Deployment

Deploy Beam as a relay-backed screenshare and stream service.

Production Beam needs more than a landing page host. The relay, signaling, API, and WebRTC surfaces must be exposed correctly so operators and viewers can complete both support sessions and live stream sessions reliably.

Core server components

Embedded signaling server

Accepts WebSocket signaling for native Beam sessions.

UDP relay

Routes low-latency video packets so both peers can connect outward through ordinary networks.

Control-plane API

Creates typed sessions, carries metadata, and returns join data to external systems.

WebRTC signaling bridge

Supports browser-facing viewer flows on top of the same relay media path.

Default server ports

Service Default Notes
Signaling 8765/tcp WebSocket signaling endpoint for the desktop app and server bridge.
Relay 8767/udp UDP relay port used by Beam peers.
Control-plane API 8770/tcp REST API for sessions and join token lifecycle.
WebRTC signaling 8771/tcp Browser-facing signaling surface for WebRTC viewer flows.
WebRTC media range 49200-49260/udp Media and ICE port range expected by the current server configuration.
Media edge WebRTC 8889/tcp Typical MediaMTX WHIP/WHEP listener, usually reverse-proxied through /whip/ and /whep/.
Media edge HLS 8888/tcp Typical MediaMTX HLS/LL-HLS listener, usually reverse-proxied through /hls/.

Environment variables

Variable Purpose
SCREENSHARE_SIGNALING_PORT Overrides the TCP signaling port.
SCREENSHARE_RELAY_PORT Overrides the UDP relay port.
SCREENSHARE_API_PORT Overrides the REST API port.
SCREENSHARE_RTC_PORT Overrides the WebRTC signaling port.
SCREENSHARE_RTC_PORT_MIN Start of the WebRTC media port range.
SCREENSHARE_RTC_PORT_MAX End of the WebRTC media port range.
SCREENSHARE_STUN_URL STUN server used for ICE candidate gathering.
SCREENSHARE_PUBLIC_HOST Public hostname returned to native clients for relay and default URLs.
SCREENSHARE_PUBLIC_SIGNALING_URL Optional external signaling URL override, useful when a reverse proxy upgrades to wss://.
SCREENSHARE_PUBLIC_RTC_URL Optional external browser-viewer signaling URL override, useful for TLS termination and non-default routing.
SCREENSHARE_API_KEYS Comma-separated API keys accepted by the control-plane API.
BEAM_MEDIA_EDGE_ENABLED Enables media-edge discovery and per-stream WHIP/WHEP/HLS URL generation.
BEAM_MEDIA_EDGE_PROVIDER Provider label returned by the API, for example mediamtx, livekit, or mediasoup.
BEAM_MEDIA_EDGE_WHIP_BASE_URL Public HTTPS base URL for WHIP ingest, for example https://beam.be-online.ro/whip.
BEAM_MEDIA_EDGE_WHEP_BASE_URL Public HTTPS base URL for WHEP playback, for example https://beam.be-online.ro/whep.
BEAM_MEDIA_EDGE_HLS_BASE_URL Public HTTPS base URL for HLS or LL-HLS playback, for example https://beam.be-online.ro/hls.
BEAM_MEDIA_EDGE_SIMULCAST_ENABLED Set to true only when the provider can consume and route simulcast layers.

Media edge proxy

When MediaMTX runs on the same VPS, keep the edge ports private and publish them through the main TLS vhost.

location /whip/ { proxy_pass http://127.0.0.1:8889/; }
location /whep/ { proxy_pass http://127.0.0.1:8889/; }
location /hls/  { proxy_pass http://127.0.0.1:8888/; }

See the Media Edge docs for the full WHIP, WHEP, HLS, and LL-HLS setup.

Production checklist

  • Expose the required TCP and UDP ports through your ingress or firewall.
  • Keep the WebRTC media port range aligned with NAT, firewall, and STUN behavior.
  • Use the public URL overrides when the API returns URLs that must be wss:// or proxy-routed.
  • Store API keys outside the website content and outside hardcoded client-side files.
  • Run the public site separately from the Beam service binaries when needed, but keep the docs aligned with the live topology.
  • Replace the in-memory session store if you need multi-node scale, durable recovery after restart, or cross-region state.
The current reference server keeps session state in memory. That is acceptable for a single-node deployment, but durable production clusters should back the session registry with Redis or a database.