yonggekkk/Cloudflare-vless-trojan: Vless and Trojan proxies on Workers and Pages
CF-workers/pages代理脚本:支持Vless-ws(tls)、Trojan-ws(tls);Socks5/http本地代理脚本:可选ECH-TLS、普通TLS、无TLS三种代理模式
At a glance
- What is it?
- A pair of deployment scripts that turn Cloudflare Workers or Pages into VLESS/Trojan proxy endpoints, plus a local Socks5/HTTP helper with ECH, plain TLS and no-TLS modes. It is built for users who want node config edited locally rather than through a subscription converter.
- Who is it for?
- Adopt it if you already run a Cloudflare account and want VLESS or Trojan endpoints whose uuid, password and proxyip live in your own deployment rather than in a third-party subscription panel. Do not adopt it if you need a documented licence, a stable tagged release cadence, or a client that cannot handle Trojan over WebSocket.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 10 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the two script families actually do
This repository is not a proxy server in the usual sense. It is a set of deployment scripts that run inside Cloudflare's edge: one family for Workers and Pages that exposes VLESS and Trojan over WebSocket, and a second family under s5http_wkpgs/ that turns a Workers, Pages or custom domain into a local Socks5 or HTTP proxy. The README states the project supports only local deployment and that all configuration is edited locally, with no subscription converter or third-party subscription link involved. That is the whole pitch: the uuid, the password and the proxyip stay in your deployment instead of passing through someone else's panel.
The intended reader is someone who already has a Cloudflare account and wants a node without buying a VPS. The README is explicit that it does not recommend custom domains, to reduce cost for newcomers, and that the default nodes use Cloudflare's own IPs so subscribers do not have to refresh preferred IPs constantly. Workers mode supports vless+ws+tls, trojan+ws+tls, vless+ws and trojan+ws; Pages mode supports only the two TLS variants. That asymmetry matters if you were planning to run a no-TLS node on Pages.
Variables, proxyip and the /pyip= path override
Configuration is done through variables rather than a config file. For VLESS the required variable is uuid, and the README lists a shared default value it calls a public uuid; for Trojan the required variable is pswd, with a default of trojan. Both are marked as suggestions, not requirements, and the README's own wording implies you should change them.
The interesting variable is proxyip. It is what lets a node reach Cloudflare-hosted sites, and the README says its validity determines whether you can open Cloudflare's own site, X and ChatGPT. It accepts an IPv4 address, a bracketed IPv6 address or a domain, with a port appended when the port is not 443. There are two ways to set it: globally through the proxyip variable, which applies to every node that has not overridden it, or per node through a path segment of the form /pyip=value. The README is clear that once /pyip= appears in a node's path, that node uses only the path value and the global setting is ignored.
There is also a subscription-oriented block of variables, ip1 through ip13 and pt1 through pt13, for preferred IPs and their ports. The README warns that ip1 to ip7 and pt1 to pt7 only apply to non-TLS nodes on 80-series ports in subscription links, while ip8 to ip13 and pt8 to pt13 only apply to TLS nodes on 443-series ports. New users are told to ignore these entirely and keep the defaults.
Deploying on Workers or Pages and reading your first link
The README describes deployment as clicking a Cloudflare deploy button and then editing at most one uuid or password. It does not print the deploy button URL in the text, so the entry point is the repository itself: the Vless_workers_pages/ and Trojan_workers_pages/ directories hold the per-platform scripts. After deploying, the README says you retrieve your configuration by appending your own uuid or password to the deployment hostname in a browser. For VLESS you enter the Pages or custom domain followed by your uuid; for Trojan you enter the same host followed by your password. The README notes that if both the pages domain and the custom domain are blocked, you must enable a proxy before the page will open, and that when you use a custom domain the pages-domain copy of the config and share links still works. What you should see is a page carrying the node link, the aggregated node links, and the sing-box and clash subscription forms.
The second family installs a local proxy helper. The README gives this one-liner, which downloads cfsh.sh and runs it:
curl -sSL https://raw.githubusercontent.com/yonggekkk/Cloudflare_vless_trojan/main/s5http_wkpgs/cfsh.sh -o cfsh.sh && chmod +x cfsh.sh && bash cfsh.shIts required variable is cf_domain, the Workers, Pages or custom domain with a 443-series or 80-series port. token is optional and must match the server side. client_ip is the local listening port, defaulting to 30000 and constrained to the 10000-65000 range. enable_ech takes y or n, cnrule takes y for split routing or n for global, and dns defaults to dns.alidns.com/dns-query. The README also names a Docker image, ygkkk/cfsh, and suggests running this on a router rather than a workstation.
The three proxy modes and where they break
The Socks5/HTTP helper offers ECH-TLS, plain TLS and no-TLS. The mode is not a separate switch. It falls out of two variables: cf_domain and enable_ech. ECH-TLS requires a Workers, Pages or custom domain on a 443-series port with enable_ech=y. Plain TLS requires a Pages or custom domain on a 443-series port with enable_ech=n. No-TLS requires a Workers domain on an 80-series port, with enable_ech either way. The README lists the 80-series ports as 80, 8080, 8880, 2052, 2082, 2086 and 2095, and the 443-series ports as 443, 2053, 2083, 2087, 2096 and 8443.
This is the most constrained part of the project. You cannot mix freely: a custom domain cannot give you a no-TLS node, and a Workers domain is the only thing that can. If your client or network path requires one specific combination, check the table before you deploy anything.
The Trojan situation is worse. The README states that Shadowrocket, v2box, v2rayN and v2rayNG force TLS on trojan+ws, which breaks the plain trojan+ws variant, and that clash subscriptions carry no trojan+ws nodes at all. So the trojan+ws non-TLS option exists in the script but is unreachable from several of the most common clients. If Trojan without TLS is your requirement, this repository will not get you there on those clients.
Preferred IPs, proxyip hosting and what it costs you
The README recommends Cloudflare's official IPs and domains by default and says you do not need to change them unless you are chasing maximum speed or a specific exit country. It lists memorable official IPs such as 104.16.0.0 through 104.27.0.0, 172.66.0.0, 172.67.0.0, 162.159.0.0 and 2606:4700::0 for IPv6 environments, plus a preferred domain pattern of yg1.ygkkk.dpdns.org where the 1 can be replaced by any number from 1 to 11.
For proxyip, the README points at two companion projects, x-ui-yg and sing-box-yg, for self-hosting a proxyip or reverse-proxy IP, and recommends a cheap IPv6-only VPS close to China. It warns that IPv4 addresses are likely to be scanned and reused by others as free or paid reverse-proxy pools, and that if you do use IPv4 you should watch your VPS traffic because both proxyip traffic and client preferred-IP traffic consume it. That is a real operational cost, not a footnote: an open proxyip endpoint is somebody else's free bandwidth.
The README also distinguishes two IP-checking sites by what they show. whatismyip.com should display Cloudflare's 104.28 or 2a09 addresses for non-Cloudflare sites, while ip.sb should display the proxyip address for Cloudflare sites. If ip.sb shows something else, your proxyip is not doing its job.
Alternatives and the difference in approach
The closest alternative in the same space is a subscription-conversion worker such as cmliu/WorkerVless2sub, which appears in the related searches around this project. The difference is architectural. WorkerVless2sub takes an existing node or subscription and rewrites it into another format, so the node list passes through a converter you or someone else operates. This repository does the opposite: it generates the node inside your own Workers or Pages deployment and keeps the format conversion on the client side, which is exactly why the README stresses that no subscription converter is used. If your concern is who can see your node parameters, the two approaches are not equivalent.
A second alternative is running your own server with Xray or sing-box directly, which the README implicitly acknowledges by recommending the author's x-ui-yg and sing-box-yg scripts for building proxyip and reverse-proxy IPs. That path gives you full control over protocols and ports but requires a VPS and a real IP, which is the cost this project exists to avoid. The trade is straightforward: Cloudflare's edge for reach and no server bill, versus your own machine for protocol freedom.
Maintenance, licence and upgrade expectations
The repository is not archived, and the last push was on 2026-09-20, so the code is being touched. That said, the release history is thin: the most recent release listed is tagged serv00 and dated 2024-12-12. The README carries a version marker, V2026.9, and points to a video dated 2026.9.19, which suggests the author ships changes in the README and the script directories rather than through tagged releases. If you pin by release tag, you will be pinning something from 2024.
The licence is not stated in the README or in the repository's top-level entries, which are README.md, Trojan_workers_pages/, Vless_workers_pages/, cf/, locations.json, s5http_wkpgs/ and 优选工具/. That is a genuine gap if you intend to redistribute or vendor the scripts, and it is worth resolving before you build anything on top of them.
Upgrade cost is mostly manual. Because configuration is edited locally and no subscription converter is in the path, moving to a newer script version means re-deploying and re-entering your uuid, password and any ip/pt variables. There is no documented rollback path in the README, and no migration notes. Treat each redeploy as something you should be able to reverse by keeping the previous deployment available.
Editorial conclusion
Adopt it if you already run a Cloudflare account and want VLESS or Trojan endpoints whose uuid, password and proxyip live in your own deployment rather than in a third-party subscription panel. Do not adopt it if you need a documented licence, a stable tagged release cadence, or a client that cannot handle Trojan over WebSocket. Before deploying, verify three things: that Workers custom domains are available on your plan, that your client supports the ws transport variant you pick, and whether you need a proxyip at all for the sites you actually visit.
Frequently asked questions
How do I find my node configuration and share link after deploying yonggekkk/Cloudflare-vless-trojan?
Open a browser and append your uuid to the Pages or custom domain for VLESS, or your password for Trojan. The README notes that if both domains are blocked you must enable a proxy before the page will load, and that the Pages-domain config remains available even when you use a custom domain.
Why can't I open Cloudflare sites, X or ChatGPT through a yonggekkk/Cloudflare-vless-trojan node?
The README states that proxyip validity determines whether Cloudflare sites, X and ChatGPT are reachable. You can set it globally with the proxyip variable, or per node with a /pyip= path segment, and the path value overrides the global one for that node.
Does yonggekkk/Cloudflare-vless-trojan work with Trojan over WebSocket in Clash?
No. The README states that clash subscriptions contain no trojan+ws nodes, and that Shadowrocket, v2box, v2rayN and v2rayNG force TLS on trojan+ws, which prevents the non-TLS trojan+ws variant from working on those clients.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/yonggekkk-cloudflare-vless-trojan)