Real-Time File Synchronization Across Multiple VPS: A Step-by-Step Guide Using Syncthing and P2P Architecture
Introduction: The Challenge of Distributed Data Consistency
In modern cloud infrastructure, maintaining real-time data consistency across multiple Virtual Private Servers (VPS) is a critical requirement. Whether you are managing high-availability web applications, distributed backups, or content delivery networks, keeping files synchronized with minimal latency is essential. Traditional methods like rsync paired with cron jobs lack the capability for immediate, multi-directional synchronization. On the other hand, centralized cloud solutions often introduce vendor lock-in, recurring costs, and compliance risks regarding data sovereignty.
This is where Syncthing becomes a game-changer. Syncthing is an open-source, decentralized file synchronization application that utilizes a Peer-to-Peer (P2P) architecture. Instead of routing your data through a central server, your VPS instances communicate and exchange data directly with one another. This guide provides an enterprise-grade, step-by-step walkthrough on configuring real-time file synchronization across your VPS fleet using Syncthing.
Why Syncthing and P2P for VPS Synchronization?
Before diving into the configuration, it is vital to understand the architectural benefits that Syncthing brings to a business infrastructure compared to traditional client-server models:
- Decentralization & High Availability: Since there is no central server, the failure of a single VPS does not halt the synchronization ecosystem. The remaining nodes continue to sync seamlessly.
- Optimized Bandwidth & Speed: The P2P protocol breaks files into smaller blocks and fetches them simultaneously from multiple nodes. If you have three or four servers, synchronization speeds scale efficiently.
- Cryptographic Security: All communication between nodes is strictly protected using TLS (Transport Layer Security). Furthermore, every node must explicitly authorize connection requests via unique cryptographic device IDs, preventing unauthorized access.
- Real-Time Auditing & Monitoring: Utilizing file system notifications (inotify), Syncthing detects modifications instantly and propagates changes without scanning the entire disk repeatedly, preserving system resources.
Prerequisites and Environment Setup
For this deployment, we will assume a scenario involving two Ubuntu 24.04 LTS VPS instances (Node A and Node B). However, the logic applies to any number of servers across different cloud providers.
- VPS Node A: Public IP:
192.0.2.10 - VPS Node B: Public IP:
198.51.100.20 - Sufficient storage space on both servers matching the directory sizes to be synced.
- Non-root user accounts with
sudoprivileges configured on both systems.
Step 1: Network and Firewall Configuration
Syncthing requires specific ports to discover peers and transfer data efficiently. Before installing the software, you must open these ports on your cloud provider's security groups or local firewalls (like UFW).
Critical Security Note: Always restrict access to management interfaces to specific administrative IPs.
Run the following commands on both servers to allow traffic:
sudo ufw allow 22000/tcp
sudo ufw allow 22000/udp
sudo ufw allow 21027/udp
sudo ufw reload- Port 22000/TCP & UDP: Used for actual file data transfer (Sync connections).
- Port 21027/UDP: Used for local discovery broadcasts on the network.
Step 2: Installing Syncthing on the VPS Instances
While Syncthing is available in official Ubuntu repositories, it is highly recommended to use the official upstream repository to ensure you receive the latest security patches and performance improvements.
Execute these commands on both Node A and Node B:
# Download the release PGP key
sudo mkdir -p /etc/apt/keyrings
sudo curl -L -o /etc/apt/keyrings/syncthing-archive-keyring.gpg [https://syncthing.net/release-key.gpg](https://syncthing.net/release-key.gpg)
# Add the official release channel to apt sources
echo "deb [signed-by=/etc/apt/keyrings/syncthing-archive-keyring.gpg] [https://apt.syncthing.net/](https://apt.syncthing.net/) syncthing stable" | sudo tee /etc/apt/sources.list.d/syncthing.list
# Update package lists and install Syncthing
sudo apt update
sudo apt install syncthing -yVerify the installation by checking the software version: syncthing --version.
Step 3: Configuring the Systemd Service for Autostart
To ensure Syncthing runs continuously in the background and automatically restarts when the server reboots, we will configure it as a systemd service under a dedicated user account.
Replace your_username with the actual system user account you want to own the synchronized files:
sudo systemctl enable syncthing@your_username.service
sudo systemctl start syncthing@your_username.serviceCheck the status to ensure it is running without issues:
sudo systemctl status syncthing@your_username.serviceStep 4: Securing the Web GUI and Allowing Remote Access
By default, Syncthing's administrative web interface listens only on 127.0.0.1:8384. Because a VPS operates headless without a local desktop environment, you have two options to access the GUI: adjust the config file to listen publicly or create a secure SSH tunnel. For production systems, an SSH Tunnel is the most secure method as it keeps the interface hidden from the public internet.
Option A: Connecting via Secure SSH Tunneling (Recommended)
From your local machine, open a terminal and execute the following command to map the remote server's GUI port to your local port:
ssh -L 9000:127.0.0.1:8384 [email protected]Now, open your local web browser and navigate to http://localhost:9000. You are now securely viewing Node A's management panel.
Option B: Configuring the GUI to Listen on Public IP
If you prefer direct access, open the configuration file located at ~/.config/syncthing/config.xml and find the 127.0.0.1:8384 block. Change it to 0.0.0.0:8384. Afterward, immediately log into the web GUI, navigate to Actions > Settings > GUI, and set a robust password and enable HTTPS.
Step 5: Pairing the VPS Nodes via P2P Device IDs
With both web interfaces accessible, it is time to establish the P2P connection between Node A and Node B. Syncthing security relies entirely on Device IDs—long cryptographic keys unique to each instance.
- On Node A, go to Actions > Show ID. Copy the alphanumeric string or note the structure.
- On Node B, click Add Remote Device under the "Remote Devices" section.
- Paste Node A's Device ID into the field. Provide a recognizable name (e.g.,
vps-node-a). - Under the Sharing tab, you can select folders you wish to sync with this device eventually. Click Save.
Now switch back to Node A's GUI. Within a few moments, a prompt will appear at the top of the interface stating that a remote device wants to connect. Click Add Device to confirm and complete the secure cryptographic handshake. The status should change to Connected (Unused).
Step 6: Setting Up and Syncing Shared Folders
Now that the infrastructure is linked, we can specify directories for real-time synchronization.
1. Define the Folder on Node A
By default, Syncthing creates a folder named "Default Folder" mapping to ~/Sync. Let us add a production folder, such as a directory containing web assets: /var/www/shared_assets.
- Click Add Folder on Node A.
- Set the Folder Label to "Shared Assets" and set a unique Folder ID (this ID must match across all nodes).
- Set the Folder Path to the absolute directory path on your disk.
- Navigate to the Sharing tab and check the box next to
vps-node-b. - Click Save.
2. Accept the Folder on Node B
An alert will promptly display on Node B's web GUI indicating that Node A wants to share the "Shared Assets" folder. Click Add, select the target directory path on Node B where these files should live, and hit save. The synchronization engine will automatically begin indexing and copying blocks over the encrypted P2P network in real time.
Step 7: Optimizing for High-Performance Production Environments
For demanding enterprise environments handling large scale modifications, tweaking these advanced parameters will prevent file corruption and system performance degradation:
Adjusting File Watcher Limits (inotify)
Linux systems place an upper limit on how many directories a system user can monitor simultaneously. If your directories hold tens of thousands of files, you may encounter system alerts. Resolve this by increasing the system limits:
echo "fs.inotify.max_user_watches=204800" | sudo tee -a /etc/sysctl.conf
sudo sysctl -pConfiguring File Versioning
Accidental deletions happen. To protect business data, click on the folder settings within Syncthing, go to the File Versioning tab, and select an option like Trash Can File Versioning or Staggered File Versioning. This acts as a safeguard, moving deleted or modified files into a hidden archival path for a predefined number of days before permanent deletion.
Conclusion
By bypassing traditional centralized cloud dependencies, configuring file synchronization over a P2P architecture via Syncthing ensures that your infrastructure remains resilient, low-latency, and safe from prying eyes. Your files are encrypted in transit, cross-verified using TLS certificates, and distributed fluidly across your network of servers. Incorporating these steps into your standard server deployment cycle safeguards high availability and maintains data consistency seamlessly.
