About this project
3X-UI is an open-source web control panel for deploying, configuring and monitoring Xray-core servers. It is described as an enhanced fork of the original X-UI project, adding broader protocol support, per-client traffic accounting and additional management features. The README notes it is intended for personal use and not for production or illegal purposes.
Protocol and transport support
Inbound protocols listed include VLESS, VMess, Trojan, Shadowsocks, WireGuard, AmneziaWG, TUIC v5, Hysteria2, MTProto, HTTP, SOCKS (Mixed), Dokodemo-door / Tunnel and TUN. Transports include TCP (Raw), mKCP, WebSocket, gRPC, HTTPUpgrade and XHTTP, with TLS, XTLS and REALITY security. Fallbacks allow multiple protocols to share one port. AmneziaWG is described as running inside the panel on a userspace network stack without a kernel module or DKMS. TUIC v5 is implemented as a sidecar with UDP relay traffic metering, 0-RTT handshakes and BBR congestion control. MTProto proxies support per-client FakeTLS secrets, ad-tags and quotas applied live.
Client and traffic management
Per-client features include traffic quotas, expiry dates, IP limits with trusted-address exemptions, HWID device limits, scheduled renewal cycles, live online status, share links, QR codes and subscriptions. Traffic statistics are tracked per inbound, per client and per outbound, with reset controls. Fail2ban integration enforces per-client IP limits.
Deployment and operations
Installation is via a shell script that generates random credentials and an access path; a management menu is opened with the x-ui command. Non-interactive installation is supported for cloud-init, with credentials written to /etc/x-ui/install-result.env. Release assets ship with .sha256 sums verified by the installer and updater. Supported operating systems include Ubuntu, Debian, Armbian, Fedora, CentOS, RHEL, AlmaLinux, Rocky Linux, Oracle Linux, Amazon Linux, Virtuozzo, Arch, Manjaro, Parch, openSUSE, Alpine and Windows, across amd64, 386, arm64, armv7, armv6, armv5 and s390x architectures. Storage can be SQLite (default) or PostgreSQL, with a documented migration command from SQLite to PostgreSQL. Docker Compose deployment is supported, including an optional bundled PostgreSQL profile; the image bundles Fail2ban and requires NET_ADMIN and NET_RAW capabilities for bans to be applied.
Other capabilities
Multi-node support allows managing and scaling across servers from one panel, including cloning inbounds to other nodes. Outbound and routing features include WARP, NordVPN, PIA, custom routing rules, load balancers with balancer-to-balancer fallback, outbound proxy chaining, and browsable geosite/geoip categories in the rule editor. A built-in subscription server outputs raw, JSON and Clash formats selected from the client User-Agent, with custom page templates. Telegram and Discord bots provide remote monitoring and management. A RESTful API offers scoped, optionally expiring tokens and an in-panel API reference. The panel is installable as a PWA. The UI is available in 13 languages with dark and light themes. A tunnel health monitor can probe a URL and restart xray after repeated failures. Node API tokens can be encrypted at rest via a keyring configuration. A full environment variable reference is linked in the documentation.
Community tools mentioned include a Terraform/OpenTofu provider for managing inbounds, clients, panel settings and Xray configuration as code, and a native Android client for dashboards, inbounds, clients with QR sharing, nodes and multi-panel management.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.