Back to articles
Technology Insight

Building a Sub-Second Low-Latency Live Streaming System: Deploying LiveKit SFU on a VPS

May 28, 2026

Introduction to the Low-Latency Streaming Revolution

In today's fast-paced digital economy, real-time engagement has transitioned from a premium feature to a core business requirement. Traditional streaming protocols like HLS (HTTP Live Streaming) and DASH, while highly scalable, introduce latencies ranging from 5 to 30 seconds. For interactive applications such as live auctions, financial trading dashboards, e-learning platforms, and interactive gaming, this delay is unacceptable. To achieve sub-second (ultra-low) latency, engineering teams are increasingly turning to WebRTC and Selective Forwarding Units (SFUs).

This technical guide provides an exhaustive blueprint for architectural design and deployment of a sub-second live streaming system using LiveKit SFU on a Virtual Private Server (VPS). By leveraging LiveKit's modern, Go-based architecture, businesses can achieve unparalleled performance without the prohibitive costs of managed cloud providers.

Understanding WebRTC and the Role of an SFU

WebRTC (Web Real-Time Communication) is the gold standard for sub-second peer-to-peer communication. However, pure peer-to-peer (Mesh) networks fail to scale when a single broadcaster streams to hundreds or thousands of viewers, as the broadcaster's upload bandwidth becomes a critical bottleneck. To solve this, a media server is introduced into the infrastructure.

There are two primary architectures for media servers:

  • MCU (Multipoint Control Unit): The server decodes, mixes, and re-encodes all incoming media streams into a single stream for each viewer. While this saves client-side CPU, it is extremely resource-intensive on the server side.
  • SFU (Selective Forwarding Unit): The server acts as an intelligent router. It accepts the media stream from the publisher and forwards it to all subscribed viewers without re-encoding. This architectural design minimizes server-side CPU utilization and preserves sub-second latency, making it the ideal choice for mass-scale live streaming.
LiveKit is a cutting-edge, open-source WebRTC ecosystem built on an SFU architecture. Developed in Go, it is highly concurrent, resource-efficient, and natively supports modern protocols like HTTP/3 and WebTransport.

Prerequisites and VPS Provisioning

Before initiating the installation, ensure your VPS aligns with the following minimum specifications to handle concurrent real-time data streams:

  • CPU: Minimum 2 vCPUs (Compute-optimized instances are highly recommended).
  • RAM: 4 GB or higher.
  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS clean installation.
  • Network: 1 Gbps port with unmetered bandwidth or high data transfer limits.
  • Domain: A fully qualified domain name (FQDN) with access to DNS management for setting up A records.

Network and Firewall Configurations

LiveKit relies on specific ports for signaling and media routing. You must configure your cloud firewall (security groups) or internal firewall (UFW) to allow traffic through the following ports:

  1. TCP 22: SSH Remote Access
  2. TCP 80 & 443: HTTP/HTTPS for SSL validation and WebSockets signaling
  3. UDP 7800: LiveKit primary media transport (WebRTC data channels, audio, video)
  4. TCP 7800: Turn/STUN fallback mechanism
  5. UDP 443: HTTP/3 / QUIC transport speeds (Optional but recommended)

Step-by-Step Deployment of LiveKit SFU

We will utilize the official LiveKit production deployment tool, which simplifies the generation of Docker configurations, automated Let's Encrypt SSL certificates, and system systemd services.

Step 1: Pointing Your DNS Records

Navigate to your DNS provider and create an A Record pointing to your VPS public IP address. For example:

  • livekit.yourdomain.com → 192.0.2.1

Step 2: Generating the Configuration

SSH into your VPS and run the LiveKit initialization script:

sudo open/curl -sSL [https://get.livekit.io/generate](https://get.livekit.io/generate) | bash

The interactive setup assistant will prompt you for several configurations:

  • Enter your primary domain name (e.g., livekit.yourdomain.com).
  • Select the latest stable version of LiveKit.
  • Choose Let's Encrypt for automated SSL generation.
  • Specify if you require a Redis instance (Highly recommended for distributed state and scaling out).

Upon completion, the generator outputs a livekit.yaml configuration file along with a docker-compose.yaml file setup.

Step 3: Reviewing the livekit.yaml Configuration

Your generated configuration file contains unique api_key and api_secret pairs essential for token generation. It should structurally resemble the following:

port: 7800
rtc:
  port_range_start: 7800
  port_range_end: 7800
  use_external_ip: true
keys:
  API_KEY_EXAMPLE: SECRET_KEY_EXAMPLE
logging:
  level: info

Step 4: Launching the Services

Navigate to the directory containing your docker-compose file and initiate the stack:

docker compose up -d

Verify that the containers are healthy and running by executing docker ps. Your LiveKit SFU is now actively listening for sub-second connections.

Optimizing the Linux Kernel for Real-Time Media Traffic

Standard Linux VPS kernel configurations are tuned for general-purpose web serving (HTTP requests), not intensive, high-throughput real-time UDP media packets. To prevent packet loss and degradation under high concurrent loads, optimize your system by modifying /etc/sysctl.conf:

# Increase maximum network buffer sizes for UDP
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
# Increase the maximum number of open files / file descriptors
fs.file-max = 2097152

Apply these changes permanently by executing sudo sysctl -p. Additionally, modify /etc/security/limits.conf to elevate soft and hard limits for open files across the system sessions.

Integrating the Client SDK and Publisher Pipelines

With the infrastructure live, you can connect publishers (e.g., OBS Studio via WHIP or a custom browser app) and subscribers. LiveKit provides robust SDKs for JavaScript, Flutter, React Native, iOS, Android, and Unity.

Generating Access Tokens

For a client to securely connect to a specific room, your backend authentication system must issue a signed JWT token using the LiveKit server SDK. Here is a conceptual implementation using Node.js:

import { AccessToken } from 'livekit-server-sdk';

const createToken = (roomName, participantName) => {
  const at = new AccessToken('API_KEY_EXAMPLE', 'SECRET_KEY_EXAMPLE', {
    identity: participantName,
  });
  at.addGrant({ roomJoin: true, room: roomName, canPublish: false, canSubscribe: true });
  return at.toJwt();
};

Connecting the Viewer Client via JavaScript

On the front-end application, initialize the LiveKit client SDK to render the incoming sub-second stream:

import { Room, RoomEvent } from 'livekit-client';

const url = 'wss://livekit.yourdomain.com';
const token = 'YOUR_GENERATED_JWT_TOKEN';

const room = new Room();
room.on(RoomEvent.TrackSubscribed, (track, publication, participant) => {
  if (track.kind === 'video' || track.kind === 'audio') {
    const element = track.attach();
    document.getElementById('video-container').appendChild(element);
  }
});

await room.connect(url, token);

Benchmarking, Monitoring, and Scalability

To ensure system reliability, production deployments must include observability metrics. LiveKit natively exports detailed telemetry data compatible with Prometheus and Grafana. Key performance indicators (KPIs) to track include:

  • NACK Count: High Negative Acknowledgements signal packet loss, indicating network congestion or insufficient UDP buffer configurations.
  • Connection Drop Rates: Sudden disconnects can pinpoint server resource exhaustion.
  • CPU and Memory Usage: Track SFU capacity to plan automated horizontal scaling triggers.

When vertical scaling reaches its threshold, LiveKit allows effortless horizontal scalability. By linking multiple VPS instances to a shared Redis cluster, instances can cross-communicate, dynamically forwarding media across nodes depending on participant locations.

Conclusion

Building a sub-second low-latency live streaming platform no longer requires massive capital investments or complex specialized hardware. By deploying LiveKit's SFU architecture on a cost-effective VPS, enterprises can achieve true real-time interaction at scale. Through deliberate kernel optimization, explicit token authentication, and systematic monitoring, your streaming infrastructure will stand ready to handle high-demand interactive business use cases effortlessly.

Building a Sub-Second Low-Latency Live Streaming System: Deploying LiveKit SFU on a VPS | DPTCloud