Run your own servers
A FreeSpeech server stores no message. Running one is simple, and administering it needs neither a web interface nor a restart: one command line is enough. A web console is offered in the Pro edition.
Three roles
| Role | What it does | Who can connect |
|---|---|---|
| Public relay | Passes messages between connected devices. May team up with other public relays through a shared secret (a whitelist kept by hand). | Everybody, except banned identities. |
| Private relay | For a family, an association, a company. Appears nowhere else and refuses all server-to-server traffic. | Only identities the administrator allowed or invited. |
| Push gateway | Wakes the app of an offline device. Never receives content: only a device token. | The relays the operator gave a key of their own. |
One device can use as many relays, public or private, as it likes: the identity depends on no server.
Getting started
The server is an ASP.NET Core 10 application. Behind nginx (which ends TLS), it listens on the local machine:
Admin__Secret="a long secret value" \
dotnet FreeSpeech.Server.dll --urls http://127.0.0.1:5290
The step-by-step guide (nginx, systemd, certificate, firewall, updates) is in the repository: sources/SERVER_INSTALLATION.en.md and sources/DEPLOYMENT.en.md.
Command-line administration free
The admin command talks to the running server's admin API. Every change applies at once and is saved: no restart, so no connection is cut.
# Private relay: accept invited people only
dotnet FreeSpeech.Server.dll admin access allowlist
dotnet FreeSpeech.Server.dll admin invite "Anna" --days 7 # single-use token, shown once
dotnet FreeSpeech.Server.dll admin clients # allowed, banned, invitations
dotnet FreeSpeech.Server.dll admin ban <identifier> "reason" # also cuts its live connections
# Public relay: sibling servers and push gateways (the other administrator accepts)
dotnet FreeSpeech.Server.dll admin add relay https://other.example.net
dotnet FreeSpeech.Server.dll admin add push https://push.example.net
dotnet FreeSpeech.Server.dll admin server-ban https://bad.example.net "abuse"
dotnet FreeSpeech.Server.dll admin drain 50 # invite 50 clients to move to a sibling before maintenance
# Push gateway: accept the relays that ask
dotnet FreeSpeech.Push.dll admin requests # requests received, with the relay's fingerprint
dotnet FreeSpeech.Push.dll admin accept <id>
dotnet FreeSpeech.Push.dll admin ban <id>
dotnet FreeSpeech.Push.dll admin maintenance on # answers "busy": relays use another gateway
For users, the server's address is added in Settings → Servers: the server tells the app whether it is private, and the app then offers to type an invitation or to request access.
Logs and tracing, console style
dotnet FreeSpeech.Server.dll admin log level relay debug # more detail, right now
dotnet FreeSpeech.Server.dll admin log tail -f # live stream
dotnet FreeSpeech.Server.dll admin trace 3fa9c1d2e4 --minutes 15 # follow one identity, stops by itself
dotnet FreeSpeech.Server.dll admin log reset
Privacy rule: a log holds metadata only. Never message content, never a key, never a device token, and identifiers are cut to 8 characters. Who writes to whom does not appear at the normal level; a precise trace must be requested, is limited to one hour and leaves a line in the log.
Administration kept out of sight
- The admin API only answers calls coming from the machine itself, with a secret. nginx does not publish it; you reach it over SSH or a VPN.
- Secrets are write-only: once entered, neither the command line nor the console shows them again.
- An unreadable access file closes the server instead of opening it.
Pro edition Pro
To run several servers without a command line.
Web administration console
One page for all your relays and gateways: clients and invitations, sibling servers, push gateways, limits, live logs and tracing. Accounts with roles (viewer, operator, administrator), two-factor sign-in, lockout after repeated failures and an audit trail of every action.
Ready-to-run installation
A Docker image and a virtual machine holding nginx, the server, the console and updates: start it, add your servers, done. In preparation.
Nothing held back from the free edition
The free server stays complete and administrable from the command line. The Pro console uses the same public APIs and changes nothing in the protocol.
Interested, or a question? contact@rebisway.com
FreeSpeech