Self-hosted service
bestruirui/BestSub avatar
bestruirui/BestSub

BestSub: a Go dashboard that turns proxy subscriptions into Clash and sing-box output

Best Sub, Best for Your Net

2,140 stars1,426 forksTypeScriptGPL-3.0

At a glance

What is it?
BestSub does not convert subscriptions itself. It depends on MiniSubConvert or Sub-Store for that, then handles filtering, scheduling and sharing through a web UI on port 8080.
Who is it for?
BestSub makes sense for someone who already has several subscription sources and wants filtering, naming, scheduling and share links managed from one screen instead of by hand. It is the wrong shape if you need conversion out of the box, because it explicitly delegates that to MiniSubConvert or Sub-Store and you must deploy one of them first.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 37 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The hard dependency is stated in the first paragraph

Most tools in this space will happily convert a subscription for you. BestSub will not, and the README says so immediately: the project must depend on MiniSubConvert or Sub-Store to perform subscription conversion. You deploy one of those first, start BestSub, log into the web UI, and configure the conversion address in the settings screen.

That constraint is the single most important thing to know, because it determines the shape of the deployment. BestSub becomes the scheduler, filter and front end, while a separate service does the parsing of raw subscription content into Clash or sing-box format. If you are deploying this, that is two services, not one.

Whether the split is good news depends on your situation. If you already run Sub-Store for something else, BestSub slots in neatly. If this is your only proxy tool, you are now running two programs to manage one workflow, and the README gives no argument for why the responsibility was divided this way.

Six screens that map to a subscription workflow

The README is short, mostly screenshots, and the screenshots are labelled in Chinese with English filenames. Six panels appear: dashboard, sub, node, task, share and setting.

Read those as a workflow. The subscription screen is where sources are added. The node screen is where individual nodes are inspected, which is the panel you would use to find out why a particular server is not making it into your output. Task is scheduling, and the presence of `github.com/robfig/cron/v3` in the module file confirms there is a real cron engine underneath rather than a hand-rolled timer. Share is for producing subscription links other clients can pull. Dashboard is the summary view.

The fact that node management is a first-class screen, separate from subscriptions, is the design choice that matters. Most subscription converters treat a subscription as an opaque blob. Having per-node visibility means you can filter by node rather than only by source, which is what you need once you have more than two or three providers.

Running it as a single binary

The direct route is to download the archive for your platform from Releases, unpack it, and run it:

bash
./bestsub start

On Windows the equivalent is:

powershell
.\bestsub.exe start

Either way you then open `http://127.0.0.1:8080` and sign in with the default username and password, both `admin`. The README states those defaults plainly, which is honest, and also means that if you expose this on a network without changing them you have effectively published your proxy configuration.

The command-line surface comes from `spf13/cobra` with `spf13/viper` for configuration, so subcommands beyond `start` are plausible, but the README documents only this one and you should assume that is the entire supported surface for now.

Docker and Compose, with a persistent data volume

The container image is on GitHub Container Registry, and both invocation styles are given in the README:

bash
docker run -d \
  --name bestsub \
  --restart unless-stopped \
  -p 8080:8080 \
  -v "$PWD/data:/app/data" \
  ghcr.io/bestruirui/bestsub:latest

The Compose file is the one to copy if you want a file you can keep in version control:

yaml
services:
  bestsub:
    image: ghcr.io/bestruirui/bestsub:latest
    container_name: bestsub
    restart: unless-stopped
    network_mode: bridge
    ports:
      - "8080:8080"
    volumes:
      - ./data:/app/data

Then `docker compose up -d`, and the README says to visit `http://服务器地址:8080`, the server address on port 8080.

The `/app/data` mount is the part not to skip. `glebarez/sqlite` and `gorm.io/gorm` are both in the dependency list, so configuration, subscriptions and schedule state live in a SQLite file inside that directory. Lose the volume and you lose the setup.

What the v2 releases fixed, and what the dependencies reveal

The recent release history is small and specific. v2.0.5 on 2026-08-31 fixed a channel deletion bug. v2.0.4 on 2026-08-25 improved HTTP server shutdown handling so long connections close correctly, and filtered vmess and vless h2 entries to stop the process crashing. v2.0.3 on 2026-08-11 added names to the proxy configuration. The default branch is `v2`, which is a small sign that the project is still finding its release shape.

Those fixes are informative. A proxy client crashing on a malformed vmess h2 entry is the kind of bug you only find by parsing a lot of hostile input, and the h2 filter suggests the parser upstream is strict where the wild is not.

The dependency list is the clearest statement of what this project is. `metacubex/mihomo` v1.19.30 is the Clash-compatible core, which is why mihomo and clash are both repository topics. `klauspost/compress` handles compression, `charmbracelet/log` handles terminal output, `gin-gonic/gin` serves the API and the UI, and `golang.org/x/crypto` does the hashing. The module targets Go 1.26. The repository language field says TypeScript, which is accurate for the `web/` frontend but misleading if you go looking for the server code.

One licensing note: GPL-3.0. For a tool you run on your own machines that is usually fine, but it is a stronger copyleft than the permissive terms most proxy clients carry, and it matters if you ever think about modifying and redistributing it.

Editorial conclusion

BestSub makes sense for someone who already has several subscription sources and wants filtering, naming, scheduling and share links managed from one screen instead of by hand. It is the wrong shape if you need conversion out of the box, because it explicitly delegates that to MiniSubConvert or Sub-Store and you must deploy one of them first. Two things to check before adopting: the default credentials are `admin` and `admin`, so change them before anything touches a network you care about, and note that GPL-3.0 is a different obligation from the permissive licenses most proxy tooling uses. Start with the Docker Compose file on a local machine, set the conversion address in settings, and only then point a real subscription at it. The last push was on 2026-08-31, with v2.0.5 fixing a channel deletion bug.

Frequently asked questions

How do I run BestSub for the first time?

Deploy MiniSubConvert or Sub-Store first, since BestSub needs one of them for conversion. Then either run `./bestsub start` from an unpacked release, or use the `ghcr.io/bestruirui/bestsub:latest` image, and open http://127.0.0.1:8080. Set the conversion address in the settings screen after logging in.

What are the default username and password for BestSub?

Both are `admin`, and the README states this as the default for the direct-run setup. Change them before the service is reachable from anywhere but your own machine, since the share panel can produce links that expose your subscription configuration.

Which proxy clients can BestSub produce configuration for?

The repository topics are clash, mihomo and sing-box, and the Go module depends on metacubex/mihomo v1.19.30, the Clash-compatible core. Conversion of raw subscription content is delegated to MiniSubConvert or Sub-Store rather than done inside BestSub.

Official sources

  1. bestruirui/BestSub on GitHub
  2. License: GPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bestruirui-bestsub.svg)](https://hysenlabs.com/projects/bestruirui-bestsub)