Run your own sync server

A short guide. The full one lives in the repository: docs/DEPLOY.md.

The Facet sync server is a small Node.js service backed by a single SQLite database. It only ever stores encrypted data and account metadata, so it needs very little: a modest Linux server is plenty for a household or a small team.

What you need

Set it up

  1. Get the code.

    git clone <repository URL>
    cd facet/deploy
  2. Configure it. Copy the example file, then set your domain and the two secrets. The comments in the file explain each value.

    cp .env.example .env
    openssl rand -base64 48   # run twice: one value for JWT_SECRET, one for SERVER_SECRET
  3. Start it.

    docker compose up -d
    curl https://your.domain/v1/health   # → {"ok":true}
  4. Point the app at it. In Facet, open Settings → Account → Sync server and enter your address, for example https://your.domain. Do this before you sign in: accounts belong to one server and don’t move between servers automatically.

Settings

The server is configured with environment variables. The ones you’re most likely to change:

VariableDefaultWhat it does
JWT_SECRETrequiredSigns sign-in tokens. At least 32 characters.
SERVER_SECRETrequiredUsed for internal hashing. At least 32 characters.
PUBLIC_URLhttp://localhost:8787Your server’s public address, used in emails.
REGISTRATION_OPENtrueSet to false once everyone has an account.
BLOB_QUOTA_BYTES2 GiBAttachment storage per account.
DATA_DIR./dataWhere the database and attachments are stored.
SMTP_URLunsetEnables password reset by email (see below).
SMTP_FROMFacet <no-reply@…>Sender for those emails.
TRUST_PROXYtrueRead client IPs from the reverse proxy.
LOG_LEVELinfoHow much the server logs.

Password resets

Without email configured, people who forget their password reset it with the recovery code Facet showed them at sign-up, and their data is kept. If you set SMTP_URL, people without a recovery code can also reset by email. Because the server can’t decrypt anything, an email reset keeps the account but permanently deletes its encrypted data.

Backups

Everything the server stores lives in DATA_DIR: the SQLite database and the folder of encrypted attachments. Back up that directory regularly. For a consistent copy of the database, use SQLite’s online backup or stop the container for a moment while you copy. Backups contain only ciphertext and account metadata.

Updating

git pull
docker compose up -d --build

More detail

See the deployment guide for running without Docker, using your own reverse proxy and monitoring, and the API reference and security model for how sync and encryption work.