Files
wild-directory/syncthing-relay

Syncthing Relay Server

strelaysrv relays encrypted Syncthing traffic between devices that cannot connect directly (e.g. both behind NAT).

Bandwidth warning

Unlike the discovery server, the relay proxies all sync traffic. Every byte synced between clients who cannot connect directly flows through your Wild Central device and your internet connection. On a home or community internet connection, heavy use by multiple members syncing large files can saturate your upstream bandwidth.

Deploy this only if you know your members need relay support and your connection can handle it. If members can connect directly, the relay is never used.

Network setup

Port 22067 (TCP) must be forwarded on your router to the relay's LoadBalancer IP. Check the assigned IP with:

kubectl get svc -n syncthing-relay syncthing-relay

Set externalAddress in your app config to your-domain-or-ip:22067 so the relay advertises the correct public address.

Privacy

This relay is configured as private (not registered with the Syncthing global relay pool). Only Syncthing clients that explicitly add your relay URL will use it. The relay operator can see which device IDs are connecting and data volumes, but not file contents — traffic is end-to-end encrypted between Syncthing clients.

Syncthing client configuration

Add the relay URI in Syncthing settings under Settings → Connections → Relays:

relay://your-domain:22067

Status

The relay status page is available at https://{{ domain }}/status.