# deploy-vercel: five files that put a proxy on a PaaS, in Chinese, in six steps

> vvxw/deploy-vercel is a deployment wrapper: an HTML page, a JavaScript entry point, a manifest and a platform config, with a Chinese-language README that walks through creating a private project, disguising the page, and putting a CDN in front. It ships no implementation and no license.

**vvxw/deploy-vercel** — Install Command：npm install

- Repository: https://github.com/vvxw/deploy-vercel
- Stars: 1,960 · Forks: 414
- Language: JavaScript
- License: not declared
- Published: 2026-09-16 · Updated: 2026-09-16 · Language: en
- Canonical page: https://hysenlabs.com/projects/vvxw-deploy-vercel

## Five files, and the implementation is not one of them

The whole repository is five entries: the README, an HTML page, a JavaScript entry point, a package manifest and a platform configuration file. There is no source directory, no test, no lock file and no build script. The manifest names the package nzws-js at version 0.1.0 with index.js as its entry point and a single start script that runs that file with node, while the repository itself is called deploy-vercel and the manifest's description field simply repeats the package name. So the naming tells you what this is: a wrapper whose purpose is to get somebody else's package running on somebody else's hosting, with the repository existing to hold the glue. Its recorded primary language is JavaScript, the last recorded push is 2026-08-18, and it has no GitHub releases.

## The repository description is a build setting

The project's one-line description is not a description at all. It reads Install Command, followed by a Chinese colon and npm install, which is a value you type into a hosting console rather than a sentence about the project. The README says the same thing at step four: open the New Project screen, import the project, keep the default configuration, turn the Install Command switch on, and set it to npm install. So the repository's metadata and its instructions are the same fact, recorded in two places. The other metadata fields are empty: no homepage, and no recorded license. There is also no license file among the five entries, so nothing in the repository states the terms under which the code may be reused, which is the first thing to sort out before copying any of it.

## Step three asks you to replace a filename that is misspelled

The README is written in Chinese throughout and is not bilingual. It works as six numbered steps. Create a private repository from the template with any name. Edit the environment variables in the entry file, leaving the ones you do not need blank. Then, using an AI tool, generate a plain HTML page and replace a file it calls index.thml, which is a typo for the HTML page that is actually in the repository, so a reader following the instruction literally will look for a file that does not exist. The stated purpose of that step is to disguise the deployment as an ordinary web page. The last two steps deal with the endpoint: put the reverse-proxied domain into the DOMAIN variable and save, after running the source through an online obfuscator the README links to, then fetch the subscription information and edit the address field so nodes use the preferred domain, with an external subscription converter offered as an option.

## The Cloudflare example is fenced as shell and stops mid-function

The last section offers a worker that puts a CDN in front of the deployment, and the example as published cannot run:

```js
export default {
    async fetch(request, env) {
        let url = new URL(request.url);
        if (url.pathname.startsWith('/')) {
            var arrStr = [
                'xxx-xxx.vercel.app',   // 此处单引号里填写你的vercel分配的域名，不包含https://
            ];
            url.protocol = 'https:'
            url.hostname = getRandomArray(arrStr)
            let new_request = new Request(url, request);
            return fetch(new_request);
        }
        return env.ASSETS.fetch(request);
    },
};
function getRandomArray(array) {
  const randomIndex = Math.floor(Math.random() * array.length);
```

Three things are wrong with that block. It is fenced as a shell block while holding an ES module with a default export. The helper function begins, computes a random index from the array length, and is cut off before it returns anything. And the hostname it forwards to is a placeholder the comment asks you to replace with your own assigned domain, with no scheme. The mechanism is simple enough to reconstruct, but a reader who copies the block gets a syntax error and a misleading hint about the environment it expects.

## Twenty-four region codes and four things to check afterwards

The longest part of the README is a reference table mapping 24 Vercel region codes to cities: Tokyo and Osaka, Seoul, Hong Kong, Singapore, Sydney, Mumbai and New Delhi, Frankfurt, London, Paris, Amsterdam, Madrid, Dublin, Dubai, Johannesburg and Cape Town, São Paulo, then five United States regions from San Francisco to Newark, and Montréal. Each row carries the country and a Chinese gloss. After the deployment the README asks for four checks: that the page loads, that the generated subscription link can fetch nodes, that the platform-assigned domain is blocked and therefore cannot be used as a direct connection, and that one monitoring field is left empty because nothing will report to it. That third check is the design constraint stated plainly, and it is the reason the CDN section exists.

## A Node 16 floor and an optional native terminal module

The manifest is short and slightly at odds with the platform it targets. Runtime dependencies are five packages: a websocket library, an HTTP client, two gRPC packages and one that reports host information. The optional dependencies add a native terminal module, which on a serverless function target is a package that has to be compiled per environment and is the kind of dependency that fails the deployment rather than degrading. The engine floor is declared as Node 16 or newer, which is well below what a current serverless runtime offers, so nothing in the manifest is pinning the function to a modern runtime. The five-entry tree has no lock file, which means two installs of the same commit can resolve different dependency versions, and no start configuration beyond the one script. The README never mentions the version of the platform runtime it expects.

## Conclusion

This repository is a deployment note, not software you adopt. Five files, one of which is the README, and the logic lives in a package the manifest names but the tree does not contain, so you are following a recipe rather than reading code. Before you follow it, settle three things. The platform's terms for serving a proxy, and Cloudflare's terms for fronting one, are not something this repository mentions and they are the part that can end your account. There is no license file and no recorded license, so you have no stated permission to reuse or modify any of it. And the disguise step, replacing the visible page and obfuscating the source, is designed to keep the function from being read, which is a decision to make knowingly rather than inherit from a template.

## FAQ

### What is inside the vvxw/deploy-vercel repository?

Five files: the README, an HTML page, a JavaScript entry point, a package manifest and a platform configuration file. The manifest names the package nzws-js, so the repository is a deployment wrapper rather than the implementation of the proxy itself.

### What does the deploy-vercel README say to do after deploying?

Put the reverse-proxied domain into the DOMAIN environment variable and save the file after running the source through an obfuscator it links to, then fetch the subscription information and edit the address field for the preferred domains. It also lists four checks, including that the platform-assigned domain is blocked and cannot be used as a direct connection.

### Does deploy-vercel recommend putting Cloudflare in front?

It has a section for it. The worker rebuilds the request URL onto the Vercel-assigned hostname chosen at random from a list and forwards it, falling back to the static assets binding for other paths. The snippet is published inside a shell fence and ends partway through its helper function.

### Which Node version does the deploy-vercel package declare?

Node 16 or newer, with a single start script running node index.js, five runtime dependencies covering websockets, an HTTP client, two gRPC packages and host information, and a native terminal module declared as an optional dependency.

### What license does deploy-vercel carry?

None is recorded. The license field is empty and the five top-level entries include no license file, so the terms for reuse or modification are not stated anywhere in the repository.

## Sources

- [Issues](https://github.com/vvxw/deploy-vercel/issues)
- [README](https://github.com/vvxw/deploy-vercel/blob/main/README.md)
- [vvxw/deploy-vercel on GitHub](https://github.com/vvxw/deploy-vercel)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/vvxw-deploy-vercel
