Open source VPN and networking tools, installed and run

VPN and networking tools you can run yourself. The list is ordered by whether each project came up when Argusic installed it fresh, with the recording of that attempt one click away.

Tested between and . Each row shows its own test date; a project can change after that day.

17 of 20 tested projects run. 33 more waiting for a test.

In short: 10 of the 20 tested projects started as-is on a fresh machine: tailscale, wgcf, boringtun, wstunnel, wireproxy, tun2socks, wg-portal, and rosenpass, and 2 more. 7 more started once a stand-in replaced a service they expect, such as a database: firezone, wireguard-install, kilo, tsdproxy, wiredoor, headscale, and MicroWARP. 3 could not be verified: wireguard-install, openvpn-install, and pivpn; the log shows where each one stopped.

Measured by Argusic on a fresh machine every time. Every number links to its evidence.

#projectverdictArgusic Scorelanguagestarstested on
1tailscaleRuns100 / 100Go37,270

The easiest, most secure way to use WireGuard and 2FA.

What the test found: Tailscale tailscale and tailscaled binaries built from source at commit d229a06f and all exercised tests pass. 11 minutes.

2wgcfRuns100 / 100Go8,780

๐Ÿšค Cross-platform, unofficial CLI for Cloudflare Warp

What the test found: The wgcf CLI builds, passes all 4 test suites (cloudflare, cmd/generate, util, wireguard), and successfully registers accounts, generates WireGuard profiles, and returns live account status and connection telemetry from the real Cloudflare WARP API. 3 minutes.

3boringtunRuns100 / 100Rust7,214

Userspace WireGuardยฎ Implementation in Rust

What the test found: BoringTun library compiles and 16/25 unit tests pass (9 integration tests skipped, require TUN/sudo); CLI binary builds and outputs version 0.7.1 and full usage text. 5 minutes.

4wstunnelRuns100 / 100Rust7,089

Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available

What the test found: wstunnel v11.0.0 builds, all 38 runnable tests pass, and end-to-end TCP tunneling via WebSocket works: a local HTTP server served content over the tunnel returning HTTP 200. 15 minutes.

5wireproxyRuns100 / 100Go5,836

Wireguard client that exposes itself as a socks5 proxy

What the test found: Wireproxy builds from source, passes all unit tests (19/19), prints version, validates configurations via --configtest, starts a WireGuard userspace interface, binds a SOCKS5 proxy port that responds correctly to SOCKS5 handshakes, and serves a health/readyz endpoint on demand. 6 minutes.

6tun2socksRuns100 / 100Go5,522

tun2socks - powered by gVisor TCP/IP stack

What the test found: tun2socks builds and passes all tests with Go 1.26.8 on linux/amd64; the binary prints version info and help flags; no packages failed or were skipped. 3 minutes.

7wg-portalRuns100 / 100Go1,838

WireGuard Configuration Portal with LDAP connection

What the test found: The wg-portal server builds, starts, serves the web UI and Prometheus metrics, accepts the documented default admin login, and its full Go test suite passes (283 tests, 0 failures). 15 minutes.

8rosenpassRuns100 / 100Rust1,423

Rosenpass is a post-quantum-secure VPN that uses WireGuard to transport the actual data.

What the test found: Rosenpass 0.3.0-dev builds, all 91 lib unit tests and 27 doc tests and 4 integration tests pass, the rosenpass binary prints help and generates Classic McEliece 8192 keypairs. 10 minutes.

9gluetunRuns95 / 100Go15,736

VPN client in a thin Docker container for multiple VPN providers, written in Go, and using OpenVPN or Wireguard, DNS over TLS, with a few proxy servers...

What the test found: The Go project builds, all non-privileged unit tests pass, and the binary successfully executes CLI commands (genkey, healthcheck) and starts up to the iptables initialization step. 11 minutes.

10wireguard-docsRuns90 / 100Shell5,050

๐Ÿ“– Unofficial WireGuard Documentation: Setup, Usage, Configuration, and full example setups for VPNs supporting both servers & roaming clients.

What the test found: The repo's example start.sh/stop.sh scripts run successfully on the container's built-in kernel WireGuard (built wg/ip toolchain in /tmp/wgtools), establishing real encrypted tunnels and passing TCP echo traffic across the example-simple-server-to-server, example-simple-client-to-server, example-internet-browsing-vpn... 30 minutes.

11firezoneRuns with mocks92 / 100Elixir9,106

Blazing-fast remote access

What the test found: Rust data-plane workspace builds gateway v1.6.3, headless-client v1.5.14, and http-test-server; 789 library tests pass; http-test-server responds 200 on its /bytes endpoint. 20 minutes.

12wireguard-installRuns with mocks92 / 100Shell4,931

WireGuard road warrior installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and Fedora

What the test found: The wireguard-install.sh script has valid shell syntax and all four code paths (install, add client, remove client, uninstall) execute correctly through their logic; the npm wireguard-tools.js package provides WireGuard key generation and config management that works in this container without root. 13 minutes.

13kiloRuns with mocks92 / 100Go2,293

Kilo is a multi-cloud network overlay built on WireGuard and designed for Kubernetes (k8s + wg = kg)

What the test found: Both binaries (kg, kgctl) compile and run. All 5 unit test packages pass. The kgctl CLI responds with correct usage output for all 5 commands. 31 minutes.

14tsdproxyRuns with mocks92 / 100Go1,712

Automatic Tailscale reverse proxy for Docker containers. Zero sidecars. Label-based config. Automatic HTTPS.

What the test found: Binary at tmp/tsdproxy builds, all 1900 unit tests pass, the server serves HTTP 200 on localhost:8080 for both the dashboard root and health/ready endpoints, and Tailscale proxy creation awaits real OAuth/AuthKey credentials. 7 minutes.

15wiredoorRuns with mocks92 / 100TypeScript1,622

Self hosted ingress-as-a-service platform that allows you to expose applications and services running in private or local networks to the internet

What the test found: All 10 test suites pass (88/88 tests), TypeScript compiles with no errors, and the application boots past database migration with a mock wg binary in PATH, failing only at system-level directory creation (/etc/wireguard, /etc/nginx) which requires root. 8 minutes.

16headscaleRuns with mocks72 / 100Go44,432

An open source, self-hosted implementation of the Tailscale control server

What the test found: Headscale builds from source with Go 1.27.1; server starts and responds 200 HTTP on /health; unit tests pass across all core packages; integration tests are unavailable without Docker. 83 minutes.

17MicroWARPRuns with mocks46 / 100Shell1,447

๐Ÿš€ An 800KB RAM ultra-lightweight Cloudflare WARP SOCKS5 proxy in Docker. ไป…้œ€ 800KB ๅ†…ๅญ˜็š„็บฏๅ†…ๆ ธๆ€ Cloudflare WARP ไปฃ็† - Docker

What the test found: microsocks SOCKS5 proxy built from source and verified with real traffic, usque v4.2.1 binary extracted and registered with real Cloudflare WARP MASQUE API, entrypoint script passes shellcheck and runs both WireGuard and MASQUE paths end-to-end through real WARP registration into listening SOCKS5 proxies. 16 minutes.

18wireguard-installCould not verify25 / 100Shell11,330

WireGuard VPN installer for Linux servers

What the test found: The bash script passes syntax, shellcheck, and shfmt validation. Its core functions (OS detection, home directory resolution, error handling) were verified via mock tests passing 10/10. The CI lint workflow (the project's only automated check) is green. The installer cannot proceed past the root-check because this... 5 minutes.

19openvpn-installCould not verify20 / 100Shell1,747

OpenVPN server installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, Fedora, openSUSE, Amazon Linux and Raspberry Pi OS. Includes interactive setup and...

What the test found: The script's shell syntax, all validation utilities, argument parsing, OS detection logic, and install flow path are verified correct; OpenSSL cryptographic primitives work. Real installation and service launch require root, /dev/net/tun, and package installation, all unavailable in this container. 14 minutes.

20pivpnCould not verify17.5 / 100Shell8,044

The Simplest VPN installer, designed for Raspberry Pi

What the test found: All PiVPN scripts pass syntax validation and ShellCheck with zero errors. The WireGuard management scripts (makeCONF/list/remove) are verified functional with real key generation via extracted wg binary. The installer requires root privileges on a Debian/Ubuntu system to complete system installation. 24 minutes.

-wireguard-installNot yet tested-Shell2,908-
-amneziawg-installerNot yet tested-Shell1,353-
-ShahanPanelNot yet tested-PHP1,203-
-onetunNot yet tested-Rust1,042-
-wireguirdNot yet tested-Go1,036-
-omniedgeNot yet tested-Rust891-
-superNot yet tested-JavaScript869-
-dsnetNot yet tested-Go753-
-wagNot yet tested-Go731-
-vortixNot yet tested-Rust707-
-awlNot yet tested-Go696-
-docker-mac-net-connectNot yet tested-Go665-
-wg-managerNot yet tested-Python633-
-MikroDashNot yet tested-Go611-
-All-jellyfin-media-serverNot yet tested-Shell571-
-app-tailscaleNot yet tested-Shell555-
-nylonNot yet tested-Go519-
-meridianNot yet tested-Python492-
-free-proxy-listNot yet tested-Go422-
-wireguard-guiNot yet tested-TypeScript326-
-wireguard_webadminNot yet tested-JavaScript291-
-tunwgNot yet tested-Go287-
-wireguard-vanity-keygenNot yet tested-Go269-
-realworlddevopscourseNot yet tested-Shell267-
-OPNsensePIAWireguardNot yet tested-Python266-
-vproxNot yet tested-Go242-
-wgrestNot yet tested-Go229-
-wg-cmdNot yet tested-Go226-
-SwizGuardNot yet tested-Shell224-
-MeshLANNot yet tested-Go222-
-uncompressedNot yet tested-Shell215-
-CELERITY-panelNot yet tested-JavaScript213-
-Wireguard-panelNot yet tested-Python207-

runs installed and started with its real dependencies. runs with mocks started after stand-ins replaced external services such as a database or a third-party API. could not verify neither the standard agent nor the stronger one got it running within the time limit; the log shows where it stopped.

How we tested

On this list as of the latest test: 10 projects ran as-is, 7 with mocks, 3 could not be verified, 33 still waiting. Languages tested: Elixir, Go, Rust, Shell, TypeScript. Every attempt used a clean single-use machine, the subject at a pinned version, and a 45-minute limit; the complete procedure is on the methodology page.

Frequently asked questions (FAQs)

How is this list ranked?

By measurement, not opinion: projects Argusic installed and launched on a fresh machine come first, then those that ran with mocks in place of external services, then those it could not verify. Ties go to the Argusic Score, then how popular it is on its own source.

Why are some projects unranked?

33 projects are still waiting for a test or for a finished attempt. They are listed without a rank until Argusic has measured them.

Where is the evidence?

Every row links to the project's Argusic page, where each run has a full log and a terminal recording stored with a sha256 fingerprint. The same pages exist for every one of the tested projects, on this list or not.

More lists in this category

All lists: Best. All tested projects: subjects.