Skip to content

Remnawave Reverse-Proxy

Open Source · v3.7.2

Deploy
Remnawave
in one command.

An interactive bash script: the Remnawave panel, Xray node, subscription page and a hardened Nginx or Caddy reverse proxy — with a hidden control panel, SelfSteal and SSL on autopilot.

1install command
6install paths
13menu items
2web servers
$bash <(curl -Ls https://raw.githubusercontent.com/eGamesAPI/remnawave-reverse-proxy/refs/heads/main/install_remnawave.sh)
Ubuntu or Debian · as root · fresh install (KVM tested)
GitHub unreachable? Install from the jsDelivr mirror:
$bash <(curl -Ls https://cdn.jsdelivr.net/gh/eGamesAPI/remnawave-reverse-proxy@main/install_remnawave.sh)
root@vps — bash
Ubuntu 22.04+ · Debian 11+root

[ 01 ]Installation

Menu item 1 offers six paths: panel and node together, panel with the subscription page, adding a node to an existing panel, a standalone node, a standalone panel, a standalone subscription page.

[ 02 ]Modules

Everything above is in the main menu of the script. Two more modules arrive through it: server routing (bridges for Russian traffic) and SSH access to remote servers.

[ 03 ]Deployment

Single server

1 server · one web server

Panel, node and subscription page on one server: one A record and CNAMEs, everything behind one web server.

panel·node·subbehind one Nginx
RecordNamePoints to
Aexample.comyour_server_ip
CNAMEpanel.example.comexample.com
CNAMEsub.example.comexample.com
CNAMEautonode.example.comexample.com

Distributed

2+ servers · port 2222

The panel on one server, nodes on their own machines: each node gets its own A record, the panel reaches it on port 2222.

panel→nodevia port 2222
RecordNamePoints to
Aexample.companel_server_ip
CNAMEpanel.example.comexample.com
CNAMEsub.example.comexample.com
Aautonode.example.comnode_server_ip
All records stay in DNS only mode.The node A record is created by the script itself — via the Cloudflare, Gcore or Bunny.net API.

[ 04 ]A panel that is not there

Without the keys the panel does not answer: an outsider gets an empty page or a 404. It opens only at the secret link with the key pair that the script prints on the final screen of the installation.

Access method
https://panel.example.com/auth/login?zIdejKtN=MWbLrRzx
Secret link (default)
Login page (TinyAuth)
Portal with MFA (Caddy)
After the first login the browser gets a secret cookie — the key in the URL is no longer needed.
Brute force is useless: the key space is huge, and without the right parameter the panel stays silent.
Panel metrics listen on 127.0.0.1:3001 only.
404
not found
what they see:

Community

Questions, ideas and reports live in the Telegram chat. The project is open source: a star on GitHub helps it grow.

Telegram chatlive chat: questions, ideas and bug reportsStar on GitHubsource code, issues and releases
Copied