All apps · 0 apps
ParleyPort
Docker app from junkerderprovinz's Repository
Overview
Readme
View on GitHub
ParleyPort is the relay for KnightLoader and BombVault. When two of your instances sit on different networks and neither can reach the other, both dial out to ParleyPort and meet there. It passes their messages on without being able to read them, and it runs as one small container that keeps no accounts and stores nothing.
A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.
If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.
Table of Contents
- What is this?
- Do I need it?
- Quick Start on Unraid
- Docker and Compose
- Configuration
- Pointing your apps at it
- What the relay sees
- Behind a reverse proxy
- License
- How AI is used here
- Support this project
1. What is this?
A parley was a meeting between two sides who did not trust each other, held under a flag of truce at the gate, so nobody had to enter the other's castle. ParleyPort is that gate for your instances.
KnightLoader and BombVault pair their instances with twelve words. Instances on the same network find each other and talk directly. Instances on different networks, behind NAT or a firewall that lets nothing in, need a third point both can dial out to. That point is a relay.
ParleyPort groups the connections that present the same relay key, a hash derived from your twelve words, and forwards their messages between them. Every message is sealed end to end with a key that never leaves your instances, so the relay carries it without being able to open it.
2. Do I need it?
Probably not. There are three ways to reach your instances across networks, and ParleyPort is only one of them:
- The project relay at
relay.halleluja.designis the default in both apps. Nothing to set up. - One of your own instances as the relay. If one KnightLoader or BombVault is already reachable from outside, switch on Serve as relay there and the others dial it.
- ParleyPort, for when you want your own relay but would rather not put a download manager or a backup tool on the open internet. It is a few megabytes, holds no data and can run on a small VPS while your instances stay at home.
3. Quick Start on Unraid
- In Apps, search for ParleyPort and install it.
- Plain mode: leave the domain empty and map port 8760. Put your reverse proxy in front of it, see section 8.
- Domain mode: enter your domain in Domain, forward port 443 on your router to the container, and ParleyPort fetches and renews its own Let's Encrypt certificate. You need neither a proxy nor certbot, and port 80 can stay closed.
- In each of your apps, set the relay to your address, see section 6.
4. Docker and Compose
Plain HTTP for a reverse proxy in front:
docker run -d --name parleyport --restart unless-stopped \
-p 8760:8760 \
junkerderprovinz/parleyport:latest
With its own certificate:
services:
parleyport:
image: junkerderprovinz/parleyport:latest
container_name: parleyport
restart: unless-stopped
ports:
- "443:443"
environment:
PARLEYPORT_DOMAIN: relay.example.org
volumes:
- ./parleyport:/var/lib/parleyport
The image is also on GHCR as ghcr.io/junkerderprovinz/parleyport, for amd64 and arm64. docker run junkerderprovinz/parleyport -version prints the version and the commit it was built from.
5. Configuration
Everything comes from the environment. Any command-line argument other than -version is refused, so a typo cannot start a relay with settings you did not mean.
| Variable | Default | What it does |
|---|---|---|
PARLEYPORT_DOMAIN |
empty | Domain for the built-in certificate. Several names can be given, separated by commas, so an old name keeps working while you move the relay. |
PARLEYPORT_ADDR |
:8760, or :443 with a domain |
Address and port to listen on. |
PARLEYPORT_CERT_DIR |
/var/lib/parleyport/certs |
Where the certificates are kept. Map /var/lib/parleyport to a volume so they survive a restart. |
ParleyPort used to ship inside KnightLoader as knightloader-relay. Its old variables KL_RELAY_DOMAIN, KL_RELAY_ADDR and KL_RELAY_CERT_DIR still work, so an existing relay can switch images without touching its configuration.
6. Pointing your apps at it
In KnightLoader and in BombVault the place is the same: Settings → Pairing → Relay → Own relay. Enter your address there, on every instance of the group:
https://relay.example.orgwith a domain or behind a proxy with a certificatehttp://192.168.1.10:8760for a relay on your own network, which works, but the app warns you that the relay key then crosses the network unencrypted
The twelve words stay the same. They carry the secret, not the address, so switching relays needs no new pairing.
7. What the relay sees
The relay learns which group a connection belongs to, through a hash of your twelve words and never the words themselves. It also sees which instance a message is for, how large the message is and when it passes.
The content stays closed to it. Messages are sealed with AES-256-GCM under a key derived from the twelve words, and the routing fields are bound into the seal, so a relay cannot redirect a message to another instance either.
It keeps no accounts, no database and no record of who connects. Client addresses are stripped from its own log output, and the rate limiter forgets an address after about an hour.
Whoever runs a relay can still see who talks to whom and when. If that matters to you, run your own, which is what ParleyPort is for.
8. Behind a reverse proxy
Run ParleyPort in plain mode and send /relay/connect to port 8760 with WebSocket upgrades allowed. /health answers with the status and the version, for a monitor or a health check.
Nginx:
location /relay/connect {
proxy_pass http://parleyport:8760;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 1h;
}
Nginx Proxy Manager: add a proxy host for your domain pointing at port 8760 and switch on Websockets Support.
9. License
Copyright (C) 2026 Junker der Provinz.
ParleyPort is free software under the GNU Affero General Public License v3.0 (AGPL-3.0); see LICENSE. You may run, study, share and modify it. If you distribute it, or run a modified version as a network service, you must release your source under the same AGPL-3.0 terms and keep the existing copyright and attribution notices intact.
Name and branding are not licensed. The AGPL covers the source code only. "ParleyPort", its logo and its branding remain reserved: a fork or derivative must use its own distinct name and branding, and may not present itself as ParleyPort. This keeps it unambiguous which project is the original.
10. How AI is used here
One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.
You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.
11. Support this project
Bugs, ideas or feature requests? Please open a GitHub issue.
A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.
If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.
Install ParleyPort on Unraid in a few clicks.
Find ParleyPort in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Categories
Download Statistics
Related apps
Explore more like this
Explore allDetails
junkerderprovinz/parleyport:latestRuntime arguments
- Network
bridge- Shell
sh- Privileged
- false
- Extra Params
--restart unless-stopped
Template configuration
Plain HTTP for a reverse proxy in front. Point the proxy at this port and allow WebSocket upgrades on /relay/connect. /health answers with the status and version.
- Target
- 8760
- Default
- 8760
- Value
- 8760
Only with a domain set below. Enter the host port your router forwards 443 to. Leave it empty in plain mode, and keep it off 443 if the Unraid web interface already uses that port.
- Target
- 443
Your relay's domain, for example relay.example.org. With it set, ParleyPort serves TLS on 443 inside the container and gets its own Let's Encrypt certificate through port 443 alone. Several names can be given, separated by commas, to keep an old name working during a move. Leave it empty for plain mode behind a proxy.
- Target
- PARLEYPORT_DOMAIN
Holds the certificates in domain mode, so a restart does not ask Let's Encrypt for a new one. Stays empty in plain mode.
- Target
- /var/lib/parleyport
- Default
- /mnt/user/appdata/parleyport
- Value
- /mnt/user/appdata/parleyport