Running on a server
Ports, public URLs and certificates for rooms hosted on your own machines.
A room is an ordinary Node process, so it runs anywhere Node runs: your own computer, a rented server, or a container. Start it directly, under a service manager such as systemd, or in Docker. If the process exits or crashes, its rooms end and disappear from the directory shortly after.
Running on a server mostly comes down to three things: letting players reach the room through your firewall, telling players the right address, and encryption, which the room handles for you.
Ports
Players connect to a room over WebTransport, a modern browser protocol that runs over UDP. So the server's firewall must allow incoming UDP traffic on the room's port.
Without
listen, a room binds0.0.0.0:4433. If that port is taken, it tries the next one, up to 4532, and fails withlisten_failedafter that. One firewall rule, UDP 4433–4532, covers up to 100 rooms.An explicit
listenport is used exactly. Port0picks a random free port.room.urlreports the port in use.
Public URL
Players need an address to connect to. Usually the room works it out by
itself: when listen is an unspecified address (0.0.0.0 or ::) and
publicUrl is omitted, the room advertises https://<ip>:<port>/room, using the address
disko observes for the host. It is re-read on every lease renewal.
Set publicUrl when the host is behind NAT or port forwarding, or has a
domain name:
Certificates
WebTransport connections are always encrypted, which needs a certificate. You
don't have to get one: without certificate, the room generates a self-signed ECDSA P-256
certificate valid for 13 days, as browsers require for WebTransport
certificate hashes, and rotates it every 6 days. Both hashes are advertised
during the overlap, so connecting players always get a valid one. No domain
or CA certificate is needed.
With certificate, the room uses your chain as PEM strings. Renew it by
restarting the room.
Secrets
The hosting token and the room password are options, not files: read them from your own secret store or environment. The token is never logged and is sent only to disko. Rotating the token in the Creator Portal disconnects the running host from the directory until it restarts with the new token.