RallyTone Server setup
Run one RallyTone party on an always-on Linux host or NAS. The Docker image supports AMD64 and ARM64. Each instance hosts one party with a capacity of 2–12 participants, including the headless host.
Start a LAN party
On Linux, use host networking for automatic LAN discovery. In QNAP Container Station or Synology Container Manager, select Host network mode. This example starts an open, LAN-only party; the management page stays disabled.
docker volume create rallytone-server-config
docker run -d \
--name rallytone-server \
--network host \
--restart unless-stopped \
--read-only \
--cap-drop ALL \
--security-opt no-new-privileges:true \
--mount source=rallytone-server-config,target=/config \
bitinggoatsoft/rallytone-server:latestParty control, chat, and encrypted voice use UDP 15381. Normal Docker bridge networking does not provide automatic LAN discovery.
Join and verify the server
Join from Nearby on the same LAN, or choose Connect by IP in the desktop app and enter the server's IPv4 or IPv6 address. The default UDP port is 15381.
Before trusting the first IP connection, compare the identity code in the app with the Certificate fingerprint in the server startup output or management page. Obtain that code from the owner through a separate trusted channel. If the identity later changes, compare it again before accepting the replacement.
Keep the configuration volume to preserve /config/identity.json across container replacements. Back up this private-key file as a secret. Losing or replacing it changes the identity code and requires clients to confirm the server again.
Optional private management
Management is disabled until an administrator token is supplied. Mount a token file readable by the container user (65532), containing 16–256 UTF-8 bytes, and set RALLYTONE_ADMIN_TOKEN_FILE to its container path. The default RALLYTONE_ADMIN_BIND is 127.0.0.1:15382.
The management page uses plain HTTP on TCP 15382. Keep it on loopback or a trusted private network; do not publish or forward this port to the internet. For access from another trusted LAN device, bind to a private interface and restrict access, or use a restricted HTTPS reverse proxy.
Settings resolve from defaults, then environment variables, then saved management-page overrides. Resetting an override restores that field's environment/default value. Listener addresses and discovery startup settings require a server process restart. A party password set on the page is saved in the private /config/server.json file.
External IP connections
- Mount a unique party-password file with at least 15 characters and set
RALLYTONE_PARTY_PASSWORD_FILEto its container path. - Set
RALLYTONE_ALLOW_EXTERNAL_CONNECTIONS=1, or enable external access through the private management page. - Make UDP 15381 reachable, forwarding it manually when the server is behind a router. Keep TCP 15382 private.
- Share the server IP and identity code through separate trusted channels.
RallyTone provides no relay, hostname resolution, automatic router setup, or NAT traversal. Active party state and chat history end with the server process. Voice is relayed without being decoded, recorded, or saved.