Server configuration reference
Complete reference for all fields in server.toml.
Top-level fields
Section titled “Top-level fields”All fields live under a [server] section, or at the root level (both are accepted).
| Field | Type | Default | Description |
|---|---|---|---|
bind_addr | string | "0.0.0.0:8443" | Address and port to listen on. Use "0.0.0.0:443" for all interfaces or "127.0.0.1:8443" for localhost-only (behind a reverse proxy). |
max_connections | integer | 1000000 | Maximum concurrent WebSocket connections. |
rate_limit_bps | integer | 1048576 | Rate limit per circuit in bytes per second. Default is 1 MB/s. |
circuit_ttl_secs | integer | 3600 | How long a circuit remains active without traffic. Default is 1 hour. |
connection_timeout_secs | integer | 300 | How long before an idle client connection is closed. Default is 5 minutes. |
message_queue_persist_path | path | (none) | Path to a JSON file for persistent message queue storage. If unset, queued messages are lost on server restart. |
redis_url | string | (none) | Redis URL for horizontal scaling (e.g. redis://localhost:6379). |
[server.tls]
Section titled “[server.tls]”TLS configuration. Required for production. Omit if running behind a reverse proxy.
| Field | Type | Default | Description |
|---|---|---|---|
cert_path | path | (none) | Path to the TLS certificate (PEM format). |
key_path | path | (none) | Path to the TLS private key (PEM format). |
[logging]
Section titled “[logging]”| Field | Type | Default | Description |
|---|---|---|---|
format | string | "json" | Log format: "json" or "pretty". |
output | string | "stdout" | Log destination: "stdout" or a file path. |
[metrics]
Section titled “[metrics]”Prometheus metrics endpoint.
| Field | Type | Default | Description |
|---|---|---|---|
enabled | bool | true | Enable the metrics endpoint. |
bind_addr | string | "0.0.0.0:9090" | Address and port for the metrics HTTP server. |
Metrics are exposed at http://<bind_addr>/metrics in Prometheus format.
[decoy]
Section titled “[decoy]”DPI evasion and TLS fingerprint masking.
| Field | Type | Default | Description |
|---|---|---|---|
enabled | bool | true | Enable decoy/TLS fingerprint randomisation. |
randomization_strength | float | 0.5 | Strength of randomisation (0.0 to 1.0). Higher values produce more variation. |
Leave enabled unless you have a specific reason to disable it.
Full example
Section titled “Full example”[server]bind_addr = "0.0.0.0:443"max_connections = 100000rate_limit_bps = 1048576circuit_ttl_secs = 3600connection_timeout_secs = 300message_queue_persist_path = "/var/lib/rchat/queue.json"
[server.tls]cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"
[logging]format = "pretty"output = "stdout"
[metrics]enabled = truebind_addr = "0.0.0.0:9090"
[decoy]enabled = truerandomization_strength = 0.5Reverse proxy mode
Section titled “Reverse proxy mode”When running behind Caddy, nginx, or another TLS-terminating reverse proxy, set bind_addr to a localhost port and omit the TLS section:
[server]bind_addr = "127.0.0.1:8443"Caddy example:
your.domain.com { reverse_proxy 127.0.0.1:8443}nginx example:
server { listen 443 ssl http2; server_name your.domain.com;
ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;
location / { proxy_pass http://127.0.0.1:8443; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_read_timeout 86400; }}