{"id":51038894,"url":"https://github.com/ipmartnetwork/ipshadowt","last_synced_at":"2026-06-22T09:01:14.763Z","repository":{"id":360788008,"uuid":"1251711000","full_name":"iPmartNetwork/iPShadowT","owner":"iPmartNetwork","description":null,"archived":false,"fork":false,"pushed_at":"2026-06-05T22:30:53.000Z","size":651,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-06-06T00:13:56.774Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/iPmartNetwork.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-27T21:00:02.000Z","updated_at":"2026-06-05T22:30:56.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/iPmartNetwork/iPShadowT","commit_stats":null,"previous_names":["ipmartnetwork/ipshadowt"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/iPmartNetwork/iPShadowT","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iPmartNetwork%2FiPShadowT","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iPmartNetwork%2FiPShadowT/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iPmartNetwork%2FiPShadowT/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iPmartNetwork%2FiPShadowT/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/iPmartNetwork","download_url":"https://codeload.github.com/iPmartNetwork/iPShadowT/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iPmartNetwork%2FiPShadowT/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34641636,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-22T02:00:06.391Z","response_time":106,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-06-22T09:01:13.266Z","updated_at":"2026-06-22T09:01:14.721Z","avatar_url":"https://github.com/iPmartNetwork.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"img/iPst.svg\" alt=\"iPShadowT Logo\" width=\"300\"/\u003e\n\u003c/p\u003e\n\n\n\u003cp align=\"center\"\u003e\n  \u003cstrong\u003eAnti-DPI Multi-Transport Tunnel Engine\u003c/strong\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/blob/master/VERSION\"\u003e\u003cimg src=\"https://img.shields.io/badge/version-v2.2.3-blue?style=flat-square\" alt=\"Version\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/blob/master/LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/license-MIT-green?style=flat-square\" alt=\"License\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://go.dev/\"\u003e\u003cimg src=\"https://img.shields.io/badge/Go-1.25+-00ADD8?style=flat-square\u0026logo=go\u0026logoColor=white\" alt=\"Go\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/releases\"\u003e\u003cimg src=\"https://img.shields.io/badge/platform-linux%20%7C%20macos%20%7C%20windows%20%7C%20freebsd-lightgrey?style=flat-square\" alt=\"Platform\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/stargazers\"\u003e\u003cimg src=\"https://img.shields.io/github/stars/iPmartNetwork/iPShadowT?style=flat-square\" alt=\"Stars\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/network/members\"\u003e\u003cimg src=\"https://img.shields.io/github/forks/iPmartNetwork/iPShadowT?style=flat-square\" alt=\"Forks\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/issues\"\u003e\u003cimg src=\"https://img.shields.io/github/issues/iPmartNetwork/iPShadowT?style=flat-square\" alt=\"Issues\"/\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/iPmartNetwork/iPShadowT/commits/main\"\u003e\u003cimg src=\"https://img.shields.io/github/last-commit/iPmartNetwork/iPShadowT?style=flat-square\" alt=\"Last Commit\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"#-quick-start\"\u003eQuick Start\u003c/a\u003e •\n  \u003ca href=\"#-features\"\u003eFeatures\u003c/a\u003e •\n  \u003ca href=\"#-transports\"\u003eTransports\u003c/a\u003e •\n  \u003ca href=\"#-anti-dpi\"\u003eAnti-DPI\u003c/a\u003e •\n  \u003ca href=\"#-configuration\"\u003eConfiguration\u003c/a\u003e •\n  \u003ca href=\"CHANGELOG.md\"\u003eChangelog\u003c/a\u003e •\n  \u003ca href=\"README-FA.md\"\u003eفارسی\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## 📋 Overview\n\niPShadowT is a high-performance, self-contained tunnel engine designed to bypass deep packet inspection (DPI) and internet censorship. It combines 9 transport protocols, 15 stealth techniques, and intelligent auto-selection into a single Go binary with zero external dependencies.\n\nBuilt to survive even the most extreme filtering scenarios — including complete internet shutdowns where only DNS traffic is allowed.\n\n### 🆕 What's New in v2.2.3\n\n- 🐛 **Direct pool race fix** — safe shutdown when `mux.enabled = false` (CI `-race` clean)\n- ✅ **Recommended release** — use v2.2.3 instead of v2.2.2\n\n\u003cdetails\u003e\n\u003csummary\u003ePrevious: v2.2.2\u003c/summary\u003e\n\n### 🆕 What's New in v2.2.2\n\n- 🔗 **Direct mode aligned** — client and server both support `mux.enabled = false` (upload path works end-to-end)\n- 🛡️ **REALITY fixed** — authentication protocol works with uTLS 1.8\n- 🧰 **CLI tools** — `-validate` and `-doctor` for config checks\n- 🛑 **Graceful shutdown** — SIGTERM/SIGINT drains connections properly\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003ePrevious: v2.2.1\u003c/summary\u003e\n\n### 🆕 What's New in v2.2.1\n\n- 📤 **Upload speed fix** — TCP buffers, 256KB relay, `kernel_tuning` wired, `upload_boost` profile works\n- 🔧 **Port-independent** — tuning applies on any port automatically\n- 📦 **Manager script** — defaults to upload_boost for Iran clients\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003ePrevious: v2.2.0\u003c/summary\u003e\n\n### 🆕 What's New in v2.2.0\n\n- 🕵️ **SNI Spoofing** — Packet-level SNI manipulation (split/replace/double)\n- 🌐 **Domain Fronting** — Client-side, no server changes needed\n- 🔌 **FakeTCP Transport** — UDP over fake TCP (bypass UDP blocking)\n- 🔗 **Pipeline Architecture** — Chain transports for max stealth\n- 🛡️ **WireGuard Forward** — Use WireGuard client through tunnel (auto key generation)\n- 📈 **Upload Boost Profile** — Optimized for max upload speed\n- 💓 **Stability Engine** — Heartbeat, quality monitor, smart reconnect, DPI detection\n- ⚖️ **Quality-Aware LB** — Routes traffic to best-performing session\n- 🔧 **KCP Tuning** — Fine-grained UDP transport parameters\n\n\u003c/details\u003e\n\n---\n\n## ⚡ Quick Start\n\n```bash\n# Download\nwget https://github.com/iPmartNetwork/iPShadowT/releases/latest/download/ipshadowt-linux-amd64\nchmod +x ipshadowt-linux-amd64\n\n# Generate keys\n./ipshadowt-linux-amd64 --gen-reality-keys\n\n# Run server (abroad)\n./ipshadowt-linux-amd64 -c server.toml\n\n# Run client (Iran)\n./ipshadowt-linux-amd64 -c client.toml\n```\n\nOr use the one-line installer:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/iPmartNetwork/iPShadowT/master/deploy/ipshadowt-manager.sh -o ipshadowt-manager.sh \u0026\u0026 sudo bash ipshadowt-manager.sh\n```\n\n---\n\n## ✨ Features\n\n### 🚀 Core\n\n| Feature | Description |\n|---------|-------------|\n| 9 Transports | TCP, WebSocket, HTTP/2, gRPC, REALITY, ShadowTLS, QUIC, KCP, Reverse |\n| 15 Stealth Techniques | uTLS, Fragment, ECH, Shaping, Domain Fronting, DNS Tunnel, and more |\n| Traffic Obfuscation | 4 modes: HTTPS mimic, Video streaming, Random burst, Constant rate |\n| Multiplexing | Thousands of streams over a single connection (smux) |\n| Multi-Path + Failover | Automatic failover with priority/round-robin/latency strategies |\n| Encryption | XChaCha20-Poly1305 AEAD |\n| Plugin System | Extensible Transport, Auth, and Filter plugins |\n| Zero Dependencies | Single static binary, no external tools needed |\n\n### 🛡️ Anti-DPI\n\n| Technique | Purpose |\n|-----------|---------|\n| REALITY | Server shows real website to probes |\n| uTLS | Mimics Chrome/Firefox/Safari TLS fingerprint |\n| TLS Fragmentation | Splits ClientHello to hide SNI |\n| ECH | Encrypted Client Hello |\n| Traffic Shaping | Makes traffic look like normal browsing |\n| Domain Fronting | Hides real destination behind CDN |\n| DNS Tunnel | Last resort — works when only DNS is allowed |\n| Protocol Morphing | Disguises traffic as HTTP/2, TLS, DNS |\n| Decoy Traffic | Generates noise to mask patterns |\n| HalfDuplex | Separate upload/download channels |\n\n### 📡 Networking\n\n| Feature | Description |\n|---------|-------------|\n| Port Forwarding | TCP, UDP, SOCKS5, HTTP proxy |\n| Split Tunneling | Iran IPs go direct, rest through tunnel (200+ CIDRs) |\n| Load Balancer | 5 strategies (round-robin, least-conn, weighted, IP-hash, fastest) |\n| CDN Support | Cloudflare, Gcore, Arvan, custom |\n| DNS over HTTPS | Automatic DoH — prevents DNS poisoning \u0026 leaks |\n| TUN/TAP | Full system traffic capture (Layer 2 \u0026 3) |\n| Adaptive Pool | Auto-scaling connection pool with warmup |\n| Cluster Mode | Multi-server with geographic routing \u0026 state sync |\n| Config Sync | Encrypted config push/pull between nodes |\n\n### 🔧 Management\n\n| Feature | Description |\n|---------|-------------|\n| Real-time Dashboard | WebSocket-based with live traffic charts |\n| REST API | Full management API with CORS \u0026 API key auth |\n| User Management | Multi-user with traffic limits, expiry, enable/disable |\n| Subscription Links | V2RayNG/Clash compatible |\n| Prometheus Metrics | Grafana-ready monitoring with alert rules |\n| Rate Limiting | Per-user/IP bandwidth control |\n| Security Manager | IP blacklist/whitelist, brute-force protection, audit log |\n| ACME/Auto-Cert | Automatic TLS certificate management \u0026 renewal |\n| Auto-Update | Self-update from GitHub releases |\n| Backup/Restore | Automatic periodic backups (cron) |\n| Hot-Reload | Change config without restart |\n| Graceful Upgrade | Zero-downtime binary updates |\n\n### 🧠 Intelligence\n\n| Feature | Description |\n|---------|-------------|\n| DPI Detection | Automatically detects active DPI |\n| Auto Protocol Selection | Picks best transport for current conditions |\n| Smart Failover | Switches transport on degradation |\n| Speed Test | Built-in throughput measurement |\n\n---\n\n## 🔌 Transports\n\n| Transport | Port | DPI Resistance | CDN | Speed |\n|-----------|------|---------------|-----|-------|\n| `tcpmux` | Any | ⭐⭐ | ❌ | ⭐⭐⭐⭐⭐ |\n| `wsmux` | 443 | ⭐⭐⭐ | ✅ | ⭐⭐⭐⭐ |\n| `h2mux` | 443 | ⭐⭐⭐⭐ | ✅ | ⭐⭐⭐⭐ |\n| `grpc` | 443 | ⭐⭐⭐⭐ | ✅ | ⭐⭐⭐⭐ |\n| `reality` | 443 | ⭐⭐⭐⭐⭐ | ❌ | ⭐⭐⭐⭐ |\n| `shadowtls` | 443 | ⭐⭐⭐⭐ | ❌ | ⭐⭐⭐⭐ |\n| `quic` | 443 | ⭐⭐⭐ | ❌ | ⭐⭐⭐⭐⭐ |\n| `kcp` | Any | ⭐⭐⭐⭐⭐ | ❌ | ⭐⭐⭐⭐⭐ |\n| `reverse` | 443 | ⭐⭐⭐ | ❌ | ⭐⭐⭐⭐ |\n\n---\n\n## ⚙️ Configuration\n\n### Server (server.toml)\n\n```toml\nmode = \"server\"\ntransport = \"reality\"\nbind_addr = \"0.0.0.0:443\"\npassword = \"your-secret\"\n\n[reality]\nserver_name = \"www.google.com\"\nprivate_key = \"SERVER_PRIVATE_KEY\"\nshort_id = \"SHORT_ID\"\ndest = \"www.google.com:443\"\n\n[performance]\nnodelay = true\nkernel_tuning = true\nbuffer_profile = \"high_throughput\"\n```\n\n### Client (client.toml)\n\n```toml\nmode = \"client\"\ntransport = \"reality\"\nremote_addr = \"your-server.com:443\"\npassword = \"your-secret\"\n\n[reality]\nserver_name = \"www.google.com\"\npublic_key = \"SERVER_PUBLIC_KEY\"\nshort_id = \"SHORT_ID\"\n\n[anti_dpi]\nenabled = true\nutls_fingerprint = \"chrome\"\nfragment = true\n\n[[forwards]]\nname = \"socks5\"\ntype = \"socks5\"\nlisten = \"127.0.0.1:1080\"\n```\n\n---\n\n## 🏗️ Architecture\n\n```\n┌─────────────────────────────────────────────────────┐\n│                    iPShadowT v2.0                    │\n├─────────────────────────────────────────────────────┤\n│  Input: SOCKS5 / HTTP / TCP / UDP / TUN             │\n│  ↓                                                  │\n│  Split Tunnel (Iran direct, rest proxy)             │\n│  ↓                                                  │\n│  Multiplexer (smux - 1000s of streams)              │\n│  ↓                                                  │\n│  Encryption (XChaCha20-Poly1305 + Padding)          │\n│  ↓                                                  │\n│  Obfuscation (HTTPS mimic / Video / Burst)          │\n│  ↓                                                  │\n│  Anti-DPI (uTLS + Fragment + Shaping + ECH)         │\n│  ↓                                                  │\n│  Transport (REALITY / WS / H2 / gRPC / QUIC / ...) │\n│  ↓                                                  │\n│  Multi-Path + Auto-Failover (priority/latency)      │\n│  ↓                                                  │\n│  DNS-over-HTTPS (leak protection)                   │\n└─────────────────────────────────────────────────────┘\n\nServer Side:\n┌─────────────────────────────────────────────────────┐\n│  Security (IP check) → Rate Limit → Plugin Filters  │\n│  → Mux Session → Stream → Destination              │\n│  → Metrics + Health + Prometheus + Dashboard        │\n└─────────────────────────────────────────────────────┘\n```\n\n---\n\n## 📦 Build\n\n```bash\ngit clone https://github.com/iPmartNetwork/iPShadowT.git\ncd iPShadowT\ngo mod tidy\nmake build-linux        # Linux AMD64\nmake build-linux-arm    # Linux ARM64\nmake build-all          # All platforms\n```\n\n---\n\n## 🐳 Docker\n\n```bash\n# Build locally\ndocker build -t ipshadowt .\ndocker run -v ./config.toml:/etc/ipshadowt/config.toml -p 443:443 -p 443:443/udp ipshadowt\n\n# Or pull from GHCR\ndocker pull ghcr.io/ipmartnetwork/ipshadowt:2.2.3\ndocker run -v ./config.toml:/etc/ipshadowt/config.toml ghcr.io/ipmartnetwork/ipshadowt:2.2.3\n```\n\n### Monitoring Stack (Prometheus + Grafana)\n\n```bash\ncd deploy/\ndocker-compose -f docker-compose.monitoring.yml up -d\n# Grafana: http://localhost:3000 (admin/admin)\n# Prometheus: http://localhost:9090\n```\n\n---\n\n## 🖥️ Manager Script\n\nFull interactive management with a single command:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/iPmartNetwork/iPShadowT/master/deploy/ipshadowt-manager.sh -o ipshadowt-manager.sh \u0026\u0026 sudo bash ipshadowt-manager.sh\n```\n\nFeatures:\n- 🚀 One-click install (auto-download binary + prerequisites)\n- ⚙️ Interactive tunnel setup wizard (Iran/Foreign)\n- 🔀 Multi-Tunnel: one-to-many, many-to-one, one-to-one\n- ☁️ CDN mode setup (Cloudflare, Gcore, Arvan)\n- 🔒 TLS option for tcpmux transport\n- 🧪 Smart transport detection (TCP/UDP/TLS/H2 probing)\n- 🔑 REALITY key generation + auto-config\n- 📊 Multi-tunnel status with per-tunnel details\n- 🐕 Watchdog integration (systemd WatchdogSec)\n- 🔥 Automatic firewall + BBR + kernel tuning\n- 💾 Backup / Restore with auto-backup (cron)\n- 📡 Port forward manager (add/remove from menu)\n- 📤 Export client config (copy-paste ready)\n- 🔄 One-click update from GitHub\n- 🩺 Health check all tunnels\n\n---\n\n## 📁 Project Structure\n\n```\niPShadowT/\n├── core/              Standalone engine (SDK) + Failover\n├── cmd/ipshadowt/     CLI application\n├── internal/\n│   ├── acme/          Auto TLS certificate management\n│   ├── antidpi/       15 anti-DPI techniques + obfuscation\n│   ├── api/           REST API server\n│   ├── cdn/           CDN connector (Cloudflare, Gcore, Arvan)\n│   ├── client/        Client with DoH + obfuscation\n│   ├── cluster/       Multi-server cluster mode\n│   ├── config/        TOML configuration\n│   ├── configsync/    Encrypted config sync\n│   ├── crypto/        XChaCha20-Poly1305 encryption\n│   ├── dns/           DNS-over-HTTPS resolver\n│   ├── health/        Health check / watchdog\n│   ├── loadbalancer/  5-strategy load balancer\n│   ├── metrics/       Prometheus-compatible metrics\n│   ├── multipath/     Multi-path + bandwidth aggregation\n│   ├── mux/           Stream multiplexing (smux)\n│   ├── plugin/        Plugin system (Transport/Auth/Filter)\n│   ├── pool/          Adaptive connection pool\n│   ├── ratelimit/     Per-user rate limiting\n│   ├── security/      IP whitelist, audit, brute-force\n│   ├── server/        Server with security + metrics + plugins\n│   ├── smart/         DPI detection + auto-select\n│   ├── stealth/       Domain fronting, DNS tunnel, mimicry\n│   ├── subscription/  V2RayNG/Clash subscription links\n│   ├── transport/     9 transport protocols (incl. full QUIC)\n│   ├── tun/           TUN device + split tunneling\n│   ├── tunnel/        Port forwarding + SOCKS5\n│   ├── upgrade/       Graceful zero-downtime upgrade\n│   ├── users/         User management\n│   └── web/           Real-time dashboard (WebSocket)\n├── configs/           Example configurations\n├── deploy/            Systemd, scripts, Prometheus, Grafana\n└── examples/          SDK usage examples\n```\n\n---\n\n## 🔒 Security\n\n- XChaCha20-Poly1305 authenticated encryption\n- ECDH X25519 key exchange (REALITY)\n- HMAC-SHA256 authentication with replay protection\n- Certificate pinning support\n- IP whitelist/blacklist\n- Brute-force protection\n- Full audit logging\n\n---\n\n## 📄 License\n\n[MIT](LICENSE)\n\n---\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"img/iPst.png\" alt=\"iPShadowT\" width=\"150\"/\u003e\n  \u003cbr/\u003e\n  \u003csub\u003eMade with ❤️ by \u003ca href=\"https://github.com/iPmartNetwork\"\u003eiPmart Network\u003c/a\u003e (Ali Hassanzadeh)\u003c/sub\u003e\n  \u003cbr/\u003e\n  \u003csub\u003e© 2026 iPmart Network. All rights reserved.\u003c/sub\u003e\n\u003c/p\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fipmartnetwork%2Fipshadowt","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fipmartnetwork%2Fipshadowt","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fipmartnetwork%2Fipshadowt/lists"}