← ClaudeAtlas

open-internetlisted

Decision logic for building a personal unrestricted-internet connection from a censored network — which architecture to use (CDN-fronted vs direct), which protocols work and which are detectable, and the boundaries of what to help with. Load before any /mac-it-guy-pro:open-internet work.
xiaolai/mac-it-guy-pro · ★ 5 · DevOps & Infrastructure · score 67
Install: claude install-skill xiaolai/mac-it-guy-pro
# Open Internet — what to build and why Facts verified July 2026. **Every price, protocol status, and provider claim in this skill and its references carries a date. Anything older than three months must be re-verified before you act on it** — this field moves, and stale advice here costs the user real money. Read `references/legal-and-limits.md` before anything else. Its boundaries are binding: personal and household use only, no resale, no "airport" operation. That is not a style preference — it is the line where the user's legal exposure changes category. The rest of the detail lives in four more references, each loaded at the step that needs it: `vps-buying.md` (what to buy, what it costs, how to get a new IP), `server-setup.md` (build the server, both architectures), `client-setup.md` (connect the Mac and verify), and `troubleshooting.md` (diagnose in cheapest-first order). This file holds only the decisions that determine which of those you follow. ## The one thing to get right: this is an architecture choice, not a protocol choice Beginners (and most tutorials) argue about protocols. The decision that actually determines how a setup fails is whether the client connects to a **CDN** or **directly to your server**. The two resist different attacks, and no protocol changes that. | | **CDN-fronted** (VLESS/VMess + WS or httpupgrade + TLS behind Cloudflare) | **Direct** (VLESS + XTLS-Vision + REALITY on 443) | |---|---|---| | What the censor sees | Ordinary HTTPS to a