{"repo":"seb0ch/vpn","free":true,"listed":false,"github":"https://github.com/seb0ch/vpn","clone":"git clone https://github.com/seb0ch/vpn.git","description":"Self-hosted VPN stack: AmneziaWG (obfuscated WireGuard) + Xray REALITY (VLESS) + dnscrypt-proxy","language":"Shell","stars":16,"topics":["amnezia-vpn","amneziawg","docker","privacy","self-hosted","vless","vless-reality","xray","xray-core"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"English Русский VPN Stack For the paranoid sysadmin who doesn't trust pre-built binaries, considers \"just use a commercial VPN\" a personal insult, and won't sleep until every line of code has been read, every key has been generated on hardware they own, and every packet goes exactly where they said it goes. Everything here is built from source. No black boxes. Sleep tight :smile: Self-hosted VPN server combining AmneziaWG (obfuscated WireGuard) and Xray REALITY (VLESS proxy), with an internal dnscrypt-proxy resolver — all orchestrated via Docker Compose. Both VPN components ship enabled; either can be switched off per host (see Choosing components). Architecture Service Role Exposed Port Optional --------------- ---------------------------------------------------------- ------------------ ---------- DNS dnscrypt-proxy — encrypts and authenticates DNS queries 53 (Docker only) follows AmneziaWG AmneziaWG Obfuscated WireGuard VPN server random/udp ENABLE AMNEZIAWG=0 Xray VLESS + REALITY proxy 443/tcp ENABLE XRAY=0 All AmneziaWG clients are forced to use the internal DNS resolver via iptables DNAT — their DNS queries never leave the server uncontrolled. Xray clients resolve through the public servers configured in config.json , which is why dns is deployed only alongside AmneziaWG. Prerequisites - Ubuntu 24.04 or newer (tested on 24.04 and 26.04 ) - Root or sudo access - git (the build resolves component release tags with git ls-remote ) — install it first if the host lacks it ( ","default_branch":null,"files":null,"tree":[],"storefront":"/r/seb0ch","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/seb0ch/vpn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}