Skiff 1
- vCPU
- 1 × shared
- RAM
- 1 GB
- Storage
- 20 GB NVMe SSD
- Transfer
- 2 TB
- IPv4 / IPv6
- 1 / /64 routed
Solution
A proxy server is bandwidth with a small CPU tax. One shared core and 1 GB of RAM saturate a gigabit port with Dante or 3proxy; Shadowsocks and VLESS add encryption overhead but still run in well under 512 MB. Buy for location and address quality, and add extra IPv4 addresses when you need rotation.
| Resource | What you actually need |
|---|---|
| CPU | 1 shared core per gigabit for plain SOCKS5 |
| RAM | 1 GB |
| IPs | Up to 8 additional IPv4 addresses per instance |
| Transfer | 2–10 TB depending on use |
Location is usually the decision that matters most for this workload — either because latency dominates, or because jurisdiction does.
Location is the whole point of a proxy; specification barely matters.
Dante for classic SOCKS5, Xray for VLESS and Shadowsocks with TLS camouflage.
An open proxy will be found by scanners within hours and abused within a day.
This is how you build rotation without a third-party proxy service.
nftables connection limits keep a compromised credential from saturating the port.
Yes. Install Dante or 3proxy, require authentication, and bind to your assigned addresses. Never leave it open — open proxies are found and abused within hours.
One instance can run many listeners; the practical limit is your IP allocation and uplink, not CPU. Eight additional IPv4 addresses per instance is our ceiling.
We do not filter outbound traffic by protocol. We do intervene on active abuse — port scanning at scale, spam, and attacks originating from your instance.