32for a single machine. Keep172.16.0.0/12if your streaming software runs on the relay host itself, because its connection arrives from the Docker network. For a streaming PC at192.168.1.50and nothing else:Drop
172.16.0.0/12if nothing streams from the relay host. -
Recreate the container:
-
Confirm the container started:
If the relay is not running, check
docker compose logs relayfor anERROR: PUBLISH_IP_RANGEline and fix the value.
127.0.0.1 can always publish, whatever this variable says. For more examples and the "access forbidden by rule" error, see IP Authentication.
4.3 Limit Who Can Watch
docker-compose.yml publishes port 1935 on every interface of the relay host. Bind it to one address instead, so only machines that can reach that address can connect, to publish or to watch.
-
In
docker-compose.yml, replace"1935:1935"with the relay host's address on your streaming network. For a relay host at192.168.1.20:To allow only software on the relay host itself, use
"127.0.0.1:1935:1935". -
Recreate the container:
-
In your streaming software, set the server to the address you bound, for example
rtmp://192.168.1.20:1935/relay. A server oflocalhostor127.0.0.1stops working unless you bound127.0.0.1.
docker-compose.yml is tracked by git, unlike env/relay.env. If a later git pull stops with Your local changes to the following files would be overwritten by merge: docker-compose.yml, save your copy, run git checkout docker-compose.yml, pull again, then put your ports: line back.
A host firewall may not block Docker ports
Docker writes its own iptables rules for published ports, so host firewall tools such as ufw may not block them. Bind the port as above, or block it at a firewall in front of the host.
4.4 Confirm
Start streaming, then run these from a machine that should not have access. Replace <RELAY_HOST> with any address of the relay host that this machine can reach, and <STREAM_NAME> with the stream name in your streaming software.
-
Try to watch:
ffprobe -v error -show_entries stream=codec_name -of csv rtmp://<RELAY_HOST>:1935/relay/<STREAM_NAME>With the port bound, this fails with
Connection refused. If it printsstream,h264, the machine can watch: check that theports:line took effect withdocker compose ps, which shows the bound address. -
Try to publish:
This fails with
Connection refusedif the port is bound, orBroken pipeif the machine can connect but is outsidePUBLISH_IP_RANGE. The relay log showsaccess forbidden by rulefor the second case.
4.5 See Also
- Security - What the relay protects against, and what it does not
- IP Authentication - Publish refused with "access forbidden by rule"
PUBLISH_IP_RANGE- Default and syntax