Sign inSign up

ruslanakhatv/trusttunnel-server

By ruslanakhatv

•Updated 7 months ago

TrustTunnel Server – secure, obfuscated VPN protocol

Image
Networking
0

638

ruslanakhatv/trusttunnel-server repository overview

⁠TrustTunnel Server – secure, obfuscated VPN protocol

This is a pre-built Docker image of the TrustTunnel server – a modern VPN protocol that mimics HTTPS traffic (HTTP/2 and HTTP/3) to bypass deep packet inspection (DPI).

The image contains both the server binary (trusttunnel_endpoint) and the interactive setup wizard (setup_wizard), allowing you to easily configure and run your own VPN server.


⁠🚀 Quick start

⁠1. Pull the image
docker pull ruslanakhatv/trusttunnel-server:latest
⁠2. Create a directory for persistent configuration
mkdir -p ~/trusttunnel-data
⁠3. Run the setup wizard (interactive)
docker run --rm -it \
  -v ~/trusttunnel-data:/etc/trusttunnel \
  --entrypoint /usr/local/bin/setup_wizard \
  ruslanakhatv/trusttunnel-server:latest

Follow the prompts to:

  • Set listening address (e.g. 0.0.0.0:443)
  • Create users (username/password)
  • Choose certificate type (Let's Encrypt recommended for production, self-signed for testing)
  • Configure optional filtering rules

After completion, your configuration files (vpn.toml, hosts.toml, credentials.toml and certificates) will be saved in ~/trusttunnel-data.

⁠4. Start the server
docker run -d \
  --name trusttunnel \
  --restart unless-stopped \
  -p 443:443/tcp \
  -p 443:443/udp \
  -v ~/trusttunnel-data:/etc/trusttunnel \
  ruslanakhatv/trusttunnel-server:latest

For a user named admin and your server address (domain or IP), run:

docker exec trusttunnel trusttunnel_endpoint \
  /etc/trusttunnel/vpn.toml \
  /etc/trusttunnel/hosts.toml \
  -c admin \
  -a your-server.com:443

Output will be a tt://... link that you can open in the TrustTunnel mobile app or use with the CLI client.


⁠🧩 Using with Docker Compose

Create a docker-compose.yml:

version: '3.8'

services:
  trusttunnel:
    image: ruslanakhatv/trusttunnel-server:latest
    container_name: trusttunnel
    restart: unless-stopped
    ports:
      - "443:443/tcp"
      - "443:443/udp"
    volumes:
      - ./trusttunnel-data:/etc/trusttunnel

Then start:

docker-compose up -d

⁠🔧 Included binaries

BinaryDescription
trusttunnel_endpointThe main server daemon. Also used to generate client configuration links.
setup_wizardInteractive configuration tool. Supports non-interactive mode for automation.

⁠📁 Data persistence

All configuration files and certificates must be stored in a volume mounted to /etc/trusttunnel. The server expects at least:

  • vpn.toml
  • hosts.toml
  • credentials.toml

If you used the wizard, these files are created automatically.


⁠🔐 Certificate management

For production, use Let's Encrypt certificates – they are automatically obtained during the wizard if you have a public domain and port 80 is accessible.

Self-signed certificates can be used for testing, but mobile clients may reject them.

To renew Let's Encrypt certificates later, you can either:

  • Run the wizard again (it will reuse existing settings), or
  • Set up a cron job on the host to run certbot and restart the container.

⁠📚 Further reading


⁠📝 License

The TrustTunnel project is open source. This Docker image is provided as-is. Please refer to the original project for license details.

Tag summary

Content type

Image

Digest

sha256:1c38a67cb…

Size

142.1 MB

Last updated

7 months ago

docker pull ruslanakhatv/trusttunnel-server