#【Sing-box family bucket】
- 1. Update information
- 2. Project Features
- 3. Sing-box for VPS run script
- 4. Speedy installation without interaction
- 5. Json Argo Tunnel Get (Recommended)
- 6. Token Argo Tunnel scheme sets any port back to the origin to use CDN
- 7. Use Cloudflare API to automatically create Argo
- 8. Vmess /Vless scheme sets any port back to origin to use CDN
- 9. Docker and Docker compose installation
- 10. Nekobox set shadowTLS method
- 11. Main directory file and description
- 12. Comparison of the processing methods of self-signed certificates in different clients
- 13. Thanks to the following authors for their articles and projects
- 14. Thanks to the sponsors
- 15. Disclaimer
- 16. Open source certificate
2026.04.25 v1.3.10 Added native protocol, but client support is extremely limited, with Shadowrocket offering the best compatibility. For the sing-box core, you must use the -glibc or -musl version according to the requirements; refer to the official documentation for details: https://sing-box.sagernet.org/configuration/outbound/naive/; Added native protocol, but client support is extremely limited, with Shadowrocket offering the best compatibility. Support is the best. The sing-box kernel needs to use the -glibc or -musl version according to the instructions. For details, see the official instructions https://sing-box.sagernet.org/zh/configuration/outbound/naive/ 2026.04.11 v1.3.9 1. remove pre-install UFW blocking logic, fallback to iptables when inactive; 2. avoid unnecessary sing-box restart for CDN /bandwidth /port hopping changes; 3. reduce redundant single-use functions; 3. Clean up single-call functions and improve the readability of the structure
History update history (click to expand or collapse)
>2026.04.10 v1.3.8 1. Automatically detect UFW and switch rule management accordingly; 2. Merge the old -p (port change) functionality into -d (config editor), simplifying usage; 3. Remove the standalone -p /-P entry points entirely; 3. Completely remove the independent -p /-P entries > >2026.04.09 v1.3.7 1. Add support for enabling/disabling Hysteria2 port hopping and modifying port ranges after installation (sb -d); 2. Allow customization of Hysteria2 upload/download bandwidth without reinstalling; 3. Enhance client configuration with proper Hysteria2 bandwidth (up/down) and port hopping parameters; 1. Support enabling/disabling Hysteria2 after installation Port hopping, and the port range can be modified (sb -d); 2. Support customization of Hysteria2 uplink and downlink bandwidth, no need to reinstall; 3. Improve client configuration, supplement Hysteria2 upload/download rate and port hopping parameters > >2026.03.22 v1.3.6 1. Refactor: Support modification after installation (CDN, Reality SNI, node name, UUID/password, server IP); 2. Perf: Rewrite text() with bash nameref and pre-scanned TEXT_NEEDS_EVAL map to eliminate per-call grep subprocesses, significantly reducing repeated string-lookup overhead; 1. Refactoring: Support multiple modifications after installation (CDN, Reality SNI, node name, UUID/password, server IP); 2. Performance optimization: Rewrite the text() function with bash nameref and pre-scan TEXT_NEEDS_EVAL associative array, eliminate the grep sub-process generated by each call, and greatly reduce the string search overhead >>2026.03.14 v1.3.5 Performance: Optimize concurrent process execution to significantly accelerate script installation. Performance optimization: Optimize concurrent process execution to significantly accelerate script installation. > >2026.02.08 v1.3.4 Chore: upgrade SS encryption method to SS-2022 spec; The newly installed Shadowsocks protocol encryption method is changed from aes-128-gcm to 2022-blake3-aes-128-gcm > >2026.01.20 v1.3.3 1. Security: In v2rayN, add pinnedPeerCertSha256 for Hysteria2/Trojan to prevent MITM (replaces AllowInsecure); 2. Compatibility: Refactor SFM/SFI/SFA configs for sing-box v1.13.0+; 1. Security enhancement: v2rayN’s Hysteria2/Trojan Support pinnedPeerCertSha256 replacement to skip certificate verification and defend against MITM attacks; 2. Adaptation update: Reconstruct SFM/SFI/SFA configuration to support sing-box v1.13.0+ > >2025.12.11 v1.3.2 Argo tunnel creation via API. Suitable for users with large-scale deployments, one Token for all. Automatically completed: Create tunnel > DNS configuration > Origin settings. Thanks to [zmlu] for providing the method: https://raw.githubusercontent.com/zmlu/sba/main/tunnel.sh; Argo tunnel creation via API. Suitable for users with large-scale deployments, one Token for all. Autocomplete: Create Tunnel > DNS Configuration > Back-to-Origin Settings. Thanks to the enthusiastic netizen [zmlu] for providing the method: https://raw.githubusercontent.com/zmlu/sba/main/tunnel.sh > >2025.11.12 v1.3.1 1. Reality Configuration Update: In Reality configurations, the original multiplexing (multiplex) has been replaced with xtls-rprx-vision flow control, improving transmission efficiency, reducing latency, and enhancing security. The original configuration conversion script command remains fully compatible and unchanged — `bash <(curl -sSL https://raw.githubusercontent.com/fscarmen/tools/main/vision.sh)`; 2. Quick Install Mode: Added a one-click installation feature that auto-fills all parameters, simplifying the deployment process. Chinese users can use -l or -L; English users can use -k or -K. Case-insensitive support makes operations more flexible; 3. Custom Reality Key Support: In response to user feedback, you can now specify a custom Reality private key via --REALITY_PRIVATE=. The script will automatically compute the corresponding public key using the integrated API. If left blank, it generates a random private-public key pair in real-time; 4. Enhanced HTTP + Reality Support in Clash Clients: Added full compatibility for HTTP + Reality transport in Clash clients, improving connection stability and performance; 1. Reality configuration changes: In the Reality configuration, the original multiplexing (multiplex) is replaced with xtls-rprx-vision flow control, improving transmission efficiency, reducing latency and enhancing security. Original configuration conversion script command -`bash <(curl -sSL https://raw.githubusercontent.com/fscarmen/tools/main/vision.sh)`; 2. Extremely fast installation mode: Added one-click installation function, all parameters are automatically filled in, simplifying the deployment process. Chinese users use -l or -L, English users use -k or -K, both upper and lower case are supported, and the operation is more flexible; 3. Custom Reality key support: In response to user feedback, it is now supported to specify a custom Reality private key through --REALITY_PRIVATE=, and the script will call the relevant API to automatically calculate the corresponding public key. If left blank, random public and private keys will be generated in real time; 4. Enhanced support for HTTP + Reality in the Clash client: Complete compatibility with the HTTP + Reality transmission method in the Clash client is added, improving connection stability and performance. > >2025.11.10 v1.3.0 Replace multiplex with xtls-rprx-vision flow control in reality configuration. The original configuration conversion script: bash <(curl -sSL https://raw.githubusercontent.com/fscarmen/tools/main/vision.sh); Original configuration conversion script: bash <(curl -sSL https://raw.githubusercontent.com/fscarmen/tools/main/vision.sh) > >2025.11.05 v1.2.19 Enhance security by replacing certificate skipping with certificate fingerprint verification; > >2025.08.27 v1.2.18 Add support for AnyTLS URI in v2rayN v7.14.3+, including subscription integration; Support v2rayN v7.14.3+, add AnyTLS URI, and support use in subscription > >2025.04.25 v1.2.17 1. Added the ability to change CDNs online using [sb -d]; 2. Change GitHub proxy; 3. Optimize code; 1. Added the ability to change CDNs online using [sb -d]; 2. Change GitHub proxy; 3. Optimize code > >2025.04.06 v1.2.16 Use OpenRC on Alpine to replace systemctl (Python3-compatible version); Use OpenRC on Alpine system to replace the Python3-compatible systemctl implementation > >2025.04.05 v1.2.15 Supports output for clients such as Shadowrocket, Clash Mihomo, and Sing-box; > >2025.03.23 v1.2.14 Added support for the AnyTLS protocol. Thanks to [Betterdoitnow] for providing the configuration; > >2025.03.18 v1.2.13 Compatible with Sing-box 1.12.0-alpha.18+; 适配 Sing-box 1.12.0-alpha.18+ > >2025.01.31 v1.2.12 In order to prevent sing-box from upgrading to a certain version which may cause errors, add a mandatory version file; > >2025.01.28 v1.2.11 1. Add server-side time synchronization configuration; 2. Replace some CDNs; 3. Fix the bug of getting the latest version error when upgrading; > >2024.12.31 v1.2.10 Adapted v1.11.0-beta.17 to add port hopping for hysteria2 in sing-box client output; Adapted v1.11.0-beta.17, add port hopping for hysteria2 in sing-box client output; > >2024.12.29 v1.2.9 Refactored the chatGPT detection method based on lmc999's detection and unlocking script; Refactored the chatGPT detection method based on lmc999's detection and unlocking script; > >2024.12.10 v1.2.8 Thank you to the veteran player Fan Glider Fangliding for the technical guidance on Warp's routing! > >2024.12.10 v1.2.7 Compatible with Sing-box 1.11.0-beta.8+. Thanks to the PR from brother Maxrxf. I've already given up myself; > >2024.10.28 v1.2.6 1. Fixed the bug that clash subscription failed when [-n] re-fetches the subscription; 2. vmess + ws encryption changed from none to auto; 3. Replaced a CDN; CDN > >2024.08.06 v1.2.5 Add detection of TCP brutal. Sing-box will not use this module if not installed. > >2024.05.09 v1.2.4 Add hysteria2 port hopping. Supported Clients: ShadowRocket /NekoBox /Clash; Add hysteria2 jumping port, supported clients: ShadowRocket /NekoBox /Clash > >2024.05.06 v1.2.3 Automatically detects native IPv4 and IPv6 for warp-installed machines to minimize interference with warp ip; For installed warp machines, automatically detects native IPv4 and IPv6 to reduce interference with warp ip > >2024.05.03 v1.2.2 Complete 8 non-interactive installation modes, direct output results. Suitable for mass installation scenarios. You can put the commands in the favorites of the ssh software. Please refer to the README.md description for details. > >2024.04.16 v1.2.1 1. Fix the bug of dynamically adding and removing protocols; 2. CentOS 7 add EPEL to install nginx; 1. Fix the bug of dynamically adding and removing protocols; 2. CentOS 7 adds EPEL software repository to install Nginx > >2024.04.12 v1.2.0 1. Add Cloudflare Argo Tunnel, so that 10 protocols, including the transport mode of ws, no longer need to bring our own domain; 2. Cloudflare Argo Tunnel supports try, Json and Token methods. Use of [sb -t] online switching; 3. Cloudflare Argo Tunnel switch is [sb -a], and the Sing-box switch is changed from [sb -o] to [sb -s]; 4. If Json or Token Argo is used, the subscription address is the domain name; 5. For details: https://github.com/fscarmen/sing-box; 1. Add Cloudflare Argo Tunnel, so that 10 protocols including ws transmission method no longer need to bring their own domain names; 2. Cloudflare Argo Tunnel supports temporary, Json and Token methods, and supports the use of [sb -t] online switching; 3. The Cloudflare Argo Tunnel switch is [sb -a], and the Sing-box switch is changed from [sb -o] to [sb -s]; 4. If Json or Token is used to fix the domain name Argo, the subscription address will use this domain name; 5. Detailed reference: https://github.com/fscarmen/sing-box > >2024.04.01 sing-box + argo container version is newly launched, for details: https://github.com/fscarmen/sing-box; sing-box family bucket + argo container version is newly launched, for details: https://github.com/fscarmen/sing-box > >2024.03.27 v1.1.11 Add two non-interactive installation modes: 1. pass parameter; 2.kv file, for details: https://github.com/fscarmen/sing-box; > >2024.03.26 v1.1.10 Thanks to UUb for the official change of the compilation, dependencies jq, qrencode from apt installation to download the binary file, reduce the installation time of about 15 seconds, the implementation of the project's positioning of lightweight, as far as possible to install the least system dependencies; The installation is changed to downloading binary files, which shortens the installation time by about 15 seconds. It implements the lightweight positioning of the project and installs the least system dependencies as much as possible. > >2024.03.22 v1.1.9 1. In the Sing-box client, add the brutal field in the TCP protocol to make it effective; 2. Compatible with CentOS 7,8,9; 3. Remove default Github CDN; Github acceleration network > >2024.3.18 v1.1.8 Move nginx for subscription services to the systemd daemon, following sing-box startup and shutdown; Move nginx for subscription services to systemd daemon, following sing-box startup and shutdown; > >2024.3.13 v1.1.7 Subscription made optional, no nginx and qrcode installed if not needed; Online subscription made optional, no nginx and qrcode installed if not needed; > >2024.3.11 v1.1.6 1. Subscription api too many problems not working properly, instead put template-2 on Github; 2. Use native IP if it supports unlocking chatGPT, otherwise use warp chained proxy unlocking; > >2024.3.10 v1.1.5 1. To protect node data security, use fake information to fetch subscribe api; 2. Adaptive the above clients. http://\:\/\//; Adaptive or above client, http://\:\/\/ > >2024.3.4 v1.1.4 1. Support V2rayN /Nekobox /Clash /sing-box /Shadowrocket subscribe. http://\:\/\/\. Index of all subscribers: http://\:\/\/. Reinstall is required; 2. Adaptive the above clients. http://\:\/\/auto ; 1. Add V2rayN /Nekobox /Clash /sing-box /Shadowrocket subscription, http://\:\/\/\, index of all subscriptions: http://\:\/\/, need to be reinstalled; 2. Adaptive or above client, http://\:\/\/auto > >2024.2.16 v1.1.3 1. Support v2rayN V6.33 Tuic and Hysteria2 protocol URLs; 2. Add DNS module to adapt Sing-box V1.9.0-alpha.8; 3. Reconstruct the installation protocol, add delete protocols and protocol export module, each parameter is more refined. ( Reinstall is required ); 4. Remove obfs obfuscation from Hysteria2; 1. Support v2rayN V6.33 Tuic and Hysteria2 protocol URL; 2. Add DNS module to adapt to Sing-box V1.9.0-alpha.8; 3. Reconstruct the installation protocol, add deletion protocol and protocol output module, and make each parameter more precise (requires reinstallation); 4. Remove obfs confusion of Hysteria2 > >2023.12.25 v1.1.2 1. support Sing-box 1.8.0 latest Rule Set and Experimental; 2. api.openai.com routes to WARP IPv4, other openai websites routes to WARP IPv6; 3. Start port changes to 100; 1. support Sing-box 1.8.0 latest Rule Set and Experimental; 2. api.openai.com is offloaded to WARP IPv4, other openai websites are diverted to WARP IPv6; 3. Change the start port to 100 > >2023.11.21 v1.1.1 1. XTLS + REALITY remove flow: xtls-reality-vision to support multiplexing and TCP brutal (requires reinstallation); 2. Clash meta add multiplexing parameter. Add multiplexing parameters > >2023.11.17 v1.1.0 1. Add [ H2 + Reality ] and [ gRPC + Reality ]. Reinstall is required; 2. Use beta version instead of alpha; 3. Support TCP brutal and add the official install script; Supports TCP brutal and provides official installation scripts > >2023.11.15 v1.0.1 1. Support TCP brutal. Reinstall is required; 2. Use alpha verion instead of latest; 3. Change the default CDN to [ cn.azhz.eu.org ]; > >2023.10.29 v1.0 official version 1. Sing-box Family bucket v1.0; 2. After installing, add [sb] shortcut; 3. Output the configuration for Sing-box Client; > >2023.10.18 beta7 1. You can add and remove protocols at any time, need to reinstall script; 2. Adjusted the order of some protocols; 1. You can add and remove protocols at any time, need to reinstall script; 2. Adjusted the order of some protocols; > >2023.10.16 beta6 1. Support Alpine; 2. Add Sing-box PID, runtime, and memory usage to the menu; 3. Remove the option of using warp on returning to China; > >2023.10.10 beta5 1. Add the option of blocking on returning to China; 2. Add a number of quality cdn's that are collected online; > >2023.10.9 beta4 1. Add v2rayN client, ShadowTLS and Tuic based on sing-box kernel configuration file output; 2. Shadowsocks encryption from aes-256-gcm to aes-128-gcm; 3. Optimize the routing and dns of sing-box on the server side; 1. Add v2rayN client, ShadowTLS and Tuic based on sing-box Kernel configuration file output; 2. Shadowsocks encryption changed from aes-256-gcm to aes-128-gcm; 3. Optimize server-side sing-box routing and dns > >2023.10.6 beta3 1. Add vmess + ws /vless + ws + tls protocols; 2. Hysteria2 add obfuscated verification of obfs; 1. Add vmess + ws /vless + ws + tls protocol; 2. Hysteria2 add obfuscated verification of obfs; > >2023.10.3 beta2 1. Single-select, multi-select or select all the required protocols; 2. Support according to the order of selection, the definition of the corresponding protocol listen port number; > >2023.9.30 beta1 Sing-box one-click script for vps
*Deploy multiple protocols with one click, you can select single, multiple or all ShadowTLS v3 /XTLS Reality /Hysteria2 /Tuic V5 /ShadowSocks /Trojan /Vmess + ws /Vless + ws + tls /H2 Reality /gRPC Reality /AnyTLS /NaiveProxy, there is always one suitable for you *All protocols do not require domain names. Cloudflare Argo Tunnel intranet penetration is optional to support traditional websocket protocols. *Node information is output to V2rayN /Clash Verge /Little Rocket /Nekobox /Sing-box (SFI, SFA, SFM), the subscription automatically adapts to the client, and one subscription url can travel around the world *Custom port, suitable for nat chicks with limited open ports *Built-in warp chain proxy to unlock chatGPT *Intelligent judgment of operating systems: Ubuntu, Debian, CentOS, Alpine and Arch Linux, please be sure to choose LTS system *Supported hardware structure types: AMD and ARM, support IPv4 and IPv6 *Non-interactive fast arrangement mode: Complete the installation of 11 protocols with one press Enter
*first run
bash <(wget -qO-https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh)
*run again
sb
| Option 参数 | Remark Remark |
|---|---|
| -c | Chinese |
| -e | English |
| -l | Quick deploy (Chinese version) |
| -k | Quick deploy (English version) |
| -u | Uninstall |
| -n | Export Nodes list |
| -d | Change config |
| -s | Stop / Start the Sing-box service |
| -a | Stop / Start the Argo Tunnel service |
| -v | Sync Argo Xray to the newest |
| -b | Upgrade kernel, turn on BBR, change Linux system |
| -r | Add and remove protocols |
bash <(wget -qO-https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) -l
bash <(wget -qO-https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) -k
bash <(wget -qO-https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) -f config.conf
Use Origin Rule + Subscribe (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--VMESS_HOST_DOMAIN vmess.test.com \
--VLESS_HOST_DOMAIN vless.test.com \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--SUBSCRIBE=true \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Use Origin Rule, do not subscribe (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--VMESS_HOST_DOMAIN vmess.test.com \
--VLESS_HOST_DOMAIN vless.test.com \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Using Argo temporary tunnels + subscriptions (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--SUBSCRIBE=true \
--ARGO=true \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Use Argo temporary tunnels, do not subscribe (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--ARGO=true \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Using Argo Json tunnel + subscription (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--SUBSCRIBE=true \
--ARGO=true \
--ARGO_DOMAIN=sb.argo.com \
--ARGO_AUTH='{"AccountTag":"9cc9e3e4d8f29d2a02e297f14f20513a","TunnelSecret":"6AYfKBOoNlPiTAuWg64ZwujsNuERpWLm6pPJ2qpN8PM=","TunnelID":"1ac55430-f4dc-47d5-a850-bdce824c4101"}' \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Use Argo Json tunnel, do not subscribe (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--ARGO=true \
--ARGO_DOMAIN=sb.argo.com \
--ARGO_AUTH='{"AccountTag":"9cc9e3e4d8f29d2a02e297f14f20513a","TunnelSecret":"6AYfKBOoNlPiTAuWg64ZwujsNuERpWLm6pPJ2qpN8PM=","TunnelID":"1ac55430-f4dc-47d5-a850-bdce824c4101"}' \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Using Argo Token tunnel + subscription (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--SUBSCRIBE=true \
--ARGO=true \
--ARGO_DOMAIN=sb.argo.com \
--ARGO_AUTH='sudo cloudflared service install eyJhIjoiOWNjOWUzZTRkOGYyOWQyYTAyZTI5N2YxNGYyMDUxM2EiLCJ0IjoiOGNiZDA4ZjItNGM0MC00OGY1LTlmZDYtZjlmMWQ0YTcxMjUyIiwicyI6IllXWTFORGN4TW1ZdE5HTXdZUzAwT0RaakxUbGxNMkl0Wm1VMk5URTFOR0l4TkdKayJ9' \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
Create an Argo tunnel using the Cloudflare API, do not subscribe (click to expand or collapse)
bash <(wget -qO- https://raw.githubusercontent.com/fscarmen/sing-box/main/sing-box.sh) \
--LANGUAGE c \
--CHOOSE_PROTOCOLS a \
--START_PORT 8881 \
--PORT_NGINX 60000 \
--SERVER_IP 123.123.123.123 \
--CDN skk.moe \
--UUID_CONFIRM 20f7fca4-86e5-4ddf-9eed-24142073d197 \
--ARGO=true \
--ARGO_DOMAIN=sb.argo.com \
--ARGO_AUTH='gKyflo59sDb5bI_fNr2OWCDnpihMUBIbJ29YsrtS' \
--PORT_HOPPING_RANGE 50000:51000 \
--REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
--NODE_NAME_CONFIRM bucket
| Key Case insensitive(Case Insensitive) | Value |
|---|---|
| --LANGUAGE | c=Chinese; e=English |
| --CHOOSE_PROTOCOLS | Multiple selections are possible, such as bcdfk a=all b=XTLS + reality c=hysteria2 d=tuic e=ShadowTLS f=shadowsocks g=trojan h=vmess + ws i=vless + ws + tls j=H2 + reality k=gRPC + reality l=AnyTLS m=NaiveProxy |
| --START_PORT | 100 - 65520 |
| --PORT_NGINX | n=no subscription required, or 100 -65520 |
| --SERVER_IP | IPv4 or IPv6 address, no square brackets required |
| --CDN | Preferred IP or domain name, such as --CHOOSE_PROTOCOLS is required when it is [a,h,i] |
| --VMESS_HOST_DOMAIN | vmess sni domain name, such as --CHOOSE_PROTOCOLS is required when it is [a,h] |
| --VLESS_HOST_DOMAIN | vless sni domain name, such as --CHOOSE_PROTOCOLS is required when it is [a,i] |
| --UUID_CONFIRM | protocol uuid or password |
| --ARGO | Whether to use Argo Tunnel, if true, if you use Origin rules, you can ignore this Key |
| --ARGO_DOMAIN | Fixed Argo domain name, which is the domain name of the Json or Token tunnel |
| --ARGO_AUTH | Json, Token The contents of the tunnel, or the Cloudflare API key |
| --PORT_HOPPING_RANGE | hysteria2 Jump port range, such as 50000:51000 |
| --REALITY_PRIVATE | reality key |
| --NODE_NAME_CONFIRM | Node name |
Users can easily obtain it through the Cloudflare Json generation network: https://fscarmen.cloudflare.now.cc
If you want to do it manually, you can refer to, taking Debian as an example, the commands you need to use, Deron Cheng -CloudFlare Argo Tunnel trial
Detailed tutorial: Synology Suite: Cloudflare Tunnel intranet penetration Chinese tutorial supports DSM6 and 7
- Visit https://dash.cloudflare.com/profile/api-tokens
- API Token > Create Token > Create Custom Token
- Add the following permissions: -Account > Cloudflare One Connector: Cloudflared > Edit -Zone > DNS > Edit
- Account Resources > Includes > Required Accounts
- Regional Resources > Includes > Specific Region > Required Domain Name
For example IPv6: vmess [2a01:4f8:272:3ae6:100b:ee7a:ad2f:1]:10006

- Resolve domain names
- Set Origin rule
*Supports three Argo types of tunnels: temporary (no domain name required) /Json /Token
*Requires 20 continuously available ports, starting with START_PORT
Docker deployment (click to expand or collapse)
docker run -dit \
--pull always \
--name sing-box \
--network host \
-e START_PORT=8800 \
-e SERVER_IP=123.123.123.123 \
-e XTLS_REALITY=true \
-e HYSTERIA2=true \
-e TUIC=true \
-e SHADOWTLS=true \
-e SHADOWSOCKS=true \
-e TROJAN=true \
-e VMESS_WS=true \
-e VLESS_WS=true \
-e H2_REALITY=true \
-e GRPC_REALITY=true \
-e ANYTLS=true \
-e UUID=20f7fca4-86e5-4ddf-9eed-24142073d197 \
-e CDN=www.csgo.com \
-e NODE_NAME=sing-box \
-e ARGO_DOMAIN=sb.argo.com \
-e ARGO_AUTH='{"AccountTag":"9cc9e3e4d8f29d2a02e297f14f20513a","TunnelSecret":"6AYfKBOoNlPiTAuWg64ZwujsNuERpWLm6pPJ2qpN8PM=","TunnelID":"1ac55430-f4dc-47d5-a850-bdce824c4101"}' \
-e REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk \
fscarmen/sb
Docker Compose deployment (click to expand or collapse)
networks:
sing-box:
name: sing-box
services:
sing-box:
image: fscarmen/sb
pull_policy: always
container_name: sing-box
restart: always
network_mode: host
environment:
- START_PORT=8800
- SERVER_IP=123.123.123.123
- XTLS_REALITY=true
- HYSTERIA2=true
- TUIC=true
- SHADOWTLS=true
- SHADOWSOCKS=true
- TROJAN=true
- VMESS_WS=true
- VLESS_WS=true
- H2_REALITY=true
- GRPC_REALITY=true
- ANYTLS=true
- UUID=20f7fca4-86e5-4ddf-9eed-24142073d197
- CDN=www.csgo.com
- NODE_NAME=sing-box
- ARGO_DOMAIN=sb.argo.com
- ARGO_AUTH=eyJhIjoiOWNjOWUzZTRkOGYyOWQyYTAyZTI5N2YxNGYyMDUxM2EiLCJ0IjoiOGNiZDA4ZjItNGM0MC00OGY1LTlmZDYtZjlmMWQ0YTcxMjUyIiwicyI6IllXWTFORGN4TW1ZdE5HTXdZUzAwT0RaakxUbGxNMkl0Wm1VMk5URTFOR0l4TkdKayJ9
- REALITY_PRIVATE=UPO3FWlg6YDJbASYi7KIESibPec_K46edTvDPbqEYFk
| Function | Command |
|---|---|
| View node information | docker exec -it sing-box cat list |
| View container logs | docker logs -f sing-box |
| Update Sing-box version | docker exec -it sing-box bash init.sh -v |
| View container memory, CPU, network and other resource usage | docker stats sing-box |
| Pause the container | docker: docker stop sing-boxcompose: docker-compose stop |
| Stop and delete the container | docker: docker rm -f sing-boxcompose: docker-compose down |
| Delete image | docker rmi -f fscarmen/sb:latest |
| Parameter | Is it required | Description |
|---|---|---|
| -p /tcp | Yes | Host port range: TCP listening ports such as container sing-box and nginx |
| -p /udp | Yes | Host port range: UDP listening ports such as container sing-box and nginx |
| -e START_PORT | Yes | Start port, must be consistent with the start port of port mapping |
| -e SERVER_IP | Yes | Server public network IP |
| -e XTLS_REALITY | yes | true to enable XTLS + reality,If not needed, delete this parameter or fill in false |
| -e HYSTERIA2 | yes | true to enable Hysteria v2 protocol,If not needed, delete this parameter or fill in false |
| -e TUIC | yes | true to enable TUIC protocol,If not needed, delete this parameter or fill in false |
| -e SHADOWTLS | yes | true to enable ShadowTLS protocol,If not needed, delete this parameter or fill in false |
| -e SHADOWSOCKS | yes | true to enable ShadowSocks protocol,If not needed, delete this parameter or fill in false |
| -e TROJAN | yes | true to enable Trojan protocol,If not needed, delete this parameter or fill in false |
| -e VMESS_WS | yes | true to enable VMess over WebSocket protocol,If not needed, delete this parameter or fill in false |
| -e VLESS_WS | yes | true to enable VLess over WebSocket protocol,If not needed, delete this parameter or fill in false |
| -e H2_REALITY | yes | true to enable H2 over reality protocol,If not needed, delete this parameter or fill in false |
| -e GRPC_REALITY | yes | true to enable gRPC over reality protocol,If not needed, delete this parameter or fill in false |
| -e ANYTLS | yes | true to enable AnyTLS protocol,If not needed, delete this parameter or fill in false |
| -e UUID | no | If not specified, UUID will be randomly generated by default. |
| -e CDN | no | Preferred domain name, will be used if not specified skk.moe |
| -e NODE_NAME | no | Node name, if not specified it will be used sing-box |
| -e ARGO_DOMAIN | no | Argo Fixed tunnel domain name, only effective when used together with ARGO_DOMAIN |
| -e ARGO_AUTH | no | Argo Authentication information, which can be yes Json, Token or Cloudflare API, can be effective when used together with ARGO_DOMAIN. If not specified, a temporary tunnel will be used. |
- Copy the two Neko links output by the script into
- Set up chain proxy and enable it Right click -> Manually enter configuration -> Select type as "Chained Proxy".
After clicking "Select Configuration", give the node a name, select 1-tls-not-use and 2-ss-not-use, and press enter or double-click to use this server. Be sure to note that the order cannot be reversed, the logic is ShadowTLS -> ShadowSocks.
/etc/sing-box/ # Project main directory
|-- cert # Directory to store certificate files
| |-- cert.pem # SSL/TLS Security certificate file (used for most protocols)
| |-- cert_200.pem # SSL/TLS Security certificate file (specific for NaiveProxy protocol)
| `-- private.key # SSL/TLS Certificate private key information
|-- conf # sing-box server Configuration file directory
| |-- 00_log.json # Log configuration file
| |-- 01_outbounds.json # Server outbound configuration file
| |-- 02_endpoints.json # Configure endpoints and add warp account information configuration file
| |-- 03_route.json # Routing configuration file, chatGPT uses warp ipv6 chain proxy outbound
| |-- 04_experimental.json # Cache configuration file
| |-- 05_dns.json # DNS rules file
| |-- 06_ntp.json # Server time synchronization configuration file
| |-- 11_xtls-reality_inbounds.json # Reality vision Protocol configuration file
| |-- 12_hysteria2_inbounds.json # Hysteria2 Protocol configuration file
| |-- 13_tuic_inbounds.json # Tuic V5 Protocol configuration file # Hysteria2 Protocol configuration file
| |-- 14_ShadowTLS_inbounds.json # ShadowTLS Protocol configuration file # Tuic V5 Protocol configuration file
| |-- 15_shadowsocks_inbounds.json # Shadowsocks Protocol configuration file
| |-- 16_trojan_inbounds.json # Trojan Protocol configuration file
| |-- 17_vmess-ws_inbounds.json # vmess + ws Protocol configuration file
| |-- 18_vless-ws-tls_inbounds.json # vless + ws + tls Protocol configuration file
| |-- 19_h2-reality_inbounds.json # Reality http2 Protocol configuration file
| |-- 20_grpc-reality_inbounds.json # Reality gRPC Protocol configuration file
| |-- 21_anytls_inbounds.json # AnyTLS Protocol configuration file
| `-- 22_naive_inbounds.json # NaiveProxy Protocol configuration file
|-- logs
| `-- box.log # sing-box Run log file
|-- subscribe # sing-box server Configuration file directory
| |-- qr # Nekoray / V2rayN / Shadowrock Subscribe QR code
| |-- shadowrocket # Shadowrock Subscription file
| |-- proxies # Clash proxy provider Subscription file
| |-- clash # Clash Subscription file1
| |-- clash2 # Clash Subscription file2
| |-- sing-box-pc # SFM Subscription file1
| |-- sing-box-phone # SFI / SFA Subscription file1
| |-- sing-box2 # SFI / SFA / SFM Subscription file2
| |-- v2rayn # V2rayN Subscription file
| `-- neko # Nekoray Subscription file
|-- cache.db # sing-box Cache files
|-- nginx.conf # nginx configuration file for subscribing to services
|-- language # Store script language files, E is English, C is Chinese
|-- list # Node information list
|-- sing-box # sing-box main program
|-- cloudflared # Argo tunnel main program
|-- tunnel.json # Argo tunnel Json information file
|-- tunnel.yml # Argo tunnel Configuration file
|-- sb.sh # shortcut script file
|-- jq # Command line json processor binary
`-- qrencode # QR code-encoded binary file
| Client/Tool | Certificate verification method used | Whether the SNI must match the SAN | Whether to rely on the full certificate chain | Hash/fingerprint type used | SNI usage description |
|---|---|---|---|---|---|
| V2RayN | Standard X.509 certificate chain validation | Yes(must match) | ✔ Yes | Does not use fingerprints | Used for TLS Hostname validation (must match SAN) |
| NekoBox | Standard | ||||
| ShadowRocket | Do SHA-256 on certificate DER full content | ✖ No matching required | ✖ Does not rely on certificate chain | SHA-256(DER) | Only used for disguise, can be empty or any domain name |
| Clash Verge /Meta | Do SHA-256 on certificate DER full content | ✖ No matching required | ✖ Does not rely on certificate chain | SHA-256(DER) | Only used for disguise, can be empty or any domain name |
| Sing-box | Only verify SPKI public key (SPKI pin) | ✖ No matching required | ✖ Does not rely on certificate chain | SHA-256(SPKI Base64) | Only used for disguise, can be empty or any domain name |
-V2RayN and NekoBox must have SAN = SNI, otherwise "x509: cannot validate certificate because it doesn't contain IP SAN". -ShadowRocket, Clash, Sing-box, HY2, and TUIC do not require SAN at allbecause they use the fingerprint mechanism.
Comparison of X.509 self-signed certificate structure and content contained in different fingerprint methods
| Certificate fields/content | X.509 full certificate (TBSCert + Sig) | DER fingerprint (SHA-256(DER)) | Public key SPKI (Subject Public Key Info) |
|---|---|---|---|
| Version | ✔ Contains | ✔ Contains | ✖ Does Not Contain |
| Serial Number | ✔ | ✔ | ✖ |
| Issuer | ✔ | ✔ | ✖ |
| Validity (Not Before /Not After) | ✔ | ✔ | ✖ |
| Subject(CN) | ✔ | ✔ | ✖ |
| SAN (Subject Alternative Name) | ✔ | ✔ | ✖ |
| Extensions | ✔ | ✔ | ✖ |
| Public Key | ✔ | ✔ | ✔ |
| Public key algorithm (ECC/P256, etc.) | ✔ | ✔ | ✔ |
| EC curve parameters | ✔ | ✔ | ✔ |
| Signature Algorithm | ✔ | ✔ | ✖ |
| Signature Value | ✔ | ✔ | ✖ |
| Usage scenarios | V2RayN /NekoBox | ShadowRocket /Clash | Sing-box /Hysteria2 /TUIC |
-Complete verification of CA → Leaf certificate -Required: SNI = a DNS name in the SAN -SAN mismatch or missing is not allowed -Used for: V2RayN/NekoBox
-Compute SHA-256 on the certificate's whole DER (binary) content -Contains all fields (Version, Serial Number, Subject, SAN, Extensions, Public Key, Signature, etc.) -Any field changes → the fingerprint will change -Used for: ShadowRocket/Clash Mihomo
-Contains only Public Key SPKI (Subject Public Key Info) -Certificate re-issuance, change of Issuer, Subject, SAN will not change -More stable and suitable for self-signed certificates -Used for: Sing-box
Chika sing-box template: https://github.com/chika0801/sing-box-examples zmlu's Cloudflare Tunnel management script: https://raw.githubusercontent.com/zmlu/sba/main/tunnel.sh
The construction and release environment of this project is supported by Sharon Networks -focusing on Asia-Pacific's top return optimization routes, high bandwidth, low latency, direct connection to mainland China, and built-in powerful high-defense DDoS cleaning capabilities.
SharonNetworks helps your business take off!
*Asia-Pacific three network backhaul is optimized to connect directly to mainland China, downloading is as fast as flying *Ultra-large bandwidth + anti-attack cleaning service to ensure business security and stability *Multi-node coverage (Hong Kong, Singapore, Japan, Taiwan, South Korea) *High protection and high-speed network; Hong Kong/Japan/New CDN will be launched soon
Want to experience the same build environment? Welcome to visit Sharon’s official website or join the Telegram group to learn more and apply for sponsorship.
Experience the speed, stability and security of VPS.Town, an all-in-one cloud computing solution -designed to drive innovation in your business.
*Safe memory. Your trustworthy partner
*Rock-solid data center. sit back and relax
*This program is for learning and understanding only. It is for non-profit purposes. Please delete it within 24 hours after downloading. It may not be used for any commercial purposes. The text, data and pictures are copyrighted. If reproduced, the source must be indicated. *Use of this program must comply with the deployment disclaimer. The use of this program must comply with the laws and regulations of the country where the server is deployed, the country where it is located, and the country where the user is located. The program author is not responsible for any inappropriate behavior by the user.
*This project strictly complies with the GNU GPL v3 License LICENSE. *Any form of copying, distribution, modification or derivative use must completely retain the original copyright statement and license text, and be open source and released under the same license. Violation of this clause (such as closed source use, commercial exclusivity or non-open source modified version) will be regarded as plagiarism, and the author reserves the right to pursue legal liability. *Community contributions are encouraged, but please submit via Pull Request.