CLI tool
fscarmen/warp-sh avatar
fscarmen/warp-sh

warp-sh: a five-year changelog for putting Cloudflare WARP on a bare server

WARP script is move to: https://gitlab.com/fscarmen/warp

2,431 stars430 forksUnknownLicense varies

At a glance

What is it?
fscarmen's WARP script collection grew from a wgcf wrapper into a menu-driven installer with four client modes, and its update log is the clearest record of how Cloudflare kept changing underneath it.
Who is it for?
The most useful thing in this repository is the changelog rather than the code, because the script now lives at a GitLab address given in the repository description and the GitHub tree holds only two README files. The pattern across five years is consistent: Cloudflare removes or restricts an account feature, or the wireguard-go userspace implementation is needed where a kernel module is unavailable, and the script follows within weeks.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 18 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on October 7, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The GitHub repository is documentation, the script lives on GitLab

The first thing to know about fscarmen/warp-sh is that it is no longer where the code is. The repository description is one line pointing elsewhere: the WARP script has moved to a GitLab address. The tree confirms it, holding `.github/`, `README.md` and `README_EN.md` and nothing else. No script, no license file, no releases, no detected language.

What remains on GitHub is the archive and the documentation, and the documentation is largely a changelog. It is unusually valuable documentation, running from a February 2022 Docker unblock release back through the origin of the project to an entry that describes taking the earliest wgcf-derived models on release. Both a Chinese and an English README exist, with the Chinese one as the primary document.

The scale suggests this was widely used before the move: 2,425 stars, 431 forks and 8 open issues. The repository is not archived and the last push is dated 2026-09-19, so the changelog is still being appended. Repository topics are `api`, `cloudflare`, `warp` and `warp-cli`.

The README's table of contents also lists sections on the script's features, the benefits of WARP, run instructions for both scripts, the Cloudflare API, refreshing WARP addresses for Netflix unblocking, SOCKS5 or interface split-routing templates for unlocking ChatGPT, obtaining WARP+ licences and identifiers, obtaining WARP Teams accounts for Linux, and the principle WARP works on.

What the script sets up on a VPS

The project's purpose, stated in the README title, is connecting Cloudflare WARP to give a server IPv4 and IPv6 networking. The motivating case is a cheap VPS that ships with only one address family, or none you can use, and WARP supplies both.

The script grew into a menu-driven installer with several client modes rather than one fixed approach, and the changelog names them. There is a SOCKS5 proxy mode reached from menu item 5, where traffic is proxied rather than rerouted. There is a WARP mode, described in the 2022 log as the first release of a network-interface approach using the official WARP client, where traffic is routed through a real interface. There is a WarpProxy mode at menu item 14, and a wireproxy mode that establishes a SOCKS5 proxy through wireproxy with systemd process supervision, which arrived in March 2022 as one of the project's first announcements of its own.

Around those sit per-platform integrations: Sing-box configuration export, an iptables with dnsmasq and ipset approach for ChatGPT access, Docker unblock recipes published in February 2022, NAT64 presets for IPv6-only hosts, and a non-global mode where only selected traffic goes through WARP. IPv4 versus IPv6 preference is switchable with `warp 4/6/d` and the warp-go equivalent.

The account layer has been the volatile part. Registration, WARP+ upgrades, Teams upgrades and remaining-data lookups all appear in the log, and most of those functions are now gone.

The 2023 rewrite that dropped wgcf for the official API

The single largest change in the project's history is dated 30 June 2023, when menu.sh v3.0.0 beta shipped with three items: the official Cloudflare WARP API replacing wgcf entirely, wireguard-go with a reserved configuration substituted for the kernel implementation, and, bluntly, a request that users reinstall because the change was too large to migrate.

Substituting wireguard-go for the kernel matters more than it sounds. On many virtualised servers the wireguard kernel module either is not present or will not load, and the earlier versions of the script dealt with that by trying to load it and re-checking, as recorded in the February 2024 entry for v3.0.2. Moving to the userspace implementation removes that class of failure entirely, and it is what makes WARP workable in places like Hong Kong and Los Angeles that the June 2023 entry calls restricted regions. A beta follow-up in July 2023 added a switch between kernel and wireguard-go-reserved where the host supports both, reachable through `warp k`, at the cost of a reinstall.

The Cloudflare API dependency has a visible cost. In August 2024 the script shipped its own WARP API, by way of a Cloudflare Worker reverse proxy, and used it for registration, Zero Trust enrolment and account queries. Later entries show that endpoint being renamed from one host to another, so the script has absorbed infrastructure churn of its own as well as upstream churn.

Cloudflare's 2026 account policy removed WARP+ and Teams

The 2 January 2026 entry for v3.2.0 is the most consequential recent change and it was not the author's choice. Cloudflare adjusted its WARP account policy, so the obsolete WARP+ and Teams account types were removed, the install flow was simplified, and the account upgrade feature went with them. The affected command was `warp a`. A later entry, v3.2.3 in April 2026, removed the licence-change function from the menu entirely.

That undoes a long line of work. In August 2022 the script was first in the world to ship a one-click warp-go installer with WARP+ and Teams upgrade functions. In August 2024 the licence generation feature was dropped because Cloudflare forbade cloning WARP+ licences, and the Client path was limited to IPv4 for WARP+ because official client support was incomplete. By 2026 the whole upgrade surface is gone.

Three smaller changes in the same period are worth noting because they affect whether an upgrade will work at all. In February 2026 the OS version check was removed to support rolling releases, which previously defeated detection. In the same entry the WARP API host changed from `cloudflare.now.cc` to `cloudflare.nyc.mn`. And v3.2.0 replaced third-party IP information lookups with a self-hosted API, which the author credits with a noticeable speedup in script startup and IP lookup.

Endpoint selection, MTU tuning and the keepalive added in v3.2.7

WARP connects to Cloudflare edge endpoints over UDP, and finding a reachable one is a recurring theme. In March 2023 the script gained automatic endpoint selection, standardising on ports 500, 1701, 2408 and 4500, and applying the best endpoint to wgcf, warp-go and the client. In June 2024 it went further, running MTU optimisation, endpoint optimisation, the wireguard-go download and dependency installation in parallel, which the author says halved the script's run time. DNS preference was set to Cloudflare's 1.1.1.1 ahead of Google's 8.8.8.8.

Then in August 2025 that endpoint optimisation feature was removed to match an official change. The general lesson is that the endpoint logic is not stable: what works in one release gets pulled in the next.

The newest entry, 8 August 2026 for v3.2.7, does two things. It optimises IPv6 routing rules so addresses in the same subnet all work rather than only the one that was configured. And it adds a built-in keepalive that periodically checks WARP interface status and automatically obtains a new WARP address after a drop, to avoid losing connectivity. Older versions handled the same problem manually: the August 2023 release refreshed addresses for Netflix unblocking, and the changelog shows the default preference moving from IPv4 to IPv6 as recently as v3.2.0.

Upgrading in place is a single command, straight from the README:

bash
bash <(curl -sSL https://raw.githubusercontent.com/fscarmen/tools/main/keepalive-upgrade.sh)

Two routing fixes sit immediately before that one. v3.2.6 in July 2026 solved a WARP interface routing conflict by narrowing the CIDR range, and v3.2.5 in May 2026 added a retry that falls back to wireguard-go when obtaining the WARP address fails on the wireguard kernel. Both are the kind of change that should be read before you apply it to a host you depend on, since routing changes are where a script like this can cut off its own access.

Platform coverage is broad, and the failure modes are operational

The supported surface reads like a list of every Linux where WARP was requested. Over the years the changelog adds Ubuntu 18.04 and CentOS 7, Debian 9 then Debian 12, Arch Linux, Fedora, Alpine edge, Ubuntu 22.04, CentOS Stream 9 LTS, then Ubuntu 24.04 and Debian 13 in August 2025, Arch and EndeavourOS in September 2025, and the RHEL 9 family of CentOS 9, Alma Linux 9 and Rocky Linux 9 in June 2024. There is also a macOS one-click script from April 2022, OpenWrt support in the warp-go script from December 2022, and NAT-type servers such as Woiden. Official arm64 client support arrived in June 2024, so both proxy and interface modes work on ARM. Docker support was extended in December 2024 to listen on 0.0.0.0/0 without host networking mode.

That last item points at the class of problem that matters most with this project. The changelog is full of networking repairs: routes lost after reboot in non-global mode, uninstall routines that broke routing and cut off the VPS, nameserver files needing restoration after uninstall on IPv6-only hosts, a wrong toggle caused by a specific client build, and MASQUE protocol support added as an option in September 2024 for both proxy modes. The February 2026 restoration of the Reserved configuration is another example, reverted because some regions still need it.

The script also refuses to run in a broken state in one case worth knowing: since December 2023 it checks whether UDP is permitted at all and aborts if none of the WARP endpoints are reachable, rather than leaving you with a configured but dead tunnel.

Because this is shell that reconfigures a server's network stack by design, reading the specific version entries before applying an upgrade is a reasonable habit, whatever the script's own convenience aims suggest.

Editorial conclusion

The most useful thing in this repository is the changelog rather than the code, because the script now lives at a GitLab address given in the repository description and the GitHub tree holds only two README files. The pattern across five years is consistent: Cloudflare removes or restricts an account feature, or the wireguard-go userspace implementation is needed where a kernel module is unavailable, and the script follows within weeks. Two specific 2026 entries are worth knowing before you run anything, the removal of WARP+ and Teams account types to match Cloudflare's policy change, and the built-in keepalive added in v3.2.7 that re-fetches a WARP address when the interface drops. Follow the upgrade one-liner in the README rather than reinstalling, and read the entries for v3.2.6 and v3.2.5 before touching routing on a box you depend on.

Frequently asked questions

Where is the WARP script code now?

The GitHub repository description points to a GitLab address, and the GitHub tree now contains only `.github/`, `README.md` and `README_EN.md`. What GitHub keeps is the documentation, including a detailed dated changelog of every version. Follow the GitLab link in the repository description for the current script.

What does the warp script install on a server?

It installs Cloudflare WARP so a VPS can get IPv4 and IPv6 networking, in several modes: a SOCKS5 proxy mode from menu item 5, a WARP network interface mode using the official client, a WarpProxy mode at menu item 14, and a wireproxy mode. It also handles IPv4 versus IPv6 preference, a non-global routing mode, and configuration export for Sing-box.

Does this script still support WARP+ and WARP Teams accounts?

No. The January 2026 release for menu.sh v3.2.0 removed the WARP+ and Teams account types, the install flow and the account upgrade function, to match a Cloudflare account policy change, which affected the `warp a` command. Licence generation had already been dropped in August 2024 because Cloudflare forbade cloning WARP+ licences.

How do I update the WARP script to a new version?

Run the one-line keepalive upgrade command published in the README, which pulls keepalive-upgrade.sh from the author's tools repository. That covers moving from an older version to one with the built-in keepalive added in v3.2.7. Note that the June 2023 release to version 3.0.0 was the exception, where users were asked to reinstall because the API and wireguard-go changes were too large to migrate.

Official sources

  1. fscarmen/warp-sh on GitHub
  2. Issues
  3. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/fscarmen-warp-sh.svg)](https://hysenlabs.com/projects/fscarmen-warp-sh)