Add SMS test reminder, "which box handled it" note, and a coturn health check

Three follow-ups from live testing on this session's actual VPS:

- tools/pstn-test-check.sh's SMS section printed the Forward-to-URL value
  to configure but never said what to do next — add the "text this DID,
  then watch journalctl -u sms-inbound -f" step right after it.
- docs/pstn-sms-test-checklist.md: the "which box actually handled this"
  question has a simple answer (a DID's inbound routing targets exactly
  one IP:port, so there's no ambiguity to resolve, only a portal setting
  to confirm) — written up so it doesn't need re-deriving. Also fixed the
  --list example to cd into the repo first; ./setup.sh is a relative path
  and silently fails with "command not found" from any other directory,
  confirmed live in this session.
- New tools/coturn-test-check.sh: health-checks the shared coturn instance
  (services/coturn.sh) and every consumer registered against it (Asterisk,
  any number of Mattermost instances) — container/identity, each cached
  consumer credential cross-checked against coturn's own live user
  database (catches the container/volume-recreated-without-db drift case),
  UFW rules for both the TURN port and the relay range, a capacity
  explanation reasoned from the actual port-range math instead of a guess,
  and a real TURN allocation test per consumer via turnutils_uclient —
  the only way to prove credentials + port range + firewall all actually
  work together, not just that each looks right in isolation. Deliberately
  does not attempt a concurrent load test, since that would consume real
  relay ports other services may be actively using.

Verified the turnadmin -l output parsing, UFW rule matching, and the
empty-array-under-set–u loop pattern against mock data before shipping.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H4k6J1qXXyYxhGEgnJaMvn
This commit is contained in:
Claude
2026-08-11 20:32:02 +00:00
parent cb1bb9b11b
commit 5c18cfa364
3 changed files with 215 additions and 2 deletions
+23 -2
View File
@@ -12,6 +12,24 @@ Asterisk or PSTN trunk reinstall, or just periodically to catch drift (a
provider-side change, an expired international allow-list, a forgotten
kill-switch trip).
## How do I know a test call/text actually used THIS box?
Short answer: there's no ambiguity to resolve — a DID can only point at one
place. In the Anveo (or any IP-auth) portal, the DID's inbound routing
targets one specific IP:port (`$[E164]$@<this box's public IP>:5060`), and
the Outbound Trunk's Authorized IP Addresses list is what lets *this* box's
outbound calls out. If you have multiple boxes, only the one whose IP is
actually configured in the portal can send or receive on that DID at all —
there's nothing to "make sure" beyond confirming the portal points at this
box's current IP (§ Provider portal checklist output from
`tools/pstn-test-check.sh` prints it directly).
The practical way to *watch* it happen on this box specifically, live,
while you place the test: run `docker exec -it $CONTAINER asterisk -rvvv`
or `journalctl -u sms-inbound -f` in one terminal, then place the call/text
from another phone in real time. If it shows up here as it happens, this
box handled it — no separate confirmation needed.
## 0. Before you start
`$CONTAINER`/`$EA_DIR` only live in the shell session where you set them —
@@ -34,10 +52,13 @@ If `$CONTAINER` prints empty, the container isn't running at all — check
Re-run this block at the start of every new terminal session, not just
once — it's cheap and removes the whole class of failure above.
Check the three services this checklist covers are actually installed:
Check the three services this checklist covers are actually installed
run this from the repo directory itself (`~/ubuntu-post-install`, not
`~/docker/asterisk` or wherever you happen to be — `./setup.sh` is a
relative path and fails with "command not found" from anywhere else):
```bash
sudo ./setup.sh --list | grep -E "asterisk|pstn-trunk|sms-inbound|security-dashboard"
cd ~/ubuntu-post-install && sudo ./setup.sh --list | grep -E "asterisk|pstn-trunk|sms-inbound|security-dashboard"
```
Read your box's own current settings before testing — this file has your