ParleyPort

ParleyPort

Docker app from junkerderprovinz's Repository

Overview

Your own relay for KnightLoader and BombVault. Both apps pair their instances with twelve words. Instances on the same network talk directly, but two instances on different networks, behind NAT or a firewall that lets nothing in, need a third point both can dial out to. ParleyPort is that point. It groups the connections that share a relay key and passes their messages on, sealed end to end with a key that never leaves your instances, so it cannot read what it carries. You only need it if you want your own relay. The project relay at relay.halleluja.design is the default in both apps, and an instance that is already reachable from outside can serve as the relay itself. ParleyPort is for running your own without putting a download manager or a backup tool on the open internet: a few megabytes, no accounts, no database, nothing stored. Plain mode listens on port 8760 for a reverse proxy in front, which must allow WebSocket upgrades on /relay/connect. Set a domain and map port 443 instead, and it fetches and renews its own Let's Encrypt certificate, with port 80 left closed. Then enter the address under Settings, Pairing, Relay, Own relay on every instance of the group.

ParleyPort

Build  Lint  Docker Pulls  Image Size  Arch  Go  Unraid  License: AGPL-3.0


ParleyPort is the relay for KnightLoader and BombVault. When two of your instances sit on different networks and neither can reach the other, both dial out to ParleyPort and meet there. It passes their messages on without being able to read them, and it runs as one small container that keeps no accounts and stores nothing.


A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.


Buy me a coffee   PayPal   Donate with crypto


Table of Contents

  1. What is this?
  2. Do I need it?
  3. Quick Start on Unraid
  4. Docker and Compose
  5. Configuration
  6. Pointing your apps at it
  7. What the relay sees
  8. Behind a reverse proxy
  9. License
  10. How AI is used here
  11. Support this project

1. What is this?

A parley was a meeting between two sides who did not trust each other, held under a flag of truce at the gate, so nobody had to enter the other's castle. ParleyPort is that gate for your instances.

KnightLoader and BombVault pair their instances with twelve words. Instances on the same network find each other and talk directly. Instances on different networks, behind NAT or a firewall that lets nothing in, need a third point both can dial out to. That point is a relay.

ParleyPort groups the connections that present the same relay key, a hash derived from your twelve words, and forwards their messages between them. Every message is sealed end to end with a key that never leaves your instances, so the relay carries it without being able to open it.


2. Do I need it?

Probably not. There are three ways to reach your instances across networks, and ParleyPort is only one of them:

  • The project relay at relay.halleluja.design is the default in both apps. Nothing to set up.
  • One of your own instances as the relay. If one KnightLoader or BombVault is already reachable from outside, switch on Serve as relay there and the others dial it.
  • ParleyPort, for when you want your own relay but would rather not put a download manager or a backup tool on the open internet. It is a few megabytes, holds no data and can run on a small VPS while your instances stay at home.

3. Quick Start on Unraid

  1. In Apps, search for ParleyPort and install it.
  2. Plain mode: leave the domain empty and map port 8760. Put your reverse proxy in front of it, see section 8.
  3. Domain mode: enter your domain in Domain, forward port 443 on your router to the container, and ParleyPort fetches and renews its own Let's Encrypt certificate. You need neither a proxy nor certbot, and port 80 can stay closed.
  4. In each of your apps, set the relay to your address, see section 6.

4. Docker and Compose

Plain HTTP for a reverse proxy in front:

docker run -d --name parleyport --restart unless-stopped \
  -p 8760:8760 \
  junkerderprovinz/parleyport:latest

With its own certificate:

services:
  parleyport:
    image: junkerderprovinz/parleyport:latest
    container_name: parleyport
    restart: unless-stopped
    ports:
      - "443:443"
    environment:
      PARLEYPORT_DOMAIN: relay.example.org
    volumes:
      - ./parleyport:/var/lib/parleyport

The image is also on GHCR as ghcr.io/junkerderprovinz/parleyport, for amd64 and arm64. docker run junkerderprovinz/parleyport -version prints the version and the commit it was built from.


5. Configuration

Everything comes from the environment. Any command-line argument other than -version is refused, so a typo cannot start a relay with settings you did not mean.

Variable Default What it does
PARLEYPORT_DOMAIN empty Domain for the built-in certificate. Several names can be given, separated by commas, so an old name keeps working while you move the relay.
PARLEYPORT_ADDR :8760, or :443 with a domain Address and port to listen on.
PARLEYPORT_CERT_DIR /var/lib/parleyport/certs Where the certificates are kept. Map /var/lib/parleyport to a volume so they survive a restart.

ParleyPort used to ship inside KnightLoader as knightloader-relay. Its old variables KL_RELAY_DOMAIN, KL_RELAY_ADDR and KL_RELAY_CERT_DIR still work, so an existing relay can switch images without touching its configuration.


6. Pointing your apps at it

In KnightLoader and in BombVault the place is the same: Settings → Pairing → Relay → Own relay. Enter your address there, on every instance of the group:

  • https://relay.example.org with a domain or behind a proxy with a certificate
  • http://192.168.1.10:8760 for a relay on your own network, which works, but the app warns you that the relay key then crosses the network unencrypted

The twelve words stay the same. They carry the secret, not the address, so switching relays needs no new pairing.


7. What the relay sees

The relay learns which group a connection belongs to, through a hash of your twelve words and never the words themselves. It also sees which instance a message is for, how large the message is and when it passes.

The content stays closed to it. Messages are sealed with AES-256-GCM under a key derived from the twelve words, and the routing fields are bound into the seal, so a relay cannot redirect a message to another instance either.

It keeps no accounts, no database and no record of who connects. Client addresses are stripped from its own log output, and the rate limiter forgets an address after about an hour.

Whoever runs a relay can still see who talks to whom and when. If that matters to you, run your own, which is what ParleyPort is for.


8. Behind a reverse proxy

Run ParleyPort in plain mode and send /relay/connect to port 8760 with WebSocket upgrades allowed. /health answers with the status and the version, for a monitor or a health check.

Nginx:

location /relay/connect {
    proxy_pass http://parleyport:8760;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_read_timeout 1h;
}

Nginx Proxy Manager: add a proxy host for your domain pointing at port 8760 and switch on Websockets Support.


9. License

Copyright (C) 2026 Junker der Provinz.

ParleyPort is free software under the GNU Affero General Public License v3.0 (AGPL-3.0); see LICENSE. You may run, study, share and modify it. If you distribute it, or run a modified version as a network service, you must release your source under the same AGPL-3.0 terms and keep the existing copyright and attribution notices intact.

Name and branding are not licensed. The AGPL covers the source code only. "ParleyPort", its logo and its branding remain reserved: a fork or derivative must use its own distinct name and branding, and may not present itself as ParleyPort. This keeps it unambiguous which project is the original.


10. How AI is used here

One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.

You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.


11. Support this project

Bugs, ideas or feature requests? Please open a GitHub issue.

A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.

Buy me a coffee   PayPal   Donate with crypto

Install ParleyPort on Unraid in a few clicks.

Find ParleyPort in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.

Open the Apps tab on your Unraid server Search Community Apps for ParleyPort Review the template variables and paths Click Install

Download Statistics

134
Total Downloads

Related apps

Details

Repository
junkerderprovinz/parleyport:latest
Last Updated2026-10-01
First Seen2026-10-02

Runtime arguments

Network
bridge
Shell
sh
Privileged
false
Extra Params
--restart unless-stopped

Template configuration

Relay Port (plain)Porttcp

Plain HTTP for a reverse proxy in front. Point the proxy at this port and allow WebSocket upgrades on /relay/connect. /health answers with the status and version.

Target
8760
Default
8760
Value
8760
Relay Port (TLS)Porttcp

Only with a domain set below. Enter the host port your router forwards 443 to. Leave it empty in plain mode, and keep it off 443 if the Unraid web interface already uses that port.

Target
443
DomainVariable

Your relay's domain, for example relay.example.org. With it set, ParleyPort serves TLS on 443 inside the container and gets its own Let's Encrypt certificate through port 443 alone. Several names can be given, separated by commas, to keep an old name working during a move. Leave it empty for plain mode behind a proxy.

Target
PARLEYPORT_DOMAIN
DataPathrw

Holds the certificates in domain mode, so a restart does not ask Let's Encrypt for a new one. Stays empty in plain mode.

Target
/var/lib/parleyport
Default
/mnt/user/appdata/parleyport
Value
/mnt/user/appdata/parleyport