# Deploy the live RTMP/SRT ingest and restream template with OpenTofu

Source: https://docs.quake.ai/resources/deployments/deploy-live-ingest-restream-template
Markdown: https://docs.quake.ai/resources/deployments/deploy-live-ingest-restream-template.md
> Stand up a CPU ingest VM that accepts an RTMP push and fans out to downstream RTMP endpoints using the live-ingest-restream OpenTofu template.

---

# Deploy the live RTMP/SRT ingest and restream template with OpenTofu

Stand up a CPU ingest VM that accepts an RTMP push and fans out to downstream RTMP endpoints using the [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked) `live-ingest-restream`. The template provisions NGINX-RTMP or SRS on CPU only; multi-rung ABR ladders are bounded on CPU, so prefer pass-through restream where possible.

<PricingCompanion
  components={[
    { kind: "template", slug: "live-ingest-restream", required: true },
  ]}
/>

<Figure size="md" caption="Live ingest topology: one floating IP accepts RTMP from your encoder; the ingest VM restreams to downstream platforms">

```d2
direction: right

encoder: OBS or hardware encoder {
  shape: person
}

cloud: Quake AI {
  fip: Floating IP\nRTMP 1935
  ingest: CPU ingest VM\nNGINX-RTMP or SRS
  optional: Object Storage\nHLS replay (optional)
  downstream: YouTube / Twitch / custom RTMP
}

encoder -> cloud.fip: RTMP push
cloud.ingest -> cloud.downstream: restream
cloud.ingest -> cloud.optional: HLS segments
```

</Figure>

## Prerequisites

You need:

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- OpenTofu 1.6.0 or later ([installation guide](https://opentofu.org/docs/intro/install/))
- OpenStack credentials sourced into the shell (`source openrc.sh`). See [the OpenStack CLI guide](/docs/tools/openstack-cli).
- An SSH key pair already uploaded to the project. See [Add an SSH key](/docs/tools/add-ssh-key).
- A copy of the `live-ingest-restream` template from [the template reference page](/resources/iac-templates/live-ingest-restream)
- One floating IP available in your project quota
- An encoder (OBS Studio or a hardware RTMP source) that can push to a public RTMP URL
- Enough project quota for one `c2a.large` instance, one 40 GB boot volume, one private network, one router, and one floating IP
- EC2-compatible Object Storage credentials in `terraform.tfvars` (required for `tofu plan` even when HLS replay is disabled)

## Step 1: Configure variables

Mint EC2-compatible credentials with `openstack ec2 credentials create` and copy `terraform.tfvars.example` to `terraform.tfvars`:

```hcl
key_name = "YOUR_KEY_NAME"

encoder_cidr = "203.0.113.10/32"
admin_cidr   = "203.0.113.10/32"

application_name = "live"

restream_targets = [
  "rtmp://a.rtmp.youtube.com/live2/YOUR_YOUTUBE_STREAM_KEY",
]

s3_access_key = "YOUR_EC2_ACCESS_KEY"
s3_secret_key = "YOUR_EC2_SECRET_KEY"
```

Replace CIDR values with your studio egress IP. Defaults for `ingest_server`, `ingest_flavor`, and HLS replay options are documented on the [Live RTMP/SRT ingest and restream](/resources/iac-templates/live-ingest-restream) reference page.

## Step 2: Apply the template

From the template directory, run:

```bash
tofu init
tofu plan
tofu apply
```

Type `yes` when prompted. Provisioning takes a few minutes while cloud-init installs the ingest software.

When the run finishes, note `rtmp_publish_url` and `ingest_floating_ip` from the outputs. Append your `stream_key` to the URL when you set one in `terraform.tfvars`.

## Step 3: Verify the ingest endpoint

In OBS Studio, open **Settings** > **Stream**, choose **Custom** service, and set:

- **Server:** the `rtmp_publish_url` output (for example `rtmp://207.x.x.x/live`)
- **Stream key:** your configured key, or leave blank when `stream_key` is empty

Start a short test stream. Confirm the ingest instance status is **Active** in the Console.

From your workstation, confirm the floating IP responds on port 1935:

```bash
nc -zv "$(tofu output -raw ingest_floating_ip)" 1935
```

A successful probe reports the port open. If OBS cannot connect, verify `encoder_cidr` includes your encoder's public egress address.

When you configured `restream_targets`, check each downstream platform's live dashboard for an incoming signal after you start streaming.

## Next steps

- [Live RTMP/SRT ingest and restream template](/resources/iac-templates/live-ingest-restream)
- [Live streaming and restream](/resources/solutions/live-streaming-and-restream)
- Set `ingest_server = "srs"` when your encoder pushes SRT instead of RTMP

## Clean up

If you enabled HLS replay, empty the bucket before destroy. Run `tofu destroy` from the project directory when finished.
