What keeps operators up

Concerns and considerations

A public relay with no policy becomes a spam sink within days. Disk fills, bandwidth bills climb, and you inherit content you never asked to host. These are the recurring pressures.

01

Spam and resource exhaustion

Valid signatures are cheap. Without write policy, rate limits, and size caps, strangers will fill your disk. Heavy REQ queries and subscription storms are the read side of the same problem.

02

Storage growth

Event databases grow with traffic and retention. Public relays can add gigabytes per month. LMDB map size, SQLite vacuum, and pruning of old or ephemeral events are operational, not optional.

03

Policy versus protocol

The protocol is censorship-resistant because users can leave. Your relay is still your house. Write plugins, allowlists, web of trust, and paid admission are how operators express policy without pretending to be a global moderator.

04

Legal and jurisdictional reality

Relays store cleartext events. Hosting country, operator country, and user country may all differ. Publish terms of service, a contact pubkey for abuse reports, and a retention story. Encrypting DMs (kinds 4 and 1059) does not remove every obligation.

05

The commons problem

Free public relays are a gift and an attractor for abuse. Paid relays (Lightning admission or subscription, advertised in NIP-11) align incentives. Personal and community relays do not need to be the world’s inbox.

06

Secrets and admin surfaces

NIP-86 management APIs, embedded admin panels, database URIs, and paid-relay keys must never face the public internet. Reverse-proxy TLS is mandatory; clients speak wss:// only.