Back to articles
Technology Insight

Self-Hosting a WebRTC SFU Media Server with LiveKit: A Startup’s Guide to Scalable Voice and Video Infrastructure

May 26, 2026

Introduction: The Cost and Sovereignty Challenge in Real-Time Mobile Apps

For modern startups building mobile applications, integrating real-time voice and video communication is no longer a luxury feature—it is a core user expectation. Whether you are developing a collaborative workplace tool, an interactive edtech platform, or a telehealth application, seamless audio and video streams dictate user retention. However, engineering teams quickly face a critical architectural crossroad: rely on third-party Communications Platform as a Service (CPaaS) providers or build a self-hosted infrastructure.

While CPaaS vendors offer rapid initial deployment, their usage-based pricing models scale aggressively, transforming a successful surge in user adoption into a financial burden. Furthermore, operating in highly regulated verticals like healthcare or fintech demands strict data sovereignty and compliance compliance that third-party routing cannot always guarantee. The alternative is self-hosting a WebRTC Selective Forwarding Unit (SFU) media server. By deploying LiveKit on a standard Virtual Private Server (VPS), startups can achieve full data control, predictable infrastructure overhead, and sub-100ms latency optimized specifically for mobile environments.

Understanding WebRTC Topologies: Why Choose an SFU?

To appreciate the efficiency of LiveKit, it is essential to contrast the primary WebRTC architectural patterns:

  • Peer-to-Peer (Mesh): Every participant establishes a direct connection with every other participant. While cost-effective for 1-on-1 calls, CPU and bandwidth consumption scale exponentially ($N \times (N - 1)$), making it completely unviable for mobile devices in group conversations.
  • Multipoint Control Unit (MCU): The server mixes all incoming media streams into a single composite stream before sending it back to each user. This minimizes client-side bandwidth but introduces massive, cost-prohibitive CPU overhead on the server.
  • Selective Forwarding Unit (SFU): Participants send their media streams to a central server exactly once. The server then forwards those unaltered streams to the other participants. This provides an ideal balance, keeping client upload bandwidth low while maintaining minimal server-side CPU processing compared to an MCU.
LiveKit operates as a modern, high-performance SFU written in Go. It leverages HTTP/3 and cutting-edge routing algorithms to handle thousands of concurrent video tracks on modest hardware, making it exceptionally well-suited for resource-constrained mobile apps.

Step 1: VPS Sizing and Prerequisites

Before initiating deployment, selecting the correct VPS architecture is paramount. WebRTC streaming is fundamentally bound by network throughput and CPU performance (primarily for cryptographic encryption and decryption of Secure Real-time Transport Protocol, or SRTP, packets).

Recommended Minimum Production Specs:

  • CPU: 4 vCPUs (Compute-optimized instances are highly recommended).
  • RAM: 8 GB RAM.
  • Network bandwidth: 1 Gbps unmetered port, or a minimum of 2 TB monthly data transfer allotment.
  • OS: Clean installation of Ubuntu 24.04 LTS or Debian 12.

Additionally, you must configure your domain DNS registry. Point a wildcard or dedicated A record (e.g., livekit.yourdomain.com) to your VPS public IPv4 address. LiveKit utilizes automatic Let's Encrypt integration, meaning standard HTTP (80) and HTTPS (443) ports must be unobstructed.

Step 2: Firewall Configuration and Network Ports

WebRTC infrastructure requires precise firewall configurations because it depends on both reliable TCP signals for handshakes and high-speed UDP streams for media distribution. Execute the following commands via SSH to configure the Uncomplicated Firewall (UFW) correctly:

# Allow SSH management
sudo ufw allow 22/tcp

# HTTP/HTTPS for LiveKit API signaling, dashboard, and Let's Encrypt validation
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# LiveKit WebRTC TCP fallback signaling
sudo ufw allow 7880/tcp

# TURN server over TCP (essential for strict corporate firewalls)
sudo ufw allow 3478/tcp

# TURN server over UDP (high-speed media routing fallback)
sudo ufw allow 3478/udp

# High-performance WebRTC UDP Media ports (Crucial for SFU operation)
sudo ufw allow 50000:60000/udp

# Enable the firewall configuration
sudo ufw enable

Step 3: Automated Installation and Configuration

LiveKit simplifies deployment through an official deployment script that orchestrates the configuration of the system, setting up Docker containers, and managing SSL certificates automatically. To generate your deployment environment, execute the following bootstrapping tool:

sudo docker run --rm -it -v $PWD:/output livekit/generate

The interactive setup wizard will prompt you for your target domain name and deployment style. Opt for "Docker Compose with Let's Encrypt". The script will generate a production-ready livekit.yaml configuration file. Inside, ensure your configuration addresses the following infrastructure parameters:

port: 7880
bind_addresses:
  - ""
rtc:
  tcp_port: 7881
  udp_port_start: 50000
  udp_port_end: 60000
  use_external_ip: true
turn:
  enabled: true
  domain: livekit.yourdomain.com
  tls_port: 3478
  udp_port: 3478
keys:
  API_KEY_HERE: API_SECRET_HERE

Launch the environment using Docker Compose: docker compose up -d. The media server is now active, listening, and securely provisioned.

Step 4: Linux Kernel Optimizations for Real-Time Media

A stock Linux VPS configuration is optimized for web serving (HTTP text/images), not high-velocity UDP packet switching. Without system-level modifications, a surge in mobile users will cause packet drops, leading to robotic audio and choppy video. Append the following parameters to your system's /etc/sysctl.conf file:

# Increase maximum network receive and send buffer sizes for UDP
net.core.rmem_max=16777216
net.core.wmem_max=16777216
net.core.rmem_default=16777216
net.core.wmem_default=16777216

# Increase the maximum number of open files and file descriptors
fs.file-max=2097152

Apply these changes instantly by executing sudo sysctl -p. These kernel adjustments ensure your VPS can comfortably manage hundreds of simultaneous high-bitrate media tracks without artificial operating system bottlenecks.

Step 5: Tailoring Infrastructure for Mobile Apps

Mobile devices present unique engineering hurdles due to fluctuating cellular coverage (switching between 5G, 4G, and intermittent Wi-Fi networks). LiveKit provides integrated features that directly mitigate these mobile-specific pain points:

1. Dynamic Broadcasting (Simulcast)

Always enable Simulcast within your mobile SDK implementation (iOS, Android, React Native, or Flutter). This forces the mobile client to publish three distinct video resolutions simultaneously (e.g., 1080p, 720p, and 360p). The SFU then dynamically serves the appropriate resolution to downstream participants depending on their individual real-time network health. If a user enters a poor reception zone, the SFU automatically downgrades their inbound feed to 360p, preventing the stream from dropping entirely.

2. Advanced Audio Coding (Opus DTX)

Mobile battery conservation is paramount. Configure your audio tracks to utilize Discontinuous Transmission (DTX). When a user stops speaking during a call, Opus DTX pauses audio packet transmission. This decreases battery draw on the smartphone and slashes overall server egress data bandwidth by up to 40% during large team meetings.

Conclusion: Long-Term Maintenance and Next Steps

By transitioning from commercial CPaaS platforms to a self-hosted LiveKit SFU instance on a standard VPS, your startup establishes predictable infrastructure costs and ensures total ownership over user data streams. The initial infrastructure setup requires meticulous attention to firewall configurations and kernel network buffers, but the long-term dividend is a highly customizable, enterprise-grade media platform built to grow alongside your application.

As your mobile application scales up, you can easily implement Prometheus and Grafana dashboards to monitor packet loss and CPU metrics, or distribute multiple nodes globally using LiveKit’s Redis-powered multi-node clustering topology.

Self-Hosting a WebRTC SFU Media Server with LiveKit: A Startup’s Guide to Scalable Voice and Video Infrastructure | DPTCloud