Skip to content

Self-host Zoraxy

updated Sep 2026prices checked · Jul 2026
We earn commissions when you shop through the links below. Full disclosure →

A general-purpose reverse proxy managed entirely from a web UI, built for homelabs: proxy rules with load balancing and basic auth, redirection rules, ACME certificates with auto-renew and DNS challenges, TCP/UDP stream proxying, country and IP allow/deny lists, plus an uptime monitor, web SSH terminal and network utilities in the same AGPL-3.0 Go binary. The admin UI listens on port 8000 and asks you to create the single admin account on first visit.

Key facts

LicenseAGPL-3.0
StackGo
Min RAM256 MB
Official imageyes
Difficulty
Our recommendation

Pick Zoraxy when you want Nginx Proxy Manager's point-and-click model with more in the box: load balancing, country-level allow/deny lists, an uptime monitor and a web SSH terminal alongside the proxy rules, ACME certificates and TCP/UDP streams both have — all one AGPL-3.0 Go binary with its admin UI on port 8000. It is built with homelabs in mind; on a single VPS with a few apps, Nginx Proxy Manager or Caddy is the simpler choice.

What you need

  • Any VPS with at least 256 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • Under an hour if you've used Docker before
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Zoraxy — a single Go binary; the project's Getting Started guide steers anyone not fluent in Docker networking to it over the image
# pick the newest tag without an -rc suffix from the Releases page — "latest" can point at a release candidate
wget https://github.com/tobychui/zoraxy/releases/download/v3.3.4/zoraxy_linux_amd64
chmod +x zoraxy_linux_amd64
sudo ./zoraxy_linux_amd64 -port=:8000
# open http://<server-ip>:8000, create the admin account, add proxy rules, then request certificates from the ACME tool
# run it under systemd for anything permanent; the repo's docker/ folder documents zoraxydocker/zoraxy if you prefer a container

What you take on

Zoraxy is actively developed and its docs are candid; three points matter before you install:

non-negotiableThe project's Getting Started guide says that if you are "not experienced with networking in a dockerized environment, DO NOT use the docker version": many features rely on protocol sniffing and "usually require direct access to the networking interface and the original (unmodified) request". That is why our snippet runs the binary. The Docker image (zoraxydocker/zoraxy, documented in the repo's docker/ folder) exists, publishes 80, 443, 443/udp and 8000, and mounts the Docker socket for extra features.
non-negotiableCertificates are not automatic per host the way Caddy's are: you set an ACME email, enable auto-renew, request the certificate for your domains in the ACME tool, then enable TLS on port 443 and the HTTP→HTTPS redirect in the status tab.
non-negotiableThe admin UI on port 8000 has a single admin account created on first visit, and nothing else protects it. Our advice is to keep 8000 off the public firewall. Anything permanent should run under systemd; the project wiki's FAQ has a service file.
non-negotiableThe fast GeoIP option (-fastgeoip / FASTGEOIP) "requires 1GB extra memory" per the docs and is not recommended for low-end devices; leave it off on a small VPS. The 256 MB floor is our estimate with it off; upstream publishes no RAM figure.

More self-hosted tools

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.