Shadowsocks

Deploy Shadowsocks, a lightweight SOCKS5 proxy for routing traffic through an encrypted proxy connection. It can be used with compatible desktop or mobile clients to connect through a self-hosted Shadowsocks server.

1. Deploy Shadowsocks

 Estimated deployment time: 2–5 minutes

Follow the deployment instructions from the Get started section to configure the app, deploy it, and verify software installation.

For information on the app-specific configurations, see the Configuration options section.

Base distribution and plan

  • Supported distribution: Ubuntu 24.04 LTS
  • Recommended plans: All plan types and sizes can be used. Select a plan with enough outbound transfer for your expected proxy traffic.

Configuration options

Configure the required options to deploy your instance. For additional customization, add advanced options.

The table maps the Cloud Manager UI fields to their corresponding API/CLI keys (stackscript_data) required for automated deployments.

StackScript ID: 604068

UI fieldAPI/CLI keyDescription
Required options
Limited sudo useruser_nameYour preferred username for the limited sudo user entered without any capital letters, spaces, or special characters.
When adding a limited sudo user, the user is created with a strong generated password for your new Linode instance, and the account is assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.
Note: For easier and more secure access with the sudo user, add an account SSH key for the Cloud Manager user during deployment and select that user as an authorized_user. Their SSH pubkey will be assigned to both the root and limited user.
Advanced options
Disable root access over SSHdisable_rootApplies to a limited sudo user. To block the root user from logging in over SSH, select Yes. Defaults to No.
Note: When you disable the root user from logging in over SSH and don't provide a valid Account SSH Key assigned to the authorized_user, you can still switch to the root user. To do that, log in as root via the Lish console and run cat /home/$USERNAME/.credentials to view the generated password for the limited sudo user.

Note: After the app deployment completes, the password for your limited sudo user is generated and stored in the .credentials file in the home directory, along with application-specific passwords. Log in to your instance as root through the Lish console or SSH, then run cat /home/$USERNAME/.credentials to view its contents.

Use API, CLI, or Terraform

In addition to deploying the app to a new Linode instance via Cloud Manager, you can also use the Linode API, CLI, or Terraform. When running the operation, you need to provide the StackScript ID, supported Linux distribution, and app-specific fields along with the standard Linode deployment configurations.

Note: Generate a personal access token to authenticate your API, CLI, or Terraform requests.

curl --location 'https://api.linode.com/v4/linode/instances' \
  --header 'Content-Type: application/json' \
  --header 'Accept: application/json' \
  --header 'Authorization: Bearer abc123def456hij789klm' \
  --data-raw '{
    "region": "us-east",
    "type": "g6-standard-2",
    "image": "linode/ubuntu24.04",
    "label": "my-shadowsocks-one-click-app",
    "root_pass": "@C0mpl3x#P@ssw0rd",
    "stackscript_id": 604068,
    "stackscript_data": {
      "user_name": "jsmith"
    }
  }'
linode-cli linodes create \
  --region us-east \
  --type g6-standard-2 \
  --label my-shadowsocks-one-click-app \
  --image linode/ubuntu24.04 \
  --root_pass @C0mpl3x#P@ssw0rd \
  --stackscript_id 604068 \
  --stackscript_data '{"user_name":"jsmith"}'
resource "linode_instance" "my-linode" {
  region         = "us-east"
  type           = "g6-standard-2"
  label          = "my-shadowsocks-one-click-app"
  image          = "linode/ubuntu24.04"
  root_pass      = "@C0mpl3x#P@ssw0rd"
  stackscript_id = 604068
  stackscript_data = {
    "user_name" = "jsmith"
  }
}

2. Access Shadowsocks

After deployment, install a Shadowsocks client on each device that needs to connect through the proxy. Client services are currently available for Windows, Mac OS X, Linux, Android, and iOS.

For a full set of instructions on how to install Shadowsocks on Windows and Mac OS X, see the Install a Shadowsocks Client section of our guide.

When the client has completed the installation process, use the following connection details in your client:

ConfigurationDescription
AddressThe IPv4 address of your Linode instance. Can be found in the Linodes section of Cloud Manager.
PortBy default, the Shadowsocks app connects through port 8000.
EncryptionSet to use the aes-256-gcm encryption mode.
PasswordThe generated Shadowsocks Password from the .credentials file.

After configuration, your Server Preferences should have the connection details you provided.

Additional resources

For more information about the installed packages, see their official documentation.

📘

Note that we can't vouch for the accuracy or timeliness of externally hosted resources.


Did this page help you?