# go-gost/gost: a Go tunnel that covers proxy, port forwarding and reverse tunnelling

> gost is a Go program that acts as a forward proxy, a port forwarder and a reverse tunnel with a plugin system and a Web API. It suits engineers who need one binary to chain protocols across hosts, and it is a poor fit for anyone who wants a small, single-purpose proxy.

**go-gost/gost** — GO Simple Tunnel - a simple tunnel written in golang

- Repository: https://github.com/go-gost/gost
- Website: https://gost.run
- Stars: 7,562 · Forks: 833
- Language: Go
- License: MIT
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/go-gost-gost

## The gap gost fills: one binary for proxy, forward and reverse

Most tunnelling tools pick one role. A SOCKS server proxies. A port forwarder maps one port to another. A reverse tunnel exposes an internal service. gost treats these as three modes of the same program, and the README lists them as the three main ways to use it: forward proxy, port forwarding, and reverse proxy. The same binary also carries DNS resolution and proxying, TUN/TAP devices, TUN2SOCKS, load balancing, routing control, admission control, rate limiting, a plugin system, Prometheus metrics, dynamic configuration and a Web API. That breadth is the point. A team that already runs a chain of hops between a laptop, a jump host and an internal service can describe the whole path in one configuration instead of stitching together three tools. The audience is infrastructure and network engineers who are comfortable reading a configuration reference, not end users who want a one-line command. If your need is a single SOCKS5 listener with no chaining, the feature list is a liability rather than an asset.

## How gost composes a chain across protocols

The README describes forward proxy as accessing the network through a proxy service, where multiple protocols can be combined into a forwarding chain. The same chain concept applies to port forwarding: a service port is mapped to another service port, and again the hop can be composed from several protocols. The protocol list in the topics is long: HTTP, HTTP/2, HTTP/3, HTTPS, SOCKS4A, SOCKS5, Shadowsocks, SSH, gRPC, QUIC, KCP, DTLS, WebSocket, ICMP tunnel, DNS. Each hop in a chain is a node, and the chain is the ordered path traffic takes. Around that core sit the concepts the wiki names separately: a resolver for DNS, a selector for load balancing, a bypass list for routing control, an admission list, a limiter, and a plugin interface. Reverse proxy and reverse proxy tunnel are the third mode, where a tunnel plus internal network penetration exposes an internal service to the public network. The configuration model is a graph of nodes, chains and services rather than a flat set of flags, which is why the project publishes a separate wiki at gost.run for concepts and tutorials. If you only read the README, you get the shape of the system but not the field names; the README links out for every one of them.

## Installing gost and running a first proxy

The README gives four installation routes: release binaries, DEB/RPM system packages, an install script, and a source build. The Docker image is also published as gogost/gost, and the README shows a version check as the smoke test.

```bash
docker run --rm gogost/gost -V
```

That command prints the version and exits, which confirms the image runs on your host before you wire it into anything. For a Debian or Ubuntu host, the README uses the package from Releases with apt:

```bash
sudo apt install ./gost_<version>_linux_amd64.deb
```

Replace the placeholder with the file you downloaded. The README notes that amd64v3 packages require a CPU with AVX2 (x86-64-v3) and that you should use the amd64 package otherwise. The package ships a systemd service, but the README is explicit that it is not enabled automatically: create /etc/gost/gost.yml first, using /usr/share/doc/gost/examples/gost.yml as the example, then enable it.

```bash
sudo systemctl enable --now gost
```

The README states that when no configuration file is present the service is skipped rather than failing with an error, so a silent no-op is the expected behaviour if you enable it too early. For a source build, the README changes into the command directory before building:

```bash
git clone https://github.com/go-gost/gost.git
cd gost/cmd/gost
go build
```

The go.mod file pins Go 1.26.3, so the toolchain on the build host must satisfy that. The install script offers both an unattended and an interactive path:

```bash
bash <(curl -fsSL https://github.com/go-gost/gost/raw/master/install.sh) --install
```

Run it without --install to choose a version instead. After any of these routes, the next step is a gost.yml that declares your nodes, chains and services; the README points at the wiki quick start for that configuration rather than inlining it.

## Where gost is the wrong tool

The configuration surface is the first limitation. Nodes, chains, services, resolvers, selectors, bypass rules, admission rules and limiters are separate concepts, each with its own page on gost.run. The README itself does not document the configuration schema, so a reader who only has the repository has to follow links to the wiki to write a working file. That is a real cost for a small deployment. Second, the systemd package behaviour is quiet by design: if /etc/gost/gost.yml is missing, the unit is skipped instead of erroring, which means a misconfigured host can look healthy while doing nothing. Third, the release stream shown here is nightly builds (v3.3.1-nightly.20260921 and earlier), so anyone who wants a stable tag needs to check whether a non-nightly release exists rather than assuming the newest artefact is the one to deploy. Fourth, the feature list is broad enough that gost is a poor choice when you want a minimal attack surface: a single-purpose SOCKS daemon has fewer moving parts to audit. Finally, the DEB/RPM route only covers Linux, and the amd64v3 variant adds a CPU requirement that will fail on older x86 hosts; the README tells you to fall back to amd64, but nothing detects the mismatch for you.

## gost against a single-purpose proxy such as Shadowsocks

Shadowsocks appears in this repository in two places: as a protocol gost supports, and as the basis of an Android plugin listed under Tools (hamid-nazari/ShadowsocksGostPlugin). That is the useful comparison. Shadowsocks is a protocol and a small client/server pair built around one encrypted proxy hop. gost is a framework that can carry that hop inside a longer chain and mix it with SSH, gRPC, QUIC, WebSocket or an ICMP tunnel. The difference in approach is configuration depth against deployment simplicity. With Shadowsocks you get a key and a port; with gost you get a node graph, and in exchange you can put a resolver, a selector for load balancing and a limiter in front of the same traffic. If your problem is one encrypted hop to a server you control, gost's extra concepts buy you nothing. If your problem is reaching an internal service through two intermediate hosts with different protocols on each leg, a single-protocol proxy cannot express it at all. The GUI and WebUI are separate repositories (go-gost/gostctl and go-gost/gost-ui), which is worth noting: the core project does not ship a desktop interface, so the graphical option is a second install.

## Maintenance, licensing and upgrade cost

The repository is not archived, and the last push was on 2026-09-21, so development is current. The release list shown here is nightly-tagged, which sets the upgrade expectation: if you track the nightly stream you are consuming builds that are cut roughly daily, and you should expect to re-verify your configuration after each one. The licence is MIT, which permits reuse and redistribution provided the copyright notice and permission notice are included; that is a permissive arrangement, but it is not legal advice and you should confirm how it interacts with your own distribution terms. The dependency picture matters for upgrade cost too: go.mod requires github.com/go-gost/core v0.6.1 and github.com/go-gost/x v0.17.2, so the core protocol and feature implementations live in separate modules with their own version lines. A binary upgrade can therefore pull in behaviour changes from x without a corresponding change in the gost repository itself. The Dockerfile is a further constraint: it disables UPX compression by default, with a comment citing issue #863 and roughly three seconds of added startup time on low-spec linux/arm systems, so a build that re-enables UPX is trading image size for cold-start latency. The image also installs iptables and nftables for TUN/TAP support, which means those features carry a larger container footprint than a plain proxy build.

## Conclusion

Adopt gost when you need a forward proxy, a port forwarder and a reverse tunnel from a single Go binary, and you are willing to write a gost.yml or drive the Web API to configure it. Do not adopt it if you want a small single-purpose SOCKS server or a tool that hides its configuration surface. Verify first that your target architecture is in the release list (amd64v3 needs AVX2), that the systemd unit finds /etc/gost/gost.yml, and that your licence obligations under MIT are met when you redistribute the binary.

## FAQ

### What does Gost mean?

The README expands the name as GO Simple Tunnel, a tunnel written in Go. It is the project name, not an acronym for anything else.

### How to install Gost?

The README lists release binaries, DEB/RPM system packages, an install script run through bash, a source build from cmd/gost, and the gogost/gost Docker image. The systemd service shipped with the packages is not enabled automatically and requires /etc/gost/gost.yml first.

### What is Gost Run?

The README points to gost.run as the wiki site for documentation, concepts and tutorials. It is the project's documentation home, separate from the repository.

## Sources

- [go-gost/gost on GitHub](https://github.com/go-gost/gost)
- [License: MIT](https://github.com/go-gost/gost/blob/master/LICENSE)
- [Project website](https://gost.run)
- [README](https://github.com/go-gost/gost/blob/master/README.md)
- [Releases](https://github.com/go-gost/gost/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/go-gost-gost
