Terraform · Ansible · SRT · nginx-rtmp · Let's Encrypt
One private EC2 instance loops Big Buck Bunny and pushes it over
SRT, encrypted end to end. A second, public-facing instance receives that
feed, relays it internally, repackages it as HLS/DASH, and serves it to you here — over
HTTPS.
Signal chain
The whole environment is provisioned by Terraform creating EC2 instances on a VPC with a public subnet hosting the frontend server and a private subnet hosting the Video Streamer. Security groups and NAT Gateway prevent the Video Streamer to have access from the internet at all. Ansible then configures both machines: ffmpeg pushing an encrypted SRT feed on one side, nginx with the RTMP module relaying it locally and a Let's Encrypt certificate on the other. Both hosts run a mirrored host-level firewall (UFW), Fail2ban against SSH brute-force, and a Wazuh agent reporting to our SOC.
secrets.yaml contenant la passphrase, afin de le committer en toute sécurité.