Open source VPN and networking tools, installed and run
VPN and networking tools you can run yourself. The list is ordered by whether each project came up when Argusic installed it fresh, with the recording of that attempt one click away.
Tested between and . Each row shows its own test date; a project can change after that day.
17 of 20 tested projects run. 33 more waiting for a test.
In short: 10 of the 20 tested projects started as-is on a fresh machine: tailscale, wgcf, boringtun, wstunnel, wireproxy, tun2socks, wg-portal, and rosenpass, and 2 more. 7 more started once a stand-in replaced a service they expect, such as a database: firezone, wireguard-install, kilo, tsdproxy, wiredoor, headscale, and MicroWARP. 3 could not be verified: wireguard-install, openvpn-install, and pivpn; the log shows where each one stopped.
Measured by Argusic on a fresh machine every time. Every number links to its evidence.
| # | project | verdict | Argusic Score | language | stars | tested on |
|---|---|---|---|---|---|---|
| 1 | tailscale | Runs | 100 / 100 | Go | 37,270 | |
The easiest, most secure way to use WireGuard and 2FA. What the test found: Tailscale tailscale and tailscaled binaries built from source at commit d229a06f and all exercised tests pass. 11 minutes. | ||||||
| 2 | wgcf | Runs | 100 / 100 | Go | 8,780 | |
๐ค Cross-platform, unofficial CLI for Cloudflare Warp What the test found: The wgcf CLI builds, passes all 4 test suites (cloudflare, cmd/generate, util, wireguard), and successfully registers accounts, generates WireGuard profiles, and returns live account status and connection telemetry from the real Cloudflare WARP API. 3 minutes. | ||||||
| 3 | boringtun | Runs | 100 / 100 | Rust | 7,214 | |
Userspace WireGuardยฎ Implementation in Rust What the test found: BoringTun library compiles and 16/25 unit tests pass (9 integration tests skipped, require TUN/sudo); CLI binary builds and outputs version 0.7.1 and full usage text. 5 minutes. | ||||||
| 4 | wstunnel | Runs | 100 / 100 | Rust | 7,089 | |
Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available What the test found: wstunnel v11.0.0 builds, all 38 runnable tests pass, and end-to-end TCP tunneling via WebSocket works: a local HTTP server served content over the tunnel returning HTTP 200. 15 minutes. | ||||||
| 5 | wireproxy | Runs | 100 / 100 | Go | 5,836 | |
Wireguard client that exposes itself as a socks5 proxy What the test found: Wireproxy builds from source, passes all unit tests (19/19), prints version, validates configurations via --configtest, starts a WireGuard userspace interface, binds a SOCKS5 proxy port that responds correctly to SOCKS5 handshakes, and serves a health/readyz endpoint on demand. 6 minutes. | ||||||
| 6 | tun2socks | Runs | 100 / 100 | Go | 5,522 | |
tun2socks - powered by gVisor TCP/IP stack What the test found: tun2socks builds and passes all tests with Go 1.26.8 on linux/amd64; the binary prints version info and help flags; no packages failed or were skipped. 3 minutes. | ||||||
| 7 | wg-portal | Runs | 100 / 100 | Go | 1,838 | |
WireGuard Configuration Portal with LDAP connection What the test found: The wg-portal server builds, starts, serves the web UI and Prometheus metrics, accepts the documented default admin login, and its full Go test suite passes (283 tests, 0 failures). 15 minutes. | ||||||
| 8 | rosenpass | Runs | 100 / 100 | Rust | 1,423 | |
Rosenpass is a post-quantum-secure VPN that uses WireGuard to transport the actual data. What the test found: Rosenpass 0.3.0-dev builds, all 91 lib unit tests and 27 doc tests and 4 integration tests pass, the rosenpass binary prints help and generates Classic McEliece 8192 keypairs. 10 minutes. | ||||||
| 9 | gluetun | Runs | 95 / 100 | Go | 15,736 | |
VPN client in a thin Docker container for multiple VPN providers, written in Go, and using OpenVPN or Wireguard, DNS over TLS, with a few proxy servers... What the test found: The Go project builds, all non-privileged unit tests pass, and the binary successfully executes CLI commands (genkey, healthcheck) and starts up to the iptables initialization step. 11 minutes. | ||||||
| 10 | wireguard-docs | Runs | 90 / 100 | Shell | 5,050 | |
๐ Unofficial WireGuard Documentation: Setup, Usage, Configuration, and full example setups for VPNs supporting both servers & roaming clients. What the test found: The repo's example start.sh/stop.sh scripts run successfully on the container's built-in kernel WireGuard (built wg/ip toolchain in /tmp/wgtools), establishing real encrypted tunnels and passing TCP echo traffic across the example-simple-server-to-server, example-simple-client-to-server, example-internet-browsing-vpn... 30 minutes. | ||||||
| 11 | firezone | Runs with mocks | 92 / 100 | Elixir | 9,106 | |
Blazing-fast remote access What the test found: Rust data-plane workspace builds gateway v1.6.3, headless-client v1.5.14, and http-test-server; 789 library tests pass; http-test-server responds 200 on its /bytes endpoint. 20 minutes. | ||||||
| 12 | wireguard-install | Runs with mocks | 92 / 100 | Shell | 4,931 | |
WireGuard road warrior installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and Fedora What the test found: The wireguard-install.sh script has valid shell syntax and all four code paths (install, add client, remove client, uninstall) execute correctly through their logic; the npm wireguard-tools.js package provides WireGuard key generation and config management that works in this container without root. 13 minutes. | ||||||
| 13 | kilo | Runs with mocks | 92 / 100 | Go | 2,293 | |
Kilo is a multi-cloud network overlay built on WireGuard and designed for Kubernetes (k8s + wg = kg) What the test found: Both binaries (kg, kgctl) compile and run. All 5 unit test packages pass. The kgctl CLI responds with correct usage output for all 5 commands. 31 minutes. | ||||||
| 14 | tsdproxy | Runs with mocks | 92 / 100 | Go | 1,712 | |
Automatic Tailscale reverse proxy for Docker containers. Zero sidecars. Label-based config. Automatic HTTPS. What the test found: Binary at tmp/tsdproxy builds, all 1900 unit tests pass, the server serves HTTP 200 on localhost:8080 for both the dashboard root and health/ready endpoints, and Tailscale proxy creation awaits real OAuth/AuthKey credentials. 7 minutes. | ||||||
| 15 | wiredoor | Runs with mocks | 92 / 100 | TypeScript | 1,622 | |
Self hosted ingress-as-a-service platform that allows you to expose applications and services running in private or local networks to the internet What the test found: All 10 test suites pass (88/88 tests), TypeScript compiles with no errors, and the application boots past database migration with a mock wg binary in PATH, failing only at system-level directory creation (/etc/wireguard, /etc/nginx) which requires root. 8 minutes. | ||||||
| 16 | headscale | Runs with mocks | 72 / 100 | Go | 44,432 | |
An open source, self-hosted implementation of the Tailscale control server What the test found: Headscale builds from source with Go 1.27.1; server starts and responds 200 HTTP on /health; unit tests pass across all core packages; integration tests are unavailable without Docker. 83 minutes. | ||||||
| 17 | MicroWARP | Runs with mocks | 46 / 100 | Shell | 1,447 | |
๐ An 800KB RAM ultra-lightweight Cloudflare WARP SOCKS5 proxy in Docker. ไป ้ 800KB ๅ ๅญ็็บฏๅ ๆ ธๆ Cloudflare WARP ไปฃ็ - Docker What the test found: microsocks SOCKS5 proxy built from source and verified with real traffic, usque v4.2.1 binary extracted and registered with real Cloudflare WARP MASQUE API, entrypoint script passes shellcheck and runs both WireGuard and MASQUE paths end-to-end through real WARP registration into listening SOCKS5 proxies. 16 minutes. | ||||||
| 18 | wireguard-install | Could not verify | 25 / 100 | Shell | 11,330 | |
WireGuard VPN installer for Linux servers What the test found: The bash script passes syntax, shellcheck, and shfmt validation. Its core functions (OS detection, home directory resolution, error handling) were verified via mock tests passing 10/10. The CI lint workflow (the project's only automated check) is green. The installer cannot proceed past the root-check because this... 5 minutes. | ||||||
| 19 | openvpn-install | Could not verify | 20 / 100 | Shell | 1,747 | |
OpenVPN server installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS, Fedora, openSUSE, Amazon Linux and Raspberry Pi OS. Includes interactive setup and... What the test found: The script's shell syntax, all validation utilities, argument parsing, OS detection logic, and install flow path are verified correct; OpenSSL cryptographic primitives work. Real installation and service launch require root, /dev/net/tun, and package installation, all unavailable in this container. 14 minutes. | ||||||
| 20 | pivpn | Could not verify | 17.5 / 100 | Shell | 8,044 | |
The Simplest VPN installer, designed for Raspberry Pi What the test found: All PiVPN scripts pass syntax validation and ShellCheck with zero errors. The WireGuard management scripts (makeCONF/list/remove) are verified functional with real key generation via extracted wg binary. The installer requires root privileges on a Debian/Ubuntu system to complete system installation. 24 minutes. | ||||||
| - | wireguard-install | Not yet tested | - | Shell | 2,908 | - |
| - | amneziawg-installer | Not yet tested | - | Shell | 1,353 | - |
| - | ShahanPanel | Not yet tested | - | PHP | 1,203 | - |
| - | onetun | Not yet tested | - | Rust | 1,042 | - |
| - | wireguird | Not yet tested | - | Go | 1,036 | - |
| - | omniedge | Not yet tested | - | Rust | 891 | - |
| - | super | Not yet tested | - | JavaScript | 869 | - |
| - | dsnet | Not yet tested | - | Go | 753 | - |
| - | wag | Not yet tested | - | Go | 731 | - |
| - | vortix | Not yet tested | - | Rust | 707 | - |
| - | awl | Not yet tested | - | Go | 696 | - |
| - | docker-mac-net-connect | Not yet tested | - | Go | 665 | - |
| - | wg-manager | Not yet tested | - | Python | 633 | - |
| - | MikroDash | Not yet tested | - | Go | 611 | - |
| - | All-jellyfin-media-server | Not yet tested | - | Shell | 571 | - |
| - | app-tailscale | Not yet tested | - | Shell | 555 | - |
| - | nylon | Not yet tested | - | Go | 519 | - |
| - | meridian | Not yet tested | - | Python | 492 | - |
| - | free-proxy-list | Not yet tested | - | Go | 422 | - |
| - | wireguard-gui | Not yet tested | - | TypeScript | 326 | - |
| - | wireguard_webadmin | Not yet tested | - | JavaScript | 291 | - |
| - | tunwg | Not yet tested | - | Go | 287 | - |
| - | wireguard-vanity-keygen | Not yet tested | - | Go | 269 | - |
| - | realworlddevopscourse | Not yet tested | - | Shell | 267 | - |
| - | OPNsensePIAWireguard | Not yet tested | - | Python | 266 | - |
| - | vprox | Not yet tested | - | Go | 242 | - |
| - | wgrest | Not yet tested | - | Go | 229 | - |
| - | wg-cmd | Not yet tested | - | Go | 226 | - |
| - | SwizGuard | Not yet tested | - | Shell | 224 | - |
| - | MeshLAN | Not yet tested | - | Go | 222 | - |
| - | uncompressed | Not yet tested | - | Shell | 215 | - |
| - | CELERITY-panel | Not yet tested | - | JavaScript | 213 | - |
| - | Wireguard-panel | Not yet tested | - | Python | 207 | - |
runs installed and started with its real dependencies. runs with mocks started after stand-ins replaced external services such as a database or a third-party API. could not verify neither the standard agent nor the stronger one got it running within the time limit; the log shows where it stopped.
How we tested
On this list as of the latest test: 10 projects ran as-is, 7 with mocks, 3 could not be verified, 33 still waiting. Languages tested: Elixir, Go, Rust, Shell, TypeScript. Every attempt used a clean single-use machine, the subject at a pinned version, and a 45-minute limit; the complete procedure is on the methodology page.
Frequently asked questions (FAQs)
How is this list ranked?
By measurement, not opinion: projects Argusic installed and launched on a fresh machine come first, then those that ran with mocks in place of external services, then those it could not verify. Ties go to the Argusic Score, then how popular it is on its own source.
Why are some projects unranked?
33 projects are still waiting for a test or for a finished attempt. They are listed without a rank until Argusic has measured them.
Where is the evidence?
Every row links to the project's Argusic page, where each run has a full log and a terminal recording stored with a sha256 fingerprint. The same pages exist for every one of the tested projects, on this list or not.
More lists in this category
- API gateways (shares tsdproxy, wiredoor with this list)
- Open source music servers, installed and played (shares All-jellyfin-media-server with this list)
- workflow automation tools (shares amneziawg-installer with this list)
- self-hosted dashboards (shares MikroDash with this list)
- AI agent frameworks
- self-hosted AI apps
- API clients
- CI/CD tools
- CMS platforms
- LLM gateways
- MCP servers
- backup tools
- browser automation tools
- code editors
- open source coding agents
- Open source databases, installed and queried
- developer CLI tools
- e-commerce platforms
- ebook readers
- game engines
- open source games
- home automation tools
- low-code platforms
- map tools
- message queues
- observability tools
- Open source office suites, installed and launched
- self-hosted password managers
- project management tools
- screen recorders
- search engines
- self-hosted analytics
- speech tools
- static site generators
- uptime monitors
- vector databases
- open source video editors
- video players
- web scraping tools
- whiteboard tools
- wikis
- self-hosted Notion alternatives
- self-hosted git servers