Deploying Nostrelt on a VPS: A Strategic Guide to Hosting Your Own Nostr Relay
Introduction to the Decentralized Social Web
In the evolving landscape of digital communication, censorship-resistance and data sovereignty have transitioned from niche technical ideals to core business imperatives. Centralized platforms have repeatedly demonstrated vulnerabilities, including arbitrary content moderation, algorithm manipulation, and catastrophic data breaches. To mitigate these risks, forward-thinking organizations are turning to Nostr (Notes and Other Stuff Transmitted by Relays), an open, decentralized protocol designed for cryptographic, censorship-resistant social networking.
Unlike traditional networks, Nostr operates on a simple architecture: clients (users) publish data, and relays store and distribute that data. To truly control your digital footprint and contribute to the network's resilience, hosting your own relay is paramount. In this professional guide, we examine how to deploy Nostrelt—a modern, efficient, and lightweight Nostr relay implementation—on a Virtual Private Server (VPS).
Why Host Your Own Nostr Relay?
Before diving into the technical architecture, it is essential to understand the strategic advantages that an enterprise or individual gains by operating an independent relay like Nostrelt:
- Absolute Data Sovereignty: Your notes, interactions, and cryptographic metadata are stored on infrastructure under your direct control.
- Performance and Latency: By connecting your personal or organizational clients to a dedicated VPS, you bypass the congestion often found on public relays, ensuring instantaneous message propagation.
- Censorship Resistance: No external entity can purge your data or restrict your access to the network. You dictate the content moderation rules for your specific relay.
- Network Contribution: Operating a stable relay strengthens the global topology of the decentralized web, providing alternative routing points for users globally.
Pre-requisites and Infrastructure Planning
To ensure optimal performance and high availability, choosing the correct VPS configuration is critical. Nostrelt is highly optimized, but its storage requirements scale based on the volume of network events you choose to index.
Minimum Recommended VPS Hardware Specifications
- CPU: 1 or 2 vCPUs (Modern architecture)
- RAM: 2 GB minimum (4 GB recommended for production workloads)
- Storage: 20 GB to 50 GB NVMe SSD (Scalable based on message retention policies)
- OS: Ubuntu 24.04 LTS or Debian 12
- Network: 1 Gbps port with unlimited or high-bandwidth allocation
Software Prerequisites
Before starting the installation, ensure you have basic command-line access to your VPS via SSH with root or sudo privileges. Additionally, we will utilize Docker and Docker Compose to containerize the application, ensuring a standardized and easily maintainable environment.
Step-by-Step Deployment of Nostrelt
Follow this structured technical workflow to provision and launch your Nostrelt instance on your Linux VPS.
Step 1: System Update and Security Baseline
First, log in to your server and update the local package index to ensure all existing system software is patched to the latest stable versions:
sudo apt update && sudo apt upgrade -yIt is also highly recommended to configure a basic firewall using UFW (Uncomplicated Firewall) to secure unauthorized ports, leaving only SSH (22), HTTP (80), and HTTPS (443) open.
Step 2: Installing Docker and Docker Compose
Because containerization simplifies dependency management, install the official Docker engine using the convenience script or your distribution's repository:
sudo apt install docker.io docker-compose-v2 -y
sudo systemctl enable --now dockerVerify that Docker is operating correctly by checking its system status or running a quick verification command.
Step 3: Cloning and Configuring Nostrelt
Navigate to your preferred installation directory (e.g., /opt/nostrelt), clone the official repository, or manually structure your deployment directory. Create a dedicated docker-compose.yml file to define the services:
version: '3.8'
services:
nostrelt:
image: ghcr.io/nostrelt/nostrelt:latest
container_name: nostrelt_relay
restart: unless-stopped
ports:
- "8080:8080"
volumes:
- ./data:/app/data
- ./config.json:/app/config.jsonNext, initialize your config.json file. This configuration governs how your relay identifies itself to the rest of the Nostr ecosystem. A standard configuration includes variables for your relay's name, description, pubkey (owner identifier), and specific limits on message sizes to prevent Denial of Service (DoS) attacks.
Step 4: Setting Up a Reverse Proxy (Nginx) and SSL
Nostr clients communicate with relays via secure WebSockets (wss://). Running Nostrelt directly exposed to the internet without encryption is a major security risk. Therefore, we utilize Nginx as a reverse proxy coupled with Let's Encrypt for automated SSL management.
Install Nginx and Certbot:
sudo apt install nginx certbot python3-certbot-nginx -yConfigure a new Nginx server block pointing your custom domain (e.g., relay.yourdomain.com) to http://localhost:8080. Ensure that the configuration explicitly permits WebSocket upgrading by defining the Upgrade and Connection headers. Once verified, execute Certbot to obtain your SSL certificate:
sudo certbot --nginx -d relay.yourdomain.comOptimizing and Maintaining Your Relay
Once your relay is live and broadcasting, monitoring and ongoing maintenance guarantee enterprise-grade uptime. Implement the following best practices:
- Regular Database Backups: Schedule automated cron jobs to backup the Nostrelt data directory to an off-site, secure cloud storage target.
- Pruning Policies: Nostr can generate an immense volume of global data. Adjust your
config.jsonparameters to restrict the maximum age of events or maximum storage footprints if your hardware resources are constrained. - Log Aggregation: Utilize standard Docker logging commands (
docker logs -f nostrelt_relay) to inspect client connection drops or parsing anomalies.
Conclusion: Embracing Sovereignty
Deploying Nostrelt on a dedicated VPS is a vital step toward asserting digital independence in an increasingly centralized world. By managing your own infrastructure, you guarantee uninterrupted access to the global Nostr protocol, enhance your organizational data security, and actively support the open-source architecture of tomorrow. As decentralized protocols continue to gain traction globally, owning the rails of your communication network is no longer just an experiment—it is a critical competitive advantage.
