Server configuration
The server reads its configuration from a TOML file (default: /etc/rchat/server.toml).
rchat-server --config /etc/rchat/server.tomlMinimal configuration
Section titled “Minimal configuration”[server]bind_addr = "0.0.0.0:443"
[server.tls]cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"Full example
Section titled “Full example”[server]bind_addr = "0.0.0.0:443"max_connections = 100000rate_limit_bps = 1048576circuit_ttl_secs = 3600connection_timeout_secs = 300
[server.tls]cert_path = "/etc/rchat/certs/fullchain.pem"key_path = "/etc/rchat/certs/privkey.pem"
[logging]format = "pretty"output = "stdout"
[metrics]enabled = truebind_addr = "0.0.0.0:9090"
[decoy]enabled = truerandomization_strength = 0.5Common options
Section titled “Common options”Bind address
Section titled “Bind address”The address and port the server listens on.
[server]bind_addr = "0.0.0.0:443"Use "127.0.0.1:8443" if running behind a reverse proxy.
Paths to your TLS certificate and private key. PEM format.
[server.tls]cert_path = "/etc/letsencrypt/live/your-domain.com/fullchain.pem"key_path = "/etc/letsencrypt/live/your-domain.com/privkey.pem"Connection limits
Section titled “Connection limits”[server]max_connections = 100000Maximum concurrent WebSocket connections.
Rate limiting
Section titled “Rate limiting”[server]rate_limit_bps = 1048576Maximum bytes per second per circuit. Default is 1 MB/s.
Circuit TTL
Section titled “Circuit TTL”[server]circuit_ttl_secs = 3600How long circuits remain active without traffic. Default is 1 hour.
Connection timeout
Section titled “Connection timeout”[server]connection_timeout_secs = 300How long before idle client connections are closed. Default is 5 minutes.
Logging
Section titled “Logging”[logging]format = "pretty" # "pretty" or "json"output = "stdout" # "stdout" or a file pathMetrics
Section titled “Metrics”[metrics]enabled = truebind_addr = "0.0.0.0:9090"Prometheus metrics are exposed at http://<bind_addr>/metrics.
[decoy]enabled = truerandomization_strength = 0.5Controls TLS fingerprint randomisation for DPI evasion. Leave enabled unless you have a specific reason to disable it.
Running behind a reverse proxy
Section titled “Running behind a reverse proxy”If you are running behind Caddy, nginx, or HAProxy, omit the TLS section and bind to a local port:
[server]bind_addr = "127.0.0.1:8443"The reverse proxy handles TLS 1.3 termination and forwards to rChat on the local port.
See Reverse Proxy Setup for complete Caddy, nginx, and HAProxy configurations.
TLS certificate renewal
Section titled “TLS certificate renewal”Let’s Encrypt certificates expire every 90 days. Certbot installs a renewal cron job automatically.
After renewal, reload rChat to pick up the new certificate:
sudo systemctl reload rchat-server# or if reload is not supported:sudo systemctl restart rchat-serverTo automate this, add a deploy hook:
#!/bin/bashsystemctl reload rchat-server 2>/dev/null || systemctl restart rchat-serverchmod +x /etc/letsencrypt/renewal-hooks/deploy/rchat-reload.shAll options
Section titled “All options”See the Server Configuration Reference for a complete list of every available setting.