Request flow
- The client requests an upload session.
- The API validates file type, size, tenant quota, and intended operation.
- The API returns a short-lived S3 signed upload URL.
- The client uploads directly to private S3 storage.
- The API or object event creates a durable processing job.
- A Worker transforms the media and writes outputs to S3.
- The client polls a status endpoint or receives a webhook.
- The API returns a signed download or CloudFront URL.
Deploy the API
Use a Springwinter Web server with a health endpoint and stateless handlers. Store job records in a database. Keep S3 object keys opaque and scoped by organization or project. Recommended endpoints include:202 Accepted when processing begins. Do not hold the request open until FFmpeg finishes.
Deploy processing Workers
Use a separate Springwinter Worker per resource profile when workloads differ significantly. Thumbnail extraction, audio normalization, and 4K transcoding should not necessarily share one queue or compute size. Workers should use an allowlist of operation profiles. Validate media withffprobe, enforce maximum duration and resolution, use execution timeouts, and delete temporary files after upload.
Security controls
- Keep buckets private.
- Use short signed-URL expirations.
- Validate actual media, not only filename extensions.
- Apply tenant quotas before accepting uploads.
- Never interpolate user input into a shell command.
- Treat parsers and codecs as attack surfaces and patch images regularly.
- Restrict outbound network access when the workload does not need it.
Streaming is a different workload
This architecture covers upload, processing, and delivery. Real-time WebRTC, RTMP ingest, UDP media, TURN, and long-lived bidirectional sessions require specialized networking. Current Springwinter Web servers target ordinary HTTP services and are not a first-class real-time media-server product.Frequently asked questions
Why upload directly to S3?
Why upload directly to S3?
Direct upload removes large request bodies from the API, avoids duplicate network transfer through the web container, and gives retries a durable destination independent of a deployment.
Should processed video be public in S3?
Should processed video be public in S3?
Usually no. Keep S3 private and issue signed URLs or use CloudFront with private-origin controls. Public buckets make authorization, revocation, and audit harder.
Can Springwinter host a WebRTC media server?
Can Springwinter host a WebRTC media server?
Not as a current first-class workload. WebRTC commonly needs UDP, TURN, multiple ports, stable session routing, and specialized load balancing beyond the standard Springwinter HTTP Web server model.