Skip to content

Server configuration reference

Complete reference for all fields in server.toml.


All fields live under a [server] section, or at the root level (both are accepted).

FieldTypeDefaultDescription
bind_addrstring"0.0.0.0:8443"Address and port to listen on. Use "0.0.0.0:443" for all interfaces or "127.0.0.1:8443" for localhost-only (behind a reverse proxy).
max_connectionsinteger1000000Maximum concurrent WebSocket connections.
rate_limit_bpsinteger1048576Rate limit per circuit in bytes per second. Default is 1 MB/s.
circuit_ttl_secsinteger3600How long a circuit remains active without traffic. Default is 1 hour.
connection_timeout_secsinteger300How long before an idle client connection is closed. Default is 5 minutes.
message_queue_persist_pathpath(none)Path to a JSON file for persistent message queue storage. If unset, queued messages are lost on server restart.
redis_urlstring(none)Redis URL for horizontal scaling (e.g. redis://localhost:6379).

TLS configuration. Required for production. Omit if running behind a reverse proxy.

FieldTypeDefaultDescription
cert_pathpath(none)Path to the TLS certificate (PEM format).
key_pathpath(none)Path to the TLS private key (PEM format).

FieldTypeDefaultDescription
formatstring"json"Log format: "json" or "pretty".
outputstring"stdout"Log destination: "stdout" or a file path.

Prometheus metrics endpoint.

FieldTypeDefaultDescription
enabledbooltrueEnable the metrics endpoint.
bind_addrstring"0.0.0.0:9090"Address and port for the metrics HTTP server.

Metrics are exposed at http://<bind_addr>/metrics in Prometheus format.


DPI evasion and TLS fingerprint masking.

FieldTypeDefaultDescription
enabledbooltrueEnable decoy/TLS fingerprint randomisation.
randomization_strengthfloat0.5Strength of randomisation (0.0 to 1.0). Higher values produce more variation.

Leave enabled unless you have a specific reason to disable it.


[server]
bind_addr = "0.0.0.0:443"
max_connections = 100000
rate_limit_bps = 1048576
circuit_ttl_secs = 3600
connection_timeout_secs = 300
message_queue_persist_path = "/var/lib/rchat/queue.json"
[server.tls]
cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"
key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"
[logging]
format = "pretty"
output = "stdout"
[metrics]
enabled = true
bind_addr = "0.0.0.0:9090"
[decoy]
enabled = true
randomization_strength = 0.5

When running behind Caddy, nginx, or another TLS-terminating reverse proxy, set bind_addr to a localhost port and omit the TLS section:

[server]
bind_addr = "127.0.0.1:8443"

Caddy example:

your.domain.com {
reverse_proxy 127.0.0.1:8443
}

nginx example:

server {
listen 443 ssl http2;
server_name your.domain.com;
ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:8443;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 86400;
}
}