this post was submitted on 16 Mar 2026
44 points (97.8% liked)

Selfhosted

60861 readers
621 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

Hi, i'm looking for a VPN that:

  • is easily deployable via a docker-compose
  • has an Android App and it doesn't drain the battery too much
  • hides as regular HTTPS traffic so it's not blockable by Firewalls. (I don't need strong censorship resistance; it just has to work in offices and hotel WiFis.)
  • Bonus: A server like caddy can also accept HTTPS traffic for some regular websites next to the VPN server.

https://github.com/TrustTunnel/TrustTunnel sounds interesting, but the PR for docker compose was closed.

Do you know something else?

you are viewing a single comment's thread
view the rest of the comments
[–] iopq@lemmy.world -1 points 4 months ago (3 children)

Doesn't work in China, can be easily blocked by censors

[–] spaghettiwestern@sh.itjust.works 7 points 4 months ago* (last edited 4 months ago) (1 children)

Who said anything about China?

OP: "I don’t need strong censorship resistance; it just has to work in offices and hotel WiFis."

[–] moonpiedumplings@programming.dev -2 points 4 months ago (1 children)

Many of the prominent https VPN protocols are for evading the great firewall of China. OP had that as a requirement, so it is not an unreasonable assumption.

If you are evading less locked down firewalls, then you don't need as stealthy VPNs.

[–] spaghettiwestern@sh.itjust.works 5 points 4 months ago* (last edited 4 months ago) (1 children)

Many of the prominent https VPN protocols are for evading the great firewall of China. OP had that as a requirement

OP said exactly the opposite. Where the fuck do you get this stuff?

[–] moonpiedumplings@programming.dev -1 points 4 months ago* (last edited 4 months ago) (1 children)

hides as regular HTTPS traffic so it’s not blockable by Firewalls

From OP's post, of course. If OP does not need to evade firewalls that are that aggressive, then they should have settled for a less stealthy VPN solution, as many of these HTTPS proxy solutions have performance and usability (can often only proxy TCP traffic) tradeoffs.

Perhaps they have already tried the wireguard on port 443 solution, and it didn't work for them. My high school would auto detect and block wireguard to any port. Perhaps they are in a similar situation.

[–] pr3d@eviltoast.org 1 points 4 months ago (1 children)

I haven't tried WG on 443/udp yet. On my last UK journey I had it on the default WG port and it was blocked a few times. Will try 443/udp @ homelab next time. Every other advanced obfuscating solution sounds pretty complicated and I'm not sure if there will be time to handle this during a journey.

[–] moonpiedumplings@programming.dev 2 points 4 months ago (1 children)

Also try wireguard over port 53. Often (udp) traffic to port 53 is unblocked because it's needed for DNS.

What is special about this setup is that it can sometimes get around captive portal wifi.

[–] pr3d@eviltoast.org 1 points 4 months ago

Pretty nice idea! Will try it. Thanks.

[–] sunbeam60@feddit.uk 2 points 4 months ago (1 children)

Most Chinese exits through port snooping. And you really need to be on a Chinese corp network to know - if you take your western mobile there they do very little blocking.

I’ve been fairly successful with most China corp networks letting me out and in to self-hosted WG server on port 123.

[–] iopq@lemmy.world 1 points 4 months ago

Because if you're roaming it creates a VPN, basically through the Chinese network

But it you want a lot of data, like for YouTube, you're not going to want to pay roaming rates

[–] eleitl@lemmy.zip 1 points 4 months ago (1 children)

Russia has harsher blocks than China, meanwhile.

[–] iopq@lemmy.world 2 points 4 months ago

Yes, they actually block legitimate websites too, apparently