{"id":37149212,"url":"https://github.com/hbahadorzadeh/stunning","last_synced_at":"2026-06-11T23:00:40.218Z","repository":{"id":57631246,"uuid":"146158139","full_name":"hbahadorzadeh/stunning","owner":"hbahadorzadeh","description":null,"archived":false,"fork":false,"pushed_at":"2026-06-11T14:56:09.000Z","size":57113,"stargazers_count":5,"open_issues_count":1,"forks_count":2,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-11T16:21:37.810Z","etag":null,"topics":["golang","hacktoberfest","network","tunnel","vpn"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hbahadorzadeh.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2018-08-26T06:46:28.000Z","updated_at":"2026-06-11T14:42:56.000Z","dependencies_parsed_at":"2022-09-26T20:20:22.832Z","dependency_job_id":null,"html_url":"https://github.com/hbahadorzadeh/stunning","commit_stats":null,"previous_names":[],"tags_count":7,"template":false,"template_full_name":null,"purl":"pkg:github/hbahadorzadeh/stunning","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hbahadorzadeh%2Fstunning","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hbahadorzadeh%2Fstunning/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hbahadorzadeh%2Fstunning/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hbahadorzadeh%2Fstunning/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hbahadorzadeh","download_url":"https://codeload.github.com/hbahadorzadeh/stunning/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hbahadorzadeh%2Fstunning/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34221150,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-11T02:00:06.485Z","response_time":57,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["golang","hacktoberfest","network","tunnel","vpn"],"created_at":"2026-01-14T17:37:34.941Z","updated_at":"2026-06-11T23:00:40.202Z","avatar_url":"https://github.com/hbahadorzadeh.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"./stunning.png\" width=\"160\" alt=\"Stunning Logo\"/\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eStunning - Network Tunneling Engine\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eProduction-ready tunneling with 10 protocols, 4 interfaces, and real-time monitoring\u003c/strong\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/hbahadorzadeh/stunning/releases/tag/v1.1.0\"\u003e\u003cimg alt=\"Release\" src=\"https://img.shields.io/badge/release-v1.1.0-blue.svg\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/hbahadorzadeh/stunning/actions\"\u003e\u003cimg alt=\"Build Status\" src=\"https://img.shields.io/badge/build-passing-brightgreen.svg\"\u003e\u003c/a\u003e\n  \u003ca href=\"#license\"\u003e\u003cimg alt=\"License\" src=\"https://img.shields.io/badge/license-MIT-green.svg\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://golang.org\"\u003e\u003cimg alt=\"Go\" src=\"https://img.shields.io/badge/go-1.25-blue.svg\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"#features\"\u003e\u003cstrong\u003eFeatures\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#installation\"\u003e\u003cstrong\u003eInstallation\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#quick-start\"\u003e\u003cstrong\u003eQuick Start\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#cli-usage\"\u003e\u003cstrong\u003eCLI Usage\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#api-usage\"\u003e\u003cstrong\u003eAPI Usage\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#monitoring\"\u003e\u003cstrong\u003eMonitoring\u003c/strong\u003e\u003c/a\u003e •\n  \u003ca href=\"#platforms\"\u003e\u003cstrong\u003ePlatforms\u003c/strong\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## 🚀 Latest Release\n\n**v1.1.0** is now available! [Download](https://github.com/hbahadorzadeh/stunning/releases/tag/v1.1.0) CLI, desktop, mobile, and C-library builds for Linux, macOS, and Windows.\n\n- 🧩 Anti-DPI plugin chains + authentication \u0026 port-knock gates\n- ✅ Full test suite (unit, race, e2e, DPI evasion, auth) in CI\n- ✅ Multi-platform release pipeline\n\n---\n\n## Overview\n\n**Stunning** is a modern tunneling engine that securely forwards network traffic through various protocols and interfaces. It's a production-ready replacement for stunnel, providing flexible multi-protocol support with real-time metrics, process-based management, and comprehensive monitoring.\n\n### Use Cases\n\n- 🔒 Secure legacy service access with TLS/HTTPS\n- 📊 Load balancing and traffic routing\n- 🌐 Protocol translation and bridging\n- 🔐 VPN alternatives with custom protocols  \n- 📡 Private network tunneling\n- 🚀 Microservice gateway and mesh integration\n\n---\n\n## Features\n\n### 🔄 Tunnel Protocols (10 Types)\n\n| Protocol | Type | Use Case |\n|----------|------|----------|\n| **TCP** | Standard | Direct TCP forwarding |\n| **UDP** | Datagram | DNS, VoIP, gaming |\n| **UDPS** | Secure | Encrypted UDP tunneling |\n| **TLS** | Encrypted | Secure socket layer tunneling |\n| **HTTP** | Web | HTTP transparent proxy |\n| **HTTPS** | Web | HTTPS/SSL proxy |\n| **H2** | Modern | HTTP/2 multiplexed tunneling |\n| **WS** | WebSocket | WebSocket tunneling (HTTP upgrade) |\n| **DNS** | Query | DNS over custom protocol |\n| **ICMP** | Echo | Stealth tunneling via ICMP |\n\n### 🎯 Interface Types (4 Modes)\n\n- **TCP Socket** — Standard network socket\n- **SOCKS5 Proxy** — SOCKS5 protocol support\n- **TUN Device** — Virtual network interface for VPN\n- **Serial** — Serial port communication\n\n### 🧩 Plugin Chains (Anti-DPI)\n\nComposable, per-connection transforms that obfuscate, encrypt, compress, and\ndisguise tunnel traffic to defeat deep-packet-inspection firewalls. Compiled in\n(no `.so`, no CGO) and combinable in any order.\n\n| Plugin | Category | Purpose |\n|--------|----------|---------|\n| `flate` | size | DEFLATE compression |\n| `aead` | security | ChaCha20-Poly1305 / AES-GCM authenticated encryption |\n| `pad` | anti-DPI | random length padding |\n| `probe-guard` | active-probe | keyed tag; silently drops censor probes |\n| `tls-mimic` | mimicry | disguises the wire as TLS |\n| `http-mimic` | mimicry | disguises the wire as HTTP/1.1 chunked |\n| `jitter` | morphing | random per-frame timing delay |\n| `bucket` | morphing | normalize frame sizes to a fixed quantum |\n| `profile` | morphing | mimic a real protocol's size/timing distribution |\n| `chaff` | morphing | inject decoy/cover traffic to mask volume \u0026 timing |\n\nA high-entropy encrypted tunnel that a censor blocks passes cleanly once wrapped\nin `tls-mimic`. See [Plugin Chains](#plugin-chains) below, the full\n[plugin reference](docs/PLUGINS.md), and [benchmarks](docs/BENCHMARKS.md).\n\n### 🛠️ Management \u0026 Monitoring\n\n- **Process-based** — Each tunnel runs as independent background process\n- **Prometheus Metrics** — Real-time metrics in standard format\n- **HTTP API** — JSON metrics and health endpoints\n- **Uptime Tracking** — Connection count, bytes transferred, error rates\n- **Auto-restart** — Automatic tunnel recovery on failure\n\n### 📦 Multiple Distributions\n\n- **CLI Tool** — Command-line tunnel manager (Linux, macOS, Windows)\n- **Desktop App** — Cross-platform GUI (Linux, macOS, Windows)\n- **Mobile Apps** — iOS and Android VPN clients\n- **C Library** — Embed tunneling in other applications\n- **Go Library** — Use as Go package\n\n---\n\n## Installation\n\n### From Releases\n\nEach release publishes, per platform:\n\n- **CLI tool** — `stunning-cli-\u003cos\u003e-\u003carch\u003e` (linux/macos/windows, amd64/arm64)\n- **Desktop app** — `stunning-desktop-\u003cos\u003e-\u003carch\u003e.{tar.gz,zip}` (Fyne GUI)\n- **C library** — `libstunning-\u003cos\u003e-\u003carch\u003e.tar.gz` (shared lib + header)\n- **Mobile** — `stunning-android.apk`, `libstunning.aar`, `stunning-ios-xcframework.zip`\n- `SHA256SUMS.txt` for verification\n\n```bash\n# CLI — Linux (amd64)\nwget https://github.com/hbahadorzadeh/stunning/releases/latest/download/stunning-cli-linux-amd64\nchmod +x ./stunning-cli-linux-amd64\n./stunning-cli-linux-amd64 help\n\n# macOS (Apple Silicon)\nwget https://github.com/hbahadorzadeh/stunning/releases/latest/download/stunning-cli-darwin-arm64\nchmod +x ./stunning-cli-darwin-arm64\n\n# Windows (amd64): download stunning-cli-windows-amd64.exe\n```\n\n### C Library\n\nEach `libstunning-\u003cos\u003e-\u003carch\u003e.tar.gz` contains the shared library and its header:\n\n```bash\n# Linux (amd64)\nwget https://github.com/hbahadorzadeh/stunning/releases/latest/download/libstunning-linux-amd64.tar.gz\ntar -xzf libstunning-linux-amd64.tar.gz\n# -\u003e libstunning-linux-amd64/{libstunning.so, libstunning.h}\n\n# Compile against it\ngcc -o myapp myapp.c -I./libstunning-linux-amd64 -L./libstunning-linux-amd64 -lstunning\n```\n\n### From Source\n\n```bash\ngit clone https://github.com/hbahadorzadeh/stunning.git\ncd stunning\ngo build -o ./stunning .\n./stunning help\n```\n\n### Desktop App\n\n```bash\n# Install Fyne first\ngo install fyne.io/fyne/v2/cmd/fyne@latest\n\n# Linux\ngo build -o ./Stunning ./app/desktop/\n\n# macOS\nfyne package -os darwin -appID io.github.hbahadorzadeh.stunning \\\n  -name Stunning -icon app/desktop/assets/icon.png \\\n  -sourceDir ./app/desktop\n```\n\n### As Go Library\n\n```bash\ngo get github.com/hbahadorzadeh/stunning\n```\n\n---\n\n## Quick Start\n\n### 1. Create Configuration\n\nCreate `tunnels.json`:\n\n```json\n{\n  \"secure-web\": {\n    \"ServiceMode\": \"server\",\n    \"ServerType\": \"tls\",\n    \"InterfaceType\": \"tcp\",\n    \"Listen\": \"127.0.0.1:443\",\n    \"Connect\": \"example.com:443\",\n    \"Cert\": \"/path/to/cert.pem\",\n    \"Key\": \"/path/to/key.pem\"\n  },\n  \n  \"http-proxy\": {\n    \"ServiceMode\": \"server\",\n    \"ServerType\": \"http\",\n    \"InterfaceType\": \"socks\",\n    \"Listen\": \"127.0.0.1:8080\",\n    \"Connect\": \"upstream-proxy.local:3128\"\n  }\n}\n```\n\n### 2. Start Tunnel\n\n```bash\n# Start in background\n./stunning start secure-web\n\n# Or run in foreground (debugging)\n./stunning fg secure-web\n```\n\n### 3. Check Status\n\n```bash\n./stunning status\n```\n\nOutput:\n```\n╔════════════════════════════════════════════════════════════════════════════════╗\n║                         Tunnel Status                                          ║\n╠════════════════════════════════════════════════════════════════════════════════╣\n║ Name                 │ Status     │ Listen                    │ PID             │\n╠════════════════════════════════════════════════════════════════════════════════╣\n║ secure-web           │ ✓ Running  │ 127.0.0.1:443             │ 12345           │\n║ http-proxy           │ ✗ Stopped  │ 127.0.0.1:8080            │ -               │\n╚════════════════════════════════════════════════════════════════════════════════╝\n\nMetrics available at: http://localhost:9090/metrics\n```\n\n---\n\n## Plugin Chains\n\nPlugin chains transform tunnel payloads to evade deep-packet inspection (DPI) and\nto add security or size optimization. Plugins are stateful per connection,\ncompiled into the binary (no `.so`, no CGO — works on every platform), and\ncombine in any order.\n\n### Enabling a chain\n\nAdd a `Plugins` field to a tunnel config. **The same chain string must be set on\nboth the client and the server** — the client's encode is the exact inverse of\nthe server's decode.\n\n```json\n{\n  \"secure-tunnel\": {\n    \"ServiceMode\": \"client\",\n    \"ServerType\": \"tcp\",\n    \"InterfaceType\": \"socks\",\n    \"Listen\": \"127.0.0.1:1080\",\n    \"Connect\": \"vps.example.com:8443\",\n    \"Plugins\": \"flate,aead?key=0123456789abcdef0123456789abcdef,tls-mimic\"\n  }\n}\n```\n\n### Chain grammar\n\n```\nname?k=v\u0026k2=v2,name2,name3?k=v\n```\n\nComma-separated plugins, each with optional `?`-prefixed `\u0026`-joined params.\n`Encode` runs left→right on the way out; the peer's `Decode` runs right→left.\n\n### Available plugins\n\n| Plugin | Category | Params | Purpose |\n|--------|----------|--------|---------|\n| `flate` | size | `level` (0–9) | DEFLATE compression |\n| `aead` | security | `key` (hex, **required**), `algo` (`chacha`\\|`aesgcm`) | authenticated encryption, random nonce |\n| `pad` | anti-DPI | `min`, `max` | random length padding |\n| `probe-guard` | active-probe | `key` (hex, **required**), `taglen` (8–32) | keyed tag; drops unauthenticated probes |\n| `tls-mimic` | mimicry | — | disguise the wire as TLS |\n| `http-mimic` | mimicry | — | disguise the wire as HTTP/1.1 chunked |\n| `jitter` | morphing | `min`, `max` (durations) | random per-frame timing delay |\n| `bucket` | morphing | `size` | pad frames to a fixed size quantum |\n| `profile` | morphing | `name` (`web`\\|`video`\\|`voip`\\|`custom`), … | mimic a real protocol's size/timing distribution |\n| `chaff` | morphing | `min`, `max`, `interval`, `jitter` | inject decoy frames to mask volume/timing (place first) |\n\n### Ordering rules\n\n- **Compress before encrypt** — `flate` must come before `aead` (ciphertext does\n  not compress).\n- **Mimicry goes last** — `tls-mimic` / `http-mimic` provide the wire framing and\n  must be the rightmost plugin, or the length prefix would precede the protocol\n  header and break the disguise.\n\n### Recommended chains\n\n```text\n# fast, strong, looks like TLS\nflate,aead?key=\u003chex\u003e,tls-mimic\n\n# add size-fingerprint resistance, look like HTTP\nflate,aead?key=\u003chex\u003e,bucket?size=512,http-mimic\n\n# minimal obfuscation without crypto\nflate,pad?min=16\u0026max=256\n```\n\n### Why it beats DPI\n\nA passive entropy detector flags high-entropy unknown protocols — exactly what a\nnaive encrypted proxy looks like. Wrapping the chain in `tls-mimic` makes the wire\nopen with a convincing TLS handshake, so a protocol allowlist passes it while the\nbody stays encrypted. `probe-guard` drops active probes (no distinguishing\nresponse), and `pad` / `bucket` defeat packet-size fingerprinting.\n\nThe [`test/dpi/`](test/dpi/) harness demonstrates this end to end against a\nsimulated GFW middlebox. See the [plugin reference](docs/PLUGINS.md) and\n[benchmarks](docs/BENCHMARKS.md) for details.\n\n### Gates: authentication \u0026 port knocking\n\nBeyond the byte-transform chain, two **connection gates** control *who* may use a\ntunnel. Each has its own config field.\n\n**Authentication** (`Auth`) — a handshake that runs inside the chain framing (so\nit is disguised too) and rejects unauthorized clients:\n\n| Authenticator | Purpose |\n|---------------|---------|\n| `psk` | HMAC challenge-response with a shared key |\n| `jwt` | verify a presented JWT (HS256 secret / RS256 public key); identity = `sub` |\n| `mtls` | mutual-TLS client certificate; identity = cert Common Name |\n| `oauth` | validate an OAuth 2.0 token via RFC 7662 introspection |\n| `ldap` | verify username/password by an LDAP bind |\n\n```json\n\"Auth\": \"jwt?alg=HS256\u0026secret=\u003chex\u003e\"\n```\n\n**Port knocking** (`Knock`) — authorizes a source IP *before* it may connect, so a\nscanner sees nothing on the tunnel port:\n\n| Knocker | Purpose |\n|---------|---------|\n| `spa` | single encrypted UDP packet (HMAC + timestamp + nonce, anti-replay) authorizes the IP for a TTL |\n\n```json\n\"Knock\": \"spa?key=\u003chex\u003e\u0026port=62201\u0026ttl=10s\"\n```\n\nGates compose with the chain — a tunnel can require a knock, look like TLS,\nencrypt with `aead`, and authenticate clients by JWT all at once. Full reference:\n[docs/PLUGINS.md](docs/PLUGINS.md#gates).\n\n### Performance at a glance\n\nPlugins are cheap; the chain runs at hundreds of MB/s to multiple GB/s with ≤2\nallocations per frame on the crypto path (4 KiB frames, Apple M-series):\n\n| Plugin / chain | Throughput | allocs/op |\n|----------------|-----------:|----------:|\n| `aead` (AES-GCM, hardware) | ~1.9 GB/s | 2 |\n| `aead` (ChaCha20) | ~420 MB/s | 2 |\n| `profile` / `pad` (size shaping) | ~6 GB/s | 1–2 |\n| `flate` (compression — the heavy one) | ~110 MB/s | 13 |\n| `aead,tls-mimic` (framed, disguised) | ~250 MB/s | 5 |\n\nEnd-to-end through the simulated firewall, the payoff scenario: a high-entropy\n`aead` tunnel the censor **blocks** passes cleanly at **136 MB/s** once wrapped in\n`tls-mimic`. Gates (`auth`/`knock`) run once at setup, off the data path. Full\nmethodology, per-chain tables, and the optimization history are in\n[docs/BENCHMARKS.md](docs/BENCHMARKS.md).\n\n---\n\n## CLI Usage\n\n### Commands\n\n```bash\n# Start tunnel in background\n./stunning start \u003cname\u003e\n\n# Run tunnel in foreground (for debugging/testing)\n./stunning fg \u003cname\u003e\n\n# Stop a running tunnel\n./stunning stop \u003cname\u003e\n\n# Show status of all tunnels\n./stunning status\n\n# List all configured tunnels\n./stunning list\n\n# View Prometheus metrics\n./stunning metrics\n\n# Show help\n./stunning help\n```\n\n### Options\n\n```bash\n-config \u003cfile\u003e       Config file (default: tunnels.json)\n-metrics-port \u003cport\u003e Metrics HTTP port (default: 9090)\n```\n\n### Examples\n\n```bash\n# Start tunnel from custom config\n./stunning -config tunnels-prod.json start my-tunnel\n\n# Start on different metrics port\n./stunning -metrics-port 9091 start my-tunnel\n\n# Stop tunnel\n./stunning stop my-tunnel\n\n# View metrics directly\ncurl http://localhost:9090/metrics\n```\n\n---\n\n## API Usage (Go Library)\n\n### Create Tunnel Programmatically\n\n```go\npackage main\n\nimport (\n\t\"github.com/hbahadorzadeh/stunning/core\"\n)\n\nfunc main() {\n\tconfig := core.TunnelConfig{\n\t\tServiceMode:   \"server\",\n\t\tServerType:    \"tcp\",\n\t\tInterfaceType: \"tcp\",\n\t\tListen:        \"127.0.0.1:8080\",\n\t\tConnect:       \"127.0.0.1:9090\",\n\t}\n\n\t// Create tunnel\n\ttunnel := core.TunnelFactory(\"my-tunnel\", config)\n\n\t// Start tunnel (blocking)\n\tgo tunnel.ListenAndServer()\n\n\t// Check if alive\n\tif tunnel.IsAlive() {\n\t\tprintln(\"Tunnel is running\")\n\t}\n\n\t// Access metrics\n\tmetrics := tunnel.GetMetrics()\n\tprintln(\"Bytes sent:\", metrics.BytesSent.Load())\n\tprintln(\"Bytes received:\", metrics.BytesReceived.Load())\n}\n```\n\n### Get Metrics\n\n```go\n// Export Prometheus format\nprometheus := tunnel.GetMetrics().Export(\"my-tunnel\")\nprintln(prometheus)\n\n// Export JSON format\njson := tunnel.GetMetrics().ExportJSON(\"my-tunnel\")\nprintln(json)\n```\n\n---\n\n## Monitoring\n\n### Prometheus Metrics\n\nMetrics are automatically exported at `http://localhost:9090/metrics`:\n\n```prometheus\ntunnel_uptime_seconds{tunnel=\"my-tunnel\"} 3600\ntunnel_bytes_received_total{tunnel=\"my-tunnel\"} 1048576\ntunnel_bytes_sent_total{tunnel=\"my-tunnel\"} 2097152\ntunnel_connections_total{tunnel=\"my-tunnel\"} 125\ntunnel_connections_current{tunnel=\"my-tunnel\"} 3\ntunnel_errors_total{tunnel=\"my-tunnel\"} 2\n```\n\n### JSON API\n\nGet metrics as JSON:\n\n```bash\ncurl http://localhost:9090/api/metrics\n\ncurl http://localhost:9090/api/metrics/my-tunnel\n```\n\n### Health Check\n\n```bash\ncurl http://localhost:9090/health\n```\n\n### Prometheus Scraping\n\nAdd to Prometheus `prometheus.yml`:\n\n```yaml\nscrape_configs:\n  - job_name: 'stunning-tunnels'\n    static_configs:\n      - targets: ['localhost:9090']\n```\n\n---\n\n## Platforms\n\n\u003cp align=\"center\"\u003e\n\n| Platform | CLI | Desktop | Mobile | Library |\n|----------|:---:|:-------:|:------:|:-------:|\n| **Linux** | ✓ | ✓ | - | ✓ |\n| **macOS** | ✓ | ✓ | - | ✓ |\n| **Windows** | ✓ | ✓ | - | ✓ |\n| **iOS** | - | - | ✓ | ✓ |\n| **Android** | - | - | ✓ | ✓ |\n\n\u003c/p\u003e\n\n### Architecture Support\n\n- Linux: x86_64, ARM64\n- macOS: Intel, Apple Silicon (M1/M2/M3)\n- Windows: x86_64, ARM64 (CLI)\n- iOS: ARM64\n- Android: ARM64\n\n---\n\n## Configuration Guide\n\n### TLS/HTTPS Tunnel\n\nFor TLS or HTTPS protocols, provide certificate and key:\n\n```json\n{\n  \"my-tls\": {\n    \"ServiceMode\": \"server\",\n    \"ServerType\": \"tls\",\n    \"InterfaceType\": \"tcp\",\n    \"Listen\": \"0.0.0.0:443\",\n    \"Connect\": \"backend-server:8080\",\n    \"Cert\": \"/etc/certs/cert.pem\",\n    \"Key\": \"/etc/certs/key.pem\"\n  }\n}\n```\n\n### TUN Device Interface\n\nFor VPN-like functionality, use TUN interface:\n\n```json\n{\n  \"vpn\": {\n    \"ServiceMode\": \"server\",\n    \"ServerType\": \"tcp\",\n    \"InterfaceType\": \"tun\",\n    \"Listen\": \"10.0.0.1\",\n    \"Connect\": \"vpn-gateway.local\",\n    \"DeviceName\": \"tun0\",\n    \"Mtu\": \"1500\"\n  }\n}\n```\n\n### SOCKS Proxy Interface\n\nFor SOCKS5 proxy:\n\n```json\n{\n  \"socks-proxy\": {\n    \"ServiceMode\": \"server\",\n    \"ServerType\": \"tcp\",\n    \"InterfaceType\": \"socks\",\n    \"Listen\": \"127.0.0.1:1080\",\n    \"Connect\": \"upstream-proxy.local:3128\"\n  }\n}\n```\n\n---\n\n## Docker Build\n\nBuild for all platforms using Docker:\n\n```bash\n# Build everything\ndocker-compose run build-all\n\n# Run tests\ndocker-compose run test\n\n# Interactive shell\ndocker-compose run shell\n```\n\nSee [DOCKER.md](DOCKER.md) for detailed Docker guide.\n\n---\n\n## Project Structure\n\n```\n.\n├── core/                    # Core tunneling library\n│   ├── tunnel/             # 10 tunnel protocol implementations\n│   ├── interface/          # 4 interface implementations\n│   ├── plugin/             # Anti-DPI plugin chain system\n│   ├── common/             # Shared utilities\n│   └── metrics/            # Prometheus metrics system\n├── app/\n│   ├── desktop/            # Fyne desktop app\n│   └── mobile/             # iOS/Android mobile apps\n├── bindings/               # Mobile language bindings (gomobile)\n├── clib/                   # C shared library wrapper\n├── test/dpi/               # 3-node docker DPI evasion harness\n├── docs/                   # PLUGINS.md, BENCHMARKS.md, design specs\n├── main.go                 # CLI tool\n└── README.md              # This file\n```\n\n---\n\n## License\n\nMIT License - See [LICENSE](LICENSE) file\n\n---\n\n## Contributing\n\nContributions welcome! Please:\n\n1. Fork the repository\n2. Create a feature branch\n3. Make your changes\n4. Run tests: `go test -race ./...`\n5. Submit a pull request\n\n---\n\n## Support\n\n- 📧 Email: h.bahadorzadeh@gmail.com\n- 🐛 Issues: [GitHub Issues](https://github.com/hbahadorzadeh/stunning/issues)\n- 📖 Docs: Check project README and inline code comments\n\n---\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eMade with ❤️ in Go\u003c/strong\u003e\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhbahadorzadeh%2Fstunning","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhbahadorzadeh%2Fstunning","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhbahadorzadeh%2Fstunning/lists"}