Ingest stream slots: let standard streaming tools (WHIP) publish into encrypted Matrix calls #145

Open
opened 2026-10-02 01:35:14 +00:00 by robocub · 0 comments
Member

Follow-up to ADR 0002 (external stream publishers), Matrix side only.

Stream slots as designed in ADR 0002 hand a publisher a scoped Matrix login, so the publisher must run a MatrixRTC client such as Element Call. Standard streaming tools (e.g. OBS) speak WHIP instead, and an SFU-side ingress cannot apply Element Call's end-to-end media encryption, so they cannot reach encrypted calls that way.

Idea: an ingest kind of slot on the same publisher keys, identities, rate limits and audit trail, where the bridge terminates WHIP and publishes the stream itself as the slot's identity with the room's E2EE.

Needs video handling in the bridge's Matrix/LiveKit side (receive WHIP, republish with frame encryption). Nothing Discord-side: Discord stays audio-only.

Follow-up to ADR 0002 (external stream publishers), Matrix side only. Stream slots as designed in ADR 0002 hand a publisher a scoped Matrix login, so the publisher must run a MatrixRTC client such as Element Call. Standard streaming tools (e.g. OBS) speak WHIP instead, and an SFU-side ingress cannot apply Element Call's end-to-end media encryption, so they cannot reach **encrypted** calls that way. Idea: an *ingest* kind of slot on the same publisher keys, identities, rate limits and audit trail, where the bridge terminates WHIP and publishes the stream itself as the slot's identity with the room's E2EE. Needs video handling in the bridge's Matrix/LiveKit side (receive WHIP, republish with frame encryption). Nothing Discord-side: Discord stays audio-only.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nether/nether-voicebridge#145
No description provided.