Simple web UI to manage OpenVPN users.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

160 lines
5.8 KiB

# ovpn-admin
Simple web UI to manage OpenVPN users, their certificates & routes in Linux. While backend is written in Go, frontend is based on Vue.js.
Originally created in [Flant]( for internal needs & used for years, then updated to be more modern and [publicly released]( in March'21. Your contributions are welcome!
## Features
* Adding OpenVPN users (generating certificates for them);
* Revoking/restoring users certificates;
* Generating ready-to-user config files;
* Providing metrics for Prometheus, including certificates expiration date, number of (connected/total) users, information about connected users;
* (optionally) Specifying CCD (`client-config-dir`) for each user;
* (optionally) Operating in a master/slave mode (syncing certs & CCD with other server);
* (optionally) Specifying/changing password for additional authorization in OpenVPN;
* (optionally) Specifying the Kubernetes LoadBalancer if it's used in front of the OpenVPN server (to get an automatically defined `remote` in the `client.conf.tpl` template).
### Screenshots
Managing users in ovpn-admin:
![ovpn-admin UI](
An example of dashboard made using ovpn-admin metrics:
![ovpn-admin metrics](
## Installation
### Disclaimer
2 years ago
This tool uses external calls for `bash`, `coreutils` and `easy-rsa`, thus **Linux systems only are supported** at the moment.
### 1. Docker
There is a ready-to-use [docker-compose.yaml](, so you can just change/add values you need and start it with [](
Requirements. You need [Docker]( and [docker-compose]( installed.
Commands to execute:
git clone
cd ovpn-admin
### 2. Building from source
Requirements. You need Linux with the following components installed:
- [golang](
- [packr2](
- [nodejs/npm](
Commands to execute:
git clone
cd ovpn-admin
2 years ago
(Please don't forget to configure all needed params in advance.)
### 3. Prebuilt binary (WIP)
You can also download and use prebuilt binaries from the [releases]( page — just choose a relevant tar.gz file.
To use password authentication (the `--auth` flag) you have to install [openvpn-user]( This tool should be available in your `$PATH` and its binary should be executable (`+x`).
## Usage
usage: ovpn-admin [<flags>]
--help show context-sensitive help (try also --help-long and --help-man)"" host for ovpn-admin
--listen.port="8080" port for ovpn-admin
--role="master" server role, master or slave
2 years ago""
(or $OVPN_MASTER_HOST) URL for the master server
--master.basic-auth.user="" user for master server's Basic Auth
2 years ago
(or $OVPN_MASTER_PASSWORD) password for master server's Basic Auth
--master.sync-frequency=600 master host data sync frequency in seconds
--master.sync-token=TOKEN master host data sync security token
2 years ago""
--ovpn.server=HOST:PORT:PROTOCOL ...
can have multiple values
--ovpn.server.behindLB enable if your OpenVPN server is behind Kubernetes
(or $OVPN_LB) Service having the LoadBalancer type
(or $OVPN_LB_SERVICE) the name of Kubernetes Service having the LoadBalancer
type if your OpenVPN server is behind it
2 years ago
--mgmt=main= ...
(or $OVPN_MGMT) ALIAS=HOST:PORT for OpenVPN server mgmt interface;
can have multiple values
--metrics.path="/metrics" URL path for exposing collected metrics
--easyrsa.path="./easyrsa/" path to easyrsa dir
(or $OVPN_INDEX_PATH) path to easyrsa index file
--ccd enable client-config-dir
(or $OVPN_CCD)
--ccd.path="./ccd" path to client-config-dir
(or $OVPN_TEMPLATES_CC_PATH) path to custom client.conf.tpl
--templates.ccd-path="" path to custom ccd.tpl
--auth.password enable additional password authorization
(or $OVPN_AUTH_DB_PATH) database path for password authorization
--debug enable debug mode
--verbose enable verbose mode
--version show application version
## Further information
Please feel free to use [issues]( and [discussions]( to get help from maintainers & community.