VeilX — self-hosting
Your server, your data. One command.
VeilX has no backend of ours to sign up for, which means the server is yours to run. On a fresh Ubuntu VPS the installer sets up the homeserver, certificates, a web client and an admin panel, and asks you six questions in plain language along the way. Ten minutes, mostly waiting.
Before you start
A server, a domain, ten minutes.
Ubuntu 22.04 or 24.04 with a public IP, and a domain you control. Size the memory by how many people will be active at once: 2 GB comfortably serves around 300. Disk is the variable that actually bites — media is end-to-end encrypted, so it cannot be deduplicated, and heavy file sharing adds up quickly.
DNS records — all pointing at your server IP
- A @
- Root domain, web client, delegation
- A matrix
- The homeserver itself
- A admin
- Web admin panel · optional
- A livekit
- Voice and video calls · optional
- A matrix-rtc
- Voice and video calls · optional
Behind Cloudflare, these must stay grey-cloud. The orange proxy caps uploads at 100 MB, blocks certificate issuance and breaks call media.
Firewall ports
- 80 TCP
- Certificate issuance
- 443 TCP + UDP
- Web and encrypted traffic
- 7881 TCP
- Call fallback channel
- 7882 UDP
- Call audio and video — the one people forget
No security-group layer at your provider? Skip this — the script configures the system firewall itself.
Install
SSH in, paste one line.
Connect with ssh root@YOUR_SERVER_IP,
then run this. The installer asks six questions — pressing Enter through
all of them gives you the safest combination: invite-only registration,
federation off, calls on.
One command
sudo apt-get update && sudo apt-get install -y wget && wget -O tuwunel.sh https://lockmere.io/veilx/install.sh && sudo bash tuwunel.sh If this domain is unreachable from where you are, the same script is on GitHub. Either host works — they are two copies of one file, and we keep both because each is blocked somewhere the other is not.
Mirror — same script, from GitHub
sudo apt-get update && sudo apt-get install -y wget && wget -O tuwunel.sh https://raw.githubusercontent.com/VeilXofficial/veilx_matrix_ocs/main/matrix-tuwunel-installer.sh && sudo bash tuwunel.sh Or, the careful way
You are about to run a stranger's script as root.
That is worth a moment's pause, and we would rather say so than let the convenience of one line paper over it. The checksum below is generated from the file this site serves, every time the site is built, so it cannot drift out of date. Verify it, read the script, then run it.
Download, verify, read, run
wget -O tuwunel.sh https://lockmere.io/veilx/install.sh
sha256sum tuwunel.sh # expect 73d2d318068052a71ef71cb63541ea96fc6e3b99fa3b3e4bd95bbdc5f4fc595e
less tuwunel.sh # read it
sudo bash tuwunel.sh - SHA-256
- 73d2d318068052a71ef71cb63541ea96fc6e3b99fa3b3e4bd95bbdc5f4fc595e
- The file
- 341 KB of shell, /veilx/install.sh. This checksum covers the copy served from this domain. GitHub holds the upstream original — if the two ever differ, GitHub is the newer one and this page has not caught up yet.
We host it here because raw.githubusercontent.com is unreachable from some of the places this software is most useful. The installer's own self-update still points at GitHub; set TUWUNEL_UPDATE_URL=https://lockmere.io/veilx/install.sh if that is blocked for you too.
Source and documentation
The full walkthrough lives in the repository.
This page is the short path. The README covers every option the installer offers, sizing guidance, client setup and troubleshooting — and it is kept current in a dozen languages, which is why we link to it rather than copy it here to rot.
Want this run for you instead?
If you would rather not maintain a server, tell us the size of the team and where the data needs to live, and we will tell you honestly whether self-hosting or something else fits.