Skip to content

TutorialsSelf-hosted apps

How to run Syncthing on a Linux server as an always-on sync peer

Install Syncthing from its official apt repository, run it as a systemd service, reach the web GUI through an SSH tunnel and sync folders with your devices.

  • Beginner
  • 25 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Add the official Syncthing repository
  3. Step 2 — Install Syncthing
  4. Step 3 — Run Syncthing as a system service
  5. Step 4 — Open the sync port in the firewall
  6. Step 5 — Open the GUI through an SSH tunnel and set a password
  7. Step 6 — Connect your devices
  8. Step 7 — Share folders
  9. Step 8 — Exclude files with ignore patterns
  10. Back up and restore
  11. Update Syncthing
  12. Troubleshooting
  13. The server shows as Disconnected
  14. The connection type shows Relay
  15. folder marker missing
  16. Permission denied on the folder path
  17. The filesystem watcher fails on large folders
  18. Next steps

Syncthing is an open-source, continuous file synchronisation program. Devices connect to each other directly over encrypted connections, so there is no central cloud service holding your files. On its own, Syncthing only syncs while two devices are online at the same time. A Linux server that is always on fixes that: your laptop, desktop and phone each sync with the server whenever they are online, and the server passes the changes on.

This guide installs Syncthing from the project's official apt repository (the stable-v2 channel), runs it as a systemd service under a dedicated user, keeps the web GUI on 127.0.0.1 and reaches it through an SSH tunnel, opens only the sync ports in the firewall, and then shows how to add devices, share folders, write ignore patterns, back up the device keys, update and fix common connection problems.

Prerequisites

  • A server running Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12 or Debian 13. The official repository is not tied to a release codename, so the same steps apply to all four. They work on a HyperDC Linux VPS, VDS or dedicated server with root access.
  • A non-root user with sudo rights and SSH key login: see Secure a new Linux server and Set up SSH keys.
  • ufw enabled with SSH allowed (covered in the security guide).
  • Syncthing installed on at least one other device, such as your laptop, from the Syncthing website or your platform's package.
ResourceMinimum (official)Suggested starting point
CPUNot published1 vCPU
RAMNot published1 GB, more for folders with many files
DiskNot publishedThe size of your synced data, plus room for versions and the index database

The project does not publish minimum requirements. The right-hand column is a conservative starting point, not a benchmark. Hashing and indexing large folders is the main load, so the first scan takes the longest.

Step 1 — Add the official Syncthing repository

Ubuntu and Debian ship their own Syncthing packages, but they lag behind upstream. The Syncthing project runs its own apt repository. Download its signing key into /etc/apt/keyrings:

Bash
sudo apt update
sudo apt install curl
sudo mkdir -p /etc/apt/keyrings
sudo curl -L -o /etc/apt/keyrings/syncthing-archive-keyring.gpg https://syncthing.net/release-key.gpg

Add the stable-v2 channel, which receives stable releases (usually on the first Tuesday of the month). The project also pins its repository at priority 990 so that the distribution's older package never wins:

Bash
echo "deb [signed-by=/etc/apt/keyrings/syncthing-archive-keyring.gpg] https://apt.syncthing.net/ syncthing stable-v2" | sudo tee /etc/apt/sources.list.d/syncthing.list
printf "Package: *\nPin: origin apt.syncthing.net\nPin-Priority: 990\n" | sudo tee /etc/apt/preferences.d/syncthing.pref

A candidate channel with release candidates also exists; use it only on test machines.

Step 2 — Install Syncthing

Bash
sudo apt update
sudo apt install syncthing
apt-cache policy syncthing
syncthing version

apt-cache policy should show the installed version coming from https://apt.syncthing.net, and syncthing version prints a 2.x version. The package also installs the systemd unit files, so you do not need to copy them by hand.

Step 3 — Run Syncthing as a system service

Syncthing's documentation offers two systemd setups: a system service, [email protected], which starts at boot without anyone logged in and is meant for servers, and a user service for desktops. Use the system service, and give Syncthing its own unprivileged account instead of your admin user:

Bash
sudo useradd --system --create-home --home-dir /srv/syncthing --shell /usr/sbin/nologin syncthing
sudo systemctl enable --now [email protected]
sudo systemctl status [email protected] --no-pager
sudo ss -tulpn | grep syncthing

The service shows active (running). The ss output lists the GUI on 127.0.0.1:8384 only, and the sync protocol on port 22000 over both TCP and UDP (QUIC). On the first start Syncthing creates its configuration and the device keys in /srv/syncthing/.local/state/syncthing. Syncthing 2 no longer creates a default folder; you add folders yourself in Step 7.

Step 4 — Open the sync port in the firewall

Other devices connect to the server on port 22000. Open it for TCP and UDP, and nothing else:

Bash
sudo ufw allow 22000/tcp
sudo ufw allow 22000/udp
sudo ufw status verbose

Do not open 8384; the GUI stays private. The Syncthing package also ships ufw profiles (sudo ufw allow syncthing), but that profile additionally opens UDP 21027, which is only useful for discovery on a local network and serves no purpose on an internet server.

Step 5 — Open the GUI through an SSH tunnel and set a password

The GUI listens on 127.0.0.1:8384, so you reach it by forwarding a local port over SSH. Run this on your own computer, not on the server. Local port 9090 avoids a clash with a Syncthing GUI already running on your computer:

Bash
ssh -N -L 9090:127.0.0.1:8384 user@203.0.113.10

Leave the command running and open http://localhost:9090 in your browser. Windows 10 and later include the same ssh command.

Syncthing warns that no GUI password is set. Fix that right away, because anyone who can reach the GUI port on the server, including other local users, could otherwise control Syncthing:

  1. Open Actions (top right), then Settings.
  2. On the General tab, give the server a recognisable Device Name.
  3. On the GUI tab, set GUI Authentication User and a long GUI Authentication Password, then click Save.

Reload the page; Syncthing now asks for the user name and password. The SSH tunnel already encrypts the connection, so you do not need to enable HTTPS for the GUI.

Step 6 — Connect your devices

Each pair of devices must add each other's device ID before they connect. Device IDs are not secret: on their own they cannot be used to connect or read files.

  1. In the server's GUI, open Actions, then Show ID, and copy the ID.
  2. On your laptop's Syncthing GUI, click Add Remote Device, paste the server's ID, give it a name and click Save.
  3. Within a minute the server's GUI shows a notice that the new device wants to connect. Click Add Device and Save.

Both sides then show each other as Connected. By default devices find each other through global discovery. Because the server has a fixed address, you can also edit the server device on your laptop and set Addresses to tcp://203.0.113.10:22000, dynamic so it connects directly even when discovery is unavailable.

Step 7 — Share folders

Create a folder on the server that belongs to the syncthing user, so the service can write to it:

Bash
sudo -u syncthing mkdir -p /srv/syncthing/data/documents

Then share a folder from your laptop:

  1. On your laptop, edit the folder you want to sync, open the Sharing tab, tick the server and click Save.
  2. The server's GUI shows that your laptop wants to share the folder. Click Add, set Folder Path to /srv/syncthing/data/documents and click Save.

The folder goes from Scanning to Up to Date once the first sync finishes. Useful options in each folder's settings:

  • Folder Type: Send & Receive (default), Send Only, Receive Only, or Receive Encrypted for untrusted devices.
  • File Versioning: keeps old or deleted versions on the server (for example Trash Can or Staggered), which protects you against accidental deletes on another device.

Step 8 — Exclude files with ignore patterns

Some files should never sync, such as editor caches or dependency folders. Syncthing reads ignore patterns from a .stignore file in the root of each synced folder; edit it in the GUI under the folder's Ignore Patterns tab. The file itself is never synced, so set it on each device. An example:

Text
// Lines starting with // are comments
(?d).DS_Store
(?d)Thumbs.db
*.tmp
/node_modules

The first matching pattern wins. * stays within one path segment while ** crosses directories, a leading / anchors the pattern to the folder root, ! re-includes a match, and (?d) lets Syncthing delete these files when they would otherwise block deleting a directory.

Back up and restore

The synced files themselves are your data; back them up like any other data, because Syncthing replicates deletions. What makes this server this Syncthing device is its configuration folder:

  • config.xml: devices, folders and settings,
  • cert.pem and key.pem: the device key pair that defines the device ID (keep the private key private),
  • https-cert.pem and https-key.pem: the GUI certificate,
  • the index database: file metadata that Syncthing can rebuild by rescanning.

Confirm the paths on your system:

Bash
sudo -u syncthing -H syncthing paths

Stop the service briefly and archive the configuration folder without the rebuildable index:

Bash
sudo mkdir -p /opt/backups
sudo systemctl stop [email protected]
sudo tar --exclude='index-*' -czf /opt/backups/syncthing-config-$(date +%F).tar.gz -C /srv/syncthing/.local/state syncthing
sudo systemctl start [email protected]

To restore on a new server, repeat Steps 1 to 4, stop the service, unpack the archive and give the files back to the syncthing user. Because the keys are the same, the device ID is unchanged and your other devices reconnect without any changes:

Bash
sudo systemctl stop [email protected]
sudo tar -xzf /opt/backups/syncthing-config-2026-10-09.tar.gz -C /srv/syncthing/.local/state
sudo chown -R syncthing:syncthing /srv/syncthing
sudo systemctl start [email protected]

Copy the archive off the server; it contains the device's private key.

Update Syncthing

With the apt package, updates come through apt. Syncthing's built-in automatic upgrade applies to the binaries downloaded from syncthing.net, not to packages. Read the release notes, then upgrade and restart the service so the new version runs:

Bash
sudo apt update
sudo apt upgrade
sudo systemctl restart [email protected]
syncthing version

A new major version (such as the move from 1.x to 2.x) can change the database format and command-line options; check the release notes for migration steps first.

Troubleshooting

The server shows as Disconnected

Both devices must have added each other, and port 22000 must be reachable. Check sudo ufw status on the server and any firewall in your provider's control panel, and check that the service runs with sudo systemctl status [email protected]. Setting the server address to tcp://203.0.113.10:22000 on your other devices removes discovery as a possible cause.

The connection type shows Relay

Syncthing uses public relays when two devices cannot connect directly. Relayed data stays end-to-end encrypted, but transfers are much slower and the relay operator sees your IP address and traffic volume. Open port 22000 for TCP and UDP and set the fixed server address as above; Syncthing switches to a direct connection as soon as one works.

folder marker missing

Syncthing places a .stfolder marker in every synced folder and stops syncing a folder when the marker disappears, so a missing disk is not mistaken for deleted files. Make sure the folder path exists and is mounted. If the marker was removed by a cleanup tool, remove and re-add the folder at the same path (this resets its sync state).

Permission denied on the folder path

The service runs as the syncthing user, so folders you created with sudo or as your admin user are not writable. Give them to the service user with sudo chown -R syncthing:syncthing /srv/syncthing/data.

The filesystem watcher fails on large folders

Linux limits the number of inotify watches per user. The Syncthing FAQ raises the limit to 204800:

Bash
echo "fs.inotify.max_user_watches=204800" | sudo tee /etc/sysctl.d/90-inotify-max-user-watches.conf
sudo sysctl --system
sudo systemctl restart [email protected]

Next steps

Frequently asked questions

Is a Syncthing server a backup?

No. Syncthing keeps folders identical, so a deletion or an unwanted change on one device reaches every other device. Turn on file versioning on the server and keep separate backups of important data.

Does the server need the web GUI port 8384 open?

No. The GUI listens on 127.0.0.1:8384 by default and you reach it through an SSH tunnel. Only the sync port 22000 over TCP and UDP needs to be open to the internet.

Do I need port 21027 on a VPS?

No. UDP 21027 is used for local discovery broadcasts on a LAN. A server on the internet is found through global discovery or a fixed address such as tcp://203.0.113.10:22000.

Can the server store my files without being able to read them?

Yes, with untrusted (encrypted) devices: you set a password when you share the folder and the server uses the Receive Encrypted folder type. Syncthing describes this feature as beta, so test it before relying on it.

Which Syncthing version does this guide install?

The stable-v2 channel of the official apt repository, which carries the current 2.x releases. Syncthing 2 stores its index in SQLite and migrates an older database on the first start, which can take a while on large setups.

Sources

Generar contrasenya

Please confirm