// the find
ossrs/oryx
Oryx (SRS Stack) is an AI-driven, all-in-one, out-of-the-box, and open-source video solution for creating online video services, including live streaming and WebRTC, in the cloud or through self-hosting.
Oryx is a self-hosted video stack packaged as a single Docker image. It wraps the SRS media server with nginx, Redis, FFmpeg, and a Go management service that handles auth, DVR, transcoding, and restreaming through a web console. It is aimed at people who want a live streaming service on one machine without assembling those parts themselves.
- The README gives the full port map (80 and 443 TCP, 1935 RTMP, 8000 UDP for WebRTC, 10080 UDP for SRT) and the /data volume layout, so you know what to back up and what to open before you run it.
- Automatic HTTPS through LEGO and Let's Encrypt is built in, and the README warns that browser WHIP will not work from localhost. That is the mistake most people hit first.
- Recording and transcoding exist as Go modules you can read: dvr-local-disk.go, dvr-tencent-cos.go, dvr-tencent-vod.go, and trancode.go under platform/. The feature list maps to code.
- MIT licensed, and the protocol work sits on SRS, which is a mature media server.
- Everything runs in one container: SRS, nginx, Redis, FFmpeg, the Go service, and the React console. That is convenient on one box, but you cannot scale or replace one piece without forking the image.
- The README was last dated 2022.11 and is mostly a feature checklist with blog links, several of them Chinese-language. Roadmap items such as GB28181, WebRTC chat rooms, log collection, and container upgrades from the UI are still unchecked. The architecture lives in DEVELOPER.md and a Figma file.
- The AI features (transcription, dubbing, OCR, the AI assistant) depend on OpenAI. The README says nothing about per-minute cost, what audio or frames leave the box, or how the API key is stored.
- The admin password is a single MGMT_PASSWORD environment variable that the README says is also saved in /data/config/.env. The roadmap still lists enhancing the Prometheus API with authentication as unfinished.