iclaoudezinandClaude Sonnet 5.5 5de0501cbc Compose: require JWT secret, seed admin via env, stop publishing internal ports
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
  APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
  host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:14:22 +00:00
2026-01-09 01:05:50 +03:00

OpenVPN Monitor & Profiler

Web suite for OpenVPN servers: real-time traffic monitoring, history/analytics, PKI and client-profile management, one UI.

Component Dir Stack Default port
UI APP_UI/ Vue 3 + Vite, served by Nginx 80 (Docker) / 8088 (native, TLS)
Monitoring API APP_CORE/ Flask (gunicorn) 5001 (internal)
Data gatherer APP_CORE/ Python daemon -
Profiler API APP_PROFILER/ FastAPI (uvicorn) 8000 (internal)

Nginx is the only public entry point: / UI, /api/ Monitoring API, /profiles-api/ Profiler API.

Quick start

After the first start: sign in, open PKI Configuration → Initialize PKI, generate the server config, start OpenVPN, create profiles.

First login and credentials

No default user is created. Seed the initial admin with OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD on first start (empty users table only), then remove them. Change the username and password and enable 2FA in Account.

Configuration

config.ini per component; overridden by OVPMON_{SECTION}_{KEY} environment variables.

Variable Purpose
OVPMON_API_SECRET_KEY JWT secret shared by both APIs (must be random)
OVPMON_INITIAL_ADMIN_USER / _PASSWORD One-time admin seed
OVPMON_CORS_ORIGINS Extra allowed CORS origins, comma-separated (empty = same-origin only)
OVPMON_OPENVPN_MONITOR_DB_PATH Monitoring DB
OVPMON_PROFILER_DB_PATH Profiler DB
OVPMON_OPENVPN_MONITOR_LOG_PATH openvpn-status.log path
OVPMON_LOGGING_LEVEL INFO / DEBUG

Documentation

Changes and results

Date Change Document
2026-09-30 Security hardening: path traversal, 2FA token bypass, CORS, log leak, HTTPS, SSH, fail2ban Security hardening
2026-09-30 Admin username change (API + UI), no built-in default admin Admin username change
2026-09-30 Route OpenVPN clients through a Hysteria2 tunnel to an exit node Egress via Hysteria2

Notes

  • ovpmon-api and ovpmon-profiler currently run as root (they manage OpenVPN and PKI).
  • Keep easy-rsa/, client-config/, databases and *.env out of git: they contain private keys and secrets.
S
Description
No description provided
Readme
665 KiB
0 Stars 1 Watchers 0 Forks
Languages
Python 48.7%
Vue 35.2%
CSS 12%
JavaScript 2.3%
Jinja 0.8%
Other 1%