Skip to content

About

Your own OpenFlux exit node on the free alwaysdata hosting in a single command

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

Alwaysdata OpenFlux

Your own OpenFlux exit node on free hosting in a single command. No VPS, no payment card.

Stars OpenFlux exit node cups.online carrier alwaysdata free plan License: MIT

🚀 Quick start  ·  📱 Clients  ·  ❓ FAQ  ·  💝 Support

⭐ If the project helped you, give it a star! It's free and really keeps it going.

A personal OpenFlux exit node on the free alwaysdata plan. The client and the node never connect to each other: they meet in cups.online rooms, and traffic exits to the internet from a French alwaysdata IP.

Warning

The alwaysdata free plan forbids proxies, so the account may get suspended at any time. Keep a fallback.

✨ Features

  • 💸 Free: runs on the alwaysdata free plan, no VPS to rent or maintain
  • 🚪 No inbound traffic: the node only dials out to the carrier, nobody connects to the server
  • 🔐 Encrypted: an authenticated OpenFlux session with AES-256-GCM, the key is generated on the server
  • ⚡ One command: from macOS, Linux or Windows over one SSH connection (the password is asked once), or right on the server
  • ✅ Verified download: the core is the one OpenFlux's own VDS installer pins, checked against its SHA-256
  • 🔁 Safe re-runs: re-running the install updates the core and the scripts, the key, rooms and link stay the same

🧭 How it works

flowchart LR
    C["📱 Client<br/>OpenFlux apps"] -- "HTTPS / WSS" --> R["cups.online<br/>rooms"]
    X["OpenFlux exit node<br/>started by start.sh"] -- "HTTPS / WSS" --> R
    X --> I["🌍 Internet<br/>French IP"]
Loading

The alwaysdata site runs start.sh as a User program. The script builds the node config from secrets.env (the session key and the room list) and starts the OpenFlux core as an l4 exit node. Both ends write the encrypted packets into the same rooms and read each other's.

The site itself only keeps the node running. alwaysdata wants a site's program to listen on the IP / PORT it assigns and stops a site that gets no requests, so start.sh answers every request there with an empty 204, remembers the address (host and path) those requests came to and requests it once a minute. If the node stops, the script starts it again.

🚀 Quick start

You need: an alwaysdata account and ssh on your computer (built into macOS, Linux and Windows 10/11).

1. Enable SSH in the alwaysdata panel: Remote access → SSH.

2. Run the installer from this folder (it also needs tar, built in as well):

# macOS / Linux
./install.sh <account>@ssh-<account>.alwaysdata.net
:: Windows 10/11
install.cmd <account>@ssh-<account>.alwaysdata.net

Or install right on the server, no need to download this repository. Log in with ssh <account>@ssh-<account>.alwaysdata.net and run:

mkdir -p ~/openflux && cd ~/openflux && curl -fsSLO "https://raw.githubusercontent.com/AppsGanin/alwaysdata-openflux/main/{start,setup}.sh" && bash setup.sh

Either way, start.sh and setup.sh end up in ~/openflux (so they don't clash with other scripts in your home folder), the OpenFlux core is installed, four cups.online rooms are opened and your link is printed:

OpenFlux node-v1.2.0 installed.
Site: User program, command /home/<account>/openflux/start.sh (restart the site after updates)
openflux://v1/…

3. Point the site at the node. In the panel: Web → Sites → edit <account>.alwaysdata.net:

Field Value
Type User program
Command /home/<account>/openflux/start.sh
Working directory /home/<account>/openflux

4. Wake the site: open https://<account>.alwaysdata.net in a browser once. alwaysdata starts a site on its first request, the node learns the site's address from it and from then on keeps the site awake. A blank page is the expected answer.

5. Import the openflux://… link into your client. Done 🎉

Tip

Lost the link? It is saved on the server:

ssh <account>@ssh-<account>.alwaysdata.net cat openflux/link.txt

📱 Clients

The link describes a multi-transport session, so the client needs session support.

Client Platform
OpenFluxAndroid Android
OpenFlux-Android Android
OpenFluxDesktop Windows, macOS, Linux
TestFlight beta iOS

Note

The link contains the session key. Share it only with people you'd give the node to: one node serves one client at a time.

🔄 Update

Re-run the install, then restart the site in the panel. That updates the core to the version OpenFlux's own VDS installer currently pins and the scripts to your local copies (or, with the server command, to the latest version on GitHub). The key and rooms are kept, the link stays the same.

Need a new key (e.g. the link leaked)? Delete ~/openflux/secrets.env on the server, re-run the install and restart the site. You get a new key, new rooms and a new link.

🗑️ Uninstall

Change the site type back in the panel (or delete the site), then:

ssh <account>@ssh-<account>.alwaysdata.net "rm -rf ~/openflux"

❓ FAQ

How fast is it?

Slow. cups.online is a shared code editor, not a tunnel: in testing the node gave about 35 KB/s with ~0.7 s latency. Fine for messengers, mail and text sites. Not for video.

The client stopped connecting and the log says a room closed

cups.online can close rooms. Open new ones and import the new link:

ssh <account>@ssh-<account>.alwaysdata.net "sed -i /^ROOMS=/d openflux/secrets.env && bash openflux/setup.sh"

Then restart the site. The key stays the same.

Can I add Mail.ru or Yandex as a backup carrier?

Yes. Create a document that anyone with the link can edit, add its link to ~/openflux/secrets.env on the server, re-run the install, restart the site and import the new link:

MAILRU_URL=https://cloud.mail.ru/public/…/…
YANDEX_URL=https://docs.yandex.ru/edit/d/…

The client then uses the Yandex document first, Mail.ru next and cups.online last, and switches over when one stops working. Yandex may ask the node for a captcha, which the OpenFlux apps pass for it.

Where are the node's logs?

In the site logs, ~/admin/logs/sites/ (an excerpt is in the panel under Logs). A working node logs Cups: зашли в 4 из 4 комнат (joined 4 of 4 rooms) and Running as EXIT NODE.

The site already runs something else (e.g. alwaysdata-xray)

One site runs one program, and the free plan has a single address, so give the node a path on it. Add a second site in Web → Sites with the address <account>.alwaysdata.net/openflux (the rest of the fields as in step 3) and open https://<account>.alwaysdata.net/openflux in step 4. Requests to /openflux… go to the node, all the others stay with the first site.

Why a site and not an alwaysdata service?

Services are only on the paid plans. On a paid plan a service is the cleaner home for the node.

Why not a VPS installer like OpenFlux's own?

OpenFlux's "Своя нода" wizard needs root and systemd and adds a direct TCP port as the backup carrier. alwaysdata gives neither root nor a raw TCP port, so this repository runs the same core as a plain user without direct.

Will the account stay alive?

Not guaranteed. Proxies are against the free plan's rules, and free accounts are also suspended if you don't log into the panel for 120 days.

Important

Log into the alwaysdata panel at least once every 120 days, otherwise the free account is suspended.

🖥️ Where to get a fallback server

alwaysdata can suspend the free account at any time. For something reliable, rent the cheapest VPS (1 vCPU, 1 GB RAM, any Linux) and deploy a node to it with the "Своя нода" wizard of the OpenFlux apps (it adds a fast direct carrier too), or run RosPanel on it: a self-hosted Xray panel from the same author, installed with one command.

If you haven't picked a host yet, sign up through the links below. It's a free way to support the project: the price is the same for you, and a share of the rent goes into development.

VDSina · Aeza · NetGrid · Serv.host · u1Host · Waicore

Thanks to everyone who signs up through them 🙏

💝 Support the project

The project is developed in spare time and distributed for free. If it turned out to be useful, the easiest way to support it is DonationAlerts or Boosty (RU cards, one-off or recurring). Thank you! 🙏

Crypto

USDT. Pick a network and copy the address carefully — the sender's and the receiver's network must match. Send USDT only, and only on the network listed: a transfer on the wrong network cannot be recovered. The cheapest fees are on TRON (TRC20) and TON.

Network Token Address
TRC20 (Tron) USDT TJwyrPVEZVZ1YrcmDiZTyFjLo3Q2DmEGzs
ERC20 (Ethereum) USDT 0xf9d663146ce902da91911b214c71cc73a5269d1d
Solana USDT 2qAZRTbaUMTfYuZbD1dCYHjkYgxkw4dUYE9XY3JhC2Cs
TON USDT UQDoat731MLYuIw8ayL3Vhhw7zTBbLvRaQFmDvab--CNNI7e

Bybit. If you're on Bybit too — transfer to UID 136462734: instant and free.

Can't support financially? Give the project a ⭐ star, or rent a server through the links in Where to get a fallback server. Both cost you nothing and help a lot. Found a bug or have an idea? Open an issue or a PR.

Star on GitHub

📄 License

MIT © 2026 Dmitry Ganin. OpenFlux itself, downloaded by setup.sh, is GPL-3.0.

About

Your own OpenFlux exit node on the free alwaysdata hosting in a single command

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages