Back to articles
Technology Insight

Securing Decentralized Communication: A Guide to Deploying a Private Nostr Relay on a VPS

June 1, 2026

Introduction: The Imperative for Censorship-Resistant Communication

In the contemporary digital landscape, centralized social media platforms have become the gatekeepers of public discourse. For enterprises, journalists, and privacy-conscious professionals, relying on these centralized entities introduces significant operational risks, including arbitrary content moderation, algorithmic bias, and sudden platform closures. To mitigate these vulnerabilities, the paradigm is shifting toward decentralized architectures.

Among these emerging technologies, Nostr (Notes and Other Stuff Transmitted by Relays) has stood out as a remarkably robust, open-source protocol designed to facilitate global, censorship-resistant publishing. Nostr does not rely on a trusted central server; instead, it utilizes a cryptographic framework of public/private key pairs and a distributed network of independent servers known as relays. This comprehensive guide provides a technical roadmap for deploying your own private Nostr relay on a Virtual Private Server (VPS), ensuring absolute autonomy over your data and communication channels.

---

Understanding the Nostr Architecture

Before diving into the technical deployment, it is crucial to understand the structural dynamics of the Nostr network. Unlike traditional architectures, Nostr operates on a lightweight, asynchronous model comprised of two primary components:

  • Clients: The user interfaces (apps or web dashboards) where users generate, sign, and view cryptographic data.
  • Relays: Stateless or stateful backend servers that accept data packets (events) via WebSockets, store them in a database, and forward them to other connected clients.
Crucially, relays do not communicate with each other; they interact solely with clients. This design ensures that if one relay censors a user, the user can seamlessly transition to another relay without losing their social graph or identity.

By hosting a private relay, you establish a dedicated, secure node that services only your authorized cryptographic keys, eliminating reliance on public relays that may suffer from latency, data retention policies, or malicious traffic filtering.

---

Prerequisites and Infrastructure Selection

To ensure optimal performance, stability, and security, your infrastructure must meet specific baseline requirements. We recommend utilizing a reliable VPS provider such as DigitalOcean, Linode, AWS, or Hetzner.

Recommended System Specifications

  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (64-bit)
  • CPU: Minimum 1 vCPU (2 vCPUs recommended for production environments)
  • Memory: 2 GB RAM minimum
  • Storage: 20 GB to 40 GB SSD/NVMe (scalable depending on your data retention policies)
  • Network: Static IPv4 address with a minimum of 1 TB bandwidth allowance

Additionally, you will require a fully qualified domain name (FQDN) pointed to your VPS IP address via an A record (e.g., relay.yourdomain.com) to facilitate SSL/TLS termination.

---

Step-by-Step Deployment Protocol

For this implementation, we will utilize Khatru or Relay-v2 (often implemented via lightweight Go or Rust-based daemons like strfry or nostr-rs-relay). In this guide, we focus on nostr-rs-relay due to its memory efficiency, robust performance, and native Docker compatibility.

Step 1: System Update and Dependency Installation

First, establish an SSH connection to your VPS and update the system repositories to secure the latest patches:

sudo apt update && sudo apt upgrade -y

Next, install essential utilities including Docker, Docker Compose, Git, and Nginx:

sudo apt install docker.io docker-compose git nginx certbot python3-certbot-nginx -y

Ensure the Docker service is enabled and running actively on boot:

sudo systemctl enable --now docker

Step 2: Configuring the Nostr Relay

Create a dedicated directory for your Nostr application to maintain organized file system governance:

mkdir -p ~/nostr-relay && cd ~/nostr-relay

Create a configuration file named config.toml to define the operational rules of your relay. This file controls access, rate limiting, and database paths:

[info]
name = "Private Enterprise Nostr Relay"
description = "A secure, private relay dedicated to confidential corporate communications."
pubkey = "your_hex_public_key_here"
contact = "[email protected]"

[network]
address = "0.0.0.0"
port = 8080

[database]
data_directory = "/data"

[limits]
max_event_size = 65536
max_ws_message_size = 131072

To make the relay strictly private, you can implement a whitelist constraint within the configuration configuration block, allowing only specific public keys to publish events to the network.

Step 3: Docker Compose Orchestration

To containerize the application for seamless lifecycle management, create a docker-compose.yml file within the same directory:

version: '3' 
services:
  relay:
    image: scinfra/nostr-rs-relay:latest
    volumes:
      - ./config.toml:/usr/src/app/config.toml
      - ./data:/data
    ports:
      - "8080:8080"
    restart: always

Launch the containerized relay service in detached mode:

sudo docker-compose up -d

Verify that the service is running properly by analyzing the real-time log output:

sudo docker-compose logs -f

---

Reverse Proxy and SSL Configuration with Nginx

Because Nostr relies on WebSocket connections (ws://), securing these data streams with TLS/SSL amplification (wss://) is non-negotiable for enterprise deployments. Nginx will serve as our reverse proxy handling this translation layer.

Step 1: Configure Nginx Block

Create a new configuration file for Nginx:

sudo nano /etc/nginx/sites-available/nostr-relay

Insert the following configuration layout, substituting your actual domain name:

server {
    server_name relay.yourdomain.com;

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "Upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}

Enable the site configuration by linking it directly to the active configuration directory and restart the web server:

sudo ln -s /etc/nginx/sites-available/nostr-relay /etc/nginx/sites-enabled/
sudo systemctl restart nginx

Step 2: Obtain an SSL Certificate

Execute Certbot to automatically provision a free, trusted Let's Encrypt SSL certificate and apply it to your configuration:

sudo certbot --nginx -d relay.yourdomain.com

Follow the onscreen prompt to complete configuration validation. Certbot will automatically inject the necessary cryptographic paths and redirect all standard HTTP traffic to secure HTTPS/WSS channels.

---

Validation and Integration

With the infrastructure operating successfully, the final step involves establishing a client connection to verify functionality.

  1. Open any professional-grade Nostr client application (such as Amethyst, Coracle, or Primal).
  2. Navigate to the settings menu and locate the Relays or Network Connections subsection.
  3. Select the option to append a new custom relay.
  4. Input your secure endpoint URI: wss://relay.yourdomain.com.
  5. Save the parameters and watch for the client status marker to shift to connected status.

Once connected, any status updates, direct messages, or encrypted payloads distributed through this channel will bypass public indexes entirely, routed safely via your private infrastructure architecture.

---

Conclusion: Future-Proofing Corporate Communications

Deploying a private Nostr relay establishes a bulletproof foundation for enterprise sovereignty and continuous availability. By investing a minimal amount of configuration effort, you gain an immutable communication node that is structurally immune to external de-platforming, single points of failure, or systemic outages. As digital privacy legislation and data collection scrutiny tighten worldwide, proactive organizations that own their communication pipelines will maintain a critical competitive advantage.

Securing Decentralized Communication: A Guide to Deploying a Private Nostr Relay on a VPS | DPTCloud