processone/eturnal
67.6
Adequate · 23 September 2026
3.2k
lines of production code
Erlang
primary language
5
measurements over time
What this system is
Eturnal is a STUN/TURN server designed for real-time communication infrastructure, providing capabilities for session management, credential handling, and network address discovery. The system supports extensive operational monitoring through Prometheus and InfluxDB metrics, alongside configurable logging and dynamic module loading for extensibility. It is distributed across multiple platforms, including Linux, macOS, and Windows, with robust deployment options via Docker, Homebrew, and native package managers.
How it got here
2020 — Build modernization and module system
6 changes.
This period focused on modernizing the build infrastructure by upgrading dependencies, switching to Wolfi OS-based Docker images, and removing legacy scripts. It introduced an extensible module system for metrics and logging, refined configuration defaults, and established a comprehensive test suite to validate core server functionality.
2021–2023 — Distribution and deployment infrastructure
10 changes.
This period focused on expanding the project's distribution and operational tooling by introducing comprehensive installers for Windows, Homebrew, and Linux package managers. It also established robust deployment examples for Docker and Kubernetes, alongside a suite of management scripts and container variants to simplify server administration and lifecycle management.
Features
Add Homebrew formula for Eturnal 1.12.3
Users can now install the Eturnal STUN/TURN server via Homebrew. The new formula builds version 1.12.3 from source, installs the application binaries and configuration files, and sets up necessary log and runtime directories. It also includes a service definition for running Eturnal as a background daemon and provides caveats regarding macOS compatibility and configuration file locations.
Formula · high confidence
Add STUN client utility and build script
A new STUN client utility (client/stun.erl) has been added to the client directory, enabling users to query STUN servers (supporting RFC 3489) to discover their public IP address via UDP. A corresponding build script (client/build) is also introduced to compile this utility into an escript for inclusion in releases, supporting both standard Rebar3 builds and manual invocation.
client · high confidence
Introduce eturnalctl management script
A new shell script, \eturnalctl\, has been added to the overlay to manage the eturnal STUN/TURN server. It provides commands for reloading configuration, viewing node info and sessions, managing credentials and passwords, adjusting log levels, and checking versions. The script handles privilege escalation by switching to the configured user via \su\ when run as root, and it dynamically locates the configuration file and server binary.
overlay · high confidence
Introduce extensible module system and new management commands
The server now supports a dynamic module system (src/eturnal\_module.erl) that allows third-party functionality to be loaded at runtime, including new built-in modules for STUN query logging (src/mod\_log\_stun.erl), InfluxDB statistics (src/mod\_stats\_influx.erl), and Prometheus metrics (src/mod\_stats\_prometheus.erl). The control utility (src/eturnal\_ctl.erl) has been expanded with commands to manage TURN sessions (list, disconnect) and retrieve runtime information, while the application startup sequence (src/eturnal\_app.erl) now integrates systemd readiness notifications (src/eturnal\_systemd.erl) and logs Erlang/OTP versions for better operational visibility.
src · high confidence
New container documentation and ACME variant
The documentation area now includes a new \CONTAINER-ACME.md\ file describing a container image variant that bundles \acme.sh\ for automatic TLS certificate management, along with new \CONTAINER-BUILD.md\ and \CONTAINER-QUICK-TEST.md\ files detailing build instructions and quick-start testing workflows. Existing container documentation (\CONTAINER.md\) has been updated to reflect the switch to Wolfi OS-based images for releases newer than 1.12.1, the availability of Alpine variants, and system-wide unprivileged port settings.
doc · high confidence
New container variants with automated TLS and Docker secrets support
The container image now includes a new 'acmesh' variant that automatically provisions and renews TLS certificates using acme.sh (supporting HTTP, ALPN, and DNS challenges) and a 'standalone' variant. Both variants support reading sensitive configuration via Docker secrets (environment variables ending in \_\_FILE). The acmesh variant also enables Prometheus metrics via the mod\_stats\_prometheus module and configures TURN/STUN listeners by default.
overlay/container · high confidence
New deployment examples and utility scripts
Added example configurations for deploying eturnal via Docker Compose and Kubernetes (using Kustomize with Traefik and cert-manager), including base manifests, overlays, and environment templates. Also added shell scripts to generate ephemeral TURN credentials and to automatically detect and update relay IP addresses in the configuration file.
examples · high confidence
New management commands and log rotation configuration for Eturnal
This change introduces several new shell-script extensions for the Eturnal STUN/TURN server, adding CLI commands to manage credentials (with configurable expiry and suffixes), disconnect users, view active sessions, retrieve passwords, check server info, and display the version. It also adds a logrotate configuration for /var/log/eturnal/\*.log. Additionally, existing loglevel and reload scripts are moved from the scripts directory to the overlay/extensions directory and updated to include a ping check before execution.
overlay/extensions, overlay/logrotate · high confidence
New release tooling and build infrastructure
The tools directory now contains a complete set of scripts for building and publishing releases, including make-binaries (which builds portable Linux tarballs using Erlang/OTP 29.1, OpenSSL 3.6.4, and crosstool-NG 1.29.0), make-containers (for building multi-architecture Docker images), make-installers (creating self-extracting installers for glibc and musl systems), and make-packages (generating DEB and RPM packages). Supporting scripts like get-version, ctrrel, and update-formula manage versioning and Homebrew formula updates, while publish-release handles uploading artifacts to the web server and updating package repositories.
tools · high confidence
Windows installer with delayed service start and explicit IPv4 listeners
The Windows distribution now includes a complete installer package (Inno Setup) that configures the eturnal service to start with a delay after boot, ensuring system stability. The installer also enforces explicit IPv4 listeners (ports 3478 UDP/TCP on 0.0.0.0 and ::) in the configuration, omits Linux-specific configuration files, and automatically installs the required Microsoft Visual C++ runtime libraries.
windows · high confidence
Removals
Removal of legacy eturnalctl and make-binary scripts
The legacy shell-based control script (eturnalctl) and the manual binary build script (make-binary) have been removed from the repository. This eliminates the previous mechanism for launching the server via su and the manual cross-compilation process using crosstool-NG, rebar3, and static linking of dependencies like OpenSSL and Erlang/OTP. Users relying on these specific scripts for service management or binary distribution will need to adopt the new build and deployment methods provided by the updated release tooling.
scripts · high confidence
Behavioural changes
Add OpenRC and SysV init scripts and update systemd service configuration for eturnal
The eturnal service now includes native support for OpenRC (with a new configuration file for environment variables like ERL\_EPMD\_ADDRESS) and SysV init systems, in addition to the existing systemd unit. The systemd service has been updated to use Type=notify instead of exec, added a dependency on the epmd.service, shortened documentation URLs to point to eturnal.net, and tightened security settings with capabilities and watchdog timers.
overlay/init · high confidence
Refactor startup hooks and add status check capability
The startup lifecycle scripts have been reorganized: a new pre\_start hook now handles configuration directory resolution and cookie retrieval, while the previous pre\_start logic has moved to post\_stop to explicitly kill the Erlport Port Mapper Daemon (epmd) on shutdown. Additionally, a new status hook is introduced that waits for the application to become alive before reporting its status, improving reliability during health checks.
overlay/hooks · high confidence
Refined configuration defaults and documentation tooling
The eturnal server now disables TLS listening and TURN support by default, requiring explicit configuration to enable them. A new 'strict\_expiry' option allows users to control whether established calls are closed when temporary TURN credentials expire. The default blacklist for peer addresses has been updated to use a 'recommended' set, removing specific Teredo and 6to4 entries. Logging can now be directed to standard output via the 'log\_dir' setting, and a new 'mod\_log\_stun' module is available to log STUN queries. The documentation build process now integrates Mermaid for rendering diagrams, and the release configuration has been streamlined to exclude unnecessary ERTS and application files.
config · high confidence
Test coverage
Initial Common Test suite for the eturnal TURN server
Added a new Common Test suite (eturnal\_SUITE) and its configuration file to validate the eturnal server's core functionality. The tests verify server startup and status checks, session management (listing and disconnecting sessions for specific users), credential generation and validation (including static credentials and various expiry formats), log level configuration, and connectivity over TCP, UDP, and TLS.
test · high confidence
Dependencies
Major dependency upgrade and build system modernization
The project has upgraded its core dependencies from Git branches to specific Hex.pm package versions, introducing new modules for Prometheus metrics (prometheus, prometheus\_httpd, accept) and InfluxDB stats (influx\_udp, poolboy, ulitos, quantile\_estimator). The build configuration (rebar.config) has been modernized to use Relx's new 'mode' option, enable rich compiler messages, and enforce stricter linting (warnings\_as\_errors). The Dockerfile has been updated to use Wolfi OS (glibc) as the base image, with Alpine variants now explicitly suffixed, and includes support for Docker secrets and an optional acme.sh variant.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 60 → 68 (+7.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 99 (+3.4)
- Architecture 100 → 100 (+0.0)
- Maturity 65 → 69 (+4.2)
- Readiness 73 → 86 (+13.3)
- Security 44 → 53 (+9.2)
Resolved (56)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 36 more
New (75)
- CI runs a third-party container image from a mutable tag (.github/workflows/container-build-publish.yml)
- Coverage not measured — no coverage collector is wired up
- High IaC: WD-DOCKER-0001 (Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 55 more
Changes since last survey
- 22 commits — 21 feature/other, 1 fixes
By area
- (root) — 8 commits
- config/reltool.config — 4 commits
- .github/workflows — 3 commits
- config/doc.config — 2 commits
- (repo) — 1 commit
- Formula/eturnal.rb — 1 commit
- doc/CONTAINER-BUILD.md — 1 commit
- tools/ctrrel — 1 commit
- tools/make-binaries — 1 commit
Notable commits
- fix: Dockerfile: fix COPY of /rootfs onto merged-/usr base
- change: Bump Erlang dependencies
- change: Bump Erlang/OTP version to 29.1
- change: Bump OpenSSL version to 3.6.4
- change: Bump container version to 1.12.2-r5
- change: CHANGELOG.md: Fix typos
- change: CI: Run "rebar3 lint" only on Erlang/OTP 29.1
- change: CONTAINER-BUILD.md: Quote edge labels in diagram
- change: Dockerfile: install wget on glibc base, update acme.sh to 3.1.4
- change: Formula: update to 1.12.3
- change: MacOS CI: Update Homebrew branch name
- change: Merge remote-tracking branch 'processone/pr/116'
- change: Release 1.12.3
- change: build(deps): bump actions/stale
- change: doc.config: Update Mermaid integration
- change: doc.config: Use binary strings throughout
- change: make-binaries: Bump Linux kernel headers to 3.19
- change: make-binaries: Bump crosstool-NG version to 1.29.0
- change: reltool.config: Also exclude actual "include" dirs
- change: reltool.config: Don't exclude 'tools' application
- …and 2 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
processone/eturnal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b09bea4f8f104697dc281ae2eb816da0337edbf7 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.