# Deploying Revenue Network Signaling Server on Debian VPS

This is the **recommended** way so friends outside your LAN can connect.

## 1. Provision a Debian VPS
- Any cheap VPS works (Hetzner Cloud, DigitalOcean, Linode, etc.).
- Choose Debian 12 (Bookworm) or Ubuntu 22.04/24.04.

## 2. Initial Setup on the VPS

```bash
# Update system
apt update && apt upgrade -y

# Install required packages
apt install -y curl git ufw

# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt install -y nodejs

# Install PM2 (process manager)
npm install -g pm2
```

## 3. Deploy the Server

### Option A: Using scp from your machine (easiest)
On your local computer:

```powershell
# From PowerShell
scp -r "C:\Users\zapm1\Revenuecord\src\equicordplugins\RevenueNetwork\server" root@YOUR_VPS_IP:/opt/
```

On the VPS:

```bash
cd /opt/server
npm install --production
```

### Option B: Git (if you push the server folder)

## 4. Run with PM2 (persistent)

```bash
cd /opt/server
pm2 start index.js --name revenue-signaling
pm2 save
pm2 startup
# Run the command that pm2 startup prints
```

## 5. Firewall

```bash
ufw allow ssh
ufw allow 8765/tcp
ufw enable
```

Test:
```bash
curl http://localhost:8765/status
```

## 6. (Recommended) Add HTTPS + Domain (wss://)

For production you should use `wss://` instead of `ws://`.

1. Point a subdomain (e.g. `voice.yourdomain.com`) to your VPS.
2. Install nginx + certbot:

```bash
apt install -y nginx certbot python3-certbot-nginx
certbot --nginx -d voice.yourdomain.com
```

3. Create nginx config `/etc/nginx/sites-available/revenue`:

```nginx
server {
    listen 443 ssl;
    server_name voice.yourdomain.com;

    ssl_certificate /etc/letsencrypt/live/voice.yourdomain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/voice.yourdomain.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:8765;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}
```

4. Enable it and reload nginx.

Now set the plugin `serverUrl` to:
```
wss://voice.yourdomain.com
```

## 7. Update Plugin Settings

In the RevenueNetwork plugin settings:
- `serverUrl`: `ws://YOUR_VPS_IP:8765` or `wss://yourdomain.com`
- Everyone who wants to join must use the **same** serverUrl and the same `revenueChannelId`.

## Notes
- The server currently has no authentication. Only share the address with trusted people.
- For larger groups you may later want to add simple token auth.
- WebRTC will work as long as STUN works (Google STUN servers are used by default). Some strict corporate networks may need TURN.

Enjoy your private voice network!