Terraform · Ansible · nginx-rtmp · Let's Encrypt
One private EC2 instance loops Big Buck Bunny and pushes it over RTMP.
A second, public-facing instance ingests that feed, repackages it as HLS/DASH,
and serves it to you here — over HTTPS, nowhere else.
Signal chain
The whole environment is provisioned by Terraform — one VPC, a public and a private subnet, security groups scoped tight enough that the Video Streamer has no inbound access from the internet at all. Ansible then configures both machines: ffmpeg and the source video on one side, nginx with the RTMP module and a Let's Encrypt certificate on the other.