Configure AWS MediaPackage live channel with SPEKE encryption and HLS/DASH endpoints

domain: aws-mediapackage · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create a MediaPackage channel, copy the ingest endpoints, and configure your upstream encoder (MediaLive or on-premises) to push two redundant RTMP or HLS ingest streams
  2. Create an HLS endpoint and a DASH endpoint on the channel; for each, open the Encryption section and enter your SPEKE key provider URL, role ARN, and system IDs for the desired DRM systems
  3. Set the segment duration and manifest window length appropriate for your latency target; for low-latency use, enable low-latency HLS (LL-HLS) on the endpoint
  4. Attach a CloudFront distribution in front of the MediaPackage endpoints and restrict origin access so segments are only served through CloudFront
  5. Test playback with Shaka Player (Widevine/PlayReady) and hls.js or Safari (FairPlay) to verify DRM handshakes succeed end-to-end

Known gotchas

Related routes

Configure AWS MediaPackage V2 live channel with SPEKE v2 DRM encryption for HLS and DASH outputs
docs.aws.amazon.com · 6 steps · unrated
Exchange multi-DRM content keys using CPIX 2.3 / AWS SPEKE 2.0
aws-mediapackage · 5 steps · unrated
Package a multi-DRM HLS and DASH stream with Shaka Packager
shaka-packager · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans