# fscarmen/sing-box: One-Click Multi-Protocol Proxy Installer for VPS

> fscarmen/sing-box is a Shell script that installs and configures the sing-box proxy core on a VPS with a menu-driven interface, supporting Reality, Hysteria2, TUIC, Trojan, VLESS, Vmess, Shadowsocks, AnyTLS, ShadowTLS, and NaiveProxy. It generates multi-client subscriptions for Clash, V2rayN, ShadowRocket, and others, and integrates with Cloudflare Argo tunnels without requiring a domain.

**fscarmen/sing-box** — Sing-box 全家桶 --- 一键多协议脚本。支持 Reality、Hysteria2 、TUIC 、Trojan 、Shadowsocks 、 AnyTLS 、ShadowTLS 、 Vmess 、 VLESS 、NaiveProxy，搭配 Argo 隧道等，多客户端订阅（Clash / V2rayN / Throne / ShadowRocket / SFA ），无须域名、功能强大、配置灵活。

- Repository: https://github.com/fscarmen/sing-box
- Website: https://fscarmen.cloudflare.now.cc/
- Stars: 5,744 · Forks: 1,140
- Language: Shell
- License: GPL-3.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/fscarmen-sing-box

## What fscarmen/sing-box does and who it is for

The upstream sing-box core (SagerNet/sing-box) is a general-purpose proxy platform that requires manually written JSON configuration files to configure each protocol, outbound, route, and inbound. That configuration is powerful but time-consuming to set up correctly, especially when combining multiple protocols with Cloudflare CDN, Argo tunnels, and multi-client subscription generation. A misformatted JSON file or a wrong field name silently breaks connectivity.

fscarmen/sing-box wraps the sing-box core in an interactive Shell script that handles the configuration through a menu interface. It generates the JSON configuration, manages the systemd or OpenRC service (including Alpine support as of v1.3.24), and outputs subscription links for multiple client applications. The README describes the project as a 全家桶 (full bundle), meaning everything needed for a working proxy deployment is included. No domain is required, which means it works on NAT VPS instances where no public inbound port is available, relying on Argo tunnels for connectivity. The target user is someone who needs a working proxy infrastructure on a VPS and wants a guided setup rather than a hand-written configuration file.

## Supported protocols and client subscription formats

The script supports ten inbound protocols: Reality, Hysteria2, TUIC, Trojan, Shadowsocks, AnyTLS, ShadowTLS, Vmess, VLESS, and NaiveProxy. Each protocol has different transport and obfuscation characteristics; Reality and VLESS are commonly used with TLS obfuscation, while Hysteria2 uses QUIC as its transport layer. AnyTLS and ShadowTLS are newer additions to the script's protocol list, both added in recent version updates. The choice of which protocols to enable is made during the interactive installation.

Subscriptions are generated in formats compatible with Clash/Mihomo, V2rayN, Throne, ShadowRocket, and SFA (Sing-box for Android/iOS). The update log shows version-level detail on client compatibility work: v1.3.11 added dedicated v2rayn:// links for TUIC, AnyTLS, and NaiveProxy subscriptions; v1.3.18 added a subscription enable/disable toggle in the `sb -d` menu; v1.3.25 added an Hysteria2 ignore_client_bandwidth toggle. The output subscription URL can be used directly in any of the supported clients, removing the need to manually translate server configuration into client import format.

## Installing the script on a VPS

Installation and configuration are handled by a single script file, sing-box.sh, at the repository root. The README's section 3 documents the VPS installation command. Section 4 covers non-interactive fast install, which the update log shows supports flags such as --HY2_REALM and --HY2_WARP for Hysteria2 configuration without interactive prompts. After installation, the `sb -d` command opens the configuration menu for modifying settings.

Docker is also supported. The Dockerfile in the repository uses a multi-stage Alpine build with s6-overlay for process supervision:

```dockerfile
FROM alpine:latest AS builder
ARG TARGETARCH
ENV ARCH=$TARGETARCH
```

The runtime image installs nginx, bash, and openssl alongside wget, and the docker_init.sh script handles initialization. Docker Compose installation is documented in the README's section 9. The Docker path suits users who want to run the proxy in a container rather than directly on the host system.

## Cloudflare Argo tunnels and the no-domain architecture

A key feature of fscarmen/sing-box is Argo tunnel integration. Cloudflare Argo tunnels allow an outbound connection from the VPS to Cloudflare's edge, which then proxies traffic without requiring an inbound port or a registered domain. The README documents two Argo approaches: a JSON token path (section 5, described as recommended) and a named Token path (section 6) that allows setting an arbitrary port for CDN passthrough.

For Vmess and VLESS, section 8 of the README covers CDN passthrough via arbitrary port back-origin. For users with NAT VPS instances (common on low-cost providers) where no public inbound IP or port is accessible, the Argo tunnel approach is the primary supported connectivity path. The update log v1.3.6 added the ability to modify CDN settings, Reality SNI, node names, and server IP after installation via `sb -d`, without reinstalling. v1.3.7 added enable/disable of Hysteria2 port hopping after installation via the same menu.

## Recent features: hot-reload, traffic monitoring, and Hysteria2 Realm

The changelog in the README shows active development. Version 1.3.17 added SIGHUP hot-reload support: configuration changes via `sb -d` now apply through a reload rather than a full restart, which reduces interruption to active connections. The README describes this as using `sing-box check + SIGHUP` internally. Version 1.3.19 added real-time traffic statistics, accessible via `-n` or from the main menu.

Version 1.3.14 added Hysteria2 Realm support for machines without public inbound access, with optional WARP-assisted hole punching for strict NAT environments. The Realm configuration can be exported to Clash/Mihomo and sing-box client formats, and can be toggled via `sb -d` after installation. Version 1.3.21 added WARP account management through the same menu, with hot-reload on successful account change. The changelog's depth and recent dates confirm that `sb -d` is the main post-install interface for all protocol and configuration changes.

## How this script compares to 3x-ui for proxy management

3x-ui (and its predecessor x-ui) is an alternative approach to multi-protocol proxy management. It provides a web-based graphical panel for managing xray or sing-box backends, accessible through a browser on a configured port. The web panel allows managing multiple inbound configurations, user accounts, traffic quotas, and subscription links through a GUI without returning to the command line after initial setup. This suits administrators who manage proxy access for multiple users or who prefer a visual interface over CLI menus.

fscarmen/sing-box takes a different path. There is no web panel; all post-install configuration happens through the `sb -d` CLI menu from the VPS terminal. The Argo tunnel and no-domain integration is a deliberate design focus that 3x-ui does not prioritize in the same way. fscarmen/sing-box is designed for a single-server, single-user or small personal deployment, not for managing a fleet of servers with many accounts. Engineers who prefer a browser-based management interface for multiple users will find 3x-ui more appropriate. Those who want a leaner deployment with Cloudflare Argo tunnel integration, no web panel to secure, and CLI-based configuration will find the Shell script approach fits better. The GPL-3.0 licence applies to fscarmen/sing-box; verify the licence of any comparison tool separately.

## Conclusion

fscarmen/sing-box is appropriate for users who want to deploy a multi-protocol proxy server on a VPS without writing JSON configuration files manually. The Cloudflare Argo tunnel integration and domain-free operation make it usable on NAT VPS instances without a public inbound port. The last push was on 2026-09-18, and the script is under active development with version 1.3.25 as of 2026-09-16. Verify local laws before deploying any proxy infrastructure. GPL-3.0 requires that modifications to the script be distributed under the same licence.

## FAQ

### What is sing-box used for?

sing-box is a general-purpose proxy platform. fscarmen/sing-box is a Shell installer script for it that sets up multi-protocol proxy servers (Reality, Hysteria2, TUIC, VLESS, Vmess, and others) on a VPS with a menu-driven interface and generates subscription links for mobile and desktop clients.

### How do I install fscarmen/sing-box on a VPS?

Run the installation command documented in section 3 of the repository README (sing-box.sh). Section 4 covers non-interactive installation with command-line flags. After installation, use the `sb -d` command to configure protocols and generate subscriptions.

### Is sing-box free to use?

The fscarmen/sing-box script is open-source under GPL-3.0. The upstream sing-box core it installs is also open-source. There is no cost for the software, though the VPS it runs on has its own cost.

### Is sing-box legal to use?

The legality of proxy software depends on the laws of your country and jurisdiction. The README includes a disclaimer section (section 15) noting legal responsibility lies with the user. Verify local regulations before deploying any proxy infrastructure.

## Sources

- [fscarmen/sing-box on GitHub](https://github.com/fscarmen/sing-box)
- [Issues](https://github.com/fscarmen/sing-box/issues)
- [License: GPL-3.0](https://github.com/fscarmen/sing-box/blob/main/LICENSE)
- [Project website](https://fscarmen.cloudflare.now.cc/)
- [README](https://github.com/fscarmen/sing-box/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/fscarmen-sing-box
