TrustTunnel Server – secure, obfuscated VPN protocol
638
This is a pre-built Docker image of the TrustTunnel server – a modern VPN protocol that mimics HTTPS traffic (HTTP/2 and HTTP/3) to bypass deep packet inspection (DPI).
The image contains both the server binary (trusttunnel_endpoint) and the interactive setup wizard (setup_wizard), allowing you to easily configure and run your own VPN server.
docker pull ruslanakhatv/trusttunnel-server:latest
mkdir -p ~/trusttunnel-data
docker run --rm -it \
-v ~/trusttunnel-data:/etc/trusttunnel \
--entrypoint /usr/local/bin/setup_wizard \
ruslanakhatv/trusttunnel-server:latest
Follow the prompts to:
0.0.0.0:443)After completion, your configuration files (vpn.toml, hosts.toml, credentials.toml and certificates) will be saved in ~/trusttunnel-data.
docker run -d \
--name trusttunnel \
--restart unless-stopped \
-p 443:443/tcp \
-p 443:443/udp \
-v ~/trusttunnel-data:/etc/trusttunnel \
ruslanakhatv/trusttunnel-server:latest
For a user named admin and your server address (domain or IP), run:
docker exec trusttunnel trusttunnel_endpoint \
/etc/trusttunnel/vpn.toml \
/etc/trusttunnel/hosts.toml \
-c admin \
-a your-server.com:443
Output will be a tt://... link that you can open in the TrustTunnel mobile app or use with the CLI client.
Create a docker-compose.yml:
version: '3.8'
services:
trusttunnel:
image: ruslanakhatv/trusttunnel-server:latest
container_name: trusttunnel
restart: unless-stopped
ports:
- "443:443/tcp"
- "443:443/udp"
volumes:
- ./trusttunnel-data:/etc/trusttunnel
Then start:
docker-compose up -d
| Binary | Description |
|---|---|
trusttunnel_endpoint | The main server daemon. Also used to generate client configuration links. |
setup_wizard | Interactive configuration tool. Supports non-interactive mode for automation. |
All configuration files and certificates must be stored in a volume mounted to /etc/trusttunnel. The server expects at least:
vpn.tomlhosts.tomlcredentials.tomlIf you used the wizard, these files are created automatically.
For production, use Let's Encrypt certificates – they are automatically obtained during the wizard if you have a public domain and port 80 is accessible.
Self-signed certificates can be used for testing, but mobile clients may reject them.
To renew Let's Encrypt certificates later, you can either:
certbot and restart the container.The TrustTunnel project is open source. This Docker image is provided as-is. Please refer to the original project for license details.
Content type
Image
Digest
sha256:1c38a67cb…
Size
142.1 MB
Last updated
7 months ago
docker pull ruslanakhatv/trusttunnel-server