A high-performance, open-source anti-DPI / anti-censorship tunnel in Go. It hides encrypted VLESS/Trojan traffic behind a 16-mimic arsenal — SSH, TLS/HTTPS, mail, databases, and hosting/devops panels — assembled into coherent server personas, over dynamic self-scaling pools. Optional TUN + transparent gateway mode route a whole LAN through the tunnel, and it runs on MikroTik/RouterOS and in Docker.
bash <(curl -fsSL https://raw.githubusercontent.com/hedioum/Hedioum-Pool-Tunnel/main/install.sh)
One node listens behind SSH, TLS/HTTPS, mail (SMTP/IMAP/SMTPS/IMAPS), databases (PostgreSQL/MySQL) and hosting/devops panels (cPanel, WHM, Webmail, DirectAdmin, Docker Registry, Grafana, Prometheus) — assembled into coherent server personas, with a per-install shifting on-wire signature.
Ships as a tiny multi-arch FROM scratch image (~17 MB). Transparent gateway mode routes a whole LAN through the tunnel with no per-device change — validated end-to-end on a real RouterOS container and a Linux router.
With a domain, the TLS mimic serves a genuine, auto-renewing ACME certificate — CT-logged like any real HTTPS host — with a safe self-signed fallback.
ChaCha20-Poly1305 + HKDF. The token is never sent on the wire and channel-bound auth defeats MITM — with a single crypto layer for high throughput.
SSH is the long-lived backbone; non-SSH pipes retire on a randomized time/byte budget and churn to fresh connections — no fixed long-lived signature.
Least-loaded balancing that scales on real bandwidth, fluctuating rate caps, and zero-downtime draining — no lag when connections cycle.
One SOCKS5 port serves TCP and UDP-over-TCP, so QUIC/HTTP3, DNS and voice/video work — on an isolated sub-pool, with no DNS leak by design.
Unauthorized probes get a real sshd, a DirectAdmin login, or a per-install-unique web page — even the bare IP looks like an ordinary host.
Non-interactive setup, in-place node editing, an interactive dashboard, safe self-update, a built-in speedtest, probe, and an egress IP-reputation check.