Skip to content

Repository files navigation

Project Nahan (پروژه نهان)

The Ultimate Serverless Gateway on Cloudflare Workers

Nahan (Persian for Hidden/Concealed) is a secure, lightweight, and highly customizable reverse proxy that runs entirely on the edge. It transforms your Cloudflare Worker into a powerful, obfuscated gateway using VLESS or Trojan protocols, managed via a beautiful, self-contained Web UI.

Cloudflare WorkersLicenseJavaScript

🇮🇷 نسخه فارسی / Persian Version


📖 Table of Contents


🌟 Why Nahan?

Nahan isn't just a proxy script — it's a complete management solution designed for stealth, speed, and ease of use.

  • 🛡️ Hidden in Plain Sight: Unauthorized access attempts are proxied to legitimate sites (e.g., ubuntu.com or docker.com), making your gateway look like a regular website to network scanners.
  • Zero Server Cost: Runs entirely on Cloudflare's free plan. No VPS, no server maintenance.
  • 🎨 Modern Dashboard: A fully embedded, mobile-friendly dashboard with Dark/Light modes and dual-language support (English / فارسی).
  • 🤖 Telegram Bot Integration: Manage your gateway, check usage, and receive login alerts directly via Telegram.
  • 📡 Multi-User & Multi-IP: Generate dedicated subscription links for different users and automatically combine them with clean IP lists.
  • 💾 D1 SQLite Storage: Configuration persists in Cloudflare D1 database, eliminating KV write limitations.

✨ Key Features

FeatureDescription
🔐 Dual ProtocolSwitch instantly between VLESS (Alpha), Trojan (Beta), or Both simultaneously
📱 QR Code GenerationModal-based QR codes for instant mobile client configuration
👥 Multi-User ProfilesCreate separate profiles with unique subscription links, per-user nodes, and per-user NAT64
🌍 Clean IP MultiplexerInput a list of clean Cloudflare IPs — Nahan auto-generates configs for all of them
🌐 NAT64 SupportAutomatic IPv4-to-NAT64-mapped IPv6 conversion with multiple prefix support
⚙️ Real-Time MetricsView Origin IP, Edge Node location, and run browser-side latency diagnostics
💾 D1 SQLite StorageAll configuration persists in Cloudflare D1 even after code updates
🚨 Kill SwitchImmediately pause all proxy traffic with one click from the dashboard or Telegram
📊 Bandwidth ManagementTrack per-user upload/download with TB/GB limits and pause/resume controls
📋 Activity LogsFull history of login attempts and configuration changes
🔒 ECH SupportToggle Encrypted Client Hello (ECH) parameters in generated client configs
📦 Backup & RestoreExport/import your full configuration as a .json file
🔄 Auto UpdateAutomatic deployment of new versions from GitHub with format and obfuscation options
🎭 Configurable Fake ConfigsCustomizable fake subscription entries with {usage} and {expiry} template variables
🖥️ Per-User NodesDefine custom hostnames per subscriber for multi-region deployments
🏷️ Rich Name StrategyConfig naming with {FLAG}, {COUNTRY}, {CITY}, {ISP}, {HOST}, {DATE}, {WORKER} tags
🌐 Bilingual Subscription PageSubscription info page with full Persian/Farsi and English support, RTL layout, and dark/light mode toggle
🤖 Telegram Bot ManagementFull gateway management via inline Telegram buttons — users, settings, logs, and advanced config
🔗 Linked Panels (Other Nodes)Connect multiple Nahan panels securely with API Keys for cross-panel management and update propagation

🔧 Prerequisites

  • A Cloudflare account (free tier is sufficient) — sign up here
  • Access to Workers & Pages and D1 SQLite Database in your Cloudflare Dashboard
  • A modern web browser
  • (Optional) A Telegram Bot Token and Chat ID for bot integration

🚀 Quick Install Options

For easier deployment you can use:

Or follow the manual steps below.


🚀 Step-by-Step Deployment Guide

Step 1: Create a D1 Database

  1. Log in to the Cloudflare Dashboard.
  2. Go to Storage and databasesD1 SQLite Database.
  3. Click Create database.
  4. Enter a name (e.g. iot_db) and click Create.

Step 2: Deploy the Worker

  1. Go to Workers & PagesCreate applicationCreate Worker.
  2. Name it (e.g. nahan-core) and click Deploy.
  3. Click Edit code, delete the placeholder, and paste the full content of _worker.js.
  4. Click Save and Deploy.

Step 3: Bind the D1 Database

  1. Open your Worker → SettingsBindingsAdd binding.
  2. Type: D1 database
  3. Variable name: IOT_DB (must be exact)
  4. Select the database you created → SaveDeploy.

Step 4: Access the Dashboard

Open:

https://<your-worker-domain>/sync/dash

Visiting / or /sync without /dash shows a camouflage page (Ubuntu/Docker). This is intentional.

Step 5: First-Time Configuration

  1. Login with the default master key: admin
  2. Immediately go to System tab and:
    • Change Master Key
    • Change API Route to a secret path (bookmark the new URL!)
    • Set or auto-generate Device UUID
  3. Click Update Config.

🖥️ Dashboard Guide

The dashboard includes these main sections:

TabPurpose
OverviewUser summary cards, traffic stats, and update banner
EndpointsConnection URIs, QR codes, and subscription links
MetricsLive usage, Origin IP, Edge Node (Colo), latency diagnostics
SystemCore settings (protocol, UUID, API Route, Master Key, ports, Auto-Update, Panel API Keys, Backup)
AdvancedClean IPs, Linked Panels, Multi-User, Telegram, Kill Switch, ECH, NAT64, etc.
LogsLogin attempts and configuration change history
ClientsVisual multi-user management
HelpBuilt-in help and FAQ

🔩 Advanced Configuration

Clean IP Multiplexer

In AdvancedClean IPs, enter one IP (or IP#Name) per line. The subscription will contain a separate config for each IP.

Recommended tools for finding Clean IPs:

Relay IP

Recommended bot: @nahanproxyipbot

Linked Panels (Other Nodes)

Connect external Nahan panels using URL + API Key for cross-panel management and update propagation.
(Legacy slaveNodes / Cascade fields are automatically migrated to linkedPanels.)

Multi-User Profiles

Format (one per line):

<uuid>:Username

Access: https://<worker>/sync/sub?sub=Username

Telegram Bot

  1. Create a bot via @BotFather
  2. Get Chat ID from @userinfobot
  3. Enter Token + Chat ID in Advanced tab and save

Commands: /status, /pause (Kill Switch)

Kill Switch

Toggle in Advanced (or send /pause via Telegram) to immediately stop all proxy traffic while keeping the worker alive.


🔗 Useful Resources

PurposeResource
Clean IP findersenpaiscanner · @itsZetaBot
Relay IP@nahanproxyipbot
Easy Install (Telegram)@itsyebekhebot
Web Installererpycode.github.io/nahan-installer

💾 Applying Configuration Changes

After changing anything in System or Advanced:

  1. Click Update Config at the bottom.
  2. Wait for “Syncing…” then the page reloads.

If you changed the API Route, the page redirects to the new path — bookmark it.


❓ FAQ & Troubleshooting

⚠️ IOT_DB namespace missing!
→ D1 binding is missing or the variable name is not exactly IOT_DB. Fix in Worker Settings → Bindings and redeploy.

Root URL shows Ubuntu/Docker
→ Expected behavior. Always use /sync/dash (or your custom API Route + /dash).

Forgot Master Key or API Route
→ Check values in the D1 Console (sys_config key).

Free plan limits
→ 100,000 requests/day. Monitor via Cloudflare Analytics integration in Advanced.


🤝 Contributing

  1. Fork the repository
  2. Create a branch
  3. Make your changes
  4. Open a Pull Request

📄 License

MIT License — see LICENSE


Made with ❤️ by the Open Source Community

⭐ Star this repo · 🐛 Report a bug · 🇮🇷 نسخه فارسی

About

A secure, lightweight, and customizable network gateway designed to run entirely on Cloudflare Workers

Resources

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages