How to Run Your Own Decentralized Nostr Relay on a VPS Using Strfry: A Complete Guide
Introduction to the Nostr Ecosystem and the Role of Relays
In the evolving landscape of digital communication, censorship-resistant and decentralized networks are transitioning from niche alternatives to mainstream business necessities. Nostr (Notes and Other Stuff Transmitted by Relays) has emerged as a frontrunner in this paradigm shift. Unlike traditional social media platforms that rely on centralized databases and corporate gatekeepers, Nostr operates on a lightweight, open protocol powered by cryptographic key pairs and a distributed network of relays.
In the Nostr architecture, clients (the user interfaces) do not communicate with each other directly. Instead, they publish data to, and fetch data from, relays. A relay is essentially a specialized server designed to accept, store, and forward cryptographic events. Running your own Nostr relay ensures data sovereignty, improves localized latency, and contributes to the overall resilience of the global decentralized web. This technical guide provides an exhaustive walkthrough for deploying Strfry, a cutting-edge, high-performance Nostr relay written in C++, onto a Virtual Private Server (VPS).
Why Choose Strfry for Your Nostr Relay?
When selecting software to power a Nostr relay, performance, memory efficiency, and database integrity are paramount. While early implementations relied heavily on Node.js or Go, Strfry has distinguished itself within the developer community due to several architectural advantages:
- Low-Level Performance: Written in C++20, Strfry maximizes CPU and memory efficiency, allowing it to handle thousands of concurrent WebSocket connections with minimal overhead.
- LMDB Backend: Strfry utilizes the Lightning Memory-Mapped Database (LMDB). LMDB is renowned for being incredibly fast, highly concurrent, and highly crash-resilient, making it ideal for the read-heavy workloads typical of social networks.
- Advanced Filtering: It includes robust built-in support for querying and filtering events via a specialized execution engine, mitigating the risk of database bloat from spam.
Prerequisites and System Requirements
Before initiating the installation process, ensure your Virtual Private Server meets or exceeds the following technical specifications to ensure stable long-term operation:
1. Hardware Specifications
- CPU: Minimum 2 vCPUs (Dedicated threads preferred for production environments).
- RAM: 4 GB minimum (8 GB or more recommended to leverage LMDB's memory-mapping capabilities effectively).
- Storage: 50 GB NVMe SSD. The database will grow over time depending on your sync settings and whitelist policies.
2. Software and Network Environment
- Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
- Network: A static IPv4 address with ports 80, 443, and 7777 open on the firewall.
- Domain Name: A fully qualified domain name (FQDN) pointed via an A record to your VPS IP address (e.g.,
relay.yourdomain.com).
Step-by-Step Deployment Guide
Step 1: System Preparation and Dependency Installation
First, establish an SSH connection to your VPS and update the local package index to ensure all system dependencies are current. We will install the essential compilation tools, libraries for LMDB, development headers for SSL, and compression utilities required by Strfry.
sudo apt update && sudo apt upgrade -y
sudo apt install -y build-essential cmake liblmdb-dev libssl-dev libz-dev libcurl4-openssl-dev git pkg-configStep 2: Cloning and Compiling Strfry
With the build dependencies in place, clone the official Strfry repository from GitHub, navigate into the source directory, initialize the submodules, and compile the binaries using CMake.
git clone [https://github.com/hoytech/strfry.git](https://github.com/hoytech/strfry.git)
cd strfry
git submodule update --init --recursive
make -j$(nproc)Note: The -j$(nproc) flag instructs the compiler to utilize all available CPU cores, significantly accelerating the compilation process.Once compilation finishes successfully, verify the binary execution by running:
./strfry infoStep 3: Configuring the Strfry Relay
Strfry relies on a main configuration file, typically formatted in JSON or a custom configuration template found in the strfry/Config/ directory. Copy the sample configuration file to your active runtime directory:
cp strfry.config.example strfry.configOpen the file with a text editor like Nano to adjust key parameters:
nano strfry.configModify the following key-value pairs to fit your operational requirements:
info.name: The public name of your Nostr relay.info.description: A brief summary outlining the purpose or community guidelines of your relay.info.pubkey: Your hex-encoded Nostr public key (NPUB converted to hex) to denote ownership.db.path: The directory where the LMDB files will reside (e.g.,./strfry-db).network.port: Set the internal listening port. By default, this is7777.
Step 4: Setting Up a Reverse Proxy with Nginx
Exposing a C++ network binary directly to the open web is not recommended for production. Instead, route inbound traffic through Nginx, which handles SSL termination and buffers WebSocket connections securely.
Install Nginx and Certbot for automated Let's Encrypt SSL management:
sudo apt install -y nginx certbot python3-certbot-nginxCreate a new Nginx configuration block for your domain:
sudo nano /etc/nginx/sites-available/strfryInsert the configuration block below, replacing the placeholder domain with your actual FQDN:
server {
server_name relay.yourdomain.com;
location / {
proxy_pass [http://127.0.0.1:7777](http://127.0.0.1:7777);
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 86400s;
proxy_send_timeout 86400s;
}
}Enable the site configuration and restart Nginx to apply changes:
sudo ln -s /etc/nginx/sites-available/strfry /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl restart nginxStep 5: Provisioning SSL Certificates
Secure the setup by obtaining a trusted SSL certificate from Let's Encrypt. Execute Certbot and follow the interactive prompts to automatically configure HTTPS redirection:
sudo certbot --nginx -d relay.yourdomain.comStep 6: Creating a Systemd Service for Persistence
To ensure your Nostr relay automatically starts up during system reboots and runs seamlessly in the background, encapsulate the binary within a systemd service file.
sudo nano /etc/systemd/system/strfry.servicePopulate the file with the configuration below, ensuring the paths point accurately to your Strfry binary installation:
[Unit]
Description=Strfry Nostr Relay Service
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/root/strfry
ExecStart=/root/strfry/strfry relay
Restart=always
RestartSec=5
LimitNOFILE=65535
[Install]
WantedBy=multi-user.targetReload the systemd daemon, enable the service, and start your node:
sudo systemctl daemon-reload
sudo systemctl enable strfry
sudo systemctl start strfryVerify that your relay is up and running by inspecting the active logs:
sudo journalctl -u strfry -f -n 50Testing and Connecting to Your Relay
With the background processes functional, test your relay using any popular Nostr client (such as Amethyst, Primal, or Coracle). Navigate to the network or relay settings within the application, add your secure WebSocket URL (e.g., wss://relay.yourdomain.com), and confirm initialization. If the client connects successfully and begins transmitting event updates, your self-hosted node is fully operational.
Conclusion
Deploying a private or community-focused Nostr relay using Strfry on a VPS grants you total autonomy over your data pipeline while strengthening the backbone of the decentralized social web. By using a compiled language like C++ coupled with a high-efficiency storage layer like LMDB, your server is well-optimized to maintain continuous uptime with low hardware overhead. As the protocol grows, configuring advanced spam mitigations and controlling event whitelists via the Strfry configuration will remain key to scaling your infrastructure efficiently.
