Skip to content

Server configuration

The server reads its configuration from a TOML file (default: /etc/rchat/server.toml).

Terminal window
rchat-server --config /etc/rchat/server.toml

[server]
bind_addr = "0.0.0.0:443"
[server.tls]
cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"
key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"

[server]
bind_addr = "0.0.0.0:443"
max_connections = 100000
rate_limit_bps = 1048576
circuit_ttl_secs = 3600
connection_timeout_secs = 300
[server.tls]
cert_path = "/etc/rchat/certs/fullchain.pem"
key_path = "/etc/rchat/certs/privkey.pem"
[logging]
format = "pretty"
output = "stdout"
[metrics]
enabled = true
bind_addr = "0.0.0.0:9090"
[decoy]
enabled = true
randomization_strength = 0.5

The address and port the server listens on.

[server]
bind_addr = "0.0.0.0:443"

Use "127.0.0.1:8443" if running behind a reverse proxy.

Paths to your TLS certificate and private key. PEM format.

[server.tls]
cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"
key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"
[server]
max_connections = 100000

Maximum concurrent WebSocket connections.

[server]
rate_limit_bps = 1048576

Maximum bytes per second per circuit. Default is 1 MB/s.

[server]
circuit_ttl_secs = 3600

How long circuits remain active without traffic. Default is 1 hour.

[server]
connection_timeout_secs = 300

How long before idle client connections are closed. Default is 5 minutes.

[logging]
format = "pretty" # "pretty" or "json"
output = "stdout" # "stdout" or a file path
[metrics]
enabled = true
bind_addr = "0.0.0.0:9090"

Prometheus metrics are exposed at http://<bind_addr>/metrics.

[decoy]
enabled = true
randomization_strength = 0.5

Controls TLS fingerprint randomisation for DPI evasion. Leave enabled unless you have a specific reason to disable it.


If you are running behind Caddy, nginx, or HAProxy, omit the TLS section and bind to a local port:

[server]
bind_addr = "127.0.0.1:8443"

The reverse proxy handles TLS 1.3 termination and forwards to rChat on the local port.

See Reverse Proxy Setup for complete Caddy, nginx, and HAProxy configurations.


Let’s Encrypt certificates expire every 90 days. Certbot installs a renewal cron job automatically.

After renewal, reload rChat to pick up the new certificate:

Terminal window
sudo systemctl reload rchat-server
# or if reload is not supported:
sudo systemctl restart rchat-server

To automate this, add a deploy hook:

/etc/letsencrypt/renewal-hooks/deploy/rchat-reload.sh
#!/bin/bash
systemctl reload rchat-server 2>/dev/null || systemctl restart rchat-server
Terminal window
chmod +x /etc/letsencrypt/renewal-hooks/deploy/rchat-reload.sh

See the Server Configuration Reference for a complete list of every available setting.