Skip to content

Remnawave Reverse-Proxy

Open Source · v3.7.0

Deploy
Remnawave
in one command.

An interactive bash script: the Remnawave panel, Xray node, subscription page and a hardened Nginx or Caddy reverse proxy — with a hidden control panel, SelfSteal and SSL on autopilot.

1install command
6install paths
13menu items
2web servers
$bash <(curl -Ls https://raw.githubusercontent.com/eGamesAPI/remnawave-reverse-proxy/refs/heads/main/install_remnawave.sh)
Ubuntu or Debian · as root · fresh install (KVM tested)
GitHub unreachable? Install from the jsDelivr mirror:
$bash <(curl -Ls https://cdn.jsdelivr.net/gh/eGamesAPI/remnawave-reverse-proxy@main/install_remnawave.sh)
root@vps — bash
Ubuntu 22.04+ · Debian 11+root

[ 01 ]Installation

Menu item 1 offers six paths: panel and node together, panel with the subscription page, adding a node to an existing panel, a standalone node, a standalone panel, a standalone subscription page.

[ 02 ]Modules

Everything above is in the main menu of the script. Two more modules arrive through it: server routing (bridges for Russian traffic) and SSH access to remote servers.

menu 5Xray Checker

host health monitoring with metrics

menu 6legiz templates

custom camouflage site templates

menu 7WARP Native→

WireGuard interface via wgcf for chosen domains

menu 8Backup and Restore

copies of configs and data

menu 9IPv6

address management and connectivity checks

menu 10Certificates

Cloudflare, Gcore, Bunny.net DNS API, ACME, own certs

menu 11NetBird→

private network for the panel and nodes

menu 12Updates

script updates from the menu

Server routing→

Shadowsocks and VLESS bridges for Russian traffic

SSH access→

run commands on remote servers from the menu

[ 03 ]Deployment

Single server

1 server · one web server

Panel, node and subscription page on one server: one A record and CNAMEs, everything behind one web server.

panel·node·subbehind one Nginx
RecordNamePoints to
Aexample.comyour_server_ip
CNAMEpanel.example.comexample.com
CNAMEsub.example.comexample.com
CNAMEautonode.example.comexample.com

Distributed

2+ servers · port 2222

The panel on one server, nodes on their own machines: each node gets its own A record, the panel reaches it on port 2222.

panel→nodevia port 2222
RecordNamePoints to
Aexample.companel_server_ip
CNAMEpanel.example.comexample.com
CNAMEsub.example.comexample.com
Aautonode.example.comnode_server_ip
All records stay in DNS only mode.The node A record is created by the script itself — via the Cloudflare, Gcore or Bunny.net API.

[ 04 ]A panel that is not there

Without the keys the panel does not answer: an outsider gets an empty page or a 404. It opens only at the secret link with the key pair that the script prints on the final screen of the installation.

Access method
https://panel.example.com/auth/login?zIdejKtN=MWbLrRzx
Secret link (default)
Login page (TinyAuth)
Portal with MFA (Caddy)
After the first login the browser gets a secret cookie — the key in the URL is no longer needed.
Brute force is useless: the key space is huge, and without the right parameter the panel stays silent.
Panel metrics listen on 127.0.0.1:3001 only.
404
not found
what they see:

Community

Questions, ideas and reports live in the Telegram chat. The project is open source: a star on GitHub helps it grow.

Telegram chatlive chat: questions, ideas and bug reportsStar on GitHubsource code, issues and releases
Copied