# AimiliVPN: one port serves HTTP, HTTPS and SOCKS5, and the proxy has no password

> A Linux VPS gateway that manages VPNGate nodes and shares a single local port between three proxy protocols, written with the Python standard library alone. Its own warning says the proxy port has no authentication facing the internet, and its update command tracks a branch rather than a release.

**baoweise-bot/aimili-vpngate** — aimili-vpngate是一个借助vpngate.net让Linux用干净ip出站的代理工具。

- Repository: https://github.com/baoweise-bot/aimili-vpngate
- Stars: 1,965 · Forks: 588
- Language: Python
- License: NOASSERTION
- Published: 2026-09-17 · Updated: 2026-09-17 · Language: en
- Canonical page: https://hysenlabs.com/projects/baoweise-bot-aimili-vpngate

## Standard library only, and the image has no pip in it

The page claims the tool manages VPNGate nodes using only the Python standard library, and the container build is where you can check that. The base is a slim Debian, and the installed packages are a certificate bundle, the routing tools, the packet filter, OpenVPN itself, two small process utilities, and Python 3. There is no package installer, no site-packages directory and no requirements file, so nothing outside the standard library can be running. Four Python modules are copied into the image one by one and byte-compiled during the build, which means a syntax error fails the image build rather than the first request. The entry point is the node manager, not a separate service, and the proxy server is a module inside the same process. The image also carries a build argument for its version label, defaulting to dev, next to a version file copied in from the repository root.

## Port 7928 speaks three protocols and has no user authentication

The design choice that makes this compact is that HTTP, HTTPS and SOCKS5 all share the single local address, and the client chooses the protocol by how it addresses the port rather than by a separate port number.

```bash
# HTTP / HTTPS
curl -x http://127.0.0.1:7928 https://api.ipify.org

# SOCKS5, with the proxy resolving the domain
curl --proxy socks5h://127.0.0.1:7928 https://api.ipify.org
```

HTTPS tunnelling is done with the CONNECT method through the HTTP proxy, so the address you configure is still the plain HTTP one, and remote DNS for SOCKS5 is requested with the socks5h scheme rather than the socks5 scheme. The page then draws the security line in bold: that port carries no user authentication toward the public internet by default, and it should not be opened without a firewall, a source address restriction or some other real access control. Its own recommendation is an SSH tunnel that forwards both the web port and the proxy port to your machine, which is the difference between a usable setup and an open proxy.

## The web panel binds to every interface behind a random path

The management panel listens on TCP 8787 and is protected by two things: a random path segment in the URL and a username with a password. The install script generates both and prints the full address, the path and the credentials to the terminal when it finishes, and the Docker path stores them in a file inside the data volume that you read out with a command into the running container. The page then tells you to change the path and the credentials after the first login, which is the right advice and quietly an admission that the generated ones are the ones printed on your screen. Note what the environment does with the two addresses: the web host is set to all interfaces while the proxy host stays on loopback, so out of the box the panel is reachable from the network and the proxy is not. The deployment tip asks you to restrict the security group to your own address, which is a manual step the installer cannot do for you.

## The compose file is tighter than the run command printed beside it

Two container paths are documented side by side and they are not equally locked down. The compose file drops all capabilities first and then adds back exactly two, the network administration and raw socket ones, and it also sets the no-new-privileges option and initialises a process reaper.

```yaml
cap_drop:
  - ALL
cap_add:
  - NET_ADMIN
  - NET_RAW
security_opt:
  - no-new-privileges:true
```

The single run command in the page adds those same two capabilities to whatever Docker already grants and sets neither the privilege option nor the reaper. Both use host networking and map the tunnel device from the host. That gap is the kind of thing that gets copied from a documentation page into a production compose file, so if you take the run command as written you end up with a broader capability set and no privilege guard than the project's own compose file gives you.

## ml update pulls from the main branch, not from a release

The installer deploys to a directory under opt and registers a system service, and the short command set is the whole operational surface: a menu, a status line that prints the panel address and the account, a live log view, a restart, a password reset, an update and an uninstall. The update command is the one to look at, because the update channel is described as the formal main branch or the latest release, and the command itself updates from the main branch. That is a moving target, so a deployment that wants a fixed version has a second path: tagged source archives with SHA-256 checksum files on the releases page, with version changes recorded in the release notes file. The recent release history shows why the distinction matters here, since three releases were published on the same day, ten hours apart, all named as formal versions of the same line.

## The health check only proves the panel port is open

The container declares a health check that runs a single Python command every thirty seconds, opening a TCP connection to the panel port on loopback and closing it. That is a liveness signal for the web listener and nothing more. It does not test the tunnel, does not test the proxy, does not check that a VPNGate node is reachable, and does not notice that the node list is empty or that every node has failed its latency test. On a gateway whose entire job is outbound traffic, that is the difference between a healthy container and a working one. The image also declares both ports for documentation purposes, sets a termination signal, keeps its data in a named volume, and unbuffered output with bytecode writing disabled, all of which are the small choices that make logs behave under a log collector.

## A README carrying a vendor table and an API relay advertisement

The page is written in Chinese at the root, with English, Japanese and Korean versions in a docs directory, and it also runs a project forum, a Telegram group and a video channel. What sits above the technical content is a four row table of recommended hosting providers and services, and every row links out through a referral code rather than a plain address. One of the four rows is not a hosting provider at all but an advertisement for an API relay service, quoting a price multiplier for United States region access, claiming no dilution of the model, and inviting stress tests. None of those referral links are reproduced here. The point for a reader is that the vendor table sits above the install instructions in the page's own navigation, so the first thing a new user scrolls into is a sales list, and the install instructions come after it.

## Volunteer nodes, six legal boundaries and a regional availability caveat

The page is unusually explicit about what it cannot promise. The nodes come from third party volunteers: the project does not own, control or audit them, and states plainly that it cannot guarantee their stability, speed, security, privacy policy or logging behaviour, followed by a warning not to send account passwords, financial information or trade secrets through an untrusted node. On top of that sits a six point boundary: use limited to legitimate research, education, development and testing, privacy protection and authorised access, with bypassing lawfully implemented measures, unauthorised access, attacks, scanning, spam, fraud and infringement named as out of scope; no promise of regional availability; responsibility for node choice, traffic, port exposure and account security on the user; the software provided as is with no warranty; and an instruction to stop and consult a qualified local lawyer if the local rules are unclear.

## Conclusion

AimiliVPN is worth considering for a VPS you already own if you want an outbound path through volunteer-run VPNGate nodes and would rather not maintain a full VPN client stack, and the standard-library-only design makes the audit surface small and the container thin. Three things to decide before you install it. Port 7928 has no authentication, so the only safe route is the SSH tunnel the page recommends, and the web panel binds to every interface on port 8787 behind a random path and a password printed to your terminal at install time. And the update command pulls from the moving main branch, so decide now whether you want branch tracking or the checksummed release archives, because those are two different upgrade paths with different failure modes.

## FAQ

### What is AimiliVPN and where does it run?

It is a gateway for Linux servers that manages VPNGate nodes and serves HTTP, HTTPS and SOCKS5 proxies from a single local port, with a web panel on port 8787. A source install deploys to /opt/aimilivpn and registers a system service, and the tool uses only the Python standard library.

### Does the AimiliVPN proxy port need a password?

No. The page states that port 7928 has no user authentication toward the public internet by default, and recommends an SSH tunnel forwarding both the web port and the proxy port rather than exposing the port directly.

### How do I update a self-hosted AimiliVPN install?

The update command pulls from the GitHub main branch rather than from a tagged release. Tagged source archives with SHA-256 checksum files are published on the releases page instead, with version changes in the release notes file.

### What does the AimiliVPN container health check verify?

Only that the web panel port accepts a TCP connection on loopback, every thirty seconds. It does not check the tunnel, the proxy, or whether any VPNGate node is reachable or passing its latency test.

### What does the AimiliVPN page say about third-party nodes?

That VPNGate nodes are run by third-party volunteers which the project does not own, control or audit, and that it cannot guarantee their stability, speed, security, privacy policy or logging. It advises against sending credentials, financial information or trade secrets through untrusted nodes.

## Sources

- [baoweise-bot/aimili-vpngate on GitHub](https://github.com/baoweise-bot/aimili-vpngate)
- [Issues](https://github.com/baoweise-bot/aimili-vpngate/issues)
- [README](https://github.com/baoweise-bot/aimili-vpngate/blob/main/README.md)
- [Releases](https://github.com/baoweise-bot/aimili-vpngate/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/baoweise-bot-aimili-vpngate
