Self-hosted service
IRNova/Nova-Server avatar
IRNova/Nova-Server

Nova-Server: a self-hosted proxy node and admin panel for any VPS

Self-hosted, censorship-resistant proxy server with an all-in-one admin panel for Xray-core, sing-box, Hysteria2, and AmneziaWG.

325 stars72 forksShellNOASSERTION

At a glance

What is it?
Nova-Server runs Xray-core, sing-box and AmneziaWG behind one port on a Linux VPS, with a trilingual admin panel, Iran bridge tunnels and a five-question setup wizard. The release notes are candid postmortems, and the licence is one to read before deploying.
Who is it for?
Nova-Server fits operators, particularly those serving users inside Iran, who want multi-protocol nodes with bridges, failover and per-user quotas managed from one panel. It does not fit minimalists who want a single WireGuard endpoint, and it does not fit anyone unwilling to run a proprietary-licensed panel over open cores.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Shell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What one VPS becomes with Nova-Server

Nova Server turns a plain Linux VPS into a private, censorship-resistant proxy node with a full admin panel, which is the README's own summary. Under the panel it runs Xray-core, sing-box for Hysteria2, and AmneziaWG behind a single port, all driven by one self-hosted agent. The protocol list is long: VLESS, VMess, Trojan, Shadowsocks, Reality, Hysteria2, TUIC, NaiveProxy, native WireGuard and AmneziaWG.

The panel is trilingual, in English, Persian and Russian, with multi-user accounts, a multi-node fleet view, a Telegram bot with a Mini App, and two-factor auth. The Persian README and the Iran bridge machinery make the primary audience clear: operators serving users inside heavily filtered networks. Nova Server is also the self-hosted sibling of Nova Proxy, which runs on Cloudflare's free tier instead of your own VPS.

Five questions to a working server

The setup wizard opens on the first panel visit and asks five things: who the node is for, where people connect from, how they reach it, whether you have a second server, and who will use it. Then it does the work itself. It issues the certificate if you gave it a domain, configures and hands over a paste-once command for an Iran bridge or an extra node, writes the configuration, creates the accounts, and finishes with a subscription link and a QR code per person.

Two design choices stand out. Every question can be skipped, each skip takes a working default that is shown before you accept it, and nothing is written until you approve a review. And a fresh install seeds a starter user with every protocol enabled, so the dashboard's Quick connect QR puts the first client online in a single scan. A Simple mode hides the engine internals entirely; one switch in Settings restores the routing rule builder, custom outbounds, tunnels, Xray engine options, resellers and API tokens, and an existing deployment keeps every page it already had.

What the repository ships, and how to drive it

The tree is a set of shell entry points rather than an application checkout: DEPLOY.md and GUIDE.md for setup, SECURITY.md, SHA256SUMS for verifying downloads, and scripts including nova-node.sh, nova-bridge.sh, nova-trial.sh and nova-uninstall.sh, with the node agent distributed as nova-node-agent.tar.gz alongside a .sha256 file. The README material here does not include the one-line installer itself, so read DEPLOY.md and GUIDE.md for the current command before touching a VPS.

One command the README does document is the bridge readiness check:

bash
nova-bridge.sh --check

It confirms a direct public IP and free ports before an Iran bridge install, which saves a failed certificate round later. For removing everything, nova-uninstall.sh is the documented counterpart.

Hysteria2 hardening and the Iran bridge path

Two areas get the deepest engineering. Hysteria2 ships hardened: UDP port hopping over a range you pick, so no single port can be blocked, Salamander obfuscation, and ECH to hide the SNI. The full port-hopping and ECH configuration is delivered inside the sing-box subscription, while the private ECH key never leaves the node.

The Iran bridge path is the other. A clean-IP server inside Iran sits in front of a foreign exit over Backhaul, BackPack, rathole or wstunnel; one click repoints every client link at the bridge across raw, Clash and sing-box formats, and only the ports you forward actually traverse the bridge. List several bridges and the exit dials all of them, so clients fail over automatically when one drops, and a port sweep finds a live control port when the default is blocked. Bridges can carry their own domains with per-SNI certificates issued over Cloudflare DNS, so clients dial them directly without allowInsecure.

Certificates, domains and recoverable failure

Certificate handling is treated as the fragile part it is. One-click SSL supports Let's Encrypt or fully automatic Cloudflare with auto DNS and wildcard, using user and account-owned API tokens, with no manual port 80 juggling. The setup tracks the UFW rule HTTP validation needs, waits for slow Xray starts, verifies the exact SNI certificate locally, rolls back safely, and then reports whether Xray, sing-box, configuration validation, DNS or the TLS front failed.

Domains scale the same way. One primary panel address plus up to 20 trusted server aliases, each with automatic issue and renewal, and each working address published as an independent subscription fallback. Activation is health-gated and restores the previous certificate, DNS, Xray and sing-box state on failure; Cloudflare orange-cloud aliases are limited to WebSocket. The panel, API, Telegram bot, installer and recovery tools share one HTTPS URL model that preserves custom front ports and brackets IPv6 addresses correctly.

Three release notes that show how it thinks

The v1.75.0 to v1.75.2 notes, all published on 2026-08-28, are candid postmortems. v1.75.0 fixed voice calls for users on Tor, Psiphon or country exits: the Route UDP through WARP setting existed, but routing rules matched in order and the exit rules were emitted before it, so the one rule that would have carried UDP was never reached for exactly the customers who needed it. It is checked first now.

v1.75.1 fixed an update path that printed four /dev/tty errors over SSH, because a new ports list was written to the terminal device, which a command run over SSH has no controlling terminal to supply; the notes also explain why the existing 2>/dev/null guard could not catch a failed redirection. v1.75.2 fixed first installs on clean servers, broken since 1.73.0 by a settings-file read that only succeeds on machines already running Nova. Useful reading, and a reminder that between those fixes, updating this panel could briefly break the exact path you were on.

Fleet, quotas and the licence question

For operators beyond one node, the fleet view manages many servers from one panel, adding a node by running a single panel-built command on a fresh VPS. Resilience mode spreads every config across the main server, all nodes and all Iran bridges, so a user's client url-tests and fails over when an IP is blocked. Per-user control covers data quota, expiry, device limits, data reset and per-user protocol access. On a fresh install the panel hides behind a random secret path, optionally on a dedicated port, and every other path returns a plain 404.

The licence needs attention. GitHub reports NOASSERTION and the README's own badge reads Proprietary, while the cores it drives are open-source projects. SECURITY.md and SHA256SUMS exist in the tree; read both, and read LICENSE, before deploying or redistributing anything. One small inconsistency worth knowing: the version badge shows 1.33.1 while the releases feed lists v1.75.2.

Against assembling the cores by hand

The alternative is doing without the panel: install Xray-core or sing-box directly and write the JSON configurations yourself. That route keeps only open-source code on your server and teaches you the config layer, at the cost of hand-maintaining certificate renewal, subscription generation, per-user quotas and, if you serve a filtered network, bridge failover logic that Nova-Server has already built.

The trade is control versus accumulated machinery. The README's own framing, a node for a serious operator rather than a toy, draws the same line. A single WireGuard endpoint for personal use needs none of this panel's breadth. An operator with several users, several protocols and bridges into a filtered network is exactly who the machinery is for.

Editorial conclusion

Nova-Server fits operators, particularly those serving users inside Iran, who want multi-protocol nodes with bridges, failover and per-user quotas managed from one panel. It does not fit minimalists who want a single WireGuard endpoint, and it does not fit anyone unwilling to run a proprietary-licensed panel over open cores. Before deploying, read LICENSE and SECURITY.md, verify the agent tarball against SHA256SUMS, and get the installer command from DEPLOY.md or GUIDE.md, since the README does not carry it. The last push was on 2026-09-10, and the releases feed shows a postmortem for every recent breakage, the latest set published on 2026-08-28.

Frequently asked questions

What is nova proxy?

Nova Proxy is the sibling project that runs on Cloudflare's free tier. Nova Server is its self-hosted, more powerful counterpart, with a real proxy core and a full admin panel on your own VPS.

Which protocols does Nova-Server support?

Per the README: VLESS, VMess, Trojan, Shadowsocks, Reality, Hysteria2, TUIC, NaiveProxy, native WireGuard and AmneziaWG, reachable behind a single port.

Does Nova-Server cost money?

The repository does not state a price; the README carries a donate link and the licence badge reads Proprietary. Check LICENSE and the project's website for terms before relying on it.

Official sources

  1. IRNova/Nova-Server on GitHub
  2. Issues
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/irnova-nova-server.svg)](https://hysenlabs.com/projects/irnova-nova-server)