Providers

A channel is what your server exits to the internet through. By default it exits directly, from its own address. If the address should be different — for example, so the vendor does not see your server, or to spread the load — create a channel: your own proxy, SOCKS5, a VPN or a Happ subscription. In the interface this is a separate section called “HTTP proxies” in the side menu, next to the “Models” section.

Channel types

  • HTTP proxy — an ordinary proxy server that a program asks to “connect me to this address”. The most common kind.
  • SOCKS5 proxy — similar in meaning, but a different, lower-level kind of proxy. Often offered where HTTP proxies are not.
  • VPN — all traffic goes through an encrypted connection to another server. The “fullest” option: the whole route changes, not just the connection to one address.
  • Happ subscription — ready-made access sold for the Happ program: instead of an address, login and password — one link. The product fetches the server list over it and raises the connection itself. Details in the “Happ subscription” section below.
  • Direct proxy — no upstream channel: traffic exits from the server’s own address. Needed when a contractor requires a separate port with key sign-in, while your own proxy is not needed.

What is in a channel’s fields

  • Name — what you will call the channel. It lands in the log, so clear names are best.
  • Type — HTTP proxy, SOCKS5, VPN, Happ subscription or direct.
  • Address and port — where to connect. A direct channel has no upstream proxy, so these fields are not needed, and for a Happ subscription the address is derived from the link itself.
  • Login and password — when the proxy requires authorization. The password shows as a mask.
  • Listen port — when set, the channel starts accepting proxy connections on this port. Empty or 0 — not exposed. The port is unique across channels.
  • Require authentication — whether this port admits only access-key holders.
  • Enabled — a disabled channel does not listen on its port: switching off silences the port but keeps the settings.

A channel as a proxy service

Any channel can be turned into its own proxy service: give it a listen port — and on that port the channel starts accepting ordinary proxy connections (HTTP proxy and SOCKS5 on one port), passing traffic only through itself. This way different contractors can be given different addresses: each their own port and their own channel.

By default nothing listens: until a port is set, a channel works only for requests to the models. The port range is 0 to 65535, where 0 means “not exposed”. In Docker every exposed port is published with its own line in the startup file — without that, it is unreachable from outside.

The channel list also shows the state: a channel with a port displays the port itself and a live mark — “Listening — {count} active” or “Not listening”. When no port is set, a dash stands in place of the mark with the hint “Not exposed as a consumer proxy”.

How to connect to such a port, how to enable key sign-in and what the log shows — in the Tunnel Service section.

Happ subscription

A Happ subscription is ready-made internet access through someone else’s VPN, sold for the Happ program. Instead of an address, login and password there is one link: the product fetches the server list over it and raises the connection itself.

A channel has just three fields. The subscription link is the access itself: it shows as a mask, saving without changes keeps the old link, and instead of the link you can write an environment-variable reference like $VARIABLE_NAME. The device ID is sent to the panel as the device identifier; leave the field empty and Happ’s default value is used. The server is picked from the list the product fetches over the link; empty — the first available server is taken, and if the chosen name disappears from the subscription, the first available one is substituted on every start.

The server list shows how much traffic has been used and until what date the subscription runs. Servers the product cannot start (Hysteria, for example) are marked as unsupported — they cannot be chosen.

The connection is raised by the Xray core built into the image. It starts on first use and shuts itself down after 60 seconds of idle. If the subscription is unreachable at startup, the last good fetch is used — so the channel keeps working while the panel stays silent. In your own build without the Xray core the channel simply counts as unavailable: the other channels keep working as usual.

The link is the subscription’s access key: whoever knows it uses your access. Keep it as carefully as a password.

Which channel traffic takes

There is no automatic channel rotation: traffic goes through the channel named explicitly. A model pinned to a channel on the “Models” page walks only through it; if the channel does not work, the request does not pass — no other channel and no direct connection is substituted. That is deliberate: pinning means “this model goes out only from here”.

Ordinary traffic through a proxy service port also exits only through its own channel. And an access key with a restricted channel list uses only the allowed ones — and never goes around them.

Checking the connection

The “Test connection” button walks the real route of this channel and shows the result: working or not, in how many milliseconds, what answer the external site returned. If the answer carries an error code, that is not a channel failure: the important part is that the connection was established — your proxy works, and the site simply did not like it. For a Happ subscription the check first raises the Xray core (that is, re-fetches the subscription) and then walks the real route — so you can see the whole channel is alive.

The password shows as a mask

A channel’s password, like a model’s vendor key, shows as a mask. Saving without changes keeps the old password. One subtlety: a saved password cannot be cleared — an empty field also means “leave as is”. If the password is no longer needed, set a different one, and the old one will simply go unused.

Updates and deletion

When you change a channel’s settings — address, login, password — connections already open switch to the new values on the next use. No container restart needed. For a Happ subscription, editing the link or the server restarts the Xray core on the next use — nothing to restart by hand.

A channel cannot be deleted while at least one model or at least one access key references it. Otherwise the link would quietly “move” to a direct connection, and that changes both the address and the security. The product names exactly who stands in the way — lift the reference first. Together with the deleted channel its proxy service port disappears too — there is nobody left to listen on it.

VPN: what it takes

A VPN channel is the most demanding. For it to work, the container needs extended network rights and the WireGuard program itself inside. The stock install provides neither, so a VPN channel has to be enabled separately, by changing the container’s startup.

The connection is raised only when it is really needed, and shuts itself down after 60–75 seconds of idle — that saves resources. If the rights or WireGuard are missing, the channel simply counts as unavailable: the other channels keep working as usual, nothing breaks.

Next: how to connect your programs to the server — in the Connecting Applications section.

← Back to the documentation index