پرش به محتویات

MoaV v2 is out

Originally published on Medium

This post first appeared on Medium on 11 August 2026, written by Shayan Eskandari (@sbetamc). It is republished here unchanged: MoaV v2 is out.

Same 16+ protocols, rebuilt underneath. Mother of all VPNs

Pull request #274 on GitHub: MoaV v2.0.0, security, reliability and modularity pass, merged with 190 commits and 161 files changed
Mother of all VPNs — v2.0.0
100 PRs · 190 commits · 162 files
+16,801 / −25,987 lines (net −9,186)
tests 3 → 24 Keys, users and certificates are preserved on upgrade.

1.9.x worked, but it had grown the failure modes of a fast-moving project: code nobody could safely edit, some loose security, stale experimental code. None of that shows up in a feature list. All of it decides whether the tool works on a bad day.

MoaV 1.9 is out. Mother of All VPNs — one command, a $5 VPS, 16+ censorship-circumvention protocols on a single box. Run MoaV and you're not just getting yourself out; you're part of the free internet's infrastructure, carrying your loved ones, and strangers behind the wall, out with you. Enable @Conduit + @The Tor Project Snowflake and someone breathes through your bandwidth tonight. The design philosophy isn't elegance, it's redundancy: the censor has to block every protocol; you only need one to get through. — — Since 1.8.4, a major anti-DPI + reliability upgrade for server and client

— the MoaV 1.9 announcement on X

Project maturity • Server and client now both under the MotherofallVPNs org. • CONTRIBUTING guide • Server: https://github.com/MotherofallVPNs/moav • Client: https://github.com/MotherofallVPNs/moav-client • https://moav.sh

Security.

Docker hardening to prevent client private key override by any local process. Metrics collection gave up its unrestricted Docker access, the admin panel is TLS-only now. Existing installs are repaired automatically on upgrade.

Independently reviewed, rather than trusting our own human read of MoaV.sh. No critical or high findings. One real medium: a container was quietly undoing part of the hardening every time it started. We'd been blaming that on stale images for weeks.

The moav.sh landing page
MoaV — Mother of all VPNs | Internet Freedom Stack

Reliability.

The theme is no silent failures. Services fail loudly rather than running half-broken, and one stuck container can't wedge the rest. You could previously hand out a config that authenticated against nothing.

Terminal output of moav status listing every service and its health
moav status

Readability, which is really about who can contribute. The main script went from one file of 9,483 lines to 1,076, across 15 focused modules. Three near-identical copies of the provisioning logic became one, so a fix lands everywhere at once instead of one of three places.

The moav.sh script split into 15 library files
Broken down moav.sh to 15 library files

Testing. 3 scripts → 24 in CI, plus an end-to-end run that builds the whole stack on a real server with a real domain and connects through every protocol. That's the merge bar for provisioning changes. The rule: every bug found ships a test that keeps it fixed.

CI and end-to-end test runs
CI and e2e testing

The docs got a full overhaul: https://moav.sh/docs Rewritten for readability and completeness. No more dead links or stale instructions, reorganized for easier use. There are terminal recordings you can watch before installing anything. And there's a real threat model too.

The rewritten MoaV documentation site
New documentation with so much more useful info

Running an AI coding agent? Hand it the project. Paste this: "Read https://moav.sh/llms.txt and set MoaV up on my VPS" Install steps, DNS records and safety caveats included. llms.txt indexes every doc page, llms-full.txt has all the docs.

An AI agent setting up MoaV from llms.txt
Tell your AI agent: Read https://moav.sh/llms.txt and set MoaV up on my VPS

Translations are open, and it's most useful thing you can contribute. Farsi and Russian are scaffolded and waiting. Untranslated pages fall back to English. Chinese or another? File an issue on Github and we'll add the scaffolding. https://moav.sh/docs/TRANSLATING

The translation guide page
Translate to your languange

Mother of all VPNs — v2 release

Upgrade:

moav update && moav build && moav start

Fresh Install:

curl -fsSL http://moav.sh/install.sh | bash

Github: https://github.com/MotherofallVPNs/MoaV

MoaV stickers
Come find me in the next conference for some cool stickers

We also have a home for the community now. Join MoaV telegram channel for updates and discussions. https://t.me/motherofallvpns

If you are running or interested in Mother of all VPNs (https://moav.sh/) , there's a telegram group to stay informed and have discussions اگر از MoaV استفاده می‌کنید و یا دوست دارید بیشتر بدانید، در گروه تلگرام زیر عضو شوید https://t.me/motherofallvpns

Announcement of the MoaV Telegram group on X
https://x.com/sbetamc/status/2082710027845160971

This article was originally posted as a X thread here: https://x.com/MotherofallVPNs/status/2087169933604008016