006
AEGISMEDIA PLATFORM
SYSTEM ONLINE
/
OPEN AEGIS
CORE STACK
WebRTCmediasoupmediasoup-clientFFmpegWebSocketcoturn / TURNNginxDocker Compose
● VERIFIED
self-hosted media control plane
AEGISMEDIA PLATFORM

Media under control.
From ingest to protected playback.

Aegis combines processing, delivery, protected playback, WebRTC and AI jobs in one self-hosted media control plane.

Self-hosted Bearer auth Protected playback Live & AI
Aegis Console / DashboardAPI: connected

Media operations

demo tenant · anonymized data
● LIVE
Total assets248+18 / 7d
Active sessions12live now
Processing73 queued
Failed jobs2needs attention
Recent assetsVIEW ALL
▶
launch-film-v07.mp4video · 3840×2160 · 1.8 GB
PUBLISHED
◩
campaign-keyvisual.webpimage · 2400×1800 · 8.2 MB
PROCESSING
♫
episode-24-master.wavaudio · 48 kHz · 412 MB
READY
Queue load3/4 ACTIVE
encode_gpu71%
package_hls38%
ai_jobs54%
Protected playback● ACTIVE
Session 7F2A•••asset: launch-film-v07 · TTL 04:32
watermarkdevice boundmanifest only
VideoVOD / protected playbackConferencesWebRTC / recording / AIAudioplayer / protected sessionsImagesresize / derivatives / watermarkDocumentsPDF / access / watermarkAIASR / moderation / summary
01 / PLATFORM

Not just storage. A complete media operations layer.

From source ingest to delivery, playback policies and AI processing, Aegis keeps the full media lifecycle inside one control plane.

Media pipeline

Assets move through ingest, processing and publishing via controlled jobs and queues.

INUpload registeredsource accepted · checksum verifieddone
ENCEncode derivativesGPU worker · profile adaptive-hlsdone
PKGPackage manifestssegments + delivery metadatarunning
AIASR / moderation / summarypolicy-driven downstream jobsqueued

Live & AI

Realtime calls, recording ingest and downstream ASR, moderation and summary jobs.

Queue routing

Priority lanes and concurrency limits for CPU/GPU workers.

Watermarking

Configurable watermark policies for protected delivery.

Access control

Bearer auth, tenants, device fingerprint and revoke controls.

02 / MEDIA SUITE

One infrastructure. Multiple media workflows.

Video is only one part of Aegis. Conferences, audio, images and documents each get their own processing flow and the same access policies.

CONFERENCE

Conferences and AI notes

WebRTC rooms, signaling, recording ingest and downstream ASR / summary.

● LIVE ROOMAEGIS / PRODUCT REVIEW04 PARTICIPANTS
AKAlex · hostMSMira · productDVDan · designIRIra · client
MIC ONCAM ON● RECAI NOTES
03 / PROTECTED PLAYBACK

The source is never public. The user receives a short-lived session.

The backend creates a playback session, the frontend receives a manifest URL, and delivery passes through a policy-aware gateway.

Your backendAuthorization: Bearer
→
Aegis APIcreate playback session
→
Playback gatewayTTL · device · watermark · revoke
POST /api/v1/playback/sessions\nAuthorization: Bearer <token>\nX-Device-Fingerprint: optional-client-fingerprint
04 / USE CASES

One platform for the whole protected media stack.

01 / VOD

Protected video

Adaptive delivery, short-lived playback sessions and active-session control.

02 / CONFERENCE

Conferences

WebRTC rooms, signaling, recording ingest and downstream AI processing.

03 / AUDIO

Private audio

Protected podcasts, lessons and voice archives with session-bound playback.

04 / IMAGE

Image processing

Resize, crop, format conversion, derivatives and watermark policies.

05 / DOCUMENT

Protected documents

PDF delivery with TTL, watermarking and device-aware access control.

06 / AI

AI media pipeline

ASR, moderation, summary and policy-driven post-processing jobs.

AEGIS / SELF-HOSTED MEDIA PLATFORM

Media infrastructure you control.

Self-hosted deployment, protected delivery, media processing and AI jobs without public source URLs.

OPEN AEGIS
07 / ENGINEERING STACK

The stack and architecture are not an appendix. They are the case.

Only technologies and engineering mechanisms actually verified for AEGIS are shown here: media plane, realtime signaling, recording, protected delivery and deployment.

01Media plane
WebRTCmediasoupmediasoup-clientPlain RTPcoturn / TURN

Realtime media transport, SFU routing and NAT traversal.

02Processing & recording
FFmpeg recorderHLS packagingMKV chunks / tracksGPU workers

Recording, adaptive derivatives and delivery packaging.

03Control plane
REST APIWebSocket signalingJWTBearer auth

Session orchestration, signaling and authenticated API access.

04Protected delivery
Playback sessionsDevice fingerprintWatermarkTTLRevoke

Short-lived access instead of permanent public media URLs.

05Infrastructure
NginxDocker ComposeSelf-hostedReverse proxyEdge routing

Portable deployment with explicit control over network and media paths.

06AI pipeline
ASR jobsModeration jobsSummary jobsRecording ingest

Policy-driven downstream jobs after live sessions and media ingest.

MEDIA / CONTROL PATHBrowser → SFU → recorder → protected delivery
CLIENTBrowser / SDKmediasoup-client · WebRTC
→
SIGNALINGWebSocketJWT · session state
→
MEDIA PLANEmediasoup SFUWebRTC · RTP routing
→
RECORDINGPlain RTPSFU → recorder
→
PROCESSINGFFmpegMKV · HLS packaging
REST APIBearer / JWT
→
Playback sessionTTL · fingerprint · revoke
→
Nginx gatewayreverse proxy · WebSocket
→
Network edgecoturn / TURN
SELF-HOSTEDREALTIME MEDIAPROTECTED DELIVERYCONTAINERIZED DEPLOYMENT