⚠️ Prerelease for testing — not for production. Stable
moav updatewill not pull this; install it explicitly (below). This is rc.5: rc.4 with a proper fix for XDNS under Xray 26.9.
Added in 2.3.0
- sing-box → 1.14.0 (all pins), validated against the real 1.14
sing-box check/format. (#329) - Snell — new protocol, ON by default. Lightweight TCP proxy, HTTP obfs, no TLS/domain. Shared-key. Needs a Snell v5 client — Surge 5 / Stash / Clash Mi / Mihomo / Clash Meta for Android / FlClash (not v2rayNG/Hiddify). (#329)
- Hysteria2 gecko obfuscation — opt-in via
HYSTERIA2_OBFS_TYPE=gecko(needs client core sing-box ≥ 1.14 / hysteria ≥ 2.9.2). (#329)
Changed — component bumps
- Grafana 13.2.0 → 13.2.1 (security: CVE-2026-12704, CVE-2026-14199), telemt 3.5.5 → 3.5.7, Xray-core v26.7.28 → v26.9.9, slipstream → v2026.04.22.1, MasterDNS → v2026.06.13. TrustTunnelClient held at 1.0.49. (#332)
Fixed
- XDNS now carries VLESS Encryption (Xray ≥ 26.9 compatible) (new in rc.5). Xray 26.9.9 rejects an unencrypted VLESS outbound dialing a public IP (xray refused to start, XDNS failed the rc.3/rc.4 e2e). XDNS dials a public resolver/server over mKCP, so the VLESS layer now carries its own encryption: a server-wide X25519 keypair minted at bootstrap (openssl, no extra binary;
state/keys/xdns.env),decryptionon the server inbound +encryptionin every client bundle. Also hardens XDNS (previously its DNS-tunnelled VLESS was unencrypted). Re-issue bundles (moav regenerate-users) after upgrading so clients get the encryption key. moav updateDiscard resets fully,-b <ref>accepts a tag,.envinline-comment leak fixed, Telegram link preview pinned to the release. (#329, #331)
Install / upgrade for testing
curl -fsSL moav.sh/install.sh | bash -s -- -b v2.3.0-rc.5
# or: moav update -b v2.3.0-rc.5 && moav build && moav start && moav regenerate-users
moav doctor && moav test <user>Please report
image build failures, any protocol that fails moav test (esp. XDNS), Snell issues (v5 clients), moav update problems.
Changes since rc.4: v2.3.0-rc.4...v2.3.0-rc.5
Full diff since stable: v2.2.4...v2.3.0-rc.5
Note: the install command below fetches the latest stable release, not
this candidate. To try this build specifically, use thegit checkoutsteps in
the notes above.
Quick Install
curl -fsSL https://moav.sh/install.sh | bashThis will install MoaV to /opt/moav and guide you through setup.
Documentation
moav.sh/docs — full documentation
Get started
- Quick Start — install to first user in ~10 minutes
- Client Setup — connect from phones and desktops
- DNS Configuration — records, delegations, freeing port 53
Reference
- CLI Reference — every command and flag
- Setup Guide — every option, in depth
- Monitoring — Grafana dashboards and metrics
- Troubleshooting — symptom-first fixes
Understand it
- Supported Protocols — per-protocol ports, ciphers, stealth
- Architecture — container topology and bundle flow
- Threat Model — what is and is not protected
- OPSEC Guide — operator-side hardening
Help out
- Support MoaV — run a server, contribute, translate, donate
- Translating the Docs — one page is a complete contribution
Running it with an AI agent? llms.txt is a compact
orientation for coding agents; llms-full.txt is the
whole corpus. Both ship as release assets.