9b2882d5f46e560f48405103245a8d89f43bc3ca
- README: short overview, quick start, config table and links. - DOCS/General: Deployment_Docker.md and Deployment_Native.md (system services, HTTPS, host hardening); refresh Index.md. - DOCS/Changes: security hardening, admin username change and egress via Hysteria2 with results and verification. - Drop mentions of the built-in admin/password account. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OpenVPN Monitor & Profiler
Web suite for OpenVPN servers: real-time traffic monitoring, history/analytics, PKI and client-profile management, one UI.
| Component | Dir | Stack | Default port |
|---|---|---|---|
| UI | APP_UI/ |
Vue 3 + Vite, served by Nginx | 80 (Docker) / 8088 (native, TLS) |
| Monitoring API | APP_CORE/ |
Flask (gunicorn) | 5001 (internal) |
| Data gatherer | APP_CORE/ |
Python daemon | - |
| Profiler API | APP_PROFILER/ |
FastAPI (uvicorn) | 8000 (internal) |
Nginx is the only public entry point: / UI, /api/ Monitoring API, /profiles-api/ Profiler API.
Quick start
- Containers:
docker-compose up -d --build, openhttp://<host>. Details: Deployment: Docker. - System services (systemd / OpenRC, no containers): Deployment: native.
After the first start: sign in, open PKI Configuration → Initialize PKI, generate the server config, start OpenVPN, create profiles.
First login and credentials
No default user is created. Seed the initial admin with OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD on first start (empty users table only), then remove them. Change the username and password and enable 2FA in Account.
Configuration
config.ini per component; overridden by OVPMON_{SECTION}_{KEY} environment variables.
| Variable | Purpose |
|---|---|
OVPMON_API_SECRET_KEY |
JWT secret shared by both APIs (must be random) |
OVPMON_INITIAL_ADMIN_USER / _PASSWORD |
One-time admin seed |
OVPMON_OPENVPN_MONITOR_DB_PATH |
Monitoring DB |
OVPMON_PROFILER_DB_PATH |
Profiler DB |
OVPMON_OPENVPN_MONITOR_LOG_PATH |
openvpn-status.log path |
OVPMON_LOGGING_LEVEL |
INFO / DEBUG |
Documentation
- Index: DOCS/General/Index.md
- Deployment: Docker · System services · Nginx · Service management
- Security model: Security Architecture
- APIs: Monitoring · Profiler
Changes and results
| Date | Change | Document |
|---|---|---|
| 2026-09-30 | Security hardening: path traversal, 2FA token bypass, CORS, log leak, HTTPS, SSH, fail2ban | Security hardening |
| 2026-09-30 | Admin username change (API + UI), no built-in default admin | Admin username change |
| 2026-09-30 | Route OpenVPN clients through a Hysteria2 tunnel to an exit node | Egress via Hysteria2 |
Notes
ovpmon-apiandovpmon-profilercurrently run as root (they manage OpenVPN and PKI).- Keep
easy-rsa/,client-config/, databases and*.envout of git: they contain private keys and secrets.
Languages
Python
48.7%
Vue
35.2%
CSS
12%
JavaScript
2.3%
Jinja
0.8%
Other
1%