# How to run Syncthing on a Linux server as an always-on sync peer

> Install Syncthing from its official apt repository, run it as a systemd service, reach the web GUI through an SSH tunnel and sync folders with your devices.

Difficulty: Beginner\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

Syncthing is an open-source, continuous file synchronisation program. Devices connect to each other directly over encrypted connections, so there is no central cloud service holding your files. On its own, Syncthing only syncs while two devices are online at the same time. A Linux server that is always on fixes that: your laptop, desktop and phone each sync with the server whenever they are online, and the server passes the changes on.

This guide installs Syncthing from the project's **official apt repository** (the `stable-v2` channel), runs it as a systemd service under a dedicated user, keeps the web GUI on `127.0.0.1` and reaches it through an SSH tunnel, opens only the sync ports in the firewall, and then shows how to add devices, share folders, write ignore patterns, back up the device keys, update and fix common connection problems.

## Prerequisites

- A server running **Ubuntu 24.04 LTS**, **Ubuntu 26.04 LTS**, **Debian 12** or **Debian 13**. The official repository is not tied to a release codename, so the same steps apply to all four. They work on a HyperDC Linux VPS, VDS or dedicated server with root access.
- A non-root user with `sudo` rights and SSH key login: see [Secure a new Linux server](/guides/secure-a-new-linux-server) and [Set up SSH keys](/guides/ssh-keys).
- ufw enabled with SSH allowed (covered in the security guide).
- Syncthing installed on at least one other device, such as your laptop, from the Syncthing website or your platform's package.

| Resource | Minimum (official) | Suggested starting point |
|---|---|---|
| CPU | Not published | 1 vCPU |
| RAM | Not published | 1 GB, more for folders with many files |
| Disk | Not published | The size of your synced data, plus room for versions and the index database |

The project does not publish minimum requirements. The right-hand column is a conservative starting point, not a benchmark. Hashing and indexing large folders is the main load, so the first scan takes the longest.

## Step 1 — Add the official Syncthing repository

Ubuntu and Debian ship their own Syncthing packages, but they lag behind upstream. The Syncthing project runs its own apt repository. Download its signing key into `/etc/apt/keyrings`:

```bash
sudo apt update
sudo apt install curl
sudo mkdir -p /etc/apt/keyrings
sudo curl -L -o /etc/apt/keyrings/syncthing-archive-keyring.gpg https://syncthing.net/release-key.gpg
```

Add the `stable-v2` channel, which receives stable releases (usually on the first Tuesday of the month). The project also pins its repository at priority 990 so that the distribution's older package never wins:

```bash
echo "deb [signed-by=/etc/apt/keyrings/syncthing-archive-keyring.gpg] https://apt.syncthing.net/ syncthing stable-v2" | sudo tee /etc/apt/sources.list.d/syncthing.list
printf "Package: *\nPin: origin apt.syncthing.net\nPin-Priority: 990\n" | sudo tee /etc/apt/preferences.d/syncthing.pref
```

A `candidate` channel with release candidates also exists; use it only on test machines.

## Step 2 — Install Syncthing

```bash
sudo apt update
sudo apt install syncthing
apt-cache policy syncthing
syncthing version
```

`apt-cache policy` should show the installed version coming from `https://apt.syncthing.net`, and `syncthing version` prints a 2.x version. The package also installs the systemd unit files, so you do not need to copy them by hand.

## Step 3 — Run Syncthing as a system service

Syncthing's documentation offers two systemd setups: a **system service**, `syncthing@USER.service`, which starts at boot without anyone logged in and is meant for servers, and a user service for desktops. Use the system service, and give Syncthing its own unprivileged account instead of your admin user:

```bash
sudo useradd --system --create-home --home-dir /srv/syncthing --shell /usr/sbin/nologin syncthing
sudo systemctl enable --now syncthing@syncthing.service
sudo systemctl status syncthing@syncthing.service --no-pager
sudo ss -tulpn | grep syncthing
```

The service shows `active (running)`. The `ss` output lists the GUI on `127.0.0.1:8384` only, and the sync protocol on port `22000` over both TCP and UDP (QUIC). On the first start Syncthing creates its configuration and the device keys in `/srv/syncthing/.local/state/syncthing`. Syncthing 2 no longer creates a default folder; you add folders yourself in Step 7.

## Step 4 — Open the sync port in the firewall

Other devices connect to the server on port 22000. Open it for TCP and UDP, and nothing else:

```bash
sudo ufw allow 22000/tcp
sudo ufw allow 22000/udp
sudo ufw status verbose
```

Do not open 8384; the GUI stays private. The Syncthing package also ships ufw profiles (`sudo ufw allow syncthing`), but that profile additionally opens UDP 21027, which is only useful for discovery on a local network and serves no purpose on an internet server.

## Step 5 — Open the GUI through an SSH tunnel and set a password

The GUI listens on `127.0.0.1:8384`, so you reach it by forwarding a local port over SSH. Run this **on your own computer**, not on the server. Local port 9090 avoids a clash with a Syncthing GUI already running on your computer:

```bash
ssh -N -L 9090:127.0.0.1:8384 user@203.0.113.10
```

Leave the command running and open `http://localhost:9090` in your browser. Windows 10 and later include the same `ssh` command.

Syncthing warns that no GUI password is set. Fix that right away, because anyone who can reach the GUI port on the server, including other local users, could otherwise control Syncthing:

1. Open **Actions** (top right), then **Settings**.
2. On the **General** tab, give the server a recognisable **Device Name**.
3. On the **GUI** tab, set **GUI Authentication User** and a long **GUI Authentication Password**, then click **Save**.

Reload the page; Syncthing now asks for the user name and password. The SSH tunnel already encrypts the connection, so you do not need to enable HTTPS for the GUI.

## Step 6 — Connect your devices

Each pair of devices must add each other's device ID before they connect. Device IDs are not secret: on their own they cannot be used to connect or read files.

1. In the server's GUI, open **Actions**, then **Show ID**, and copy the ID.
2. On your laptop's Syncthing GUI, click **Add Remote Device**, paste the server's ID, give it a name and click **Save**.
3. Within a minute the server's GUI shows a notice that the new device wants to connect. Click **Add Device** and **Save**.

Both sides then show each other as **Connected**. By default devices find each other through global discovery. Because the server has a fixed address, you can also edit the server device on your laptop and set **Addresses** to `tcp://203.0.113.10:22000, dynamic` so it connects directly even when discovery is unavailable.

## Step 7 — Share folders

Create a folder on the server that belongs to the `syncthing` user, so the service can write to it:

```bash
sudo -u syncthing mkdir -p /srv/syncthing/data/documents
```

Then share a folder from your laptop:

1. On your laptop, edit the folder you want to sync, open the **Sharing** tab, tick the server and click **Save**.
2. The server's GUI shows that your laptop wants to share the folder. Click **Add**, set **Folder Path** to `/srv/syncthing/data/documents` and click **Save**.

The folder goes from **Scanning** to **Up to Date** once the first sync finishes. Useful options in each folder's settings:

- **Folder Type**: `Send & Receive` (default), `Send Only`, `Receive Only`, or `Receive Encrypted` for untrusted devices.
- **File Versioning**: keeps old or deleted versions on the server (for example **Trash Can** or **Staggered**), which protects you against accidental deletes on another device.

> **Tip**
>
> If you do not want the server to see your files, share the folder with an encryption password on your trusted device and choose **Receive Encrypted** on the server. The server then stores only encrypted data. Syncthing marks this untrusted-device feature as beta.

## Step 8 — Exclude files with ignore patterns

Some files should never sync, such as editor caches or dependency folders. Syncthing reads ignore patterns from a `.stignore` file in the root of each synced folder; edit it in the GUI under the folder's **Ignore Patterns** tab. The file itself is never synced, so set it on each device. An example:

```text
// Lines starting with // are comments
(?d).DS_Store
(?d)Thumbs.db
*.tmp
/node_modules
```

The first matching pattern wins. `*` stays within one path segment while `**` crosses directories, a leading `/` anchors the pattern to the folder root, `!` re-includes a match, and `(?d)` lets Syncthing delete these files when they would otherwise block deleting a directory.

## Back up and restore

The synced files themselves are your data; back them up like any other data, because Syncthing replicates deletions. What makes this server **this** Syncthing device is its configuration folder:

- `config.xml`: devices, folders and settings,
- `cert.pem` and `key.pem`: the device key pair that defines the device ID (keep the private key private),
- `https-cert.pem` and `https-key.pem`: the GUI certificate,
- the index database: file metadata that Syncthing can rebuild by rescanning.

Confirm the paths on your system:

```bash
sudo -u syncthing -H syncthing paths
```

Stop the service briefly and archive the configuration folder without the rebuildable index:

```bash
sudo mkdir -p /opt/backups
sudo systemctl stop syncthing@syncthing.service
sudo tar --exclude='index-*' -czf /opt/backups/syncthing-config-$(date +%F).tar.gz -C /srv/syncthing/.local/state syncthing
sudo systemctl start syncthing@syncthing.service
```

To restore on a new server, repeat Steps 1 to 4, stop the service, unpack the archive and give the files back to the `syncthing` user. Because the keys are the same, the device ID is unchanged and your other devices reconnect without any changes:

```bash
sudo systemctl stop syncthing@syncthing.service
sudo tar -xzf /opt/backups/syncthing-config-2026-10-09.tar.gz -C /srv/syncthing/.local/state
sudo chown -R syncthing:syncthing /srv/syncthing
sudo systemctl start syncthing@syncthing.service
```

Copy the archive off the server; it contains the device's private key.

## Update Syncthing

With the apt package, updates come through apt. Syncthing's built-in automatic upgrade applies to the binaries downloaded from syncthing.net, not to packages. Read the [release notes](https://github.com/syncthing/syncthing/releases), then upgrade and restart the service so the new version runs:

```bash
sudo apt update
sudo apt upgrade
sudo systemctl restart syncthing@syncthing.service
syncthing version
```

A new major version (such as the move from 1.x to 2.x) can change the database format and command-line options; check the release notes for migration steps first.

## Troubleshooting

### The server shows as Disconnected

Both devices must have added each other, and port 22000 must be reachable. Check `sudo ufw status` on the server and any firewall in your provider's control panel, and check that the service runs with `sudo systemctl status syncthing@syncthing.service`. Setting the server address to `tcp://203.0.113.10:22000` on your other devices removes discovery as a possible cause.

### The connection type shows Relay

Syncthing uses public relays when two devices cannot connect directly. Relayed data stays end-to-end encrypted, but transfers are much slower and the relay operator sees your IP address and traffic volume. Open port 22000 for TCP and UDP and set the fixed server address as above; Syncthing switches to a direct connection as soon as one works.

### folder marker missing

Syncthing places a `.stfolder` marker in every synced folder and stops syncing a folder when the marker disappears, so a missing disk is not mistaken for deleted files. Make sure the folder path exists and is mounted. If the marker was removed by a cleanup tool, remove and re-add the folder at the same path (this resets its sync state).

### Permission denied on the folder path

The service runs as the `syncthing` user, so folders you created with `sudo` or as your admin user are not writable. Give them to the service user with `sudo chown -R syncthing:syncthing /srv/syncthing/data`.

### The filesystem watcher fails on large folders

Linux limits the number of inotify watches per user. The Syncthing FAQ raises the limit to 204800:

```bash
echo "fs.inotify.max_user_watches=204800" | sudo tee /etc/sysctl.d/90-inotify-max-user-watches.conf
sudo sysctl --system
sudo systemctl restart syncthing@syncthing.service
```

## Next steps

- Combine Syncthing with a sharing and collaboration platform such as [Nextcloud All-in-One](/guides/install-nextcloud-aio).
- Keep backups of synced data on [self-hosted S3 storage](/guides/self-hosted-s3-storage).
- Reach the server's private services through [a WireGuard VPN server](/guides/wireguard-vpn-server).
- See more apps you can run yourself on the [self-hosted apps](/self-hosted-apps) page.
- Read the [Syncthing documentation](https://docs.syncthing.net/) for advanced options.

## Frequently asked questions

### Is a Syncthing server a backup?

No. Syncthing keeps folders identical, so a deletion or an unwanted change on one device reaches every other device. Turn on file versioning on the server and keep separate backups of important data.

### Does the server need the web GUI port 8384 open?

No. The GUI listens on 127.0.0.1:8384 by default and you reach it through an SSH tunnel. Only the sync port 22000 over TCP and UDP needs to be open to the internet.

### Do I need port 21027 on a VPS?

No. UDP 21027 is used for local discovery broadcasts on a LAN. A server on the internet is found through global discovery or a fixed address such as tcp://203.0.113.10:22000.

### Can the server store my files without being able to read them?

Yes, with untrusted (encrypted) devices: you set a password when you share the folder and the server uses the Receive Encrypted folder type. Syncthing describes this feature as beta, so test it before relying on it.

### Which Syncthing version does this guide install?

The stable-v2 channel of the official apt repository, which carries the current 2.x releases. Syncthing 2 stores its index in SQLite and migrates an older database on the first start, which can take a while on large setups.

---

Source: <https://hyperdc.com/guides/tutorials/install-syncthing>\
Updated: 2026-10-09
