Skip to content

Releases: rasonyang/freesbc

Release list

FreeSBC v0.1.0

Choose a tag to compare

@rasonyang rasonyang released this 20 Sep 13:13

First public release of FreeSBC — an all-in-one open-source Session Border
Controller in pure Go: one static binary, one YAML file, ./freesbc run.
No database, no Redis, no kernel modules, no external media process.

Two planes

  • Trunk B2BUA — carrier/PBX interconnect over UDP/TCP/TLS with routing,
    ordered failover, outbound REGISTER and SRTP (SDES). Configured with
    peers: and routes:.
  • Edge proxy — stateful SIP and media edge proxy in front of FreeSWITCH:
    registration proxying, UDP/WS/WSS interworking, RTP anchoring,
    WebRTC (ICE-Lite, DTLS-SRTP, RTCP-mux) relayed to plain RTP, a
    multi-upstream pool with per-user hashing and dialog stickiness, and an
    optional peer-to-peer PSTN trunk with gateway failover.

Highlights

  • Routing engine: regex matching, number transformation, ordered failover
    with passive per-endpoint cooldown, DNS SRV (RFC 3263) resolution.
  • B2BUA topology hiding: independent legs with their own Call-ID, From-tag
    and Via, and full SDP rewrite.
  • Typed SDP subsystem over pion/sdp/v3 — bodies are constructed, never
    derived from the other leg.
  • Built-in security: per-IP rate limiting, scanner fingerprinting with
    instant ban, optional nftables integration that degrades to in-memory bans.
  • Embedded WebUI + REST API: live dashboard, validated atomic config
    write-back, hot reload, Prometheus metrics, bcrypt Basic Auth, and
    DELETE /api/calls/{id} to tear down a stuck call.
  • Carrier interop baseline: OPTIONS answering and session timers (RFC 4028),
    including the 422/Min-SE exchange on both legs.
  • Opt-in interop suite that runs against a live FreeSWITCH.

Not in this release

Transcoding, CDR and clustering are explicit non-goals. Also missing:
100rel/PRACK, mid-call re-INVITE on the trunk plane, inbound digest
challenge, active peer qualification, SUBSCRIBE/NOTIFY through the edge
proxy (so MWI and BLF do not reach phones), and consistent hashing for
sip.upstreams. Inbound calls to a browser are offered plain RTP, which a
browser rejects. See the README's "Known limitations" and "Roadmap".

Performance targets in the README are design targets, not measured results —
this repo carries no benchmarks and no load-test harness.

Getting started

go build -o freesbc ./cmd/freesbc      # requires Go >= 1.25.7
cp sbc.example.yaml sbc.yaml
./freesbc check -c sbc.yaml
./freesbc run   -c sbc.yaml

Read the networking/deployment topology and security model sections of
docs/design.md before exposing this to the public internet.

Apache License 2.0.