[{"data":1,"prerenderedAt":2455},["ShallowReactive",2],{"navigation_docs_en":3,"-en-installation-control-and-encoder-same-host":431,"-en-installation-control-and-encoder-same-host-surround":2450},[4,25,83,133,247,262,332,365,411],{"title":5,"path":6,"stem":7,"children":8,"page":24},"Getting Started","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[9,14,19],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fen\u002Fgetting-started\u002Fintroduction","en\u002F1.getting-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Quickstart","\u002Fen\u002Fgetting-started\u002Fquickstart","en\u002F1.getting-started\u002F2.quickstart","i-lucide-rocket",{"title":20,"path":21,"stem":22,"icon":23},"Concepts","\u002Fen\u002Fgetting-started\u002Fconcepts","en\u002F1.getting-started\u002F3.concepts","i-lucide-book-open",false,{"title":26,"path":27,"stem":28,"children":29,"page":24},"Live Production","\u002Fen\u002Flive-production","en\u002F2.live-production",[30,35,55,69],{"title":31,"path":32,"stem":33,"icon":34},"On air","\u002Fen\u002Flive-production\u002Fon-air","en\u002F2.live-production\u002F1.on-air","i-lucide-radio",{"title":36,"path":37,"stem":38,"children":39,"page":24},"Live Streams","\u002Fen\u002Flive-production\u002Flive-streams","en\u002F2.live-production\u002F2.live-streams",[40,45,50],{"title":41,"path":42,"stem":43,"icon":44},"Overview","\u002Fen\u002Flive-production\u002Flive-streams\u002Foverview","en\u002F2.live-production\u002F2.live-streams\u002F1.overview","i-lucide-list",{"title":46,"path":47,"stem":48,"icon":49},"Options","\u002Fen\u002Flive-production\u002Flive-streams\u002Flive-stream-options","en\u002F2.live-production\u002F2.live-streams\u002F2.live-stream-options","i-lucide-file-text",{"title":51,"path":52,"stem":53,"icon":54},"Start and stop","\u002Fen\u002Flive-production\u002Flive-streams\u002Fstart-stop","en\u002F2.live-production\u002F2.live-streams\u002F3.start-stop","i-lucide-play-circle",{"title":56,"path":57,"stem":58,"children":59,"page":24},"Scheduler","\u002Fen\u002Flive-production\u002Fscheduler","en\u002F2.live-production\u002F3.scheduler",[60,64],{"title":41,"path":61,"stem":62,"icon":63},"\u002Fen\u002Flive-production\u002Fscheduler\u002Foverview","en\u002F2.live-production\u002F3.scheduler\u002F1.overview","i-lucide-calendar-clock",{"title":65,"path":66,"stem":67,"icon":68},"Planned actions","\u002Fen\u002Flive-production\u002Fscheduler\u002Fplanned-actions","en\u002F2.live-production\u002F3.scheduler\u002F2.planned-actions","i-lucide-alarm-clock",{"title":70,"path":71,"stem":72,"children":73,"page":24},"Recordings","\u002Fen\u002Flive-production\u002Frecordings","en\u002F2.live-production\u002F4.recordings",[74,78],{"title":41,"path":75,"stem":76,"icon":77},"\u002Fen\u002Flive-production\u002Frecordings\u002Foverview","en\u002F2.live-production\u002F4.recordings\u002F1.overview","i-lucide-circle-dot",{"title":79,"path":80,"stem":81,"icon":82},"Editor","\u002Fen\u002Flive-production\u002Frecordings\u002Feditor","en\u002F2.live-production\u002F4.recordings\u002F2.editor","i-lucide-scissors",{"title":84,"path":85,"stem":86,"children":87,"page":24},"Configuration","\u002Fen\u002Fconfiguration","en\u002F3.configuration",[88,102,107,120],{"title":89,"path":90,"stem":91,"children":92,"page":24},"Devices","\u002Fen\u002Fconfiguration\u002Fdevices","en\u002F3.configuration\u002F1.devices",[93,97],{"title":89,"path":94,"stem":95,"icon":96},"\u002Fen\u002Fconfiguration\u002Fdevices\u002Fdevices","en\u002F3.configuration\u002F1.devices\u002F1.devices","i-lucide-server",{"title":98,"path":99,"stem":100,"icon":101},"Groups","\u002Fen\u002Fconfiguration\u002Fdevices\u002Fgroups","en\u002F3.configuration\u002F1.devices\u002F2.groups","i-lucide-network",{"title":103,"path":104,"stem":105,"icon":106},"Sources","\u002Fen\u002Fconfiguration\u002Fsources","en\u002F3.configuration\u002F2.sources","i-lucide-cable",{"title":108,"path":109,"stem":110,"children":111,"page":24},"Encodings","\u002Fen\u002Fconfiguration\u002Fencodings","en\u002F3.configuration\u002F3.encodings",[112,116],{"title":108,"path":113,"stem":114,"icon":115},"\u002Fen\u002Fconfiguration\u002Fencodings\u002Fprofiles","en\u002F3.configuration\u002F3.encodings\u002F1.profiles","i-lucide-sliders-horizontal",{"title":98,"path":117,"stem":118,"icon":119},"\u002Fen\u002Fconfiguration\u002Fencodings\u002Fgroups","en\u002F3.configuration\u002F3.encodings\u002F2.groups","i-lucide-layers",{"title":121,"path":122,"stem":123,"children":124,"page":24},"Destinations","\u002Fen\u002Fconfiguration\u002Fdestinations","en\u002F3.configuration\u002F4.destinations",[125,129],{"title":121,"path":126,"stem":127,"icon":128},"\u002Fen\u002Fconfiguration\u002Fdestinations\u002Fdestinations","en\u002F3.configuration\u002F4.destinations\u002F1.destinations","i-lucide-send",{"title":98,"path":130,"stem":131,"icon":132},"\u002Fen\u002Fconfiguration\u002Fdestinations\u002Fpublishing-groups","en\u002F3.configuration\u002F4.destinations\u002F2.publishing-groups","i-lucide-share-2",{"title":134,"path":135,"stem":136,"children":137,"page":24},"Settings","\u002Fen\u002Fsettings","en\u002F4.settings",[138,151,156,172,188],{"title":139,"path":140,"stem":141,"children":142,"page":24},"Users","\u002Fen\u002Fsettings\u002Fusers","en\u002F4.settings\u002F1.users",[143,147],{"title":139,"path":144,"stem":145,"icon":146},"\u002Fen\u002Fsettings\u002Fusers\u002Fusers","en\u002F4.settings\u002F1.users\u002F1.users","i-lucide-user",{"title":98,"path":148,"stem":149,"icon":150},"\u002Fen\u002Fsettings\u002Fusers\u002Fuser-groups","en\u002F4.settings\u002F1.users\u002F2.user-groups","i-lucide-users",{"title":152,"path":153,"stem":154,"icon":155},"Security","\u002Fen\u002Fsettings\u002Fsecurity","en\u002F4.settings\u002F2.security","i-lucide-shield",{"title":157,"icon":158,"path":159,"stem":160,"children":161,"page":24},"Assets","i-lucide-image","\u002Fen\u002Fsettings\u002Fassets","en\u002F4.settings\u002F3.assets",[162,167],{"title":163,"path":164,"stem":165,"icon":166},"Logos","\u002Fen\u002Fsettings\u002Fassets\u002Flogos","en\u002F4.settings\u002F3.assets\u002F1.logos","i-lucide-images",{"title":168,"path":169,"stem":170,"icon":171},"Files","\u002Fen\u002Fsettings\u002Fassets\u002Ffiles","en\u002F4.settings\u002F3.assets\u002F2.files","i-lucide-clapperboard",{"title":173,"icon":174,"path":175,"stem":176,"children":177,"page":24},"External Storage","i-lucide-folder-cog","\u002Fen\u002Fsettings\u002Fexternal-storage","en\u002F4.settings\u002F4.external-storage",[178,183],{"title":179,"path":180,"stem":181,"icon":182},"Remote Folders","\u002Fen\u002Fsettings\u002Fexternal-storage\u002Fremote-folders","en\u002F4.settings\u002F4.external-storage\u002F1.remote-folders","i-lucide-folder-archive",{"title":184,"path":185,"stem":186,"icon":187},"Target Folders","\u002Fen\u002Fsettings\u002Fexternal-storage\u002Ftarget-folders","en\u002F4.settings\u002F4.external-storage\u002F2.target-folders","i-lucide-folder-up",{"title":189,"path":190,"stem":191,"children":192,"page":24},"Integrations","\u002Fen\u002Fsettings\u002Fintegrations","en\u002F4.settings\u002F5.integrations",[193,197,202,216],{"title":41,"path":194,"stem":195,"icon":196},"\u002Fen\u002Fsettings\u002Fintegrations\u002Foverview","en\u002F4.settings\u002F5.integrations\u002F1.overview","i-lucide-plug",{"title":198,"path":199,"stem":200,"icon":201},"MediaCopilot","\u002Fen\u002Fsettings\u002Fintegrations\u002Fmediacopilot","en\u002F4.settings\u002F5.integrations\u002F2.mediacopilot","i-lucide-sparkles",{"title":203,"icon":204,"path":205,"stem":206,"children":207,"page":24},"C21 Live Cloud","i-lucide-cloud","\u002Fen\u002Fsettings\u002Fintegrations\u002Fc21livecloud","en\u002F4.settings\u002F5.integrations\u002F3.c21livecloud",[208,211],{"title":41,"path":209,"stem":210,"icon":204},"\u002Fen\u002Fsettings\u002Fintegrations\u002Fc21livecloud\u002Foverview","en\u002F4.settings\u002F5.integrations\u002F3.c21livecloud\u002F1.overview",{"title":212,"path":213,"stem":214,"icon":215},"Accounts","\u002Fen\u002Fsettings\u002Fintegrations\u002Fc21livecloud\u002Faccounts","en\u002F4.settings\u002F5.integrations\u002F3.c21livecloud\u002F2.accounts","i-lucide-key-round",{"title":217,"icon":155,"path":218,"stem":219,"children":220,"page":24},"DRM Providers","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm","en\u002F4.settings\u002F5.integrations\u002F4.drm",[221,225,229,233,237,242],{"title":41,"path":222,"stem":223,"icon":224},"\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Foverview","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F1.overview","i-lucide-shield-check",{"title":226,"path":227,"stem":228,"icon":155},"Widevine","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Fwidevine","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F2.widevine",{"title":230,"path":231,"stem":232,"icon":155},"PlayReady","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Fplayready","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F3.playready",{"title":234,"path":235,"stem":236,"icon":155},"FairPlay","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Ffairplay","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F4.fairplay",{"title":238,"path":239,"stem":240,"icon":241},"Providers","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Fproviders","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F5.providers","i-lucide-shield-half",{"title":243,"path":244,"stem":245,"icon":246},"Workflow","\u002Fen\u002Fsettings\u002Fintegrations\u002Fdrm\u002Fworkflow","en\u002F4.settings\u002F5.integrations\u002F4.drm\u002F6.workflow","i-lucide-workflow",{"title":248,"path":249,"stem":250,"children":251,"page":24},"System Status","\u002Fen\u002Fsystem-status","en\u002F5.system-status",[252,257],{"title":253,"path":254,"stem":255,"icon":256},"Commands","\u002Fen\u002Fsystem-status\u002Fcommands","en\u002F5.system-status\u002F1.commands","i-lucide-square-terminal",{"title":258,"path":259,"stem":260,"icon":261},"Logs","\u002Fen\u002Fsystem-status\u002Flogs","en\u002F5.system-status\u002F2.logs","i-lucide-scroll-text",{"title":263,"path":264,"stem":265,"children":266,"page":24},"How Tos","\u002Fen\u002Fhow-tos","en\u002F6.how-tos",[267,272,277,282,286,291,296,300,304,309,313,318,323,328],{"title":268,"path":269,"stem":270,"icon":271},"Start and stop a Live stream","\u002Fen\u002Fhow-tos\u002Fstart-stream-via-api","en\u002F6.how-tos\u002F1.start-stream-via-api","i-lucide-terminal",{"title":273,"path":274,"stem":275,"icon":276},"Ingest a YouTube Live broadcast","\u002Fen\u002Fhow-tos\u002Fingest-youtube-live","en\u002F6.how-tos\u002F10.ingest-youtube-live","i-lucide-youtube",{"title":278,"path":279,"stem":280,"icon":281},"Source Synchronized Encoding (SSE) — bit-identical redundancy","\u002Fen\u002Fhow-tos\u002Fsource-synchronized-encoding","en\u002F6.how-tos\u002F11.source-synchronized-encoding","i-lucide-copy-check",{"title":283,"path":284,"stem":285,"icon":34},"Broadcast radio as video","\u002Fen\u002Fhow-tos\u002Fbroadcast-radio-as-video","en\u002F6.how-tos\u002F12.broadcast-radio-as-video",{"title":287,"path":288,"stem":289,"icon":290},"Real Time streaming to Dolby Millicast","\u002Fen\u002Fhow-tos\u002Freal-time-streaming","en\u002F6.how-tos\u002F13.real-time-streaming","i-lucide-zap",{"title":292,"path":293,"stem":294,"icon":295},"Publish to object storage (S3, Azure Blob)","\u002Fen\u002Fhow-tos\u002Fpublish-to-object-storage","en\u002F6.how-tos\u002F14.publish-to-object-storage","i-lucide-database",{"title":297,"path":298,"stem":299,"icon":224},"Protect a Live stream with multi-DRM","\u002Fen\u002Fhow-tos\u002Fmulti-drm-destination","en\u002F6.how-tos\u002F2.multi-drm-destination",{"title":301,"path":302,"stem":303,"icon":63},"Schedule a weekly recurring broadcast","\u002Fen\u002Fhow-tos\u002Fweekly-recurring-broadcast","en\u002F6.how-tos\u002F3.weekly-recurring-broadcast",{"title":305,"path":306,"stem":307,"icon":308},"Cut a clip in the Editor and send it to MediaCopilot","\u002Fen\u002Fhow-tos\u002Fexport-recording-to-mediacopilot","en\u002F6.how-tos\u002F4.export-recording-to-mediacopilot","i-lucide-upload-cloud",{"title":310,"path":311,"stem":312,"icon":158},"Apply a logo overlay to a running Live stream","\u002Fen\u002Fhow-tos\u002Fapply-logo-overlay","en\u002F6.how-tos\u002F5.apply-logo-overlay",{"title":314,"path":315,"stem":316,"icon":317},"Black out or replace the program on a running Live stream","\u002Fen\u002Fhow-tos\u002Fbroadcast-blackout","en\u002F6.how-tos\u002F6.broadcast-blackout","i-lucide-square",{"title":319,"path":320,"stem":321,"icon":322},"Switch the source of a running Live stream","\u002Fen\u002Fhow-tos\u002Fruntime-source-switch","en\u002F6.how-tos\u002F7.runtime-source-switch","i-lucide-repeat-2",{"title":324,"path":325,"stem":326,"icon":327},"Toggle a Publishing mid-broadcast","\u002Fen\u002Fhow-tos\u002Ftoggle-publishing-mid-broadcast","en\u002F6.how-tos\u002F8.toggle-publishing-mid-broadcast","i-lucide-toggle-right",{"title":329,"path":330,"stem":331,"icon":34},"Contribute a live signal to MediaCopilot Live","\u002Fen\u002Fhow-tos\u002Fcontribute-to-mediacopilot-live","en\u002F6.how-tos\u002F9.contribute-to-mediacopilot-live",{"title":333,"path":334,"stem":335,"children":336,"page":24},"Installation","\u002Fen\u002Finstallation","en\u002F7.installation",[337,342,347,352,357,361],{"title":338,"path":339,"stem":340,"icon":341},"Prepare the host","\u002Fen\u002Finstallation\u002Fprepare-host","en\u002F7.installation\u002F1.prepare-host","i-lucide-server-cog",{"title":343,"path":344,"stem":345,"icon":346},"Install C21 Live Control","\u002Fen\u002Finstallation\u002Fcontrol","en\u002F7.installation\u002F2.control","i-lucide-cloud-download",{"title":348,"path":349,"stem":350,"icon":351},"Install C21 Live Encoder","\u002Fen\u002Finstallation\u002Fencoder","en\u002F7.installation\u002F3.encoder","i-lucide-cpu",{"title":353,"path":354,"stem":355,"icon":356},"Updates","\u002Fen\u002Finstallation\u002Fupdates","en\u002F7.installation\u002F4.updates","i-lucide-refresh-cw",{"title":358,"path":359,"stem":360,"icon":215},"Licenses","\u002Fen\u002Finstallation\u002Flicenses","en\u002F7.installation\u002F5.licenses",{"title":362,"path":363,"stem":364,"icon":96},"Install C21 Live Control and C21 Live Encoder on one host","\u002Fen\u002Finstallation\u002Fcontrol-and-encoder-same-host","en\u002F7.installation\u002F6.control-and-encoder-same-host",{"title":366,"path":367,"stem":368,"children":369,"page":24},"Developers","\u002Fen\u002Fdevelopers","en\u002F8.developers",[370,374,392],{"title":41,"path":371,"stem":372,"icon":373},"\u002Fen\u002Fdevelopers\u002Foverview","en\u002F8.developers\u002F1.overview","i-lucide-code",{"title":375,"icon":373,"path":376,"stem":377,"children":378,"page":24},"API","\u002Fen\u002Fdevelopers\u002Fapi","en\u002F8.developers\u002F2.api",[379,382,387],{"title":41,"path":380,"stem":381,"icon":373},"\u002Fen\u002Fdevelopers\u002Fapi\u002Foverview","en\u002F8.developers\u002F2.api\u002F1.overview",{"title":383,"path":384,"stem":385,"icon":386},"Authentication","\u002Fen\u002Fdevelopers\u002Fapi\u002Fauthentication","en\u002F8.developers\u002F2.api\u002F2.authentication","i-lucide-key",{"title":388,"path":389,"stem":390,"icon":391},"Pagination and Errors","\u002Fen\u002Fdevelopers\u002Fapi\u002Fpagination-errors","en\u002F8.developers\u002F2.api\u002F3.pagination-errors","i-lucide-list-ordered",{"title":393,"icon":394,"path":395,"stem":396,"children":397,"page":24},"MCP Server","i-lucide-bot","\u002Fen\u002Fdevelopers\u002Fmcp-server","en\u002F8.developers\u002F3.mcp-server",[398,401,406],{"title":41,"path":399,"stem":400,"icon":394},"\u002Fen\u002Fdevelopers\u002Fmcp-server\u002Foverview","en\u002F8.developers\u002F3.mcp-server\u002F1.overview",{"title":402,"path":403,"stem":404,"icon":405},"Tools","\u002Fen\u002Fdevelopers\u002Fmcp-server\u002Ftools","en\u002F8.developers\u002F3.mcp-server\u002F2.tools","i-lucide-wrench",{"title":407,"path":408,"stem":409,"icon":410},"Examples","\u002Fen\u002Fdevelopers\u002Fmcp-server\u002Fexamples","en\u002F8.developers\u002F3.mcp-server\u002F3.examples","i-lucide-play",{"title":412,"path":413,"stem":414,"children":415,"page":24},"Resources","\u002Fen\u002Fresources","en\u002F9.resources",[416,421,426],{"title":417,"path":418,"stem":419,"icon":420},"Links","\u002Fen\u002Fresources\u002Flinks","en\u002F9.resources\u002F1.links","i-lucide-link",{"title":422,"path":423,"stem":424,"icon":425},"Release Notes","\u002Fen\u002Fresources\u002Frelease-notes","en\u002F9.resources\u002F2.release-notes","i-lucide-clipboard-list",{"title":427,"path":428,"stem":429,"icon":430},"Glossary","\u002Fen\u002Fresources\u002Fglossary","en\u002F9.resources\u002F3.glossary","i-lucide-book-a",{"id":432,"title":362,"body":433,"description":2443,"extension":2444,"links":2445,"meta":2446,"navigation":2447,"path":363,"seo":2448,"stem":364,"__hash__":2449},"docs_en\u002Fen\u002F7.installation\u002F6.control-and-encoder-same-host.md",{"type":434,"value":435,"toc":2424},"minimark",[436,441,457,467,480,484,492,598,601,617,624,628,666,673,677,2284,2287,2290,2325,2332,2384,2388,2420],[437,438,440],"h2",{"id":439},"when-to-use-this-layout","When to use this layout",[442,443,444,445,449,450,453,454,456],"p",{},"A single host runs both ",[446,447,448],"strong",{},"C21 Live Control"," (a Docker compose stack) and ",[446,451,452],{},"C21 Live Encoder"," (the encoding engine and its Apache front end, installed on the host).\nLive Control manages the Encoder on its own host through the ",[446,455,89],{}," section, and can manage other Encoders on other hosts as well.",[442,458,459,460,463,464,466],{},"This layout suits deployments with few hosts available, such as a cloud VM that has to provide both the control plane and the first encoding capacity.\nWhen you have more than one host, the standard layout — Control and each Encoder on their own hosts — is simpler to operate: follow\n",[461,462,343],"a",{"href":344}," and ",[461,465,348],{"href":349}," instead.",[468,469,471,474,475,479],"callout",{"icon":470},"i-lucide-triangle-alert",[446,472,473],{},"Updating Live Control interrupts the local Encoder."," Every Live Control update restarts the Docker service, and the Encoder service is stopped and\nstarted with it. Live streams on the Encoder of the same host drop for about one to two minutes and then recover on their own.\nPlan every Live Control update in a maintenance window — see ",[461,476,478],{"href":477},"#updates-on-a-shared-host","Updates on a shared host",".",[437,481,483],{"id":482},"how-the-two-products-share-the-host","How the two products share the host",[442,485,486,487,491],{},"Both products serve HTTPS on port ",[488,489,490],"code",{},"443"," by default, so one of them has to move. Everything else coexists without changes.",[493,494,495,514],"table",{},[496,497,498],"thead",{},[499,500,501,505,508,511],"tr",{},[502,503,504],"th",{},"Port",[502,506,507],{},"Live Control",[502,509,510],{},"Live Encoder",[502,512,513],{},"On a shared host",[515,516,517,540,556,570,584],"tbody",{},[499,518,519,525,528,531],{},[520,521,522],"td",{},[488,523,524],{},"443\u002Ftcp",[520,526,527],{},"HTTPS — operator UI and REST API",[520,529,530],{},"HTTPS — Encoder API and outputs",[520,532,533,536,537,479],{},[446,534,535],{},"Conflict."," Live Control moves to ",[488,538,539],{},"9443",[499,541,542,547,550,553],{},[520,543,544],{},[488,545,546],{},"80\u002Ftcp",[520,548,549],{},"—",[520,551,552],{},"HTTP",[520,554,555],{},"Unchanged.",[499,557,558,563,566,568],{},[520,559,560],{},[488,561,562],{},"9080\u002Ftcp",[520,564,565],{},"HTTP (redirects to HTTPS)",[520,567,549],{},[520,569,555],{},[499,571,572,577,580,582],{},[520,573,574],{},[488,575,576],{},"3100\u002Ftcp",[520,578,579],{},"MCP server",[520,581,549],{},[520,583,555],{},[499,585,586,591,593,596],{},[520,587,588],{},[488,589,590],{},"8484\u002Ftcp",[520,592,549],{},[520,594,595],{},"Delivery of outputs",[520,597,555],{},[442,599,600],{},"Live Control is the product that moves, not the Encoder, because:",[602,603,604,612],"ul",{},[605,606,607,608,611],"li",{},"Live Control reaches every registered Encoder at ",[488,609,610],{},"https:\u002F\u002F\u003Cencoder-ip>\u002F"," — the Device form takes an IP, not a port.",[605,613,614,615,479],{},"Players, CDNs and origins that pull the Encoder's local output fetch it from port ",[488,616,490],{},[442,618,619,620,623],{},"Both products also share the ",[446,621,622],{},"host fingerprint",": the license for both is bound to the same value.",[437,625,627],{"id":626},"before-you-start","Before you start",[602,629,630,647,650,653,663],{},[605,631,632,633,636,637,639,640,463,643,646],{},"A host that meets the prerequisites of ",[446,634,635],{},"both"," products — see ",[461,638,338],{"href":339},",\n",[461,641,343],{"href":642},"\u002Fen\u002Finstallation\u002Fcontrol#before-you-start",[461,644,348],{"href":645},"\u002Fen\u002Finstallation\u002Fencoder#before-you-start",".\nSize CPU and RAM for the Encoder workload plus the Control stack, which is capped at 4 cores and 3 GiB of RAM.",[605,648,649],{},"Ubuntu 24.04 LTS (required by the Encoder) with a fixed IP address.",[605,651,652],{},"The platform certificate and its private key for the host, issued by Cires21 for the host's IP (full chain: leaf and intermediate).\nThe self-signed certificate the installers generate is not enough: Live Control must be able to validate the Encoder's certificate to register it.",[605,654,655,656,659,660,662],{},"The same target version for both products, and ",[446,657,658],{},"6.12.0 or later on every Encoder this Control manages"," — local and remote.\nFrom 6.12.0 on, Live Control delivers logos and blackout files to the Encoder before each order. Earlier Encoders download them from Live Control\non port ",[488,661,490],{},", which on this host answers as the Encoder, so logo overlays and blackouts fail on them.",[605,664,665],{},"A maintenance window — the Encoder installer updates the SSH server and drops SSH sessions for one to two minutes.",[468,667,668,669,672],{"icon":271},"Run both installers detached from the SSH session (for example with ",[488,670,671],{},"nohup",") so that the SSH restart does not abort the install,\nand read the log to follow progress.",[437,674,676],{"id":675},"steps","Steps",[675,678,679,684,694,698,710,791,794,802,806,817,900,920,983,989,993,1045,1052,1056,1059,1087,1090,1166,1172,1176,1184,1316,1319,1374,1381,1385,1397,1403,1425,1429,1432,1508,1514,1531,1534,1599,1611,1687,1693,2022,2027,2097,2150,2160,2164,2174,2203,2210,2214,2278],{},[680,681,683],"h3",{"id":682},"_1-prepare-the-host","1. Prepare the host",[442,685,686,687,689,690,693],{},"Apply ",[461,688,338],{"href":339}," — DNS, NTP, swap and the OS update policy. For the firewall, follow step 8 below instead of the\n",[488,691,692],{},"ufw"," section of that page: on a shared host the Control ports are published by Docker and need a different rule set.",[680,695,697],{"id":696},"_2-install-live-control-first","2. Install Live Control first",[442,699,700,701,703,704,706,707,709],{},"Live Control goes first because its installer requires port ",[488,702,490],{}," to be free. Once it is moved to ",[488,705,539],{}," in the next step, port ",[488,708,490],{}," is free for the Encoder.",[711,712,717],"pre",{"className":713,"code":714,"language":715,"meta":716,"style":716},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sudo nohup bash -c \"curl -fsSL https:\u002F\u002Fget.cires21.com\u002Flivecontrol \\\n  | bash -s -- --version \u003CX.Y.Z> --yes; echo INSTALL_EXIT=\\$?\" > \u002Ftmp\u002Flc-install.log 2>&1 &\ntail -f \u002Ftmp\u002Flc-install.log      # Wait for INSTALL_EXIT=0\n","bash","",[488,718,719,749,776],{"__ignoreMap":716},[720,721,724,728,732,735,738,742,745],"span",{"class":722,"line":723},"line",1,[720,725,727],{"class":726},"sBMFI","sudo",[720,729,731],{"class":730},"sfazB"," nohup",[720,733,734],{"class":730}," bash",[720,736,737],{"class":730}," -c",[720,739,741],{"class":740},"sMK4o"," \"",[720,743,744],{"class":730},"curl -fsSL https:\u002F\u002Fget.cires21.com\u002Flivecontrol ",[720,746,748],{"class":747},"sTEyZ","\\\n",[720,750,752,755,758,761,764,767,770,773],{"class":722,"line":751},2,[720,753,754],{"class":730},"  | bash -s -- --version \u003CX.Y.Z> --yes; echo INSTALL_EXIT=",[720,756,757],{"class":747},"\\$",[720,759,760],{"class":730},"?",[720,762,763],{"class":740},"\"",[720,765,766],{"class":740}," >",[720,768,769],{"class":730}," \u002Ftmp\u002Flc-install.log",[720,771,772],{"class":740}," 2>&1",[720,774,775],{"class":740}," &\n",[720,777,779,782,785,787],{"class":722,"line":778},3,[720,780,781],{"class":726},"tail",[720,783,784],{"class":730}," -f",[720,786,769],{"class":730},[720,788,790],{"class":789},"sHwdD","      # Wait for INSTALL_EXIT=0\n",[442,792,793],{},"Keep the access details and the initial credentials that the installer prints at the end of the log.",[468,795,797,798,801],{"icon":796},"i-lucide-shield-alert","From this point the operator UI and the MCP server are reachable from any address that can reach the host, and ",[488,799,800],{},"admin"," still has its initial password.\nOn a host exposed to the Internet, apply the Control part of the firewall (step 8) right after step 3, before you go on.",[680,803,805],{"id":804},"_3-move-live-control-https-to-port-9443","3. Move Live Control HTTPS to port 9443",[442,807,808,809,812,813,816],{},"Create a compose override in the Live Control installation directory (",[488,810,811],{},"\u002Fopt\u002Flivecontrol"," by default). The installer only regenerates\n",[488,814,815],{},"docker-compose.yml",", so this file survives updates.",[711,818,820],{"className":713,"code":819,"language":715,"meta":716,"style":716},"sudo tee \u002Fopt\u002Flivecontrol\u002Fdocker-compose.override.yml >\u002Fdev\u002Fnull \u003C\u003C'EOF'\n# Shared Control + Encoder host: the Encoder serves HTTPS on 443.\nservices:\n  livecontrol:\n    ports: !override\n      - \"9080:80\"\n      - \"9443:443\"\nEOF\nsudo systemctl restart livecontrol   # Recreates the containers with the new ports\n",[488,821,822,843,848,853,859,865,871,877,883],{"__ignoreMap":716},[720,823,824,826,829,832,834,837,840],{"class":722,"line":723},[720,825,727],{"class":726},[720,827,828],{"class":730}," tee",[720,830,831],{"class":730}," \u002Fopt\u002Flivecontrol\u002Fdocker-compose.override.yml",[720,833,766],{"class":740},[720,835,836],{"class":730},"\u002Fdev\u002Fnull",[720,838,839],{"class":740}," \u003C\u003C",[720,841,842],{"class":740},"'EOF'\n",[720,844,845],{"class":722,"line":751},[720,846,847],{"class":730},"# Shared Control + Encoder host: the Encoder serves HTTPS on 443.\n",[720,849,850],{"class":722,"line":778},[720,851,852],{"class":730},"services:\n",[720,854,856],{"class":722,"line":855},4,[720,857,858],{"class":730},"  livecontrol:\n",[720,860,862],{"class":722,"line":861},5,[720,863,864],{"class":730},"    ports: !override\n",[720,866,868],{"class":722,"line":867},6,[720,869,870],{"class":730},"      - \"9080:80\"\n",[720,872,874],{"class":722,"line":873},7,[720,875,876],{"class":730},"      - \"9443:443\"\n",[720,878,880],{"class":722,"line":879},8,[720,881,882],{"class":740},"EOF\n",[720,884,886,888,891,894,897],{"class":722,"line":885},9,[720,887,727],{"class":726},[720,889,890],{"class":730}," systemctl",[720,892,893],{"class":730}," restart",[720,895,896],{"class":730}," livecontrol",[720,898,899],{"class":789},"   # Recreates the containers with the new ports\n",[442,901,902,905,906,909,910,913,914,916,917,919],{},[488,903,904],{},"livecontrol restart"," is not enough here: it restarts the containers without applying the new port mapping.\nThe ",[488,907,908],{},"!override"," tag requires Docker Compose 2.24.4 or later — check it with ",[488,911,912],{},"docker compose version",". Verify that Live Control answers on ",[488,915,539],{}," and that ",[488,918,490],{}," is free:",[711,921,923],{"className":713,"code":922,"language":715,"meta":716,"style":716},"curl -sk -o \u002Fdev\u002Fnull -w \"%{http_code}\\n\" https:\u002F\u002F127.0.0.1:9443\u002F   # 200\nsudo ss -ltnp | grep ':443 '                                         # No output\n",[488,924,925,955],{"__ignoreMap":716},[720,926,927,930,933,936,939,942,944,947,949,952],{"class":722,"line":723},[720,928,929],{"class":726},"curl",[720,931,932],{"class":730}," -sk",[720,934,935],{"class":730}," -o",[720,937,938],{"class":730}," \u002Fdev\u002Fnull",[720,940,941],{"class":730}," -w",[720,943,741],{"class":740},[720,945,946],{"class":730},"%{http_code}\\n",[720,948,763],{"class":740},[720,950,951],{"class":730}," https:\u002F\u002F127.0.0.1:9443\u002F",[720,953,954],{"class":789},"   # 200\n",[720,956,957,959,962,965,968,971,974,977,980],{"class":722,"line":751},[720,958,727],{"class":726},[720,960,961],{"class":730}," ss",[720,963,964],{"class":730}," -ltnp",[720,966,967],{"class":740}," |",[720,969,970],{"class":726}," grep",[720,972,973],{"class":740}," '",[720,975,976],{"class":730},":443 ",[720,978,979],{"class":740},"'",[720,981,982],{"class":789},"                                         # No output\n",[442,984,985,986,479],{},"From now on the operator UI is at ",[488,987,988],{},"https:\u002F\u002F\u003Chost>:9443\u002F",[680,990,992],{"id":991},"_4-install-live-encoder","4. Install Live Encoder",[711,994,996],{"className":713,"code":995,"language":715,"meta":716,"style":716},"sudo nohup bash -c \"curl -fsSL https:\u002F\u002Fget.cires21.com\u002Fliveencoder \\\n  | bash -s -- --version \u003CX.Y.Z> --yes; echo INSTALL_EXIT=\\$?\" > \u002Ftmp\u002Fle-install.log 2>&1 &\ntail -f \u002Ftmp\u002Fle-install.log      # Wait for INSTALL_EXIT=0; SSH drops for 1–2 minutes during the run\n",[488,997,998,1015,1034],{"__ignoreMap":716},[720,999,1000,1002,1004,1006,1008,1010,1013],{"class":722,"line":723},[720,1001,727],{"class":726},[720,1003,731],{"class":730},[720,1005,734],{"class":730},[720,1007,737],{"class":730},[720,1009,741],{"class":740},[720,1011,1012],{"class":730},"curl -fsSL https:\u002F\u002Fget.cires21.com\u002Fliveencoder ",[720,1014,748],{"class":747},[720,1016,1017,1019,1021,1023,1025,1027,1030,1032],{"class":722,"line":751},[720,1018,754],{"class":730},[720,1020,757],{"class":747},[720,1022,760],{"class":730},[720,1024,763],{"class":740},[720,1026,766],{"class":740},[720,1028,1029],{"class":730}," \u002Ftmp\u002Fle-install.log",[720,1031,772],{"class":740},[720,1033,775],{"class":740},[720,1035,1036,1038,1040,1042],{"class":722,"line":778},[720,1037,781],{"class":726},[720,1039,784],{"class":730},[720,1041,1029],{"class":730},[720,1043,1044],{"class":789},"      # Wait for INSTALL_EXIT=0; SSH drops for 1–2 minutes during the run\n",[442,1046,1047,1048,1051],{},"On a cloud VM without capture cards or GPU, add ",[488,1049,1050],{},"--skip-drivers"," to the installer flags. Live Control keeps running during the Encoder install.",[680,1053,1055],{"id":1054},"_5-install-the-licenses","5. Install the licenses",[442,1057,1058],{},"Both products report the same fingerprint:",[711,1060,1062],{"className":713,"code":1061,"language":715,"meta":716,"style":716},"sudo livecontrol license info\nsudo liveencoder license info\n",[488,1063,1064,1076],{"__ignoreMap":716},[720,1065,1066,1068,1070,1073],{"class":722,"line":723},[720,1067,727],{"class":726},[720,1069,896],{"class":730},[720,1071,1072],{"class":730}," license",[720,1074,1075],{"class":730}," info\n",[720,1077,1078,1080,1083,1085],{"class":722,"line":751},[720,1079,727],{"class":726},[720,1081,1082],{"class":730}," liveencoder",[720,1084,1072],{"class":730},[720,1086,1075],{"class":730},[442,1088,1089],{},"Send that single value to your Cires21 representative with the product slots your contract covers. Cires21 returns one license file per product;\ninstall each with its own CLI:",[711,1091,1093],{"className":713,"code":1092,"language":715,"meta":716,"style":716},"sudo livecontrol license install \u002Fpath\u002Fto\u002Fcontrol-license.txt\nsudo livecontrol restart\nsudo livecontrol license verify\n\nsudo liveencoder license install \u002Fpath\u002Fto\u002Fencoder-license.txt\nsudo liveencoder restart\nsudo liveencoder license verify\n",[488,1094,1095,1109,1118,1129,1135,1148,1156],{"__ignoreMap":716},[720,1096,1097,1099,1101,1103,1106],{"class":722,"line":723},[720,1098,727],{"class":726},[720,1100,896],{"class":730},[720,1102,1072],{"class":730},[720,1104,1105],{"class":730}," install",[720,1107,1108],{"class":730}," \u002Fpath\u002Fto\u002Fcontrol-license.txt\n",[720,1110,1111,1113,1115],{"class":722,"line":751},[720,1112,727],{"class":726},[720,1114,896],{"class":730},[720,1116,1117],{"class":730}," restart\n",[720,1119,1120,1122,1124,1126],{"class":722,"line":778},[720,1121,727],{"class":726},[720,1123,896],{"class":730},[720,1125,1072],{"class":730},[720,1127,1128],{"class":730}," verify\n",[720,1130,1131],{"class":722,"line":855},[720,1132,1134],{"emptyLinePlaceholder":1133},true,"\n",[720,1136,1137,1139,1141,1143,1145],{"class":722,"line":861},[720,1138,727],{"class":726},[720,1140,1082],{"class":730},[720,1142,1072],{"class":730},[720,1144,1105],{"class":730},[720,1146,1147],{"class":730}," \u002Fpath\u002Fto\u002Fencoder-license.txt\n",[720,1149,1150,1152,1154],{"class":722,"line":867},[720,1151,727],{"class":726},[720,1153,1082],{"class":730},[720,1155,1117],{"class":730},[720,1157,1158,1160,1162,1164],{"class":722,"line":873},[720,1159,727],{"class":726},[720,1161,1082],{"class":730},[720,1163,1072],{"class":730},[720,1165,1128],{"class":730},[442,1167,1168,1169,1171],{},"See ",[461,1170,358],{"href":359}," for the slots of each product.",[680,1173,1175],{"id":1174},"_6-install-the-certificate-in-both-products","6. Install the certificate in both products",[442,1177,1178,1179,1181,1182,479],{},"Both products present the same certificate: the Encoder through its Apache front end on ",[488,1180,490],{},", Live Control on ",[488,1183,539],{},[711,1185,1187],{"className":713,"code":1186,"language":715,"meta":716,"style":716},"# Live Encoder\nsudo install -m 644 \u003Chost>.crt \u002Fetc\u002Fssl\u002Fcerts\u002Fcert.pem\nsudo install -m 600 \u003Chost>.key \u002Fetc\u002Fssl\u002Fprivate\u002Fprivate-key.pem\nsudo apache2ctl configtest && sudo systemctl reload apache2\n\n# Live Control\nsudo livecontrol ssl import \u003Chost>.crt \u003Chost>.key\n",[488,1188,1189,1194,1225,1250,1274,1278,1283],{"__ignoreMap":716},[720,1190,1191],{"class":722,"line":723},[720,1192,1193],{"class":789},"# Live Encoder\n",[720,1195,1196,1198,1200,1203,1207,1210,1213,1216,1219,1222],{"class":722,"line":751},[720,1197,727],{"class":726},[720,1199,1105],{"class":730},[720,1201,1202],{"class":730}," -m",[720,1204,1206],{"class":1205},"sbssI"," 644",[720,1208,1209],{"class":740}," \u003C",[720,1211,1212],{"class":730},"hos",[720,1214,1215],{"class":747},"t",[720,1217,1218],{"class":740},">",[720,1220,1221],{"class":730},".crt",[720,1223,1224],{"class":730}," \u002Fetc\u002Fssl\u002Fcerts\u002Fcert.pem\n",[720,1226,1227,1229,1231,1233,1236,1238,1240,1242,1244,1247],{"class":722,"line":778},[720,1228,727],{"class":726},[720,1230,1105],{"class":730},[720,1232,1202],{"class":730},[720,1234,1235],{"class":1205}," 600",[720,1237,1209],{"class":740},[720,1239,1212],{"class":730},[720,1241,1215],{"class":747},[720,1243,1218],{"class":740},[720,1245,1246],{"class":730},".key",[720,1248,1249],{"class":730}," \u002Fetc\u002Fssl\u002Fprivate\u002Fprivate-key.pem\n",[720,1251,1252,1254,1257,1260,1263,1266,1268,1271],{"class":722,"line":855},[720,1253,727],{"class":726},[720,1255,1256],{"class":730}," apache2ctl",[720,1258,1259],{"class":730}," configtest",[720,1261,1262],{"class":740}," &&",[720,1264,1265],{"class":726}," sudo",[720,1267,890],{"class":730},[720,1269,1270],{"class":730}," reload",[720,1272,1273],{"class":730}," apache2\n",[720,1275,1276],{"class":722,"line":861},[720,1277,1134],{"emptyLinePlaceholder":1133},[720,1279,1280],{"class":722,"line":867},[720,1281,1282],{"class":789},"# Live Control\n",[720,1284,1285,1287,1289,1292,1295,1297,1299,1301,1303,1305,1307,1309,1311,1313],{"class":722,"line":873},[720,1286,727],{"class":726},[720,1288,896],{"class":730},[720,1290,1291],{"class":730}," ssl",[720,1293,1294],{"class":730}," import",[720,1296,1209],{"class":740},[720,1298,1212],{"class":730},[720,1300,1215],{"class":747},[720,1302,1218],{"class":740},[720,1304,1221],{"class":730},[720,1306,1209],{"class":740},[720,1308,1212],{"class":730},[720,1310,1215],{"class":747},[720,1312,1218],{"class":740},[720,1314,1315],{"class":730},".key\n",[442,1317,1318],{},"Check that Live Control validates the Encoder's certificate. Live Control reaches the Encoder through the host's IP, as it would reach a remote Encoder:",[711,1320,1322],{"className":713,"code":1321,"language":715,"meta":716,"style":716},"sudo docker exec livecontrol curl -s -o \u002Fdev\u002Fnull -w \"%{ssl_verify_result}\\n\" https:\u002F\u002F\u003Chost-ip>\u002F   # 0\n",[488,1323,1324],{"__ignoreMap":716},[720,1325,1326,1328,1331,1334,1336,1339,1342,1344,1346,1348,1350,1353,1355,1358,1361,1364,1366,1368,1371],{"class":722,"line":723},[720,1327,727],{"class":726},[720,1329,1330],{"class":730}," docker",[720,1332,1333],{"class":730}," exec",[720,1335,896],{"class":730},[720,1337,1338],{"class":730}," curl",[720,1340,1341],{"class":730}," -s",[720,1343,935],{"class":730},[720,1345,938],{"class":730},[720,1347,941],{"class":730},[720,1349,741],{"class":740},[720,1351,1352],{"class":730},"%{ssl_verify_result}\\n",[720,1354,763],{"class":740},[720,1356,1357],{"class":730}," https:\u002F\u002F",[720,1359,1360],{"class":740},"\u003C",[720,1362,1363],{"class":730},"host-i",[720,1365,442],{"class":747},[720,1367,1218],{"class":740},[720,1369,1370],{"class":730},"\u002F",[720,1372,1373],{"class":789},"   # 0\n",[442,1375,1376,1377,1380],{},"Any value other than ",[488,1378,1379],{},"0"," means the certificate chain or the IP in the certificate does not match, and registering the Encoder in step 9 will fail.",[680,1382,1384],{"id":1383},"_7-first-login-and-admin-password-rotation","7. First login and admin password rotation",[442,1386,1387,1388,1390,1391,1393,1394,1396],{},"Open ",[488,1389,988],{}," and sign in as ",[488,1392,800],{}," with the initial password printed by the installer. The UI asks you to rotate the password before\nanything else. Until the password is rotated, the REST API and the MCP server reject every request made with the ",[488,1395,800],{}," account.",[442,1398,1399,1402],{},[488,1400,1401],{},"livecontrol security password reset"," does not replace this step: it sets a new password but leaves the account pending rotation.",[468,1404,1405,1408,1409,1411,1412,1414,1415,463,1418,1421,1422,479],{"icon":394},[446,1406,1407],{},"Bundled MCP server."," The MCP server that ships with Live Control signs in with the ",[488,1410,800],{}," account, using the password stored in the installation\ndirectory (",[488,1413,811],{}," by default). After the rotation, replace the admin password in that directory's ",[488,1416,1417],{},".env",[488,1419,1420],{},".credentials"," files with the new\none, then recreate the MCP service with ",[488,1423,1424],{},"cd \u002Fopt\u002Flivecontrol && sudo docker compose up -d livecontrol-mcp",[680,1426,1428],{"id":1427},"_8-configure-the-firewall","8. Configure the firewall",[442,1430,1431],{},"The two products need two different rule sets, because their ports reach the host through different paths:",[493,1433,1434,1447],{},[496,1435,1436],{},[499,1437,1438,1441,1444],{},[502,1439,1440],{},"Product",[502,1442,1443],{},"How its ports are exposed",[502,1445,1446],{},"Where to filter",[515,1448,1449,1478],{},[499,1450,1451,1455,1468],{},[520,1452,1453],{},[446,1454,510],{},[520,1456,1457,1458,1461,1462,1461,1464,1467],{},"Directly on the host: ",[488,1459,1460],{},"80",", ",[488,1463,490],{},[488,1465,1466],{},"8484"," and the ingest ports of your Channels (SRT, RTMP, UDP…).",[520,1469,1470,1471,1473,1474,1477],{},"The host firewall (",[488,1472,692],{}," or the ",[488,1475,1476],{},"INPUT"," chain), as usual.",[499,1479,1480,1484,1495],{},[520,1481,1482],{},[446,1483,507],{},[520,1485,1486,1487,1461,1489,1461,1492,479],{},"Published by Docker: ",[488,1488,539],{},[488,1490,1491],{},"9080",[488,1493,1494],{},"3100",[520,1496,1497,1498,1501,1502,1504,1505,1507],{},"The ",[488,1499,1500],{},"DOCKER-USER"," chain. Docker-published ports skip the ",[488,1503,1476],{}," chain, so ",[488,1506,692],{}," rules do not apply to them.",[442,1509,1510,1511,1513],{},"Without a ",[488,1512,1500],{}," rule set, the Control ports — the MCP server included — are open to any address that can reach the host.",[442,1515,1516,1519,1520,1522,1523,1522,1525,1527,1528,1530],{},[446,1517,1518],{},"Encoder."," Keep the policy of your deployment: allow the ingest ports your sources use, and restrict ",[488,1521,1460],{}," \u002F ",[488,1524,490],{},[488,1526,1466],{}," to the clients that pull the\nEncoder output and to any other Live Control that manages this Encoder. If you restrict ",[488,1529,490],{},", re-run the certificate check of step 6 afterwards to confirm\nthat the local Live Control still reaches the Encoder.",[442,1532,1533],{},"With a default-deny policy, also allow the Encoder's own multicast traffic. The Encoder sends it to itself, and it arrives on the WAN interface with\nthe host IP as source; if the firewall drops it, running Live streams stop:",[711,1535,1537],{"className":713,"code":1536,"language":715,"meta":716,"style":716},"sudo ufw allow in on \u003Cwan-interface> from \u003Chost-ip> to 224.0.0.0\u002F4 proto udp comment 'Encoder internal multicast'\n",[488,1538,1539],{"__ignoreMap":716},[720,1540,1541,1543,1546,1549,1552,1555,1557,1560,1563,1565,1568,1570,1572,1574,1576,1579,1582,1585,1588,1591,1593,1596],{"class":722,"line":723},[720,1542,727],{"class":726},[720,1544,1545],{"class":730}," ufw",[720,1547,1548],{"class":730}," allow",[720,1550,1551],{"class":730}," in",[720,1553,1554],{"class":730}," on",[720,1556,1209],{"class":740},[720,1558,1559],{"class":730},"wan-interfac",[720,1561,1562],{"class":747},"e",[720,1564,1218],{"class":740},[720,1566,1567],{"class":730}," from",[720,1569,1209],{"class":740},[720,1571,1363],{"class":730},[720,1573,442],{"class":747},[720,1575,1218],{"class":740},[720,1577,1578],{"class":730}," to",[720,1580,1581],{"class":730}," 224.0.0.0\u002F4",[720,1583,1584],{"class":730}," proto",[720,1586,1587],{"class":730}," udp",[720,1589,1590],{"class":730}," comment",[720,1592,973],{"class":740},[720,1594,1595],{"class":730},"Encoder internal multicast",[720,1597,1598],{"class":740},"'\n",[442,1600,1601,1602,1604,1605,1607,1608,1610],{},"The local Live Control runs in a container, so its requests reach the Encoder from the Docker network of Live Control, not from the host IP.\nAllow that subnet on ",[488,1603,490],{}," — Live Control does not use the Encoder's ",[488,1606,1460],{}," or ",[488,1609,1466],{},":",[711,1612,1614],{"className":713,"code":1613,"language":715,"meta":716,"style":716},"sudo docker network inspect livecontrol_network -f '{{(index .IPAM.Config 0).Subnet}}'   # For example 172.18.0.0\u002F16\nsudo ufw allow from \u003Ccontrol-docker-subnet> to any port 443 proto tcp comment 'Encoder HTTPS from local Control'\n",[488,1615,1616,1643],{"__ignoreMap":716},[720,1617,1618,1620,1622,1625,1628,1631,1633,1635,1638,1640],{"class":722,"line":723},[720,1619,727],{"class":726},[720,1621,1330],{"class":730},[720,1623,1624],{"class":730}," network",[720,1626,1627],{"class":730}," inspect",[720,1629,1630],{"class":730}," livecontrol_network",[720,1632,784],{"class":730},[720,1634,973],{"class":740},[720,1636,1637],{"class":730},"{{(index .IPAM.Config 0).Subnet}}",[720,1639,979],{"class":740},[720,1641,1642],{"class":789},"   # For example 172.18.0.0\u002F16\n",[720,1644,1645,1647,1649,1651,1653,1655,1658,1660,1662,1664,1667,1670,1673,1675,1678,1680,1682,1685],{"class":722,"line":751},[720,1646,727],{"class":726},[720,1648,1545],{"class":730},[720,1650,1548],{"class":730},[720,1652,1567],{"class":730},[720,1654,1209],{"class":740},[720,1656,1657],{"class":730},"control-docker-subne",[720,1659,1215],{"class":747},[720,1661,1218],{"class":740},[720,1663,1578],{"class":730},[720,1665,1666],{"class":730}," any",[720,1668,1669],{"class":730}," port",[720,1671,1672],{"class":1205}," 443",[720,1674,1584],{"class":730},[720,1676,1677],{"class":730}," tcp",[720,1679,1590],{"class":730},[720,1681,973],{"class":740},[720,1683,1684],{"class":730},"Encoder HTTPS from local Control",[720,1686,1598],{"class":740},[442,1688,1689,1692],{},[446,1690,1691],{},"Control."," The script below allows the listed sources and drops everything else that enters on the WAN interface. Replies to connections started from\nthe host, and traffic between containers, are not affected.",[711,1694,1696],{"className":713,"code":1695,"language":715,"meta":716,"style":716},"#!\u002Fusr\u002Fbin\u002Fenv bash\n# \u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\nset -euo pipefail\nWAN_IF=\"\u003Cwan-interface>\"                         # For example eth0\nALLOW_SRC=\"\u003Coffice-ip>\u002F32 \u003Cvpn-subnet>\"          # Sources allowed to reach 9443, 9080 and 3100\n\nfor ipt in iptables ip6tables; do                # Docker also publishes on IPv6\n  $ipt -N DOCKER-USER 2>\u002Fdev\u002Fnull || true\n  $ipt -F DOCKER-USER\n  $ipt -A DOCKER-USER -i \"$WAN_IF\" -m conntrack --ctstate RELATED,ESTABLISHED -j RETURN\ndone\nfor src in $ALLOW_SRC; do\n  case \"$src\" in *:*) ipt=ip6tables ;; *) ipt=iptables ;; esac\n  $ipt -A DOCKER-USER -i \"$WAN_IF\" -s \"$src\" -j RETURN\ndone\nfor ipt in iptables ip6tables; do\n  $ipt -A DOCKER-USER -i \"$WAN_IF\" -j DROP\n  $ipt -A DOCKER-USER -j RETURN\ndone\n",[488,1697,1698,1703,1708,1720,1738,1755,1759,1786,1808,1818,1855,1861,1879,1931,1960,1965,1982,2004,2017],{"__ignoreMap":716},[720,1699,1700],{"class":722,"line":723},[720,1701,1702],{"class":789},"#!\u002Fusr\u002Fbin\u002Fenv bash\n",[720,1704,1705],{"class":722,"line":751},[720,1706,1707],{"class":789},"# \u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\n",[720,1709,1710,1714,1717],{"class":722,"line":778},[720,1711,1713],{"class":1712},"s2Zo4","set",[720,1715,1716],{"class":730}," -euo",[720,1718,1719],{"class":730}," pipefail\n",[720,1721,1722,1725,1728,1730,1733,1735],{"class":722,"line":855},[720,1723,1724],{"class":747},"WAN_IF",[720,1726,1727],{"class":740},"=",[720,1729,763],{"class":740},[720,1731,1732],{"class":730},"\u003Cwan-interface>",[720,1734,763],{"class":740},[720,1736,1737],{"class":789},"                         # For example eth0\n",[720,1739,1740,1743,1745,1747,1750,1752],{"class":722,"line":861},[720,1741,1742],{"class":747},"ALLOW_SRC",[720,1744,1727],{"class":740},[720,1746,763],{"class":740},[720,1748,1749],{"class":730},"\u003Coffice-ip>\u002F32 \u003Cvpn-subnet>",[720,1751,763],{"class":740},[720,1753,1754],{"class":789},"          # Sources allowed to reach 9443, 9080 and 3100\n",[720,1756,1757],{"class":722,"line":867},[720,1758,1134],{"emptyLinePlaceholder":1133},[720,1760,1761,1765,1768,1771,1774,1777,1780,1783],{"class":722,"line":873},[720,1762,1764],{"class":1763},"s7zQu","for",[720,1766,1767],{"class":747}," ipt ",[720,1769,1770],{"class":1763},"in",[720,1772,1773],{"class":730}," iptables",[720,1775,1776],{"class":730}," ip6tables",[720,1778,1779],{"class":740},";",[720,1781,1782],{"class":1763}," do",[720,1784,1785],{"class":789},"                # Docker also publishes on IPv6\n",[720,1787,1788,1791,1794,1797,1800,1802,1805],{"class":722,"line":879},[720,1789,1790],{"class":747},"  $ipt ",[720,1792,1793],{"class":730},"-N",[720,1795,1796],{"class":730}," DOCKER-USER",[720,1798,1799],{"class":740}," 2>",[720,1801,836],{"class":730},[720,1803,1804],{"class":740}," ||",[720,1806,1807],{"class":1712}," true\n",[720,1809,1810,1812,1815],{"class":722,"line":885},[720,1811,1790],{"class":747},[720,1813,1814],{"class":730},"-F",[720,1816,1817],{"class":730}," DOCKER-USER\n",[720,1819,1821,1823,1826,1828,1831,1833,1836,1838,1840,1843,1846,1849,1852],{"class":722,"line":1820},10,[720,1822,1790],{"class":747},[720,1824,1825],{"class":730},"-A",[720,1827,1796],{"class":730},[720,1829,1830],{"class":730}," -i",[720,1832,741],{"class":740},[720,1834,1835],{"class":747},"$WAN_IF",[720,1837,763],{"class":740},[720,1839,1202],{"class":730},[720,1841,1842],{"class":730}," conntrack",[720,1844,1845],{"class":730}," --ctstate",[720,1847,1848],{"class":730}," RELATED,ESTABLISHED",[720,1850,1851],{"class":730}," -j",[720,1853,1854],{"class":730}," RETURN\n",[720,1856,1858],{"class":722,"line":1857},11,[720,1859,1860],{"class":1763},"done\n",[720,1862,1864,1866,1869,1871,1874,1876],{"class":722,"line":1863},12,[720,1865,1764],{"class":1763},[720,1867,1868],{"class":747}," src ",[720,1870,1770],{"class":1763},[720,1872,1873],{"class":747}," $ALLOW_SRC",[720,1875,1779],{"class":740},[720,1877,1878],{"class":1763}," do\n",[720,1880,1882,1885,1887,1890,1892,1894,1897,1899,1902,1905,1908,1910,1913,1916,1919,1921,1923,1926,1928],{"class":722,"line":1881},13,[720,1883,1884],{"class":1763},"  case",[720,1886,741],{"class":740},[720,1888,1889],{"class":747},"$src",[720,1891,763],{"class":740},[720,1893,1551],{"class":1763},[720,1895,1896],{"class":740}," *",[720,1898,1610],{"class":730},[720,1900,1901],{"class":740},"*",[720,1903,1904],{"class":740},")",[720,1906,1907],{"class":747}," ipt",[720,1909,1727],{"class":740},[720,1911,1912],{"class":730},"ip6tables",[720,1914,1915],{"class":740}," ;;",[720,1917,1918],{"class":740}," *)",[720,1920,1907],{"class":747},[720,1922,1727],{"class":740},[720,1924,1925],{"class":730},"iptables",[720,1927,1915],{"class":740},[720,1929,1930],{"class":1763}," esac\n",[720,1932,1934,1936,1938,1940,1942,1944,1946,1948,1950,1952,1954,1956,1958],{"class":722,"line":1933},14,[720,1935,1790],{"class":747},[720,1937,1825],{"class":730},[720,1939,1796],{"class":730},[720,1941,1830],{"class":730},[720,1943,741],{"class":740},[720,1945,1835],{"class":747},[720,1947,763],{"class":740},[720,1949,1341],{"class":730},[720,1951,741],{"class":740},[720,1953,1889],{"class":747},[720,1955,763],{"class":740},[720,1957,1851],{"class":730},[720,1959,1854],{"class":730},[720,1961,1963],{"class":722,"line":1962},15,[720,1964,1860],{"class":1763},[720,1966,1968,1970,1972,1974,1976,1978,1980],{"class":722,"line":1967},16,[720,1969,1764],{"class":1763},[720,1971,1767],{"class":747},[720,1973,1770],{"class":1763},[720,1975,1773],{"class":730},[720,1977,1776],{"class":730},[720,1979,1779],{"class":740},[720,1981,1878],{"class":1763},[720,1983,1985,1987,1989,1991,1993,1995,1997,1999,2001],{"class":722,"line":1984},17,[720,1986,1790],{"class":747},[720,1988,1825],{"class":730},[720,1990,1796],{"class":730},[720,1992,1830],{"class":730},[720,1994,741],{"class":740},[720,1996,1835],{"class":747},[720,1998,763],{"class":740},[720,2000,1851],{"class":730},[720,2002,2003],{"class":730}," DROP\n",[720,2005,2007,2009,2011,2013,2015],{"class":722,"line":2006},18,[720,2008,1790],{"class":747},[720,2010,1825],{"class":730},[720,2012,1796],{"class":730},[720,2014,1851],{"class":730},[720,2016,1854],{"class":730},[720,2018,2020],{"class":722,"line":2019},19,[720,2021,1860],{"class":1763},[442,2023,2024,2026],{},[488,2025,1925],{}," rules live only in memory and are lost when the host reboots, so apply the script from a systemd unit bound to Docker: it runs every time\nDocker starts, including after a reboot and after a Live Control update.",[711,2028,2032],{"className":2029,"code":2030,"language":2031,"meta":716,"style":716},"language-ini shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# \u002Fetc\u002Fsystemd\u002Fsystem\u002Fc21-docker-user-fw.service\n[Unit]\nDescription=DOCKER-USER rules for C21 Live Control\nAfter=docker.service\nPartOf=docker.service\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=\u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\n\n[Install]\nWantedBy=docker.service\n","ini",[488,2033,2034,2039,2044,2049,2054,2059,2063,2068,2073,2078,2083,2087,2092],{"__ignoreMap":716},[720,2035,2036],{"class":722,"line":723},[720,2037,2038],{},"# \u002Fetc\u002Fsystemd\u002Fsystem\u002Fc21-docker-user-fw.service\n",[720,2040,2041],{"class":722,"line":751},[720,2042,2043],{},"[Unit]\n",[720,2045,2046],{"class":722,"line":778},[720,2047,2048],{},"Description=DOCKER-USER rules for C21 Live Control\n",[720,2050,2051],{"class":722,"line":855},[720,2052,2053],{},"After=docker.service\n",[720,2055,2056],{"class":722,"line":861},[720,2057,2058],{},"PartOf=docker.service\n",[720,2060,2061],{"class":722,"line":867},[720,2062,1134],{"emptyLinePlaceholder":1133},[720,2064,2065],{"class":722,"line":873},[720,2066,2067],{},"[Service]\n",[720,2069,2070],{"class":722,"line":879},[720,2071,2072],{},"Type=oneshot\n",[720,2074,2075],{"class":722,"line":885},[720,2076,2077],{},"RemainAfterExit=yes\n",[720,2079,2080],{"class":722,"line":1820},[720,2081,2082],{},"ExecStart=\u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\n",[720,2084,2085],{"class":722,"line":1857},[720,2086,1134],{"emptyLinePlaceholder":1133},[720,2088,2089],{"class":722,"line":1863},[720,2090,2091],{},"[Install]\n",[720,2093,2094],{"class":722,"line":1881},[720,2095,2096],{},"WantedBy=docker.service\n",[711,2098,2100],{"className":713,"code":2099,"language":715,"meta":716,"style":716},"sudo chmod 755 \u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\nsudo systemctl daemon-reload\nsudo systemctl enable --now c21-docker-user-fw.service\nsudo iptables -S DOCKER-USER\n",[488,2101,2102,2115,2124,2139],{"__ignoreMap":716},[720,2103,2104,2106,2109,2112],{"class":722,"line":723},[720,2105,727],{"class":726},[720,2107,2108],{"class":730}," chmod",[720,2110,2111],{"class":1205}," 755",[720,2113,2114],{"class":730}," \u002Fusr\u002Flocal\u002Fsbin\u002Fc21-docker-user-fw.sh\n",[720,2116,2117,2119,2121],{"class":722,"line":751},[720,2118,727],{"class":726},[720,2120,890],{"class":730},[720,2122,2123],{"class":730}," daemon-reload\n",[720,2125,2126,2128,2130,2133,2136],{"class":722,"line":778},[720,2127,727],{"class":726},[720,2129,890],{"class":730},[720,2131,2132],{"class":730}," enable",[720,2134,2135],{"class":730}," --now",[720,2137,2138],{"class":730}," c21-docker-user-fw.service\n",[720,2140,2141,2143,2145,2148],{"class":722,"line":855},[720,2142,727],{"class":726},[720,2144,1773],{"class":730},[720,2146,2147],{"class":730}," -S",[720,2149,1817],{"class":730},[442,2151,2152,2153,1461,2155,463,2157,2159],{},"From an address outside the allowlist, ports ",[488,2154,539],{},[488,2156,1491],{},[488,2158,1494],{}," must now be closed.",[680,2161,2163],{"id":2162},"_9-register-the-encoder-in-live-control","9. Register the Encoder in Live Control",[442,2165,2166,2167,2170,2171,2173],{},"In the Live Control UI open ",[446,2168,2169],{},"Devices → Add device"," and register the Encoder of this host as you would register any other one — see\n",[461,2172,348],{"href":349},", step 4:",[602,2175,2176,2184],{},[605,2177,2178,2181,2182,479],{},[446,2179,2180],{},"Server IP"," — the IP of the host, the same one the certificate is issued for. No port: Live Control reaches the Encoder on ",[488,2183,490],{},[605,2185,2186,1522,2189,2192,2193,2195,2196,1522,2199,2202],{},[446,2187,2188],{},"Register username",[446,2190,2191],{},"Register password"," — the Encoder's ",[488,2194,800],{}," credentials (",[488,2197,2198],{},"sudo liveencoder credentials show",[488,2200,2201],{},"credentials reset",").",[442,2204,2205,2206,2209],{},"The Device row must show ",[488,2207,2208],{},"registration_status: registered",". Other Encoders, on other hosts, are registered in the same way.",[680,2211,2213],{"id":2212},"_10-verify","10. Verify",[711,2215,2217],{"className":713,"code":2216,"language":715,"meta":716,"style":716},"curl -sk -o \u002Fdev\u002Fnull -w \"%{http_code}\\n\" https:\u002F\u002F127.0.0.1:9443\u002F   # Live Control UI: 200\nsudo livecontrol status                                             # Live Control services healthy\nsudo liveencoder status                                             # Encoder service running\nsudo iptables -S DOCKER-USER                                        # Control firewall in place\n",[488,2218,2219,2242,2254,2265],{"__ignoreMap":716},[720,2220,2221,2223,2225,2227,2229,2231,2233,2235,2237,2239],{"class":722,"line":723},[720,2222,929],{"class":726},[720,2224,932],{"class":730},[720,2226,935],{"class":730},[720,2228,938],{"class":730},[720,2230,941],{"class":730},[720,2232,741],{"class":740},[720,2234,946],{"class":730},[720,2236,763],{"class":740},[720,2238,951],{"class":730},[720,2240,2241],{"class":789},"   # Live Control UI: 200\n",[720,2243,2244,2246,2248,2251],{"class":722,"line":751},[720,2245,727],{"class":726},[720,2247,896],{"class":730},[720,2249,2250],{"class":730}," status",[720,2252,2253],{"class":789},"                                             # Live Control services healthy\n",[720,2255,2256,2258,2260,2262],{"class":722,"line":778},[720,2257,727],{"class":726},[720,2259,1082],{"class":730},[720,2261,2250],{"class":730},[720,2263,2264],{"class":789},"                                             # Encoder service running\n",[720,2266,2267,2269,2271,2273,2275],{"class":722,"line":855},[720,2268,727],{"class":726},[720,2270,1773],{"class":730},[720,2272,2147],{"class":730},[720,2274,1796],{"class":730},[720,2276,2277],{"class":789},"                                        # Control firewall in place\n",[442,2279,2280,2281,479],{},"Then run a test Live stream on the local Encoder and check that its output is served from ",[488,2282,2283],{},"https:\u002F\u002F\u003Chost>\u002F",[437,2285,478],{"id":2286},"updates-on-a-shared-host",[442,2288,2289],{},"Update both products in the same maintenance window, with the operation stopped:",[493,2291,2292,2302],{},[496,2293,2294],{},[499,2295,2296,2299],{},[502,2297,2298],{},"Update",[502,2300,2301],{},"Effect on the shared host",[515,2303,2304,2316],{},[499,2305,2306,2310],{},[520,2307,2308],{},[446,2309,507],{},[520,2311,2312,2313,2315],{},"The update reconfigures and restarts the Docker service. The Encoder service depends on Docker, so it is stopped and started with it: local Live streams drop for one to two minutes and recover on their own. The port override and the ",[488,2314,1500],{}," rules are kept.",[499,2317,2318,2322],{},[520,2319,2320],{},[446,2321,510],{},[520,2323,2324],{},"Live Control is not affected. SSH sessions can drop while the SSH server is updated.",[442,2326,2327,2328,2331],{},"Follow the order recommended in ",[461,2329,353],{"href":2330},"\u002Fen\u002Finstallation\u002Fupdates#compatibility"," — Encoder first, then Live Control — and after the Live Control update check:",[711,2333,2335],{"className":713,"code":2334,"language":715,"meta":716,"style":716},"curl -sk -o \u002Fdev\u002Fnull -w \"%{http_code}\\n\" https:\u002F\u002F127.0.0.1:9443\u002F   # Live Control still on 9443\nsudo liveencoder status                                             # Encoder back up\nsudo iptables -S DOCKER-USER                                        # Firewall rules still in place\n",[488,2336,2337,2360,2371],{"__ignoreMap":716},[720,2338,2339,2341,2343,2345,2347,2349,2351,2353,2355,2357],{"class":722,"line":723},[720,2340,929],{"class":726},[720,2342,932],{"class":730},[720,2344,935],{"class":730},[720,2346,938],{"class":730},[720,2348,941],{"class":730},[720,2350,741],{"class":740},[720,2352,946],{"class":730},[720,2354,763],{"class":740},[720,2356,951],{"class":730},[720,2358,2359],{"class":789},"   # Live Control still on 9443\n",[720,2361,2362,2364,2366,2368],{"class":722,"line":751},[720,2363,727],{"class":726},[720,2365,1082],{"class":730},[720,2367,2250],{"class":730},[720,2369,2370],{"class":789},"                                             # Encoder back up\n",[720,2372,2373,2375,2377,2379,2381],{"class":722,"line":778},[720,2374,727],{"class":726},[720,2376,1773],{"class":730},[720,2378,2147],{"class":730},[720,2380,1796],{"class":730},[720,2382,2383],{"class":789},"                                        # Firewall rules still in place\n",[437,2385,2387],{"id":2386},"cross-links","Cross-links",[602,2389,2390,2395,2400,2405,2410,2415],{},[605,2391,2392,2394],{},[461,2393,338],{"href":339}," — DNS, NTP, swap and OS update policy.",[605,2396,2397,2399],{},[461,2398,343],{"href":344}," — installer flags, CLI, backups, SSL.",[605,2401,2402,2404],{},[461,2403,348],{"href":349}," — installer flags, hardware drivers, CLI.",[605,2406,2407,2409],{},[461,2408,353],{"href":354}," — update flow, rollback and version compatibility.",[605,2411,2412,2414],{},[461,2413,358],{"href":359}," — license catalog and file format.",[605,2416,2417,2419],{},[461,2418,89],{"href":94}," — the section where the registered Encoders appear.",[2421,2422,2423],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}",{"title":716,"searchDepth":751,"depth":751,"links":2425},[2426,2427,2428,2429,2441,2442],{"id":439,"depth":751,"text":440},{"id":482,"depth":751,"text":483},{"id":626,"depth":751,"text":627},{"id":675,"depth":751,"text":676,"children":2430},[2431,2432,2433,2434,2435,2436,2437,2438,2439,2440],{"id":682,"depth":778,"text":683},{"id":696,"depth":778,"text":697},{"id":804,"depth":778,"text":805},{"id":991,"depth":778,"text":992},{"id":1054,"depth":778,"text":1055},{"id":1174,"depth":778,"text":1175},{"id":1383,"depth":778,"text":1384},{"id":1427,"depth":778,"text":1428},{"id":2162,"depth":778,"text":2163},{"id":2212,"depth":778,"text":2213},{"id":2286,"depth":751,"text":478},{"id":2386,"depth":751,"text":2387},"Run C21 Live Control and C21 Live Encoder on a single host — port layout, install order, the move of Control to port 9443, licenses, certificate, firewall and the impact of updates.","md",null,{},{"icon":96},{"title":362,"description":2443},"yNWErO4eRL_xWgeaoMJH--vnjmoKAAS7yvwJHNuIhNU",[2451,2453],{"title":358,"path":359,"stem":360,"description":2452,"icon":215,"children":-1},"The product licenses that gate C21 Live Control and C21 Live Encoder, how they are installed, where they are administered, and what happens when one is missing or expires.",{"title":41,"path":371,"stem":372,"description":2454,"icon":373,"children":-1},"Build against C21 Live Control — the REST API at \u002Fc21apiv2 and the MCP server, both behind one bearer token.",1790334262289]