# eooce/Sing-box: a one-command installer for four proxy protocols on VPS and free hosting

> The eooce/Sing-box repository is a set of shell scripts that install and keep alive sing-box nodes speaking VLESS-reality, VMess-ws-tls through Argo, Hysteria2 and TUIC5. It is built for people running cheap NAT VPS boxes or free hosting panels such as Serv00 and CT8, not for desktop users who want a sing-box GUI.

**eooce/Sing-box** — 既然来了，就留下你的Star吧！Serv00 | CT8 | Hostuno | VPS | 游戏机 | sing-box(reality + hy2 + vmess-argo +tuic5)四合一无交互一键安装脚本(已适配Alpine)，支持纯V6 vps，丰富的分流服务, 可添加anytls,socks5,ss-2022等协议

- Repository: https://github.com/eooce/Sing-box
- Website: https://serv00.eooce.com
- Stars: 5,147 · Forks: 1,847
- Language: Shell
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/eooce-sing-box

## What eooce/Sing-box actually installs, and for whom

This repository is not a sing-box fork and it is not a client. It is a collection of Shell scripts that download the sing-box binary, generate a configuration, register a service, and print subscription links. The README describes four protocols in one run: VLESS-reality, VMess-ws-tls through an Argo tunnel, Hysteria2, and TUIC5. The project also integrates the Nezha probe in both v0 and v1 forms, so the same script can report host metrics to a panel.

The intended audience is narrow and specific. The README targets VPS machines, NAT boxes where only a few ports are forwarded, and free hosting products named Serv00 and CT8. It also ships folders for game-hosting environments in nodejs, python, go, java and php, each with its own entry file such as index.js or app.py. A desktop user looking for a sing-box GUI gets nothing here; the output is a sub.txt node file meant for clients like V2ray, Nekbox or Shadowrocket.

The value proposition is the absence of interaction. The README repeatedly describes the scripts as no-interaction one-click installs, with keep-alive included when you choose the full option. That matters on free hosting, where processes are killed periodically and a node that is not restarted simply disappears.

## How the scripts turn environment variables into a running node

The mechanism is variable-driven. Rather than prompting, the scripts read environment variables placed before the command, and each variable maps to one field in the generated sing-box configuration or in the Nezha client config. The README lists the accepted names: UUID, ARGO_DOMAIN, ARGO_AUTH, CFIP, CFPORT, SUB_TOKEN, CHAT_ID, BOT_TOKEN, NEZHA_SERVER, NEZHA_PORT and NEZHA_KEY, plus HY2_PORT, REALITY_PORT and TUIC_PORT for multi-port hosting.

Two of those variables carry branching logic. ARGO_DOMAIN and ARGO_AUTH control the Cloudflare tunnel: the README states that when either one is empty, a temporary tunnel is used, and when both are set, a fixed tunnel is used. ARGO_AUTH accepts either a token or a JSON blob, and the README requires that JSON be wrapped in single quotes. The Nezha variables branch on version: v0 uses NEZHA_SERVER=nezha.abc.com, while v1 uses NEZHA_SERVER=nezha.abc.com:8008 and does not need NEZHA_PORT.

The port handling is where the design shows its constraints. On NAT machines the README warns that after installation you must manually change the subscription port and node port into the allowed range, otherwise the node does not work. Passing PORT= before the script defines the port, but the README adds that the three ports after it must be available. That is a hard requirement, not a suggestion: the four protocols need consecutive free ports, and a NAT provider that forwards only one port cannot host all four.

## Installing on a VPS and reading the first node

The VPS path is a single command. The README gives this example, which downloads and executes the installer script directly:

```bash
bash <(curl -Ls https://raw.githubusercontent.com/eooce/sing-box/main/sing-box.sh)
```

On a NAT machine the README shows the same command with a PORT prefix. The comment next to it says the port must be open and that three more ports after it must be usable:

```bash
PORT=你的端口 bash <(curl -Ls https://raw.githubusercontent.com/eooce/sing-box/main/sing-box.sh)
```

After installation the script installs a shortcut named sb. Running it with the check flag prints node information and subscription links, which is the first thing to verify:

```bash
sb -c
```

The README lists the other flags in the same help block: -i or --install for a no-interaction install, -r or --restart to fetch a new Argo temporary tunnel and update the subscription, -u or --uninstall to remove sing-box including nginx, and -h for help. There is also a separate SSH toolbox script at ssh_tool.eooce.com, which the README says the VPS installer has been integrated into.

For Serv00, CT8 or similar hosting, the four-protocol script is a different file. The README gives the command and notes that the interactive version includes a keep-alive service, and that installing option 1 alone has no keep-alive while installing 1 and 2, or option 2 directly, does:

```bash
bash <(curl -Ls https://raw.githubusercontent.com/eooce/sing-box/main/sb_serv00.sh)
```

The no-interaction variant is sb4.sh, and the README shows a fully parameterized invocation with a Telegram bot, Nezha v1 and a fixed Argo tunnel:

```bash
CHAT_ID=12345 BOT_TOKEN=5678:AA812jqIA NEZHA_SERVER=nezha.abc.com:8008 NEZHA_KEY=abc123 ARGO_DOMAIN=abc.2go.com ARGO_AUTH='{"AccountTag":"123","TunnelSecret":"123","TunnelID":"123"}' bash <(curl -Ls https://github.com/eooce/Sing-box/releases/download/00/sb4.sh)
```

One client-side setting is stated plainly in the README: skip certificate verification must be set to true, otherwise Hysteria2 and TUIC do not connect.

## Port arithmetic, certificate verification and other failure modes

The most common failure is not a bug in the script. It is a port that is not reachable. The README repeats the warning in several places: on NAT machines you must move the subscription and node ports into the allowed range, and PORT must have three free ports behind it. If your provider forwards a single port, the four-in-one install produces nodes that never connect, and the script itself will not tell you which one failed.

The second failure is the certificate check. Hysteria2 and TUIC5 use self-signed material here, and the README instructs the client to skip certificate verification. A user who leaves verification on will see two of the four protocols fail while VMess and reality work, which is a confusing partial failure.

A third limitation is the hosting terms. The README links to Serv00's updated terms of service and tells the reader to judge for themselves whether to install. It does not resolve the question. Free hosting also means the keep-alive service is the difference between a node that survives and one that does not, and the README is explicit that installing only option 1 on Serv00 leaves you without keep-alive.

Finally, the game-hosting path is manual. The README says to download the file from the matching language folder, upload it, grant permissions, edit the variables in the main run file, and start it. The README does not document an automated upgrade for those deployments, and the repository has no changelog explaining what changes between script versions.

## How this differs from running sing-box directly

The obvious alternative is the upstream sing-box binary and its own configuration file. The difference in approach is who owns the configuration. With upstream sing-box you write the JSON yourself, choose the inbound types, decide on the TLS material, and run it under whatever supervisor you prefer. You get the full protocol list and full control over routing rules, but you also get every decision, including the ones this project has already made for you.

With eooce/Sing-box the configuration is generated from environment variables, and the trade is speed for flexibility. The README's own description of the project mentions rich traffic-splitting services and the ability to add protocols such as anytls, socks5 and ss-2022, but those additions are not shown as commands in the README, so a reader cannot follow a documented path to them. If your requirement is a custom routing table or a protocol combination the scripts do not expose, upstream sing-box is the more direct route.

A second alternative is a client-side application. The related searches around this project are mostly about sing-box on Windows, Android, iOS, macOS and OpenWrt, and those are client questions. This repository does not answer them. It produces a subscription link and a sub.txt file; the client that consumes them is a separate piece of software, and the README names V2ray, Nekbox and Shadowrocket as examples.

## Maintenance, licence and what an upgrade costs you

The repository is MIT licensed, which is permissive and places no conditions on how you run the scripts. That licence covers this repository's Shell code, not the sing-box binary the scripts download, and not the Nezha probe or the Argo tunnel service. Anyone deploying this should check the terms of those components separately. Nothing here is legal advice.

On maintenance, the last push to the default branch was on 2026-08-26, and the repository is not archived. The release list is thin: one release tagged other (IDX) on 2025-05-05 and one tagged 00 on 2024-08-19. Two of the install commands in the README point at release assets rather than the main branch, which means those scripts are pinned to a 2024 release while the branch has moved on. That split is worth knowing before you copy a command.

Upgrade cost is the weak point. The README does not document rollback, and the uninstall flag is described as removing sing-box together with nginx, which is broader than some users will expect on a machine that had nginx first. There is no documented version pinning for the sing-box binary itself, so reinstalling later may pull a different build. If you need reproducible deployments, this project does not offer the mechanism.

## Conclusion

Adopt eooce/Sing-box if you already have a VPS or a Serv00/CT8 account and you want four sing-box inbounds with keep-alive without writing configuration by hand. Do not adopt it if you need a desktop or mobile client, a documented upgrade path, or a clean uninstall that leaves nginx in place. Before installing, confirm that the port you pass in PORT has three more free ports above it, that your client skips certificate verification for Hysteria2 and TUIC5, and read the Serv00 ToS the README links to.

## FAQ

### What is eooce/Sing-box used for?

It is a set of Shell scripts that install a sing-box server with four protocols (VLESS-reality, VMess-ws-tls through Argo, Hysteria2 and TUIC5) and print subscription links. The README also describes an optional Nezha probe and a keep-alive service for free hosting.

### Is eooce/Sing-box free?

The repository is MIT licensed, so the scripts themselves carry no fee. The README does not price anything; it does list a sponsor and affiliate links, and the sing-box binary and Argo tunnel are separate components with their own terms.

### What platforms does eooce/Sing-box run on?

The README shows install commands for VPS machines, for Serv00 and CT8 hosting, and for game-hosting environments in nodejs, python, go, java and php. The install scripts are Shell, and the README notes Alpine support.

### Is eooce/Sing-box legal to use?

The README does not answer this. It carries a disclaimer stating the program is for learning purposes, that it must be deleted within 24 hours of download, and that users must follow the laws of the server's country and their own.

### How do I use eooce/Sing-box?

The README's flow is to run the install script for your environment, then run the sb shortcut with the -c flag to print node information and subscription links. The resulting sub.txt file is imported into a client such as V2ray, Nekbox or Shadowrocket.

## Sources

- [eooce/Sing-box on GitHub](https://github.com/eooce/Sing-box)
- [License: MIT](https://github.com/eooce/Sing-box/blob/main/LICENSE)
- [Project website](https://serv00.eooce.com)
- [README](https://github.com/eooce/Sing-box/blob/main/README.md)
- [Releases](https://github.com/eooce/Sing-box/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/eooce-sing-box
