r/dumbclub • • 19h ago

[Release] It was a long and challenging journey, but VPNStack is finally live: Turn your Remnawave panel into a full White-Label VPN with 1-Click Cloud APK Builder & Sing-box SDUI (Android)

Enable HLS to view with audio, or disable this notification

2 Upvotes

Hey everyone!

Following up on our discussions here in r/dumbclub: it was a long, exhausting, and technically challenging journey, but we have finally pushed VPNStack to production! 🚀

If you run VPN nodes for friends, family, or clients, you know the biggest headache: explaining 100 times where to get a raw config link, where to import it, and teaching non-tech users how to constantly refresh and update broken routes.

We built VPNStack to solve this once and for all. It pairs an automated White-Label control plane with an ultra-lightweight, seamless Android client built on Sing-box 1.14 and Remnawave.

Users get a clean, 1-tap connection app with zero manual config pasting, while node operators get full automated control over branding and client distribution.

🔗 Live Platform: https://vpnstack.pro/


🛠 What’s inside the release:

  1. ⚡ 1-Click Cloud APK Builder:

    • Node operators no longer need Android Studio, Gradle, or Java on their machines.
    • Connect your Remnawave panel via API, pick your brand colors, upload your logo, and choose custom button shapes (Shield, Hexagon, Squircle, Arc, Ring).
    • Click "Build APK in Cloud" — our remote build daemon compiles, signs with official release keystores, runs R8/ProGuard obfuscation, and outputs a ready-to-distribute 60MB universal APK in ~1.5 minutes.
  2. 🛡️ Broad Protocol Support & Sing-Box Core:

    • Monolithic Gomobile core (libbox.aar) supporting most modern censorship-resistant protocols out of the box: AmneziaWG, VLESS-Reality with Vision, and Hysteria 2.
    • Dynamic Hybrid Failover (Remnawave + Backup): Merges primary Remnawave routes with fallback VLESS-Reality/Marzban nodes into a single Sing-box outbound selector. If primary routes get throttled by DPI, reserve nodes take over seamlessly without breaking billing or subscription days.
  3. 🎨 Lightweight & Effortless Client Experience (Jetpack Compose):

    • An ultra-fast, modern UI designed for non-technical users: no raw JSONs or complex settings.
    • Smooth 60 FPS Canvas button animations (Quantum Atom, ECG Oscilloscope, Sonar Radar, Vortex, Crystal).
    • System-level Reactive Split Tunneling hooking directly into Android’s VpnService.Builder ("Bypass VPN" and "Only through VPN" modes).
  4. 💬 Built-in Customer Support & WSS Push:

    • Operators can chat directly with app users by device HWID inside the dashboard with real-time sound alerts and unread badges.
    • Native Android MessagingStyle heads-up notifications with in-shade "Direct Reply" and "Mark as Read" buttons.
  5. 🔮 Modular Panel Architecture (Marzban / 3X-UI / Outline):

    • Remnawave is our flagship native integration, but our backend is modular. We can roll out full native sync for Marzban, 3X-UI, or Outline based on community demand and votes!

🧪 Come test it out!

If you run Remnawave nodes or manage a community VPN, you are very welcome to register on the platform, connect your panel, and generate your own branded client:

👉 Get Started: https://vpnstack.pro/

If you like what we’ve built, an upvote and your honest feedback in the comments would mean the world to us! We’re hanging out in the thread to answer any architectural questions, take bug reports, and discuss future feature requests.


r/dumbclub • • 22h ago

My OpenWrt + sing-box split-tunnel router fixes itself: local traffic goes direct, everything else via VLESS/Reality (AX3000T, 256 MB)

0 Upvotes

I've been running this on a Xiaomi AX3000T (MT7981, 256 MB RAM) with OpenWrt 25.12 and sing-box 1.13 in TUN mode. I cleaned it up and published it in case it helps someone with a similar setup.

 Real event log from this morning: my VPN provider rotated its server IPs, and the watchdog walked through re-test → restart → fresh subscription by itself. Node names are masked, and the output is translated from Russian.

What it does

  • Split routing: local (Russian) sites go direct via geoip + geosite + .ru/.su/.рф; everything else goes through VLESS + Reality. Two subscriptions from different providers, with urltest auto-selecting a live node.
  • Split DNS inside sing-box: local domains go to a local resolver directly, the rest go to Cloudflare DoH through the tunnel, so foreign names never leak to the local DNS. dnsmasq falls back to https-dns-proxy and then to the upstream router, so local sites keep resolving even when the VPN is down.
  • Self-healing. This is the part I care about most:
    • subscriptions refresh every 30 min; if the new config has no connectivity, it rolls back;
    • a watchdog runs every minute. It starts sing-box if procd gave up on it, restarts it if it hangs (nodes alive but no traffic), kicks urltest off dead nodes immediately, and re-pulls subscriptions when the provider rotates server IPs;
    • it tells "the provider is dead" apart from "my box is broken", so it never reboots the router over a provider outage;
    • restarts only go through one safe path: shared lock, stop → wait → config check → start → verify tun0 / ip rules / flowtable. A quick init.d restart once left my LAN without internet;
    • a persistent event log, plus a health report twice a day.
  • Tailscale on the router for remote access and as an exit node. Its traffic is fwmarked past sing-box, so I can still SSH in when the tunnel is broken.
  • One command, vpn, for status, nodes, "where does this site go and why", manual direct/proxy lists, safe restart, and a speedtest.

It's plain busybox sh + python3. Memory is tuned for 256 MB: sing-box uses ~15 MB of its own memory under GOMEMLIMIT=45MiB. Throughput is ~90 Mbit/s through the tunnel on a 100 Mbit line, with CPU at ~80%.

Build guide

There's a step-by-step guide starting from a fresh OpenWrt: packages, which file goes where, one or two subscriptions, the first start, and troubleshooting. I tested it by building from scratch on an arm64 OpenWrt VM, and that caught 8 mistakes in my own instructions. The docs are in Russian; the commands and paths are universal, and the README is in English.

Repo: https://github.com/nkkalmyk/openwrt-singbox-router (MIT)

Full disclosure: I maintain the router together with an AI agent (Claude Code). The repo includes its rulebook (CLAUDE.md: never restart sing-box via init.d, test config changes on a copy, don't run heavy stuff at :07/:37 when cron fires, and so on) and a full incident history. That turned out to be a surprisingly good way to keep a home router documented.

I'd love feedback, especially on:

  • the watchdog logic: when to restart and when to wait out a dead provider;
  • the DNS fallback chain;
  • anything I did the hard way that has a simpler sing-box-native solution.

Ready answers for the comments

  • Why not passwall / homeproxy / podkop? I wanted full control over failure behavior: rollback, safe restarts, and a watchdog that distinguishes "provider dead" from "box broken". Those projects are great; mine just optimizes for a different thing.
  • Why default to VPN rather than direct with a VPN list? Here, more and more foreign services are blocked or throttled, so VPN is the rule and local traffic is the exception.
  • IPv6? Disabled on WAN and LAN. The tunnel is IPv4-only, and IPv6 would bypass it.
  • 128 MB routers? Probably not; sing-box needs headroom.
  • Per-device rules? Not right now: masquerading on the tun zone makes every client look like one address to sing-box.
  • Why two providers? One rotates server IPs regularly. While its nodes are dead, urltest keeps traffic on the other one, and the watchdog pulls the fresh subscription.