Skip to content

Repository files navigation

⚑ Outless

Outless is a monolithic VLESS node and subscription manager. The backend is written in Go and built on top of sing-box: it runs VLESS REALITY inbounds, distributes clients across node groups, collects traffic, and serves subscriptions. The web UI is built with Nuxt 4 + shadcn-vue.


✨ Features

  • VLESS REALITY inbounds β€” create and manage server-side entry points directly from the UI.
  • Nodes & groups β€” add private or public VLESS nodes and organize them into groups with random selection limits.
  • Tokens & subscriptions β€” issue access tokens with traffic quotas, expiry dates, and group/inbound bindings.
  • Public sources β€” import third-party node lists by URL and auto-assign them to a group.
  • Traffic & statistics β€” collect and display per-token traffic in real time.
  • Multi-admin β€” manage administrators with JWT authentication and optional TOTP.
  • OpenWrt β€” ready-made init scripts and a guide for building an .ipk package.

πŸ› οΈ Tech Stack

  • Backend: Go 1.26, embedded sing-box runtime, SQLite (GORM), Huma/v2 OpenAPI, chi
  • Frontend: Nuxt 4, Vue 3, TypeScript, Tailwind CSS, shadcn-vue, TanStack Query, Zod
  • API: REST + Server-Sent Events (logs, connections, system metrics)
  • Build: Docker multi-stage, Air for Go hot-reload, pnpm

πŸš€ Quick Start

Requirements

  • Go 1.26+
  • Node.js 22+ and pnpm 9+
  • (optional) Docker

Clone & Build

git clone https://github.com/quonaro/outless.git
cd outless
# Build frontendcd frontend
pnpm install
pnpm generate
cd ..
# Build backend with REALITY server and uTLS support
CGO_ENABLED=0 go build -trimpath -tags "with_reality_server with_utls" \
-ldflags="-s -w" -o outless ./cmd/outless

Configuration

Edit config.yaml in the project root:

app:
http_port: 41220external_host: "your-server-ip-or-domain"log_level: infosingbox_log_level: warnjwt:
secret: "your-64-char-hex-secret-must-be-changed"# make sure to change thisdatabase: ./outless.db

Security: on first start a default user admin with password admin is created. Change it immediately after login.

Run

./outless server run

Open in your browser: http://localhost:41220


πŸ–₯️ CLI

The app uses the custom lota CLI engine. Available commands:

CommandDescription
./outless server runStart the HTTP server and sing-box runtime
./outless server statusCheck whether the server is running on the configured port
./outless admin reset-password <username> <password>Reset an administrator password
./outless config showShow current configuration (secrets hidden)
./outless config show trueShow current configuration including secrets
./outless config validateValidate configuration without starting the app
./outless db backupCreate a tar.gz backup of the database
./outless versionShow version

You can override the config path via environment variable:

OUTLESS_CONFIG=/etc/outless/config.yaml ./outless server run

βš™οΈ Configuration

Main parameters in config.yaml:

app:
shutdown_gracetime: 10s# graceful shutdown timeouthttp_port: 41220# web UI and API portexternal_host: ""# host used in subscription URLssingbox_log_level: warn # trace/debug/info/warn/error/fatal/paniclog_level: info # debug/info/warn/errordisable_docs: false # disable OpenAPI/Swagger UIpprof_enabled: false # enable Go profilingpprof_bind: "127.0.0.1:6060"jwt:
secret: ""# hex string, must be changedexpiry: 24h0m0sdatabase: /var/lib/outless/outless.db
  • external_host is used in subscription URLs when the inbound has no URLHost set.
  • The database is SQLite. For production, store the file under /var/lib/outless/.

🐳 Docker

# Build
docker build -t outless:latest .# Run with config and DB mounted
docker run -d \
--name outless \
-p 41220:41220 \
-v $(pwd)/config.yaml:/config.yaml \
-v $(pwd)/outless.db:/outless.db \
outless:latest server run

The Dockerfile builds a static frontend, compiles the Go binary, and packs everything into a scratch image. By default it runs server run.


πŸ“‘ OpenWrt

OpenWrt files are located in deploy/openwrt/:

  • files/outless.init β€” procd init script
  • files/outless.config β€” UCI config
  • Makefile β€” package Makefile for .ipk builds

Quick install using a prebuilt binary:

scp outless-linux-arm64 root@router:/usr/bin/outless
ssh root@router chmod +x /usr/bin/outless
scp deploy/openwrt/files/outless.init root@router:/etc/init.d/outless
scp deploy/openwrt/files/outless.config root@router:/etc/config/outless
ssh root@router chmod +x /etc/init.d/outless
# Configure
ssh root@router uci set outless.app.external_host='your-public-ip'
ssh root@router uci set outless.jwt.secret='your-64-char-hex-secret'
ssh root@router uci commit outless
# Start
ssh root@router /etc/init.d/outless enable
ssh root@router /etc/init.d/outless start

More details: deploy/openwrt/README.md.


πŸ—οΈ Architecture

cmd/outless/ # entry point, CLI commands, wiring
internal/
adapter/http/ # HTTP handlers, middleware, SSE
adapter/repository/ # SQLite repositories (GORM)
adapter/singbox/ # embedded sing-box runtime adapter
domain/ # entities, repositories (ports)
service/ # business logic: auth, subscription, traffic, cleanup...
utils/ # helper utilities
shared/
config/ # configuration loading and validation
crypto/ # cryptography
logging/ # logger
template/ # subscription templates
vless/ # VLESS URL parsing/building
frontend/ # Nuxt 4 SPA
web/ # embedded static assets (dist -> embed)
  • Clean Architecture: the domain layer does not depend on adapters.
  • Embedded sing-box: the runtime controls inbounds and routing directly, without an external sing-box config.
  • SSE streams: logs, connections, and system metrics are pushed to the UI via Server-Sent Events.

πŸ’» Development

Backend

For hot reload:

# Install air if you haven't already
go install github.com/cosmtrek/air@latest
air

Without Air:

CGO_ENABLED=0 go build -trimpath -tags "with_reality_server with_utls" \
-ldflags="-s -w" -o ./tmp/outless ./cmd/outless
./tmp/outless server run

Formatting and linting:

gofmt -w .
goimports -w .
golangci-lint run ./...

Frontend

cd frontend
pnpm install
pnpm dev # http://localhost:41221
pnpm typecheck
pnpm lint:all
pnpm format

When generating a static site, the frontend expects the API on the same host (/api). In dev mode, it proxies to http://localhost:41220.


πŸ” Security

  • JWT secret: make sure to change the default; config.Validate() will refuse to start with CHANGE_ME_IN_PRODUCTION.
  • Admin password: the first run creates admin/admin β€” change the password and enable TOTP.
  • TOTP: two-factor authentication is supported for admins.
  • REALITY: inbounds use X25519 key pairs and short_id.

πŸ“„ License

MIT


πŸ‘€ Author

Developed by quonaro.

About

πŸš€ Outless β€” VLESS proxy manager for link anonymization and user control. Hides real nodes behind your server, manages users by expiration/traffic, and organizes links into convenient groups.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages