Why self-host Syncthing on a VPS
Syncthing is a decentralized file synchronization tool: each device talks directly to the others, with no central server or copy held by a provider. The problem with pure peer-to-peer is that your machines aren't always on at the same time — your laptop is off when your desktop wants to sync. A VPS solves exactly this: it acts as a permanent node available 24/7, present on the Internet with a stable public IP, toward which all your devices converge. Files transit encrypted (TLS) and the VPS holds a synchronized copy that also serves as an off-site backup. Unlike shared hosting, a VPS allows opening the transfer ports and keeping a Syncthing daemon running permanently.
Concrete benefits of Syncthing on a VPS
- Permanent relay node: your devices no longer need to be on simultaneously to synchronize.
- End-to-end encryption (TLS) between all nodes, with no trust granted to any cloud.
- Natural off-site backup: the VPS keeps an up-to-date copy of your shared folders.
- File versioning (staggered/simple), configurable folder by folder, to recover a previous version.
- No per-gigabyte storage cost: only the VPS disk space matters.
- Discovery by static IP: fast direct connection without depending on public discovery servers.
Technical prerequisites
Syncthing is remarkably frugal in CPU and RAM, but it's the disk that sizes the server: you need as much space as the volume of data to synchronize. Plan for 1 vCPU and 1 GB of RAM, plus the storage suited to your folders (20, 50 GB or more depending on your needs). On the network side, two ports must be reachable: 22000 (TCP/UDP, data transfer) and 21027 (UDP, local discovery, optional on a remote VPS). The admin interface runs on port 8384 and must absolutely stay protected. Docker and Docker Compose are enough; a sync.yourdomain.com subdomain is useful to access the interface over HTTPS via a reverse proxy.
Deploy Syncthing step by step
Prepare the container
On the VPS, create
/opt/syncthingand adocker-compose.ymlbased on thesyncthing/syncthing:latestimage. Mount a configuration volume and a data volume, and set thePUID/PGIDvariables for file permissions.Open the transfer ports
Map port 22000 in TCP and UDP to the container and open it in the VPS firewall:
ufw allow 22000. This is the port through which data transits between nodes. Do not publish port 8384 to the Internet.Start Syncthing and retrieve the ID
Start with
docker compose up -d. Retrieve the node identifier (Device ID) from the logs or via the interface: it's the unique fingerprint that will be used to pair your other devices.Secure the admin interface
Expose port 8384 only behind an HTTPS reverse proxy with authentication. With Caddy:
sync.yourdomain.com { reverse_proxy syncthing:8384 }. Also set an interface username/password in Syncthing's GUI settings.Pair your devices
On each device (desktop, laptop, mobile), add the VPS as a new device via its Device ID, then accept the reciprocal request on the server side. Set up a shared folder and choose the mode (send only, receive only, or bidirectional).
Enable versioning
For important folders, enable "staggered" versioning on the VPS side: Syncthing keeps the successive versions of modified or deleted files there, turning your node into a safety net against handling mistakes.
Advanced configuration of shared folders
Once the basic deployment is working, open the GUI (via sync.yourdomain.com) to fine-tune each folder. For each shared folder, set the type: Send-Receive (bidirectional), Send Only (the VPS cannot modify your files) or Receive Only (the VPS archives without overwriting). The Folder ID field in the configuration — visible in config.xml under /opt/syncthing/config/ — must be identical on all devices sharing the same folder: it's what ties the nodes together. For storage-side encryption, Syncthing has supported the Encrypted mode since version 1.15: the VPS never sees your data in clear text, it only stores encrypted blobs. Enable it in the Sharing tab of a folder, Encrypted option for the VPS device. Sharing ACLs are managed per device: in each folder, select which devices are allowed to access it — a device not listed receives nothing even if it knows your Device ID.
Connecting multiple devices: Android, laptop, NAS
The power of the VPS as a central hub becomes clear when you connect a full ecosystem. On Android, install Syncthing via F-Droid (the official app, free, no Google telemetry) — the Play Store version has been deprecated since 2024. Open Syncthing on the phone, copy its Device ID, and add it on the VPS side via "Add Device". Reciprocally, add the VPS on the phone with its Device ID and the explicit address tcp://VPS_IP:22000 in the Addresses field. On a laptop, the process is identical: install syncthing via the package manager (apt install syncthing or official binary), start it with systemctl --user enable --now syncthing, and pair it to the VPS the same way. For a Synology or TrueNAS NAS, Syncthing is available as an official package or Docker container — configure the same Device ID and shared folders. Disable public relay servers in advanced preferences (relays disabled) and declare tcp://VPS_IP:22000 as a static address on each node for direct, fast connections without depending on Syncthing Foundation services.
Securing the web interface with nginx
Exposing port 8384 directly on the Internet is a critical mistake: anyone can attempt to connect. Best practice is to bind Syncthing to 127.0.0.1:8384 in the config (GUI Settings > GUI Listen Address: 127.0.0.1:8384) and front it with nginx or Caddy over HTTPS. With nginx, create a vhost in /etc/nginx/sites-available/sync: define a server block on port 443 with your Let's Encrypt certificate, a location / with proxy_pass http://127.0.0.1:8384 and the X-Real-IP, X-Forwarded-For headers. Add HTTP basic authentication (auth_basic, htpasswd) as an additional layer: even if someone finds the URL, they must pass two barriers — nginx and the Syncthing GUI password. In config.xml, ensure <insecureAdminAccess>false</insecureAdminAccess>. Finally, back up /opt/syncthing/config/ regularly — this folder contains the node's TLS keys, folder configuration and paired Device IDs: losing it means reconfiguring all devices from scratch.
Monitoring health with the REST API
Syncthing exposes a full REST API at http://127.0.0.1:8384/rest/. The API token is found in the GUI under Settings > GUI > API Key. Some useful queries from the VPS: curl -H 'X-API-Key: YOUR_KEY' http://127.0.0.1:8384/rest/db/status?folder=FOLDER_ID returns the sync state of a folder (keys: globalFiles, localFiles, needFiles, state). The idle state confirms everything is synced; syncing means a sync is in progress; error signals a problem to investigate in the logs. For real-time event monitoring: GET /rest/events?since=0 returns the event stream (connections, transfers, errors). For minimal production monitoring, add a cron job or Uptime-Kuma check that polls /rest/noauth/health — this endpoint requires no API key and returns {"status":"OK"} if Syncthing is running.
Troubleshooting common errors
Port 22000 unreachable. Remote devices appear as "Disconnected" even though Syncthing is running. Verify that ufw allow 22000/tcp and ufw allow 22000/udp were applied (ufw status). Also check that the compose maps 22000:22000/tcp and 22000:22000/udp — missing the UDP mapping blocks discovery. Confirm with nc -zv VPS_IP 22000 from a remote machine. Device not found. If auto-discovery fails, declare the VPS address manually in each client's config: Devices tab > Addresses > tcp://VPS_IP:22000. Version conflict. Two devices modified the same file while offline. Syncthing creates a .sync-conflict-YYYYMMDD-HHMMSS-DEVICEID file next to the original — intentional, no data is lost. Review both versions and delete the one you don't need. Insufficient disk space. Syncthing stops syncing and enters error state if available space drops below the configured threshold (default: 1% of disk). Free up space or expand the VPS disk; also check that staggered versioning isn't keeping years of revisions — limit the retention period in the folder settings.
Configure the VPS node in "Receive Only" mode for folders you only want to back up: that way the server will never overwrite your devices, it only archives what is sent to it. And since you have a static IP, disable the global discovery servers and declare the VPS address explicitly (tcp://IP:22000) in the config of the other nodes: connections establish faster and don't depend on any external service.
Syncthing, Nextcloud Files or rclone: when to choose which
Scroll the table
| Tool | When to use it |
|---|---|
| Syncthing | Pure peer-to-peer synchronization. Ideal if you just want to sync folders between devices with no web interface or link sharing. Minimal footprint, simple config, no server-side language. |
| Nextcloud Files | Full suite (link sharing, calendar, contacts, online Office). Choose Nextcloud if you need to collaborate or share files with others. Heavier: PHP, database, Redis. |
| rclone | Copy/sync tool supporting 70+ backends (S3, B2, SFTP…). Choose rclone for scheduled backups to object storage or data migration between clouds, not for real-time multi-device sync. |