Skip to content

WebRTC Remote Access

Pluvira provides encrypted, out-of-band remote WebUI access powered by WebRTC Data Channels, allowing you to manage your home server from anywhere without exposing open ports to the public internet.


1. Zero-Configuration Remote Management

  • No Port Forwarding: Eliminates UPnP/NAT-PMP and firewall port forwarding rules on your home router.
  • No Dynamic DNS Required: Operates across dynamic residential IP addresses and Carrier-Grade NAT (CGNAT) environments.
  • P2P Direct Connection: Once signaling completes, management traffic flows directly between your browser and your local appliance.

2. Cryptographic Security & “Mere Conduit” Relay

[Remote Client Browser] [Local Home Appliance]
│ │
│ ── 1. Ephemeral WebSockets Signaling (Encrypted SDP) ────► │
│ (via pluvira.com/ws/v1/signaling blind relay) │
│ │
│ <========================================================> │
│ 2. Direct WebRTC Data Channel (AES-256-GCM E2EE) │
│ [Zero visibility by SaaS Cloud Relay] │
  • AES-256-GCM End-to-End Encryption: Control sessions, playlist management commands, and settings are encrypted peer-to-peer.
  • Blind Signaling Relay: The SaaS signaling relay (/ws/v1/signaling/{session_id}) acts strictly as an uninspected “Mere Conduit” for NAT traversal.
  • Zero Decryption: Pluvira Cloud has zero cryptographic ability to inspect, log, or decrypt management payloads, credentials, or video streams.

3. STUN/TURN Traversal (Coturn Integration)

  • Ephemeral TURN Credentials: For restrictive symmetric NAT or corporate firewall topologies, Pluvira dynamically requests short-lived Coturn TURN relay credentials (RFC 5766).
  • High Availability: Built-in fallback ensures remote reachability across 99.8% of global network topologies.