Repository navigation
Installation
This guide covers the Linux installer, user-level systemd service, post-install commands, and host optimization tools.
The provider is designed to run as a non-privileged user service for maximum security and reliability.
Important
Recommended: run this command as your normal non-root user. If run as root, the installer will guide you through creating a dedicated service user named urnet.
Install:
curl -fSsL https://dl.fullbars.xyz/install.sh | shUninstall:
curl -fSsL https://dl.fullbars.xyz/uninstall.sh | shAfter installation, source your terminal profile so the new commands are available in the terminal you installed from (new terminals, ssh host urnet-tools ..., cron and root find them without this step: the installer links urnet-tools and urnetwork into ~/.local/bin and /usr/local/bin and writes the PATH block to ~/.bashrc, ~/.profile and ~/.zshenv), and authenticate the provider. Then you can load your proxy list:
source ~/.bashrc
urnetwork auth
urnet-tools proxy add ~/proxies.txt
urnet-tools proxy refreshTip
Path Formatting
You can use either ~/proxies.txt or /home/you/proxies.txt. Both syntaxes work.
Full proxy-loading walkthrough (including Windows): Adding Proxies.
Note
Alpine Linux (OpenRC)? The command above is the same, but the installer takes a different path and the service is a system service, not a user service. Follow Alpine Linux (OpenRC) instead of the systemd notes on this page.
Alpine and other OpenRC distributions are supported. The installer detects OpenRC on its own, so there is nothing new to type: the install command is the one every other Linux uses. This section walks through a first install from a root shell, which is how Alpine starts out.
You need a root shell and a regular account for the provider to run as. OpenRC has no per-user service manager, so the provider runs as a system service under a dedicated, unprivileged user. The installer expects that user to exist and uses urnet by default.
adduser -D urnet
apk add --no-cache curladduser -D urnet creates the urnet user with a home directory and no password. If the user does not exist when you install, the installer still downloads the files but does not install the service, and prints the commands to finish. To run the provider under a different account, set URNET_OPENRC_USER=<name> for the install command.
curl -fSsL https://dl.fullbars.xyz/install.sh | sh| What it does | Why |
|---|---|
Installs the provider and urnet-tools under /usr/local/lib/urnetwork-provider, owned by root and readable by everyone. Only the state dir (/home/urnet/.urnetwork) lives in the service user's home, because the provider must write it. |
The scheduled auto-update runs as root, and sudo urnet-tools update is the documented upgrade path. Root-owned files do not defend a path whose ANCESTOR a user can rewrite β a tree under /home/urnet could be renamed aside and replaced with the service user's own binary, which root would then execute. Keeping the tree off any user-writable path makes that impossible by construction. |
Writes the service script /etc/init.d/urnetwork and runs rc-update add urnetwork default. |
The default runlevel is what OpenRC starts at boot, so the provider comes back after a reboot with nobody logged in. |
Runs the provider under supervise-daemon as the urnet user. |
The provider drops root, and supervise-daemon restarts it after a crash with a five-second delay, increasing by five seconds per restart up to 60 seconds, with a limit of 10 restarts per hour. |
Sends the provider's output to /var/log/urnetwork.log (stdout) and /var/log/urnetwork.err (stderr), both owned by the service user; /var/log remains root-owned. |
supervise-daemon opens these files after dropping privileges, so the service user must be able to write them. Because the log is a plain file, urnet-tools logs can read it even while the service is stopped. |
Keeps the provider's state, including the login token, in /home/urnet/.urnetwork. |
The provider reads its credentials from the home directory of the user it runs as. |
The installer does not start the service. It finishes by printing the commands for the next two steps.
Note
OpenRC has no equivalent of systemd's enable-linger, and none is needed: a service in the default runlevel starts at boot whether or not anyone logs in.
The provider needs an auth code from https://ur.io, and the login token it produces has to land in the urnet user's home, not root's. A token written to /root/.urnetwork is invisible to the service, which would start and then have no credentials.
Run the authentication as the service user:
su -s /bin/sh urnet -c 'urnetwork auth <code>'The installer prints this exact command when it finishes. When you run it in an interactive terminal it can also offer to do this step for you: answer y, enter the code, and the installer runs the authentication as urnet. The prompt is read from the terminal device itself, not from standard input, so it works for the one-line curl ... | sh form as well β the script arriving on standard input does not take the terminal away. Where there is no terminal at all (a provisioning script, a CI job, a cron entry) the prompt is skipped and the command is printed instead. If the prompt was skipped, or the authentication did not complete, run the command above at any time. Auth codes are single-use, so fetch a new one if a code was already submitted.
rc-service urnetwork start
rc-service urnetwork statusstatus should report started. To see what the provider is doing:
urnet-tools logs
tail -f /var/log/urnetwork.logurnet-tools logs follows the same file. If the service does not stay up, read /var/log/urnetwork.err as well as the main log. If you have not authenticated yet, go back to Authenticate.
A node with no proxy list configured serves traffic directly from the box's own address. The [profit] line in the log says so with mode=direct; see the Log Reference.
To add proxies, see Adding Proxies.
Stop the provider now (it starts again at the next boot):
rc-service urnetwork stopStop it and keep it from starting at boot:
rc-service urnetwork stop
rc-update del urnetwork defaultTurn boot start back on later:
rc-update add urnetwork default
rc-service urnetwork startUninstall, as root:
curl -fSsL https://dl.fullbars.xyz/uninstall.sh | shThis stops the service, removes /etc/init.d/urnetwork, its default runlevel entry and any auto-update entry, and deletes the install directory. It also deletes /home/urnet/.urnetwork, which holds the login token, so you would need a new auth code to install again. It leaves two things behind: the urnet user and the log files. Remove them if you want a clean slate:
deluser urnet
rm -f /var/log/urnetwork.log /var/log/urnetwork.errUpdating is a root action on OpenRC, the same way systemctl restart is for a system service under systemd. Restarting an OpenRC service needs root, and so does replacing the root-owned binaries, so run the update from a root shell:
urnet-tools updateTo have it run on a schedule, turn on auto-update as root. On OpenRC it is a busybox crond entry, not a systemd timer:
urnet-tools auto-update weeklyThe interval can be daily, weekly or monthly, and urnet-tools auto-update off removes it. The entry only fires while crond is running. If urnet-tools reports that crond is not installed or not started, run:
apk add busybox-openrc
rc-update add crond default
rc-service crond start-
Updates need root. Every update restarts the service and replaces root-owned files, so run
urnet-tools updatefrom a root shell. There is no rootless update path on OpenRC. -
No zero-downtime hotswap.
supervise-daemoncannot hand its supervised process over to a new one, sournet-tools updatestops the provider and starts it again, with a brief gap in service. See HotSwap on OpenRC. -
Several providers on one box.
urnet-tools stopandrestartask you to name the target when other providers run beside the service. See OpenRC command parity.
The macOS installer is the equivalent of the Linux installer but uses launchd instead of systemd:
curl -fSsL https://dl.fullbars.xyz/install-mac.sh | shUninstall (manual β macOS uninstall script not yet available):
# Remove binary and service files
rm -rf ~/.local/share/urnetwork-provider
launchctl unload ~/Library/LaunchAgents/com.urnetwork.provider.plist 2>/dev/null
rm -f ~/Library/LaunchAgents/com.urnetwork.provider.plist
# Remove identity and proxy data (β οΈ deletes all JWTs and proxy state)
rm -rf ~/.urnetwork
# Remove PATH additions from ~/.bashrc / ~/.zshrc| Component | Location |
|---|---|
| Provider binary | ~/.local/share/urnetwork-provider/bin/urnetwork |
| launchd plist | ~/Library/LaunchAgents/com.urnetwork.provider.plist |
| Logs |
~/Library/Logs/com.urnetwork.provider/stdout.log + stderr.log
|
| State directory |
~/.urnetwork/ (same as Linux) |
All urnet-tools commands work identically to Linux:
# Start/stop
urnet-tools start
urnet-tools stop
urnet-tools restart
urnet-tools status
# Hot-restart toggle
urnet-tools hot-restart on
urnet-tools hot-restart off
# Session save/load
urnet-tools session save backup.urnsession
urnet-tools session load backup.urnsession
# Auth and proxy
urnetwork auth
urnet-tools proxy add ~/proxies.txt
urnet-tools proxy refresh
urnet-tools proxy summaryNote
macOS doesn't support eco, ramlogs, or optimize (those tune Linux kernel parameters). optimize in particular has no effect on macOS β it runs Linux-specific sysctl keys that don't exist there and prints "done" while actually changing nothing. All other commands work natively.
Unlike traditional services that run as root, this build defaults to a systemd user unit.
- Security: the provider binary does not need root privileges.
- Isolation: configuration and JWT tokens are stored in the user's home directory.
-
Linger: the installer enables
loginctl enable-linger, so the provider starts automatically on boot and keeps running after logout. -
Root guard: if installed as root, the script can create a restricted
urnetuser and add it to the appropriate admin group.
The installation includes the urnet-tools suite for management. Since v3.23.0-fix.27.0 this is the provider-aware Go binary β on multi-provider machines, pass a target (--unit / --user / --network / --network-id / --state-dir) or the tool refuses. See urnet-tools-go.md.
| Command | Description |
|---|---|
urnet-tools status |
Check service health and uptime. |
urnet-tools logs |
Stream logs, automatically detecting RAM vs disk logging. |
urnet-tools auto on |
Enable Smart Auto. Recommended for most hosts. |
urnet-tools optimize |
Full host optimization for many-proxy deployments and high-volume traffic. Add -f to skip prompts. |
urnet-tools turbo v4 |
Enable Turbo V4 mode. |
urnet-tools turbo v8 |
Enable Turbo V8 mode. |
urnet-tools eco on/off |
Toggle Eco mode. |
urnet-tools ramlogs on/off |
Toggle RAM-disk logging independently. |
urnet-tools update |
Upgrade to the latest version (prompts before restarting the provider). |
urnet-tools update -f |
Non-interactive upgrade: stop, update, and restart the provider with no prompts. Use in scripts/automation. |
Install via PowerShell (no admin required):
irm https://dl.fullbars.xyz/install-win.ps1 | iexWindows Defender may flag this one-liner. See the note below.
Note
Windows Defender may flag the Windows install one-liner, and it may flag the downloaded
binaries. What we see are machine-learning heuristics (the !ml suffix), not signatures;
for the binaries we publish they are false positives. Recent release pages record the scan
results for the published binaries. If Defender blocks the one-liner, download the script,
review it, and run it from disk instead. If Defender quarantines an extracted binary,
allow it from Windows Security > Virus & threat protection > Protection history. Both lines
go in PowerShell:
irm https://dl.fullbars.xyz/install-win.ps1 -OutFile "$env:TEMP\install-win.ps1"
powershell -NoProfile -ExecutionPolicy Bypass -File "$env:TEMP\install-win.ps1"The detections you may see, and what each one means
-
Trojan:Script/Wacatac.B!ml,Trojan:Script/Wacatac.C!ml: Defender's machine-learning label for the PowerShell installer script fetching and extracting a remote payload. -
Trojan:Win32/Wacatac.B!ml,Trojan:Win32/Wacatac.C!ml: Defender's machine-learning label for files whose shape looks like a packed trojan. Our Go binaries are stripped, statically linked and unsigned, which reads as a packed payload. The B and C variants are different model generations, so one binary can be flagged under more than one name.Trojan:Win32/Execution.A!mlis another label from the same family on some builds. -
Trojan:Win32/Commando.A!ml: fires on the download-and-run command line itself (theirm ... | iexone-liner), not on the installed files. Fetching a remote script and piping it into execution reads as a trojan-downloader pattern to the model. -
Trojan:Win32/Bearfoos.A!ml: a behavioural label for scheduled-task activity. The installer registers Task Scheduler tasks β a weekly update task (onlatestinstalls) and, if you accept auto-start, a logon task so the provider starts at login β and a behavioural model cannot tell that apart from persistence malware.
Uninstall via PowerShell (no admin required):
irm https://dl.fullbars.xyz/uninstall-win.ps1 | iex| Component | Location |
|---|---|
| Provider binary | %LOCALAPPDATA%\urnetwork\provider\windows\<arch>\urnetwork.exe |
| Management tool |
urnet-tools (Go binary, v3.23.0-fix.27.0+) |
| State directory | %USERPROFILE%\.urnetwork\ |
| Startup (optional) | Task Scheduler logon task urnetwork-autostart
|
| PATH | User PATH updated to include %LOCALAPPDATA%\urnetwork\provider\windows\<arch>\
|
# Authenticate
urnetwork auth
# Start in foreground
urnetwork provide
# Start in background
urnet-tools start
# Manage proxies
urnet-tools proxy add "$env:USERPROFILE\Downloads\proxies.txt"
urnet-tools proxy refresh
urnet-tools proxy summary
# View logs
urnet-tools logs
# Hot-restart toggle
urnet-tools hot-restart on
urnet-tools hot-restart off
# Session save/load
urnet-tools session save C:\Users\You\backup.urnsession
urnet-tools session load C:\Users\You\backup.urnsession
# Update
urnet-tools updateSee Adding Proxies for per-OS proxy-loading instructions and the Windows
.txt.txtextension trap.
Starting with v3.23.0-fix.31.2, the Windows release tarball includes urnet-tools alongside the provider binary. If you prefer a manual or offline install:
- Download the release tarball from GitHub Releases.
- Extract the archive to your desired location (e.g.
%LOCALAPPDATA%\urnetwork). - Open PowerShell and run the included install script:
.\Provider_Install_Win32.ps1This registers the PATH entry and optional Task Scheduler logon task β the same result as the CDN installer, but sourced entirely from the tarball. No internet access is required at install time. The script detects amd64/arm64 automatically and places the correct binaries.
Tip
The tarball method is useful for air-gapped machines or when you want to pin a specific release version rather than always pulling latest.
When the provider starts, it logs a System Auditor report that checks kernel limits and disk I/O performance:
[audit] Conntrack Max: 262144 (Suboptimal! Target: 2097152)
[audit] Hint: Container detected suboptimal host limits. Run 'urnet-tools optimize' on the HOST to fix.
Warning
The provider cannot modify host-level kernel settings from inside a container. Run urnet-tools optimize on the host machine when deploying many proxies, or whenever you see Suboptimal! warnings.
For Docker-only users who do not want the systemd provider service, run the installer on the host to install the tools:
curl -fSsL https://dl.fullbars.xyz/install.sh | shThen optimize the host:
urnet-tools optimize -foptimize re-executes itself under sudo with its own resolved binary path when it needs root, so you don't have to type sudo /path/to/urnet-tools (and it does NOT work as bare sudo urnet-tools β the binary lives on a per-user path, not root's PATH).
The -f flag skips interactive prompts. This applies:
- Conntrack max:
262144->2097152 - Conntrack timeout:
432000s->5400s - TCP established timeout: 5 days -> 1 hour
- BBR congestion control and Fair Queuing
- Auto-install of
zramandconntrack-tools - Boot persistence for kernel modules
After optimization, your Docker container should restart and report:
[audit] Conntrack Max: 2097152 (Optimal!)
Note
If you only run Docker and do not intend to use the systemd provider service, the installer still offers just the tools. Choose n when prompted to enable the systemd service.