Anonymous Nostr Relay VPS: Host Your Own Node with No KYC

Run strfry or nostr-rs-relay on a no-ID KVM: 1 vCPU class fits a personal relay, Scout 2 GB ECC from $5.49, XMR/BTC/USDT checkout.
Le corps de l'article est en anglais. L'interface, le catalogue et la caisse sont traduits.
Why self-host a Nostr relay
On a public relay you live under someone else’s config: events can be dropped, pubkeys rate-limited, the websocket closed on a policy change you never saw. A relay on a VM you pay for answers to your config file instead — NIP traffic lands on your disk, your retention rules, your allow and deny lists. The division of labor is the same as anonymous relay infrastructure or other self-run nodes: the host sells KVM with root access and leaves the daemon to you.
The honest scope: a personal inbox relay, a small community, or a write-only outbox for your own keys. Clients only find you if you publish the URL, so discovery stays your job. Content must be legal — CSAM and attack traffic are AUP failures that end the account, relay or not.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.
Launch nowRequirements: 1 vCPU and 1 GB RAM
A quiet personal or small-community relay fits in 1 vCPU and 1 GB RAM provided the event database stays bounded — retention and limits live in the relay config, not in hope. The catalog has no 1 GB SKU, so the practical floor is Scout: 1 vCPU / 2 GB ECC / 40 GB NVMe / unmetered 1 Gbps at $5.49 list ($3.00 annual-eff), which absorbs the 1 GB profile with headroom. A busier public relay grows in two dimensions — RAM for connected clients and NVMe for the event store — so the next steps are Sentry (2 vCPU / 4 GB / 60 GB, $7.50 list, $6.00 annual-eff) and Ranger (4 vCPU / 8 GB / 120 GB, $12.50 list, $10.00 annual-eff). One list price covers all twenty-one locations, and nested virtualization is enabled if you containerize the daemon.

strfry | nostr-rs-relay via Docker
Two daemons cover most deployments: strfry (LMDB-backed, websocket on 7777 by default) and nostr-rs-relay (commonly 8080). Install Docker from the distro’s own packages, move your project tree onto the VM with scp or rsync, and build locally — no marketplace pulls, no pasted clone URLs into a root shell. Put Caddy or nginx on 443 in front of the container so clients get wss://.
# strfry — build from the tree you uploaded. No registry or VCS URLs.
# Save as docker-compose.yml next to ./strfry/ and ./strfry.conf
services:
strfry:
build:
context: ./strfry
dockerfile: Dockerfile
container_name: strfry
restart: unless-stopped
ports:
- "7777:7777"
volumes:
- ./strfry.conf:/etc/strfry.conf:ro
- strfry-data:/var/lib/strfry
# a personal/small relay fits 1 vCPU / 1 GB once DB retention is set.
mem_limit: 1g
cpus: 1.0
logging:
driver: json-file
options:
max-size: "10m"
max-file: "3"
volumes:
strfry-data:
# nostr-rs-relay: identical pattern — build locally, bind 8080, mount config + data volumes.
# docker compose up -d
The config file is where the policy lives: NIP support, event retention, accepted pubkeys. Write it yourself — no relay image ships with the server, and the defaults of neither daemon are a community policy.
Pay crypto, stay anonymous
Checkout is a live-rate crypto invoice across sixteen coins: XMR, BTC, USDT on four networks (TRC-20 / BEP-20 / SPL plus the base asset), ETH, SOL, LTC, TRX and the rest — no passport, selfie, or phone number anywhere in the flow. Signup takes a 32-character token alone or an email plus a 12-character password; the token-only path keeps an inbox off the account entirely. Paying in Monero does not rewrite the AUP, and it does not change who operates the relay: you do.
| Topic | Anonymous VPS relay (you) | Public relays |
|---|---|---|
| Censorship | Your config and process. Clients you tell the URL to. | Operator policy: mute, rate-limit, or drop events without notice. |
| Logs | Relay and event logs sit on your own disk; the published privacy policy, not a promise, defines host-side metadata (24 h connection metadata, no payload logs). | Third-party operators; you do not control their retention or subpoenas. |
| KYC | No ID at NulNet checkout. Crypto invoice or prepaid balance. | Free public relays abound — you are the product, not a named customer, and you still trust their stack. |
Launch on Scout if 1 GB RSS is the plan; settle in XMR when the hosting bill should not sit on a transparent chain.
Operating notes: discovery, NIP-05, backups
Three chores decide whether the relay earns its keep. Discovery: the URL has to reach clients — a NIP-05 identifier on your domain points at the relay, and DNS is the one layer no hosting invoice cleans up. Backups: the event store is a single directory; a nightly dump to the NVMe storage line (1–5 TB from $24/mo annual-eff) or an offsite pull keeps a disk loss from becoming a history loss. Monitoring: websocket accept latency and DB size are the two numbers that say when Scout is done and Sentry is due — upgrade by metrics, not by vibes. If a workload outgrows shared slices entirely, the dedicated line puts the relay on whole cores with IPMI.
What is a no-KYC VPS for a Nostr relay?
A KVM you rent without any ID step — token or email plus password, then a crypto invoice — on which you install strfry or nostr-rs-relay yourself and publish the websocket. The host never operates Nostr for you.
Is 1 GB RAM enough?
Yes for a personal or small-community relay with bounded retention in the config. The catalog floor is Scout at 1 vCPU / 2 GB ECC — more than the 1 GB profile needs — and Sentry doubles the RAM when the community grows.
Can I pay with Monero?
Yes. XMR sits on the live-rate invoice beside BTC, USDT on four networks and the other coins in the sixteen-coin catalog, with no KYC attached to any of them.
Which ports does a relay need open?
Only the websocket port — 7777 for default strfry, 8080 for nostr-rs-relay — preferably behind TLS on 443. Inbound firewall policy on the VM is yours; the host does not filter outbound.
How do clients find my relay?
You publish the URL — in a NIP-05 identifier on your domain, a profile post, or wherever your community lives. Self-hosting changes who runs the policy, not the mechanics of discovery.
What happens if someone posts illegal content?
The AUP still applies to your relay's traffic: CSAM and attack traffic end accounts. Run the allow/deny lists, answer abuse mail, and keep retention bounded so review stays feasible.
Ready to launch?
Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.