RustPBX Basics: Recording — From Compliance Checkbox to Evidence System
“Record all calls” is how recording requirements start. Then legal arrives: some calls must not be recorded. Finance wants the billing segments separately. The auditor wants retention measured in years, storage in object buckets, and downloads that don’t melt the PBX. Here’s how RustPBX’s recording pipeline grows with you.
The Master Switch
[recording]
enabled = true
type = "local" # "local" | "http" | "s3" | "sipflow"
auto_start = true
auto_start installs the recorder on every call automatically; auto_start_at controls whether capture begins at the first completed caller-media setup or at answer.
Per-Trunk and Per-App Overrides
Compliance is never “all calls”:
# config/trunks/partner.toml
[recording]
enabled = false
A trunk can override the global policy (record only that carrier’s traffic), and auto-start exemptions list routed applications that must opt out — the PCI-call pattern: agent presses a key, recording pauses for the card number.
Segments, Not One Blob
Real calls are not one conversation. A consult transfer creates two conversations; hold/resume changes context. RustPBX records per segment, each with its own id and metadata, all linked to the same session id. The call record’s detail page plays them back in order.

Storage That Scales
With [storage] pointed at S3/Azure/GCS, recordings upload off-box:
- Upload retry worker — a failed upload retries with backoff instead of being lost.
- Presigned download URLs — recordings are served through time-limited S3 links rather than proxied through the console.
- Archive addon — long-term retention to CSV/archives for compliance programs.
- Configurable upload scheme — http vs https to match your bucket setup.
When Recording Isn’t the Recording You Need
For pure signaling evidence, [sipflow] captures the full SIP/RTP ladder (and can record media itself with type = "sipflow"). The two systems are independent:
| Recording | SipFlow | |
|---|---|---|
| Captures | Audio (WAV) | SIP messages + RTP packets |
| Answers | “What was said” | “What was signaled, when, to whom” |
| Storage | WAV on storage backend | ZSTD-compressed binary + SQLite index |
| 典型问题 | 合规留证、质检 | 互通故障、信令取证 |
Compliance programs usually want both — recordings for the conversation, SipFlow to prove what was signaled, when, and to whom.
A Note on the Exemption Audit
Auto-start exemptions are config, and config goes through Git — so when the auditor asks “which calls are NOT recorded and why”, the answer is a commit diff, not a tribal-knowledge session. Pair each exemption with a policy reference in the commit message and the audit is a non-event.
Ops guidance: Operations Manual and Basic Setup → Storage.