How to Build a High-Performance Proxy Server in 15 Minutes: A Practical Guide to the sing-box One-Click Script
A step-by-step tutorial on deploying a multi-protocol proxy server (VLESS-REALITY, TUIC, Hysteria2, Trojan) on Linux using the 233boy sing-box script. Covers rapid installation, configuration management, daily maintenance, BBR acceleration, and troubleshooting.

How to Build a High-Performance Proxy Server in 15 Minutes: A Practical Guide to the sing-box One-Click Script
Bought a new overseas VPS last week to set up a proxy for research and development debugging, but staring at the official sing-box documentation and a pile of JSON configuration files was overwhelming. After hours of tinkering, I still hit errors during startup because I couldn't figure out the TLS certificates and REALITY key pairs. If you've been through the same struggle, this tutorial is exactly for you.
I'll walk you through deploying a proxy service supporting REALITY, TUIC, Hysteria2, and more on a fresh Linux server using 233boy's sing-box one-click script. The entire process involves just a few commands, but I'll explain the "why" behind every step so you don't just learn how to use it, but also understand the underlying principles.
By the end of this guide, you'll have a ready-to-use proxy node, plus the ability to add/remove configurations, switch protocols, and manage multiple users on the fly.
Prerequisites
Before starting, ensure you meet the following requirements:
- An overseas Linux server (Ubuntu 20.04+ or Debian 11+ works fine; this guide uses Ubuntu 22.04)
rootaccess, or sudo privileges- Stable network connection to download scripts from GitHub
- No prior installations needed—the script handles dependencies automatically
If you don't have a server yet, a lightweight 1C1G VPS is more than enough. Since sing-box is written in Go, its resource footprint is extremely low, making it perfect for low-memory servers.
Step 1: Install the Script
SSH into your server and run the one-click installation command:
bash
bash <(wget -qO- https://raw.githubusercontent.com/233boy/sing-box/main/sing-box.sh)
This command handles several tasks: fetches the latest script from GitHub, checks your system environment, installs the sing-box core (if not already present), and automatically configures components like Caddy for website camouflage and automated TLS. The installation usually takes 1-2 minutes.
Why use this method instead of git clone? The author specifically designed this standalone script for "rapid deployment" scenarios. It wraps the entire download, installation, and initialization process into one step, saving you the hassle of cloning the repo and hunting for installation entry points.
After installation, verify it:
bash
sing-box version
sing-box help
If you see the version number and help output, the installation was successful.
Step 2: Add Your First Protocol Configuration (VLESS-REALITY)
By default, no usable protocol configurations exist after installation. Let's add one—the combination highly recommended by default and widely considered the best balance of stealth and security: VLESS-REALITY.
Run:
bash
sing-box a vless auto
What this command does:
a(oradd): Shorthand for adding a configurationvless: Specifies the VLESS protocolauto: Instructs the script to auto-generate required parameters (UUID, port, REALITY public/private keys, etc.) and configure TLS automatically
In under a second, the configuration is ready. You can immediately check the output:
bash
sing-box i
The output includes a server configuration summary and the client connection URL/QR code. Copy this URL into your client (e.g., Sing-box Client, NekoBox, etc.) to connect.
Why choose the REALITY protocol? REALITY is an innovative feature in sing-box that eliminates the need to buy a domain or manage certificates. Instead, it borrows TLS certificates from major websites (like Microsoft or Apple) for traffic camouflage. Compared to traditional TLS setups, it saves you from domain resolution, certificate requests, and renewals, all without compromising security.
Real-World Scenario: Multi-Protocol, Multi-User Setup for Teams
What if you're not just using it for yourself, but need to set up nodes for colleagues or friends who require different protocols in varying network environments? This is where the script truly shines: running multiple configurations simultaneously.
Add TUIC Protocol
TUIC operates over UDP, offering lower latency in weak network conditions. One command does it:
bash
sing-box a tuic auto
Add Hysteria2 Protocol
Hysteria2 excels in high packet-loss environments, making it ideal for cross-border links:
bash
sing-box a hy2 auto
Add Trojan Protocol
If you need compatibility with clients that only support Trojan:
bash
sing-box a trojan auto
Once added, view all active configurations:
bash
sing-box s # Check running status
sing-box url # List connection URLs for all protocols
Each protocol runs independently on separate ports without interfering. You can distribute different URLs to different users or switch flexibly based on current network conditions.
Daily Maintenance: Modify, Delete, & Troubleshoot
Change Port
If a port gets blocked by a firewall and you need to switch:
bash
sing-box port v1 auto
auto selects a random available port; you can also specify one, e.g., sing-box port v1 18443.
Change Camouflage Website
sing-box uses Caddy by default for the camouflage site. You can switch to another domain:
bash
sing-box web v1 www.example.com
Delete Configuration
Remove a config when it's no longer needed:
bash
sing-box d v1
⚠️ Note: The del command deletes configurations immediately without confirmation. Always verify with sing-box info <config_name> before deleting.
View Logs
If the client fails to connect, check the server logs first:
bash
sing-box log
Logs will pinpoint issues like port conflicts, certificate errors, or protocol mismatches.
Fix Configuration
If manual edits caused config corruption, use the built-in fix command:
bash
sing-box fix v1
To fix all configurations:
bash
sing-box fix-all
Enable BBR Acceleration
If your kernel supports BBR (Linux 4.9+), it's highly recommended to enable it. BBR significantly boosts TCP throughput:
bash
sing-box bbr
Enabling it may require a server reboot to take effect, but the improvements in latency and throughput are immediate once active.
Common Issues & Pitfall Alerts
- Script installation fails with network errors: Check if your server can reach
raw.githubusercontent.com. Operations on mainland Chinese servers may time out; always use an overseas VPS for installation. - Client fails to connect with no server log errors: Verify that the client's UUID, port, and protocol match the server exactly. For REALITY, ensure the client supports the latest protocol version.
- Port conflicts: The
automode auto-detects free ports, avoiding conflicts. If specifying manually, runsing-box get-portfirst to verify. - Camouflage site unreachable: The Caddy service might have crashed. Run
sing-box restart caddy, then checksing-box logfor details. - Complete uninstall & reinstall: Run
sing-box uninstallto clear all configs and dependencies, then re-run the installation command.
Summary
We just walked through the complete workflow:
- One-click installed the sing-box script and all dependencies.
- Used
sing-box addto quickly deploy VLESS-REALITY as the primary protocol. - Added TUIC, Hysteria2, and Trojan configurations, understanding their ideal use cases.
- Mastered daily maintenance: port changes, config deletion, log analysis, and troubleshooting.
- Enabled BBR network acceleration.
Throughout this process, we wrote zero JSON configurations, applied for zero TLS certificates, and avoided deep-diving into protocol specifics—all abstracted by the script. Yet, by understanding each command and parameter, you now know exactly what's happening under the hood, which is the key to solving problems independently.
Next Steps:
- Visit the 233boy/sing-box repository for full parameter documentation and advanced usage.
- To deeply understand REALITY and sing-box routing rules, check out the official sing-box docs.
- Try configuring upstream DNS with
sing-box dnsto further optimize resolution speed and privacy.
May your network remain stable and your development debugging run smooth. Feel free to drop your questions in the comments!