init
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
root=true
|
||||
|
||||
[*]
|
||||
indent_style=space
|
||||
indent_size=4
|
||||
end_of_line=lf
|
||||
charset=utf-8
|
||||
trim_trailing_whitespace=true
|
||||
insert_final_newline=true
|
||||
[makefile]
|
||||
indent_style=tab
|
||||
@@ -0,0 +1,5 @@
|
||||
/app/config.php
|
||||
/cert/*
|
||||
!/cert/.gitkeep
|
||||
/sftp-config.json
|
||||
/tg.pyr
|
||||
+800
@@ -0,0 +1,800 @@
|
||||
<?php
|
||||
|
||||
class Bot
|
||||
{
|
||||
public $input;
|
||||
|
||||
public function __construct($key)
|
||||
{
|
||||
$this->key = $key;
|
||||
$this->api = "https://api.telegram.org/bot$key/";
|
||||
$this->file = "https://api.telegram.org/file/bot$key/";
|
||||
$this->clients = __DIR__ . '/clients.json';
|
||||
}
|
||||
|
||||
public function input()
|
||||
{
|
||||
$this->input_raw = $input = json_decode(file_get_contents('php://input'), true);
|
||||
$this->input = [
|
||||
'message' => $input['callback_query']['message']['text'] ?? $input['message']['text'] ?? $input['channel_post']['text'] ?? '',
|
||||
'message_id' => $input['callback_query']['message']['message_id'] ?? $input['message']['message_id'] ?? $input['channel_post']['message_id'],
|
||||
'chat' => $input['message']['chat']['id'] ?? $input['callback_query']['message']['chat']['id'] ?? $input['channel_post']['chat']['id'] ?? $input['my_chat_member']['chat']['id'],
|
||||
'from' => $input['message']['from']['id'] ?? $input['inline_query']['from']['id'] ?? $input['callback_query']['from']['id'] ?? $input['channel_post']['chat']['id'] ?? $input['my_chat_member']['from']['id'],
|
||||
'username' => $input['message']['from']['username'] ?? $input['inline_query']['from']['username'] ?? $input['callback_query']['from']['username'],
|
||||
'query' => $input['inline_query']['query'] ?? '',
|
||||
'inlid' => $input['inline_query']['id'] ?? '',
|
||||
'group' => 'group' == $input['message']['chat']['type'],
|
||||
'sticker_id' => $input['message']['sticker']['file_id'] ?? false,
|
||||
'channel' => !empty($input['channel_post']['message_id']),
|
||||
'callback' => $input['callback_query']['data'] ?? false,
|
||||
'callback_id' => $input['callback_query']['id'] ?? false,
|
||||
'photo' => $input['message']['photo'] ?? false,
|
||||
'file_name' => $input['message']['document']['file_name'] ?? false,
|
||||
'file_id' => $input['message']['document']['file_id'] ?? false,
|
||||
'caption' => $input['message']['caption'] ?? false,
|
||||
'reply' => $input['message']['reply_to_message']['message_id'] ?? false,
|
||||
'reply_from' => $input['message']['reply_to_message']['from']['id'] ?? $input['callback_query']['message']['reply_to_message']['from']['id'] ?? false,
|
||||
'reply_text' => $input['message']['reply_to_message']['text'] ?? false,
|
||||
'new_member_id' => $input['my_chat_member']['new_chat_member']['user']['id'] ?? false,
|
||||
'new_member_status' => $input['my_chat_member']['new_chat_member']['status'] ?? false,
|
||||
];
|
||||
$this->session();
|
||||
$this->action();
|
||||
$this->callbackCheck();
|
||||
}
|
||||
|
||||
public function callbackCheck()
|
||||
{
|
||||
if (empty($this->callback) && !empty($this->input['callback_id'])) {
|
||||
$this->answer($this->input['callback_id']);
|
||||
}
|
||||
}
|
||||
|
||||
public function session()
|
||||
{
|
||||
session_id($this->input['from']);
|
||||
session_start();
|
||||
if (!empty($_SESSION['reply'])) {
|
||||
if (empty($this->input['reply'])) {
|
||||
foreach ($_SESSION['reply'] as $k => $v) {
|
||||
$this->delete($this->input['chat'], $k);
|
||||
}
|
||||
unset($_SESSION['reply']);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public function sd($var, $log = false, $json = false)
|
||||
{
|
||||
if ($log) {
|
||||
if ($json) {
|
||||
file_put_contents(__DIR__ . '/logs/input', json_encode($var, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
} else {
|
||||
file_put_contents(__DIR__ . '/logs/input', var_export($var, true));
|
||||
}
|
||||
}
|
||||
$this->send($this->input['chat'], var_export($var, true), $this->input['message_id']);
|
||||
}
|
||||
|
||||
public function action()
|
||||
{
|
||||
switch (true) {
|
||||
// смена айпи сервера
|
||||
case preg_match('~^/menu$~', $this->input['message'], $m):
|
||||
case preg_match('~^/menu$~', $this->input['callback'], $m):
|
||||
case preg_match('~^/client (\d+)$~', $this->input['callback'], $m):
|
||||
$this->menu($m[1] ?? false);
|
||||
break;
|
||||
case preg_match('~^/download (\d+)$~', $this->input['callback'], $m):
|
||||
$this->downloadPeer($m[1]);
|
||||
break;
|
||||
case preg_match('~^/delete (\d+)$~', $this->input['callback'], $m):
|
||||
$this->deletePeer($m[1]);
|
||||
break;
|
||||
case preg_match('~^/add$~', $this->input['callback'], $m):
|
||||
$this->addPeer(); // добавление клиента "весь траффик"
|
||||
break;
|
||||
case preg_match('~^/showadd$~', $this->input['callback'], $m):
|
||||
$this->showaddclient(); // меню добавления клиента
|
||||
break;
|
||||
case preg_match('~^/add_ips$~', $this->input['callback'], $m):
|
||||
$this->addips(); // ответ с предложением ввести список подсетей
|
||||
break;
|
||||
case preg_match('~^/showreset$~', $this->input['callback'], $m):
|
||||
$this->showreset();
|
||||
break;
|
||||
case preg_match('~^/reset$~', $this->input['callback'], $m):
|
||||
$this->reset();
|
||||
break;
|
||||
case preg_match('~^/proxy$~', $this->input['callback'], $m):
|
||||
$this->proxy();
|
||||
break;
|
||||
case preg_match('~^/showpac$~', $this->input['callback'], $m):
|
||||
$this->showpac();
|
||||
break;
|
||||
case preg_match('~^/export$~', $this->input['callback'], $m):
|
||||
$this->export();
|
||||
break;
|
||||
case preg_match('~^/import$~', $this->input['callback'], $m):
|
||||
$this->import();
|
||||
break;
|
||||
case !empty($this->input['reply']):
|
||||
$this->reply();
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
public function export()
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$export = [
|
||||
'server' => $this->readConfig(),
|
||||
'clients' => json_decode(file_get_contents($this->clients), true) ?: [],
|
||||
];
|
||||
$this->upload(date('d_m_Y_H_i') . '.json', json_encode($export, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
}
|
||||
|
||||
public function import()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} перешлите файл экспорта:",
|
||||
$this->input['message_id'],
|
||||
reply: 'перешлите файл экспорта:',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'start_callback' => $this->input['callback_id'],
|
||||
'callback' => 'importFile',
|
||||
];
|
||||
}
|
||||
|
||||
public function importFile()
|
||||
{
|
||||
$r = $this->request('getFile', ['file_id' => $this->input['file_id']]);
|
||||
$json = json_decode(file_get_contents($this->file . $r['result']['file_path']), true);
|
||||
if (empty($json) || !is_array($json)) {
|
||||
$this->answer($this->input['callback_id'], 'ошибка', true);
|
||||
} else {
|
||||
file_put_contents($this->clients, json_encode($json['clients'], JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
$this->restartWG($this->createConfig($json['server']));
|
||||
}
|
||||
}
|
||||
|
||||
public function downloadPeer($client)
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$peer = $conf['peers'][$client];
|
||||
$clients = json_decode(file_get_contents($this->clients), true);
|
||||
foreach ($clients as $k => $v) {
|
||||
if ($v['interface']['Address'] == $peer['AllowedIPs']) {
|
||||
$client_conf = $v;
|
||||
break;
|
||||
}
|
||||
}
|
||||
$name = explode('/', $peer['AllowedIPs'])[0];
|
||||
$code = $this->createConfig($client_conf);
|
||||
$this->upload("$name.conf", $code);
|
||||
}
|
||||
|
||||
public function upload($name, $code)
|
||||
{
|
||||
$path = __DIR__ . "/logs/$name";
|
||||
file_put_contents($path, $code);
|
||||
$this->sendFile(
|
||||
$this->input['chat'],
|
||||
curl_file_create($path),
|
||||
);
|
||||
unlink($path);
|
||||
}
|
||||
|
||||
public function pac($domains)
|
||||
{
|
||||
$domains = implode(' || ', array_map(fn($el) => 'shExpMatch(url, "*' . trim($el) . '*")', explode(PHP_EOL, $domains)));
|
||||
$proxy = trim($this->ssh("getent hosts proxy | awk '{ print $1 }'"));
|
||||
$pac = <<<PAC
|
||||
function FindProxyForURL(url, host)
|
||||
{
|
||||
if ($domains) {
|
||||
return "SOCKS $proxy:1080";
|
||||
} else {
|
||||
return "DIRECT";
|
||||
}
|
||||
}
|
||||
PAC;
|
||||
$this->send(
|
||||
$this->input['chat'],
|
||||
"<code>$pac</code>",
|
||||
$this->input['message_id'],
|
||||
);
|
||||
}
|
||||
|
||||
public function showpac()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} перечислите домены (каждый домен на новой строке, можно часть домена):",
|
||||
$this->input['message_id'],
|
||||
reply: 'перечислите домены (каждый домен на новой строке, можно часть домена):',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'start_callback' => $this->input['callback_id'],
|
||||
'callback' => 'pac',
|
||||
];
|
||||
}
|
||||
|
||||
public function proxy()
|
||||
{
|
||||
$proxy = trim($this->ssh("getent hosts proxy | awk '{ print $1 }'"));
|
||||
$this->createPeer("$proxy/32");
|
||||
$this->menu();
|
||||
}
|
||||
|
||||
public function change_server_ip($ip)
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$conf['interface']['Address'] = $ip;
|
||||
$this->restartWG($this->createConfig($conf));
|
||||
}
|
||||
|
||||
public function reply()
|
||||
{
|
||||
if (!empty($_SESSION['reply'][$this->input['reply']])) {
|
||||
$this->delete($this->input['chat'], $this->input['reply']);
|
||||
$callback = $_SESSION['reply'][$this->input['reply']]['callback'];
|
||||
$this->{$callback}($this->input['message']);
|
||||
switch ($callback) {
|
||||
case 'createPeer':
|
||||
case 'importFile':
|
||||
$this->delete($this->input['chat'], $this->input['message_id']);
|
||||
$this->input['message_id'] = $this->input['callback_id'] = $_SESSION['reply'][$this->input['reply']]['start_message'];
|
||||
$this->menu();
|
||||
$this->answer($_SESSION['reply'][$this->input['reply']]['start_message']);
|
||||
break;
|
||||
case 'pac':
|
||||
$this->answer($_SESSION['reply'][$this->input['reply']]['start_callback']);
|
||||
break;
|
||||
}
|
||||
unset($_SESSION['reply'][$this->input['reply']]);
|
||||
}
|
||||
}
|
||||
|
||||
public function addips()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} перечислите через запятую подсети",
|
||||
$this->input['message_id'],
|
||||
reply: 'перечислите через запятую подсети',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'callback' => 'createPeer',
|
||||
];
|
||||
}
|
||||
|
||||
public function showaddclient()
|
||||
{
|
||||
[$text, $data] = $this->menu(return: true);
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
'text' => "весь трафик",
|
||||
'callback_data' => "/add",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "подсеть",
|
||||
'callback_data' => "/add_ips",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "прокси",
|
||||
'callback_data' => "/proxy",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "назад",
|
||||
'callback_data' => "/menu",
|
||||
],
|
||||
],
|
||||
];
|
||||
$this->update(
|
||||
$this->input['chat'],
|
||||
$this->input['message_id'],
|
||||
$text,
|
||||
$data,
|
||||
);
|
||||
}
|
||||
|
||||
public function showreset()
|
||||
{
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
'text' => "подтвердить",
|
||||
'callback_data' => "/reset",
|
||||
],
|
||||
[
|
||||
'text' => "назад",
|
||||
'callback_data' => "/menu",
|
||||
],
|
||||
],
|
||||
];
|
||||
$this->update(
|
||||
$this->input['chat'],
|
||||
$this->input['message_id'],
|
||||
"Сбросить?",
|
||||
$data,
|
||||
);
|
||||
}
|
||||
|
||||
public function reset()
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$r = $this->ssh("/bin/sh /reset_wg.sh {$_SERVER['ADDRESS']} {$_SERVER['PORT_WG']}");
|
||||
file_put_contents($this->clients, '');
|
||||
$this->menu();
|
||||
}
|
||||
|
||||
public function addPeer()
|
||||
{
|
||||
$this->createPeer();
|
||||
$this->menu();
|
||||
}
|
||||
|
||||
public function config()
|
||||
{
|
||||
$conf = $this->createConfig($this->readConfig());
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
'text' => "назад",
|
||||
'callback_data' => "/menu",
|
||||
],
|
||||
],
|
||||
];
|
||||
$this->update(
|
||||
$this->input['chat'],
|
||||
$this->input['message_id'],
|
||||
"Конфиг сервера:\n\n<code>$conf</code>",
|
||||
$data,
|
||||
);
|
||||
}
|
||||
|
||||
public function deletePeer($client)
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$this->deleteClient($conf['peers'][$client]);
|
||||
unset($conf['peers'][$client]);
|
||||
$this->restartWG($this->createConfig($conf));
|
||||
$this->menu();
|
||||
}
|
||||
|
||||
public function menu($client = false, $return = false)
|
||||
{
|
||||
$status = $this->ssh('wg');
|
||||
$conf = $this->readConfig();
|
||||
$text = "<b>Статус</b>\n\nСеть: {$conf['interface']['Address']}:{$conf['interface']['ListenPort']}\n\n<code>$status</code>\n$text";
|
||||
if ($client !== false) {
|
||||
$clients = json_decode(file_get_contents($this->clients), true);
|
||||
foreach ($clients as $k => $v) {
|
||||
if ($v['interface']['Address'] == $conf['peers'][$client]['AllowedIPs']) {
|
||||
$client_conf = $v;
|
||||
break;
|
||||
}
|
||||
}
|
||||
$client_ip = explode('/', $conf['peers'][$client]['AllowedIPs'])[0];
|
||||
$client_conf_str = $this->createConfig($client_conf);
|
||||
$text = "<b>$client_ip</b>\n\n<code>$client_conf_str</code>";
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
'text' => "скачать {$conf['peers'][$client]['AllowedIPs']}",
|
||||
'callback_data' => "/download $client",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "удалить {$conf['peers'][$client]['AllowedIPs']}",
|
||||
'callback_data' => "/delete $client",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "назад",
|
||||
'callback_data' => "/menu",
|
||||
],
|
||||
],
|
||||
];
|
||||
} else {
|
||||
if (!empty($conf['peers'])) {
|
||||
foreach ($conf['peers'] as $k => $v) {
|
||||
$peers[] = [[
|
||||
'text' => "{$v['AllowedIPs']}",
|
||||
'callback_data' => "/client $k",
|
||||
]];
|
||||
}
|
||||
}
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
'text' => "добавить клиента",
|
||||
'callback_data' => "/showadd",
|
||||
],
|
||||
[
|
||||
'text' => "PAC скрипт",
|
||||
'callback_data' => "/showpac",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => "экспорт",
|
||||
'callback_data' => "/export",
|
||||
],
|
||||
[
|
||||
'text' => "импорт",
|
||||
'callback_data' => "/import",
|
||||
],
|
||||
[
|
||||
'text' => "сброс",
|
||||
'callback_data' => "/showreset",
|
||||
],
|
||||
],
|
||||
];
|
||||
if ($peers) {
|
||||
$data = array_merge($peers, $data);
|
||||
}
|
||||
array_unshift($data, [
|
||||
[
|
||||
'text' => "обновить статус",
|
||||
'callback_data' => "/menu",
|
||||
],
|
||||
]);
|
||||
}
|
||||
|
||||
if ($return) {
|
||||
return [$text, $data];
|
||||
}
|
||||
|
||||
if (!empty($this->input['callback_id'])) {
|
||||
$this->update(
|
||||
$this->input['chat'],
|
||||
$this->input['message_id'],
|
||||
$text,
|
||||
$data,
|
||||
);
|
||||
} else {
|
||||
$this->send(
|
||||
$this->input['chat'],
|
||||
$text,
|
||||
$this->input['message_id'],
|
||||
$data,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
public function readConfig()
|
||||
{
|
||||
$r = $this->ssh('cat /etc/wireguard/wg0.conf');
|
||||
$r = explode(PHP_EOL, $r);
|
||||
$r = array_filter($r);
|
||||
$i = 0;
|
||||
foreach ($r as $k => $v) {
|
||||
if (preg_match('~\[(.+)\]~', $v, $m)) {
|
||||
$i++;
|
||||
if ($m[1] == 'Interface') {
|
||||
$data[$i]['type'] = 'interface';
|
||||
} else {
|
||||
$data[$i]['type'] = 'peer';
|
||||
}
|
||||
} else {
|
||||
$t = explode('=', $v, 2);
|
||||
$data[$i][trim($t[0])] = trim($t[1]);
|
||||
}
|
||||
}
|
||||
foreach ($data as $v) {
|
||||
$type = $v['type'];
|
||||
unset($v['type']);
|
||||
if ($type == 'interface') {
|
||||
$d['interface'] = $v;
|
||||
} else {
|
||||
$d['peers'][] = $v;
|
||||
}
|
||||
}
|
||||
return $d;
|
||||
}
|
||||
|
||||
public function createConfig($data)
|
||||
{
|
||||
$conf[] = "[Interface]";
|
||||
foreach ($data['interface'] as $k => $v) {
|
||||
$conf[] = "$k = $v";
|
||||
}
|
||||
if (!empty($data['peers'])) {
|
||||
foreach ($data['peers'] as $peer) {
|
||||
$conf[] = '';
|
||||
$conf[] = '[Peer]';
|
||||
foreach ($peer as $k => $v) {
|
||||
$conf[] = "$k = $v";
|
||||
}
|
||||
}
|
||||
}
|
||||
return implode(PHP_EOL, $conf);
|
||||
}
|
||||
|
||||
public function createPeer($ips_user = false)
|
||||
{
|
||||
$conf = $this->readConfig();
|
||||
$ipnet = explode('/', $conf['interface']['Address']);
|
||||
$server_ip = ip2long($ipnet[0]);
|
||||
$ips = [$server_ip];
|
||||
$bitmask = $ipnet[1];
|
||||
if (!empty($conf['peers'])) {
|
||||
foreach ($conf['peers'] as $k => $v) {
|
||||
$ips[] = ip2long(explode('/', $v['AllowedIPs'])[0]);
|
||||
}
|
||||
}
|
||||
$ip_count = (1 << (32 - $bitmask)) - count($ips) - 1;
|
||||
for ($i=1; $i < $ip_count; $i++) {
|
||||
$ip = $i + $server_ip;
|
||||
if (!in_array($ip, $ips)) {
|
||||
$client_ip = long2ip($ip);
|
||||
break;
|
||||
}
|
||||
}
|
||||
$public_server_key = trim($this->ssh("echo {$conf['interface']['PrivateKey']} | wg pubkey"));
|
||||
$private_peer_key = trim($this->ssh("wg genkey"));
|
||||
$public_peer_key = trim($this->ssh("echo $private_peer_key | wg pubkey"));
|
||||
|
||||
$conf['peers'][] = [
|
||||
'PublicKey' => $public_peer_key,
|
||||
'AllowedIPs' => "$client_ip/32",
|
||||
];
|
||||
$client_conf = [
|
||||
'interface' => [
|
||||
'PrivateKey' => $private_peer_key,
|
||||
'Address' => "$client_ip/32",
|
||||
'MTU' => 1350,
|
||||
],
|
||||
'peers' => [
|
||||
[
|
||||
'PublicKey' => $public_server_key,
|
||||
'Endpoint' => "{$_SERVER['HTTP_HOST']}:{$_SERVER['PORT_WG']}",
|
||||
'AllowedIPs' => $ips_user ?: "0.0.0.0/0",
|
||||
'PersistentKeepalive' => 20,
|
||||
]
|
||||
]
|
||||
];
|
||||
$this->saveClient($client_conf);
|
||||
$this->restartWG($this->createConfig($conf));
|
||||
}
|
||||
|
||||
public function deleteClient($conf)
|
||||
{
|
||||
$clients = json_decode(file_get_contents($this->clients), true);
|
||||
foreach ($clients as $k => $v) {
|
||||
if ($v['interface']['Address'] == $conf['AllowedIPs']) {
|
||||
unset($clients[$k]);
|
||||
}
|
||||
}
|
||||
file_put_contents($this->clients, json_encode($clients, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
}
|
||||
|
||||
public function saveClient($client)
|
||||
{
|
||||
if (file_exists($this->clients)) {
|
||||
$conf = json_decode(file_get_contents($this->clients), true) ?: [];
|
||||
} else {
|
||||
$conf = [];
|
||||
}
|
||||
$conf = array_merge($conf, [$client]);
|
||||
file_put_contents($this->clients, json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
}
|
||||
|
||||
public function restartWG($conf_str)
|
||||
{
|
||||
$this->ssh("wg-quick down wg0");
|
||||
$this->ssh("echo '$conf_str' > /etc/wireguard/wg0.conf");
|
||||
$this->ssh("wg-quick up wg0");
|
||||
return true;
|
||||
}
|
||||
|
||||
public function ssh($cmd)
|
||||
{
|
||||
try {
|
||||
$c = ssh2_connect('wg', 22);
|
||||
ssh2_auth_pubkey_file($c, 'root', '/ssh/key.pub', '/ssh/key');
|
||||
$s = ssh2_exec($c, $cmd);
|
||||
stream_set_blocking($s, true);
|
||||
$data = "";
|
||||
while ($buf = fread($s, 4096)) {
|
||||
$data .= $buf;
|
||||
}
|
||||
fclose($s);
|
||||
ssh2_disconnect($c);
|
||||
} catch (Exception | Error $e) {
|
||||
$this->send($this->input['chat'], 'нет подключения к wg', $this->input['message_id']);
|
||||
die();
|
||||
}
|
||||
return $data;
|
||||
}
|
||||
|
||||
public function request($method, $data, $json_header = 0)
|
||||
{
|
||||
$ch = curl_init();
|
||||
curl_setopt_array($ch, [
|
||||
CURLOPT_URL => $this->api . $method,
|
||||
CURLOPT_CUSTOMREQUEST => 'POST',
|
||||
CURLOPT_RETURNTRANSFER => true,
|
||||
CURLOPT_HTTPHEADER => $json_header ? [
|
||||
'Content-Type: application/json'
|
||||
]: [],
|
||||
CURLOPT_POSTFIELDS => $data,
|
||||
]);
|
||||
$res = curl_exec($ch);
|
||||
return json_decode($res, true);
|
||||
}
|
||||
|
||||
public function setwebhook()
|
||||
{
|
||||
$ip = file_get_contents('https://ipinfo.io/ip');
|
||||
if (empty($ip)) {
|
||||
die('нет айпи');
|
||||
}
|
||||
echo "$ip\n";
|
||||
var_dump($this->request('setWebhook', [
|
||||
'url' => "https://$ip/{$this->key}",
|
||||
'certificate' => curl_file_create('/cert/nginx_public.pem'),
|
||||
]));
|
||||
}
|
||||
|
||||
public function setcommands()
|
||||
{
|
||||
$data = [
|
||||
'commands' => [
|
||||
[
|
||||
'command' => 'menu',
|
||||
'description' => '...',
|
||||
],
|
||||
]
|
||||
];
|
||||
var_dump($this->request('setMyCommands', json_encode($data), 1));
|
||||
}
|
||||
|
||||
public function send($chat, $text, ?int $to = 0, $button = false, $reply = false)
|
||||
{
|
||||
if ($button) {
|
||||
$extra = ['inline_keyboard' => $button];
|
||||
}
|
||||
if (false !== $reply) {
|
||||
$extra = [
|
||||
'force_reply' => true,
|
||||
'input_field_placeholder' => $reply,
|
||||
'selective' => true,
|
||||
];
|
||||
}
|
||||
$length = 3096;
|
||||
if (mb_strlen($text, 'utf-8') > $length) {
|
||||
$tails = $this->splitText($text, $length);
|
||||
foreach ($tails as $k => $v) {
|
||||
$data = [
|
||||
'chat_id' => $chat,
|
||||
'text' => "$v\n",
|
||||
'parse_mode' => 'HTML',
|
||||
// 'disable_web_page_preview' => true,
|
||||
// 'disable_notification' => !empty($to) && 0 == $k,
|
||||
'reply_to_message_id' => 0 == $k && $to > 0 ? $to : false,
|
||||
];
|
||||
if ($k == array_key_last($tails)) {
|
||||
if ($extra) {
|
||||
$data['reply_markup'] = json_encode($extra);
|
||||
}
|
||||
}
|
||||
$r = $this->request('sendMessage', $data);
|
||||
}
|
||||
} else {
|
||||
$data = [
|
||||
'chat_id' => $chat,
|
||||
'text' => $text,
|
||||
'parse_mode' => 'HTML',
|
||||
// 'disable_web_page_preview' => true,
|
||||
// 'disable_notification' => !empty($to),
|
||||
'reply_to_message_id' => $to,
|
||||
];
|
||||
if (!empty($extra)) {
|
||||
$data['reply_markup'] = json_encode($extra);
|
||||
}
|
||||
$r = $this->request('sendMessage', $data);
|
||||
}
|
||||
return $r;
|
||||
}
|
||||
|
||||
public function splitText($text, $size = 4096)
|
||||
{
|
||||
$tails = preg_split('~\n~', $text);
|
||||
if (!empty($tails)) {
|
||||
foreach ($tails as $v) {
|
||||
$lines[] = [
|
||||
'length' => mb_strlen($v, 'utf-8'),
|
||||
'text' => $v,
|
||||
];
|
||||
}
|
||||
$i = 0;
|
||||
foreach ($lines as $v) {
|
||||
$i += $v['length'];
|
||||
$output[ceil($i / $size)] .= $v['text'] . "\n";
|
||||
}
|
||||
return array_values($output);
|
||||
} else {
|
||||
return [$text];
|
||||
}
|
||||
}
|
||||
|
||||
public function image($chat, $id_url_cFile, $caption = false, $to = false)
|
||||
{
|
||||
return $this->request('sendPhoto', [
|
||||
'chat_id' => $chat,
|
||||
'photo' => $id_url_cFile,
|
||||
'caption' => $caption,
|
||||
'reply_to_message_id' => $to,
|
||||
]);
|
||||
}
|
||||
|
||||
public function sendFile($chat, $id_url_cFile, $caption = false, $to = false)
|
||||
{
|
||||
return $this->request('sendDocument', [
|
||||
'chat_id' => $chat,
|
||||
'document' => $id_url_cFile,
|
||||
'caption' => $caption,
|
||||
'reply_to_message_id' => $to,
|
||||
'parse_mode' => 'html',
|
||||
]);
|
||||
}
|
||||
|
||||
public function update($chat, $message_id, $text, $button = false, $reply = false)
|
||||
{
|
||||
if ($button) {
|
||||
$extra = ['inline_keyboard' => $button];
|
||||
}
|
||||
if ($reply !== false) {
|
||||
$extra = [
|
||||
'force_reply' => true,
|
||||
'input_field_placeholder' => $reply
|
||||
];
|
||||
}
|
||||
$data = [
|
||||
'chat_id' => $chat,
|
||||
'message_id' => $message_id,
|
||||
'text' => $text,
|
||||
'parse_mode' => 'HTML',
|
||||
'disable_web_page_preview' => true,
|
||||
];
|
||||
if (!empty($extra)) {
|
||||
$data['reply_markup'] = json_encode($extra);
|
||||
}
|
||||
return $this->request('editMessageText', $data);
|
||||
}
|
||||
|
||||
public function answer($callback_id, $textNotify = false, $notify = false)
|
||||
{
|
||||
return $this->callback = $this->request('answerCallbackQuery', [
|
||||
'callback_query_id' => $callback_id,
|
||||
'show_alert' => $notify,
|
||||
'text' => $textNotify,
|
||||
]);
|
||||
}
|
||||
|
||||
public function delete($chat, $message_id)
|
||||
{
|
||||
$data = [
|
||||
'chat_id' => $chat,
|
||||
'message_id' => $message_id,
|
||||
];
|
||||
return $this->request('deleteMessage', $data);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
<?php
|
||||
|
||||
error_reporting(E_ALL & ~E_NOTICE);
|
||||
// ini_set('display_errors', 'On');
|
||||
ini_set("log_errors", 1);
|
||||
ini_set("error_log", __DIR__ . "/error_log");
|
||||
|
||||
$debug = [
|
||||
'raw' => file_get_contents('php://input'),
|
||||
'json' => json_decode(file_get_contents('php://input'), true),
|
||||
'post' => $_POST,
|
||||
'file' => $_FILES,
|
||||
];
|
||||
register_shutdown_function('exit_log', $debug);
|
||||
|
||||
function exit_log($debug)
|
||||
{
|
||||
$output = ob_get_contents();
|
||||
$debug['response'] = json_decode($output, true) ?: $output;
|
||||
file_put_contents(__DIR__ . '/debug', "\n" . date('Y-m-d H:i:s') . "\n" . var_export($debug, true) . "\n", FILE_APPEND);
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
<?php
|
||||
|
||||
// require __DIR__ . '/debug.php';
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/config.php';
|
||||
|
||||
$url = trim($_SERVER['REQUEST_URI'], '/');
|
||||
if (!('POST' == $_SERVER['REQUEST_METHOD'] && $url == $key)) {
|
||||
header('500', true, 500);
|
||||
die();
|
||||
}
|
||||
|
||||
$bot = new Bot($key);
|
||||
$bot->input();
|
||||
@@ -0,0 +1,9 @@
|
||||
<?php
|
||||
|
||||
// require __DIR__ . '/debug.php';
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/config.php';
|
||||
|
||||
$bot = new Bot($key);
|
||||
$bot->setwebhook($key);
|
||||
$bot->setcommands();
|
||||
@@ -0,0 +1,20 @@
|
||||
<?php
|
||||
|
||||
$c = ssh2_connect('wg', 22);
|
||||
ssh2_auth_pubkey_file($c, 'root', '/ssh/key.pub', '/ssh/key');
|
||||
|
||||
function ssh($c, $cmd)
|
||||
{
|
||||
$stream = ssh2_exec($c, $cmd);
|
||||
stream_set_blocking($stream, true);
|
||||
$data = "";
|
||||
while ($buf = fread($stream, 4096)) {
|
||||
$data .= $buf;
|
||||
}
|
||||
fclose($stream);
|
||||
return $data;
|
||||
}
|
||||
|
||||
$data[] = ssh($c, 'wg');
|
||||
// $data[] = ssh($c, 'wg-quick up wg0');
|
||||
var_dump($data);
|
||||
@@ -0,0 +1,17 @@
|
||||
export LANG=ru_RU.utf8
|
||||
|
||||
alias ls='ls $LS_OPTIONS'
|
||||
alias ll='ls -lah'
|
||||
|
||||
|
||||
PS1='[\[\e[0;94m\]\u\[\e[0;37m\]@\[\e[0;31m\]\h\[\e[0;36m\] $PWD\[\e[0;37m\]]\$\[\e[0m\] '
|
||||
|
||||
export LS_OPTIONS='--color=auto'
|
||||
|
||||
case "$TERM" in
|
||||
xterm*|rxvt*)
|
||||
PS1="\[\e]0;${debian_chroot:+($debian_chroot)}\u@\h: \w\a\]$PS1"
|
||||
;;
|
||||
*)
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1,2 @@
|
||||
#PEAR_Config 0.9
|
||||
a:33:{s:9:"cache_dir";s:15:"/tmp/pear/cache";s:15:"default_channel";s:12:"pear.php.net";s:16:"preferred_mirror";s:12:"pear.php.net";s:13:"remote_config";s:0:"";s:13:"auto_discover";i:0;s:13:"master_server";s:12:"pear.php.net";s:10:"http_proxy";s:0:"";s:7:"php_dir";s:18:"/usr/local/lib/php";s:7:"ext_dir";s:55:"/usr/local/lib/php/extensions/no-debug-non-zts-20210902";s:7:"doc_dir";s:22:"/usr/local/lib/php/doc";s:7:"bin_dir";s:14:"/usr/local/bin";s:8:"data_dir";s:23:"/usr/local/lib/php/data";s:7:"cfg_dir";s:22:"/usr/local/lib/php/cfg";s:7:"www_dir";s:25:"/usr/local/lib/php/htdocs";s:7:"man_dir";s:28:"/usr/local/lib/php/local/man";s:8:"test_dir";s:23:"/usr/local/lib/php/test";s:8:"temp_dir";s:14:"/tmp/pear/temp";s:12:"download_dir";s:18:"/tmp/pear/download";s:7:"php_bin";s:18:"/usr/local/bin/php";s:10:"php_prefix";s:0:"";s:10:"php_suffix";s:0:"";s:7:"php_ini";s:0:"";s:12:"metadata_dir";s:0:"";s:8:"username";s:0:"";s:8:"password";s:0:"";s:7:"verbose";i:1;s:15:"preferred_state";s:6:"stable";s:5:"umask";i:18;s:9:"cache_ttl";i:3600;s:8:"sig_type";s:3:"gpg";s:7:"sig_bin";s:18:"/usr/local/bin/gpg";s:9:"sig_keyid";s:0:"";s:10:"sig_keydir";s:23:"/usr/local/etc/pearkeys";}
|
||||
@@ -0,0 +1,143 @@
|
||||
;;;;;;;;;;;;;;;;;;;;;
|
||||
; FPM Configuration ;
|
||||
;;;;;;;;;;;;;;;;;;;;;
|
||||
|
||||
; All relative paths in this configuration file are relative to PHP's install
|
||||
; prefix (/usr/local). This prefix can be dynamically changed by using the
|
||||
; '-p' argument from the command line.
|
||||
|
||||
;;;;;;;;;;;;;;;;;;
|
||||
; Global Options ;
|
||||
;;;;;;;;;;;;;;;;;;
|
||||
|
||||
[global]
|
||||
; Pid file
|
||||
; Note: the default prefix is /usr/local/var
|
||||
; Default Value: none
|
||||
;pid = run/php-fpm.pid
|
||||
|
||||
; Error log file
|
||||
; If it's set to "syslog", log is sent to syslogd instead of being written
|
||||
; into a local file.
|
||||
; Note: the default prefix is /usr/local/var
|
||||
; Default Value: log/php-fpm.log
|
||||
;error_log = log/php-fpm.log
|
||||
|
||||
; syslog_facility is used to specify what type of program is logging the
|
||||
; message. This lets syslogd specify that messages from different facilities
|
||||
; will be handled differently.
|
||||
; See syslog(3) for possible values (ex daemon equiv LOG_DAEMON)
|
||||
; Default Value: daemon
|
||||
;syslog.facility = daemon
|
||||
|
||||
; syslog_ident is prepended to every message. If you have multiple FPM
|
||||
; instances running on the same server, you can change the default value
|
||||
; which must suit common needs.
|
||||
; Default Value: php-fpm
|
||||
;syslog.ident = php-fpm
|
||||
|
||||
; Log level
|
||||
; Possible Values: alert, error, warning, notice, debug
|
||||
; Default Value: notice
|
||||
;log_level = notice
|
||||
|
||||
; Log limit on number of characters in the single line (log entry). If the
|
||||
; line is over the limit, it is wrapped on multiple lines. The limit is for
|
||||
; all logged characters including message prefix and suffix if present. However
|
||||
; the new line character does not count into it as it is present only when
|
||||
; logging to a file descriptor. It means the new line character is not present
|
||||
; when logging to syslog.
|
||||
; Default Value: 1024
|
||||
;log_limit = 4096
|
||||
|
||||
; Log buffering specifies if the log line is buffered which means that the
|
||||
; line is written in a single write operation. If the value is false, then the
|
||||
; data is written directly into the file descriptor. It is an experimental
|
||||
; option that can potentially improve logging performance and memory usage
|
||||
; for some heavy logging scenarios. This option is ignored if logging to syslog
|
||||
; as it has to be always buffered.
|
||||
; Default value: yes
|
||||
;log_buffering = no
|
||||
|
||||
; If this number of child processes exit with SIGSEGV or SIGBUS within the time
|
||||
; interval set by emergency_restart_interval then FPM will restart. A value
|
||||
; of '0' means 'Off'.
|
||||
; Default Value: 0
|
||||
;emergency_restart_threshold = 0
|
||||
|
||||
; Interval of time used by emergency_restart_interval to determine when
|
||||
; a graceful restart will be initiated. This can be useful to work around
|
||||
; accidental corruptions in an accelerator's shared memory.
|
||||
; Available Units: s(econds), m(inutes), h(ours), or d(ays)
|
||||
; Default Unit: seconds
|
||||
; Default Value: 0
|
||||
;emergency_restart_interval = 0
|
||||
|
||||
; Time limit for child processes to wait for a reaction on signals from master.
|
||||
; Available units: s(econds), m(inutes), h(ours), or d(ays)
|
||||
; Default Unit: seconds
|
||||
; Default Value: 0
|
||||
;process_control_timeout = 0
|
||||
|
||||
; The maximum number of processes FPM will fork. This has been designed to control
|
||||
; the global number of processes when using dynamic PM within a lot of pools.
|
||||
; Use it with caution.
|
||||
; Note: A value of 0 indicates no limit
|
||||
; Default Value: 0
|
||||
; process.max = 128
|
||||
|
||||
; Specify the nice(2) priority to apply to the master process (only if set)
|
||||
; The value can vary from -19 (highest priority) to 20 (lowest priority)
|
||||
; Note: - It will only work if the FPM master process is launched as root
|
||||
; - The pool process will inherit the master process priority
|
||||
; unless specified otherwise
|
||||
; Default Value: no set
|
||||
; process.priority = -19
|
||||
|
||||
; Send FPM to background. Set to 'no' to keep FPM in foreground for debugging.
|
||||
; Default Value: yes
|
||||
;daemonize = yes
|
||||
|
||||
; Set open file descriptor rlimit for the master process.
|
||||
; Default Value: system defined value
|
||||
;rlimit_files = 1024
|
||||
|
||||
; Set max core size rlimit for the master process.
|
||||
; Possible Values: 'unlimited' or an integer greater or equal to 0
|
||||
; Default Value: system defined value
|
||||
;rlimit_core = 0
|
||||
|
||||
; Specify the event mechanism FPM will use. The following is available:
|
||||
; - select (any POSIX os)
|
||||
; - poll (any POSIX os)
|
||||
; - epoll (linux >= 2.5.44)
|
||||
; - kqueue (FreeBSD >= 4.1, OpenBSD >= 2.9, NetBSD >= 2.0)
|
||||
; - /dev/poll (Solaris >= 7)
|
||||
; - port (Solaris >= 10)
|
||||
; Default Value: not set (auto detection)
|
||||
;events.mechanism = epoll
|
||||
|
||||
; When FPM is built with systemd integration, specify the interval,
|
||||
; in seconds, between health report notification to systemd.
|
||||
; Set to 0 to disable.
|
||||
; Available Units: s(econds), m(inutes), h(ours)
|
||||
; Default Unit: seconds
|
||||
; Default value: 10
|
||||
;systemd_interval = 10
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;
|
||||
; Pool Definitions ;
|
||||
;;;;;;;;;;;;;;;;;;;;
|
||||
|
||||
; Multiple pools of child processes may be started with different listening
|
||||
; ports and different management options. The name of the pool will be
|
||||
; used in logs and stats. There is no limitation on the number of pools which
|
||||
; FPM can handle. Your system will tell you anyway :)
|
||||
|
||||
; Include one or more files. If glob(3) exists, it is used to include a bunch of
|
||||
; files from a glob(3) pattern. This directive can be used everywhere in the
|
||||
; file.
|
||||
; Relative path can also be used. They will be prefixed by:
|
||||
; - the global prefix if it's been set (-p argument)
|
||||
; - /usr/local otherwise
|
||||
include=etc/php-fpm.d/*.conf
|
||||
@@ -0,0 +1,143 @@
|
||||
;;;;;;;;;;;;;;;;;;;;;
|
||||
; FPM Configuration ;
|
||||
;;;;;;;;;;;;;;;;;;;;;
|
||||
|
||||
; All relative paths in this configuration file are relative to PHP's install
|
||||
; prefix (/usr/local). This prefix can be dynamically changed by using the
|
||||
; '-p' argument from the command line.
|
||||
|
||||
;;;;;;;;;;;;;;;;;;
|
||||
; Global Options ;
|
||||
;;;;;;;;;;;;;;;;;;
|
||||
|
||||
[global]
|
||||
; Pid file
|
||||
; Note: the default prefix is /usr/local/var
|
||||
; Default Value: none
|
||||
;pid = run/php-fpm.pid
|
||||
|
||||
; Error log file
|
||||
; If it's set to "syslog", log is sent to syslogd instead of being written
|
||||
; into a local file.
|
||||
; Note: the default prefix is /usr/local/var
|
||||
; Default Value: log/php-fpm.log
|
||||
;error_log = log/php-fpm.log
|
||||
|
||||
; syslog_facility is used to specify what type of program is logging the
|
||||
; message. This lets syslogd specify that messages from different facilities
|
||||
; will be handled differently.
|
||||
; See syslog(3) for possible values (ex daemon equiv LOG_DAEMON)
|
||||
; Default Value: daemon
|
||||
;syslog.facility = daemon
|
||||
|
||||
; syslog_ident is prepended to every message. If you have multiple FPM
|
||||
; instances running on the same server, you can change the default value
|
||||
; which must suit common needs.
|
||||
; Default Value: php-fpm
|
||||
;syslog.ident = php-fpm
|
||||
|
||||
; Log level
|
||||
; Possible Values: alert, error, warning, notice, debug
|
||||
; Default Value: notice
|
||||
;log_level = notice
|
||||
|
||||
; Log limit on number of characters in the single line (log entry). If the
|
||||
; line is over the limit, it is wrapped on multiple lines. The limit is for
|
||||
; all logged characters including message prefix and suffix if present. However
|
||||
; the new line character does not count into it as it is present only when
|
||||
; logging to a file descriptor. It means the new line character is not present
|
||||
; when logging to syslog.
|
||||
; Default Value: 1024
|
||||
;log_limit = 4096
|
||||
|
||||
; Log buffering specifies if the log line is buffered which means that the
|
||||
; line is written in a single write operation. If the value is false, then the
|
||||
; data is written directly into the file descriptor. It is an experimental
|
||||
; option that can potentially improve logging performance and memory usage
|
||||
; for some heavy logging scenarios. This option is ignored if logging to syslog
|
||||
; as it has to be always buffered.
|
||||
; Default value: yes
|
||||
;log_buffering = no
|
||||
|
||||
; If this number of child processes exit with SIGSEGV or SIGBUS within the time
|
||||
; interval set by emergency_restart_interval then FPM will restart. A value
|
||||
; of '0' means 'Off'.
|
||||
; Default Value: 0
|
||||
;emergency_restart_threshold = 0
|
||||
|
||||
; Interval of time used by emergency_restart_interval to determine when
|
||||
; a graceful restart will be initiated. This can be useful to work around
|
||||
; accidental corruptions in an accelerator's shared memory.
|
||||
; Available Units: s(econds), m(inutes), h(ours), or d(ays)
|
||||
; Default Unit: seconds
|
||||
; Default Value: 0
|
||||
;emergency_restart_interval = 0
|
||||
|
||||
; Time limit for child processes to wait for a reaction on signals from master.
|
||||
; Available units: s(econds), m(inutes), h(ours), or d(ays)
|
||||
; Default Unit: seconds
|
||||
; Default Value: 0
|
||||
;process_control_timeout = 0
|
||||
|
||||
; The maximum number of processes FPM will fork. This has been designed to control
|
||||
; the global number of processes when using dynamic PM within a lot of pools.
|
||||
; Use it with caution.
|
||||
; Note: A value of 0 indicates no limit
|
||||
; Default Value: 0
|
||||
; process.max = 128
|
||||
|
||||
; Specify the nice(2) priority to apply to the master process (only if set)
|
||||
; The value can vary from -19 (highest priority) to 20 (lowest priority)
|
||||
; Note: - It will only work if the FPM master process is launched as root
|
||||
; - The pool process will inherit the master process priority
|
||||
; unless specified otherwise
|
||||
; Default Value: no set
|
||||
; process.priority = -19
|
||||
|
||||
; Send FPM to background. Set to 'no' to keep FPM in foreground for debugging.
|
||||
; Default Value: yes
|
||||
;daemonize = yes
|
||||
|
||||
; Set open file descriptor rlimit for the master process.
|
||||
; Default Value: system defined value
|
||||
;rlimit_files = 1024
|
||||
|
||||
; Set max core size rlimit for the master process.
|
||||
; Possible Values: 'unlimited' or an integer greater or equal to 0
|
||||
; Default Value: system defined value
|
||||
;rlimit_core = 0
|
||||
|
||||
; Specify the event mechanism FPM will use. The following is available:
|
||||
; - select (any POSIX os)
|
||||
; - poll (any POSIX os)
|
||||
; - epoll (linux >= 2.5.44)
|
||||
; - kqueue (FreeBSD >= 4.1, OpenBSD >= 2.9, NetBSD >= 2.0)
|
||||
; - /dev/poll (Solaris >= 7)
|
||||
; - port (Solaris >= 10)
|
||||
; Default Value: not set (auto detection)
|
||||
;events.mechanism = epoll
|
||||
|
||||
; When FPM is built with systemd integration, specify the interval,
|
||||
; in seconds, between health report notification to systemd.
|
||||
; Set to 0 to disable.
|
||||
; Available Units: s(econds), m(inutes), h(ours)
|
||||
; Default Unit: seconds
|
||||
; Default value: 10
|
||||
;systemd_interval = 10
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;
|
||||
; Pool Definitions ;
|
||||
;;;;;;;;;;;;;;;;;;;;
|
||||
|
||||
; Multiple pools of child processes may be started with different listening
|
||||
; ports and different management options. The name of the pool will be
|
||||
; used in logs and stats. There is no limitation on the number of pools which
|
||||
; FPM can handle. Your system will tell you anyway :)
|
||||
|
||||
; Include one or more files. If glob(3) exists, it is used to include a bunch of
|
||||
; files from a glob(3) pattern. This directive can be used everywhere in the
|
||||
; file.
|
||||
; Relative path can also be used. They will be prefixed by:
|
||||
; - the global prefix if it's been set (-p argument)
|
||||
; - /usr/local otherwise
|
||||
include=NONE/etc/php-fpm.d/*.conf
|
||||
@@ -0,0 +1,15 @@
|
||||
[global]
|
||||
error_log = /proc/self/fd/2
|
||||
|
||||
; https://github.com/docker-library/php/pull/725#issuecomment-443540114
|
||||
log_limit = 8192
|
||||
|
||||
[www]
|
||||
; if we send this to /proc/self/fd/1, it never appears
|
||||
access.log = /proc/self/fd/2
|
||||
|
||||
clear_env = no
|
||||
|
||||
; Ensure worker stdout and stderr are sent to the main error log.
|
||||
catch_workers_output = yes
|
||||
decorate_workers_output = no
|
||||
@@ -0,0 +1,463 @@
|
||||
; Start a new pool named 'www'.
|
||||
; the variable $pool can be used in any directive and will be replaced by the
|
||||
; pool name ('www' here)
|
||||
[www]
|
||||
|
||||
; Per pool prefix
|
||||
; It only applies on the following directives:
|
||||
; - 'access.log'
|
||||
; - 'slowlog'
|
||||
; - 'listen' (unixsocket)
|
||||
; - 'chroot'
|
||||
; - 'chdir'
|
||||
; - 'php_values'
|
||||
; - 'php_admin_values'
|
||||
; When not set, the global prefix (or NONE) applies instead.
|
||||
; Note: This directive can also be relative to the global prefix.
|
||||
; Default Value: none
|
||||
;prefix = /path/to/pools/$pool
|
||||
|
||||
; Unix user/group of processes
|
||||
; Note: The user is mandatory. If the group is not set, the default user's group
|
||||
; will be used.
|
||||
user = www-data
|
||||
group = www-data
|
||||
|
||||
; The address on which to accept FastCGI requests.
|
||||
; Valid syntaxes are:
|
||||
; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
|
||||
; a specific port;
|
||||
; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
|
||||
; a specific port;
|
||||
; 'port' - to listen on a TCP socket to all addresses
|
||||
; (IPv6 and IPv4-mapped) on a specific port;
|
||||
; '/path/to/unix/socket' - to listen on a unix socket.
|
||||
; Note: This value is mandatory.
|
||||
listen = 127.0.0.1:9000
|
||||
|
||||
; Set listen(2) backlog.
|
||||
; Default Value: 511 (-1 on FreeBSD and OpenBSD)
|
||||
;listen.backlog = 511
|
||||
|
||||
; Set permissions for unix socket, if one is used. In Linux, read/write
|
||||
; permissions must be set in order to allow connections from a web server. Many
|
||||
; BSD-derived systems allow connections regardless of permissions. The owner
|
||||
; and group can be specified either by name or by their numeric IDs.
|
||||
; Default Values: user and group are set as the running user
|
||||
; mode is set to 0660
|
||||
;listen.owner = www-data
|
||||
;listen.group = www-data
|
||||
;listen.mode = 0660
|
||||
; When POSIX Access Control Lists are supported you can set them using
|
||||
; these options, value is a comma separated list of user/group names.
|
||||
; When set, listen.owner and listen.group are ignored
|
||||
;listen.acl_users =
|
||||
;listen.acl_groups =
|
||||
|
||||
; List of addresses (IPv4/IPv6) of FastCGI clients which are allowed to connect.
|
||||
; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
|
||||
; PHP FCGI (5.2.2+). Makes sense only with a tcp listening socket. Each address
|
||||
; must be separated by a comma. If this value is left blank, connections will be
|
||||
; accepted from any ip address.
|
||||
; Default Value: any
|
||||
;listen.allowed_clients = 127.0.0.1
|
||||
|
||||
; Specify the nice(2) priority to apply to the pool processes (only if set)
|
||||
; The value can vary from -19 (highest priority) to 20 (lower priority)
|
||||
; Note: - It will only work if the FPM master process is launched as root
|
||||
; - The pool processes will inherit the master process priority
|
||||
; unless it specified otherwise
|
||||
; Default Value: no set
|
||||
; process.priority = -19
|
||||
|
||||
; Set the process dumpable flag (PR_SET_DUMPABLE prctl) even if the process user
|
||||
; or group is different than the master process user. It allows to create process
|
||||
; core dump and ptrace the process for the pool user.
|
||||
; Default Value: no
|
||||
; process.dumpable = yes
|
||||
|
||||
; Choose how the process manager will control the number of child processes.
|
||||
; Possible Values:
|
||||
; static - a fixed number (pm.max_children) of child processes;
|
||||
; dynamic - the number of child processes are set dynamically based on the
|
||||
; following directives. With this process management, there will be
|
||||
; always at least 1 children.
|
||||
; pm.max_children - the maximum number of children that can
|
||||
; be alive at the same time.
|
||||
; pm.start_servers - the number of children created on startup.
|
||||
; pm.min_spare_servers - the minimum number of children in 'idle'
|
||||
; state (waiting to process). If the number
|
||||
; of 'idle' processes is less than this
|
||||
; number then some children will be created.
|
||||
; pm.max_spare_servers - the maximum number of children in 'idle'
|
||||
; state (waiting to process). If the number
|
||||
; of 'idle' processes is greater than this
|
||||
; number then some children will be killed.
|
||||
; pm.max_spawn_rate - the maximum number of rate to spawn child
|
||||
; processes at once.
|
||||
; ondemand - no children are created at startup. Children will be forked when
|
||||
; new requests will connect. The following parameter are used:
|
||||
; pm.max_children - the maximum number of children that
|
||||
; can be alive at the same time.
|
||||
; pm.process_idle_timeout - The number of seconds after which
|
||||
; an idle process will be killed.
|
||||
; Note: This value is mandatory.
|
||||
pm = dynamic
|
||||
|
||||
; The number of child processes to be created when pm is set to 'static' and the
|
||||
; maximum number of child processes when pm is set to 'dynamic' or 'ondemand'.
|
||||
; This value sets the limit on the number of simultaneous requests that will be
|
||||
; served. Equivalent to the ApacheMaxClients directive with mpm_prefork.
|
||||
; Equivalent to the PHP_FCGI_CHILDREN environment variable in the original PHP
|
||||
; CGI. The below defaults are based on a server without much resources. Don't
|
||||
; forget to tweak pm.* to fit your needs.
|
||||
; Note: Used when pm is set to 'static', 'dynamic' or 'ondemand'
|
||||
; Note: This value is mandatory.
|
||||
pm.max_children = 5
|
||||
|
||||
; The number of child processes created on startup.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Default Value: (min_spare_servers + max_spare_servers) / 2
|
||||
pm.start_servers = 2
|
||||
|
||||
; The desired minimum number of idle server processes.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
pm.min_spare_servers = 1
|
||||
|
||||
; The desired maximum number of idle server processes.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
pm.max_spare_servers = 3
|
||||
|
||||
; The number of rate to spawn child processes at once.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
; Default Value: 32
|
||||
;pm.max_spawn_rate = 32
|
||||
|
||||
; The number of seconds after which an idle process will be killed.
|
||||
; Note: Used only when pm is set to 'ondemand'
|
||||
; Default Value: 10s
|
||||
;pm.process_idle_timeout = 10s;
|
||||
|
||||
; The number of requests each child process should execute before respawning.
|
||||
; This can be useful to work around memory leaks in 3rd party libraries. For
|
||||
; endless request processing specify '0'. Equivalent to PHP_FCGI_MAX_REQUESTS.
|
||||
; Default Value: 0
|
||||
;pm.max_requests = 500
|
||||
|
||||
; The URI to view the FPM status page. If this value is not set, no URI will be
|
||||
; recognized as a status page. It shows the following information:
|
||||
; pool - the name of the pool;
|
||||
; process manager - static, dynamic or ondemand;
|
||||
; start time - the date and time FPM has started;
|
||||
; start since - number of seconds since FPM has started;
|
||||
; accepted conn - the number of request accepted by the pool;
|
||||
; listen queue - the number of request in the queue of pending
|
||||
; connections (see backlog in listen(2));
|
||||
; max listen queue - the maximum number of requests in the queue
|
||||
; of pending connections since FPM has started;
|
||||
; listen queue len - the size of the socket queue of pending connections;
|
||||
; idle processes - the number of idle processes;
|
||||
; active processes - the number of active processes;
|
||||
; total processes - the number of idle + active processes;
|
||||
; max active processes - the maximum number of active processes since FPM
|
||||
; has started;
|
||||
; max children reached - number of times, the process limit has been reached,
|
||||
; when pm tries to start more children (works only for
|
||||
; pm 'dynamic' and 'ondemand');
|
||||
; Value are updated in real time.
|
||||
; Example output:
|
||||
; pool: www
|
||||
; process manager: static
|
||||
; start time: 01/Jul/2011:17:53:49 +0200
|
||||
; start since: 62636
|
||||
; accepted conn: 190460
|
||||
; listen queue: 0
|
||||
; max listen queue: 1
|
||||
; listen queue len: 42
|
||||
; idle processes: 4
|
||||
; active processes: 11
|
||||
; total processes: 15
|
||||
; max active processes: 12
|
||||
; max children reached: 0
|
||||
;
|
||||
; By default the status page output is formatted as text/plain. Passing either
|
||||
; 'html', 'xml' or 'json' in the query string will return the corresponding
|
||||
; output syntax. Example:
|
||||
; http://www.foo.bar/status
|
||||
; http://www.foo.bar/status?json
|
||||
; http://www.foo.bar/status?html
|
||||
; http://www.foo.bar/status?xml
|
||||
;
|
||||
; By default the status page only outputs short status. Passing 'full' in the
|
||||
; query string will also return status for each pool process.
|
||||
; Example:
|
||||
; http://www.foo.bar/status?full
|
||||
; http://www.foo.bar/status?json&full
|
||||
; http://www.foo.bar/status?html&full
|
||||
; http://www.foo.bar/status?xml&full
|
||||
; The Full status returns for each process:
|
||||
; pid - the PID of the process;
|
||||
; state - the state of the process (Idle, Running, ...);
|
||||
; start time - the date and time the process has started;
|
||||
; start since - the number of seconds since the process has started;
|
||||
; requests - the number of requests the process has served;
|
||||
; request duration - the duration in µs of the requests;
|
||||
; request method - the request method (GET, POST, ...);
|
||||
; request URI - the request URI with the query string;
|
||||
; content length - the content length of the request (only with POST);
|
||||
; user - the user (PHP_AUTH_USER) (or '-' if not set);
|
||||
; script - the main script called (or '-' if not set);
|
||||
; last request cpu - the %cpu the last request consumed
|
||||
; it's always 0 if the process is not in Idle state
|
||||
; because CPU calculation is done when the request
|
||||
; processing has terminated;
|
||||
; last request memory - the max amount of memory the last request consumed
|
||||
; it's always 0 if the process is not in Idle state
|
||||
; because memory calculation is done when the request
|
||||
; processing has terminated;
|
||||
; If the process is in Idle state, then informations are related to the
|
||||
; last request the process has served. Otherwise informations are related to
|
||||
; the current request being served.
|
||||
; Example output:
|
||||
; ************************
|
||||
; pid: 31330
|
||||
; state: Running
|
||||
; start time: 01/Jul/2011:17:53:49 +0200
|
||||
; start since: 63087
|
||||
; requests: 12808
|
||||
; request duration: 1250261
|
||||
; request method: GET
|
||||
; request URI: /test_mem.php?N=10000
|
||||
; content length: 0
|
||||
; user: -
|
||||
; script: /home/fat/web/docs/php/test_mem.php
|
||||
; last request cpu: 0.00
|
||||
; last request memory: 0
|
||||
;
|
||||
; Note: There is a real-time FPM status monitoring sample web page available
|
||||
; It's available in: /usr/local/share/php/fpm/status.html
|
||||
;
|
||||
; Note: The value must start with a leading slash (/). The value can be
|
||||
; anything, but it may not be a good idea to use the .php extension or it
|
||||
; may conflict with a real PHP file.
|
||||
; Default Value: not set
|
||||
;pm.status_path = /status
|
||||
|
||||
; The address on which to accept FastCGI status request. This creates a new
|
||||
; invisible pool that can handle requests independently. This is useful
|
||||
; if the main pool is busy with long running requests because it is still possible
|
||||
; to get the status before finishing the long running requests.
|
||||
;
|
||||
; Valid syntaxes are:
|
||||
; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
|
||||
; a specific port;
|
||||
; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
|
||||
; a specific port;
|
||||
; 'port' - to listen on a TCP socket to all addresses
|
||||
; (IPv6 and IPv4-mapped) on a specific port;
|
||||
; '/path/to/unix/socket' - to listen on a unix socket.
|
||||
; Default Value: value of the listen option
|
||||
;pm.status_listen = 127.0.0.1:9001
|
||||
|
||||
; The ping URI to call the monitoring page of FPM. If this value is not set, no
|
||||
; URI will be recognized as a ping page. This could be used to test from outside
|
||||
; that FPM is alive and responding, or to
|
||||
; - create a graph of FPM availability (rrd or such);
|
||||
; - remove a server from a group if it is not responding (load balancing);
|
||||
; - trigger alerts for the operating team (24/7).
|
||||
; Note: The value must start with a leading slash (/). The value can be
|
||||
; anything, but it may not be a good idea to use the .php extension or it
|
||||
; may conflict with a real PHP file.
|
||||
; Default Value: not set
|
||||
;ping.path = /ping
|
||||
|
||||
; This directive may be used to customize the response of a ping request. The
|
||||
; response is formatted as text/plain with a 200 response code.
|
||||
; Default Value: pong
|
||||
;ping.response = pong
|
||||
|
||||
; The access log file
|
||||
; Default: not set
|
||||
;access.log = log/$pool.access.log
|
||||
|
||||
; The access log format.
|
||||
; The following syntax is allowed
|
||||
; %%: the '%' character
|
||||
; %C: %CPU used by the request
|
||||
; it can accept the following format:
|
||||
; - %{user}C for user CPU only
|
||||
; - %{system}C for system CPU only
|
||||
; - %{total}C for user + system CPU (default)
|
||||
; %d: time taken to serve the request
|
||||
; it can accept the following format:
|
||||
; - %{seconds}d (default)
|
||||
; - %{milliseconds}d
|
||||
; - %{milli}d
|
||||
; - %{microseconds}d
|
||||
; - %{micro}d
|
||||
; %e: an environment variable (same as $_ENV or $_SERVER)
|
||||
; it must be associated with embraces to specify the name of the env
|
||||
; variable. Some examples:
|
||||
; - server specifics like: %{REQUEST_METHOD}e or %{SERVER_PROTOCOL}e
|
||||
; - HTTP headers like: %{HTTP_HOST}e or %{HTTP_USER_AGENT}e
|
||||
; %f: script filename
|
||||
; %l: content-length of the request (for POST request only)
|
||||
; %m: request method
|
||||
; %M: peak of memory allocated by PHP
|
||||
; it can accept the following format:
|
||||
; - %{bytes}M (default)
|
||||
; - %{kilobytes}M
|
||||
; - %{kilo}M
|
||||
; - %{megabytes}M
|
||||
; - %{mega}M
|
||||
; %n: pool name
|
||||
; %o: output header
|
||||
; it must be associated with embraces to specify the name of the header:
|
||||
; - %{Content-Type}o
|
||||
; - %{X-Powered-By}o
|
||||
; - %{Transfert-Encoding}o
|
||||
; - ....
|
||||
; %p: PID of the child that serviced the request
|
||||
; %P: PID of the parent of the child that serviced the request
|
||||
; %q: the query string
|
||||
; %Q: the '?' character if query string exists
|
||||
; %r: the request URI (without the query string, see %q and %Q)
|
||||
; %R: remote IP address
|
||||
; %s: status (response code)
|
||||
; %t: server time the request was received
|
||||
; it can accept a strftime(3) format:
|
||||
; %d/%b/%Y:%H:%M:%S %z (default)
|
||||
; The strftime(3) format must be encapsulated in a %{<strftime_format>}t tag
|
||||
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
|
||||
; %T: time the log has been written (the request has finished)
|
||||
; it can accept a strftime(3) format:
|
||||
; %d/%b/%Y:%H:%M:%S %z (default)
|
||||
; The strftime(3) format must be encapsulated in a %{<strftime_format>}t tag
|
||||
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
|
||||
; %u: remote user
|
||||
;
|
||||
; Default: "%R - %u %t \"%m %r\" %s"
|
||||
;access.format = "%R - %u %t \"%m %r%Q%q\" %s %f %{milli}d %{kilo}M %C%%"
|
||||
|
||||
; The log file for slow requests
|
||||
; Default Value: not set
|
||||
; Note: slowlog is mandatory if request_slowlog_timeout is set
|
||||
;slowlog = log/$pool.log.slow
|
||||
|
||||
; The timeout for serving a single request after which a PHP backtrace will be
|
||||
; dumped to the 'slowlog' file. A value of '0s' means 'off'.
|
||||
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
|
||||
; Default Value: 0
|
||||
;request_slowlog_timeout = 0
|
||||
|
||||
; Depth of slow log stack trace.
|
||||
; Default Value: 20
|
||||
;request_slowlog_trace_depth = 20
|
||||
|
||||
; The timeout for serving a single request after which the worker process will
|
||||
; be killed. This option should be used when the 'max_execution_time' ini option
|
||||
; does not stop script execution for some reason. A value of '0' means 'off'.
|
||||
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
|
||||
; Default Value: 0
|
||||
;request_terminate_timeout = 0
|
||||
|
||||
; The timeout set by 'request_terminate_timeout' ini option is not engaged after
|
||||
; application calls 'fastcgi_finish_request' or when application has finished and
|
||||
; shutdown functions are being called (registered via register_shutdown_function).
|
||||
; This option will enable timeout limit to be applied unconditionally
|
||||
; even in such cases.
|
||||
; Default Value: no
|
||||
;request_terminate_timeout_track_finished = no
|
||||
|
||||
; Set open file descriptor rlimit.
|
||||
; Default Value: system defined value
|
||||
;rlimit_files = 1024
|
||||
|
||||
; Set max core size rlimit.
|
||||
; Possible Values: 'unlimited' or an integer greater or equal to 0
|
||||
; Default Value: system defined value
|
||||
;rlimit_core = 0
|
||||
|
||||
; Chroot to this directory at the start. This value must be defined as an
|
||||
; absolute path. When this value is not set, chroot is not used.
|
||||
; Note: you can prefix with '$prefix' to chroot to the pool prefix or one
|
||||
; of its subdirectories. If the pool prefix is not set, the global prefix
|
||||
; will be used instead.
|
||||
; Note: chrooting is a great security feature and should be used whenever
|
||||
; possible. However, all PHP paths will be relative to the chroot
|
||||
; (error_log, sessions.save_path, ...).
|
||||
; Default Value: not set
|
||||
;chroot =
|
||||
|
||||
; Chdir to this directory at the start.
|
||||
; Note: relative path can be used.
|
||||
; Default Value: current directory or / when chroot
|
||||
;chdir = /var/www
|
||||
|
||||
; Redirect worker stdout and stderr into main error log. If not set, stdout and
|
||||
; stderr will be redirected to /dev/null according to FastCGI specs.
|
||||
; Note: on highloaded environment, this can cause some delay in the page
|
||||
; process time (several ms).
|
||||
; Default Value: no
|
||||
;catch_workers_output = yes
|
||||
|
||||
; Decorate worker output with prefix and suffix containing information about
|
||||
; the child that writes to the log and if stdout or stderr is used as well as
|
||||
; log level and time. This options is used only if catch_workers_output is yes.
|
||||
; Settings to "no" will output data as written to the stdout or stderr.
|
||||
; Default value: yes
|
||||
;decorate_workers_output = no
|
||||
|
||||
; Clear environment in FPM workers
|
||||
; Prevents arbitrary environment variables from reaching FPM worker processes
|
||||
; by clearing the environment in workers before env vars specified in this
|
||||
; pool configuration are added.
|
||||
; Setting to "no" will make all environment variables available to PHP code
|
||||
; via getenv(), $_ENV and $_SERVER.
|
||||
; Default Value: yes
|
||||
;clear_env = no
|
||||
|
||||
; Limits the extensions of the main script FPM will allow to parse. This can
|
||||
; prevent configuration mistakes on the web server side. You should only limit
|
||||
; FPM to .php extensions to prevent malicious users to use other extensions to
|
||||
; execute php code.
|
||||
; Note: set an empty value to allow all extensions.
|
||||
; Default Value: .php
|
||||
;security.limit_extensions = .php .php3 .php4 .php5 .php7
|
||||
|
||||
; Pass environment variables like LD_LIBRARY_PATH. All $VARIABLEs are taken from
|
||||
; the current environment.
|
||||
; Default Value: clean env
|
||||
env[HOSTNAME] = $HOSTNAME
|
||||
env[PATH] = /usr/local/bin:/usr/bin:/bin
|
||||
env[TMP] = /tmp
|
||||
env[TMPDIR] = /tmp
|
||||
env[TEMP] = /tmp
|
||||
|
||||
; Additional php.ini defines, specific to this pool of workers. These settings
|
||||
; overwrite the values previously defined in the php.ini. The directives are the
|
||||
; same as the PHP SAPI:
|
||||
; php_value/php_flag - you can set classic ini defines which can
|
||||
; be overwritten from PHP call 'ini_set'.
|
||||
; php_admin_value/php_admin_flag - these directives won't be overwritten by
|
||||
; PHP call 'ini_set'
|
||||
; For php_*flag, valid values are on, off, 1, 0, true, false, yes or no.
|
||||
|
||||
; Defining 'extension' will load the corresponding shared extension from
|
||||
; extension_dir. Defining 'disable_functions' or 'disable_classes' will not
|
||||
; overwrite previously defined php.ini values, but will append the new value
|
||||
; instead.
|
||||
|
||||
; Note: path INI options can be relative and will be expanded with the prefix
|
||||
; (pool, global or /usr/local)
|
||||
|
||||
; Default Value: nothing is defined by default except the values in php.ini and
|
||||
; specified at startup with the -d argument
|
||||
;php_admin_value[sendmail_path] = /usr/sbin/sendmail -t -i -f www@my.domain.com
|
||||
;php_flag[display_errors] = off
|
||||
;php_admin_value[error_log] = /var/log/fpm-php.www.log
|
||||
;php_admin_flag[log_errors] = on
|
||||
;php_admin_value[memory_limit] = 32M
|
||||
@@ -0,0 +1,463 @@
|
||||
; Start a new pool named 'www'.
|
||||
; the variable $pool can be used in any directive and will be replaced by the
|
||||
; pool name ('www' here)
|
||||
[www]
|
||||
|
||||
; Per pool prefix
|
||||
; It only applies on the following directives:
|
||||
; - 'access.log'
|
||||
; - 'slowlog'
|
||||
; - 'listen' (unixsocket)
|
||||
; - 'chroot'
|
||||
; - 'chdir'
|
||||
; - 'php_values'
|
||||
; - 'php_admin_values'
|
||||
; When not set, the global prefix (or NONE) applies instead.
|
||||
; Note: This directive can also be relative to the global prefix.
|
||||
; Default Value: none
|
||||
;prefix = /path/to/pools/$pool
|
||||
|
||||
; Unix user/group of processes
|
||||
; Note: The user is mandatory. If the group is not set, the default user's group
|
||||
; will be used.
|
||||
user = www-data
|
||||
group = www-data
|
||||
|
||||
; The address on which to accept FastCGI requests.
|
||||
; Valid syntaxes are:
|
||||
; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
|
||||
; a specific port;
|
||||
; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
|
||||
; a specific port;
|
||||
; 'port' - to listen on a TCP socket to all addresses
|
||||
; (IPv6 and IPv4-mapped) on a specific port;
|
||||
; '/path/to/unix/socket' - to listen on a unix socket.
|
||||
; Note: This value is mandatory.
|
||||
listen = 127.0.0.1:9000
|
||||
|
||||
; Set listen(2) backlog.
|
||||
; Default Value: 511 (-1 on FreeBSD and OpenBSD)
|
||||
;listen.backlog = 511
|
||||
|
||||
; Set permissions for unix socket, if one is used. In Linux, read/write
|
||||
; permissions must be set in order to allow connections from a web server. Many
|
||||
; BSD-derived systems allow connections regardless of permissions. The owner
|
||||
; and group can be specified either by name or by their numeric IDs.
|
||||
; Default Values: user and group are set as the running user
|
||||
; mode is set to 0660
|
||||
;listen.owner = www-data
|
||||
;listen.group = www-data
|
||||
;listen.mode = 0660
|
||||
; When POSIX Access Control Lists are supported you can set them using
|
||||
; these options, value is a comma separated list of user/group names.
|
||||
; When set, listen.owner and listen.group are ignored
|
||||
;listen.acl_users =
|
||||
;listen.acl_groups =
|
||||
|
||||
; List of addresses (IPv4/IPv6) of FastCGI clients which are allowed to connect.
|
||||
; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
|
||||
; PHP FCGI (5.2.2+). Makes sense only with a tcp listening socket. Each address
|
||||
; must be separated by a comma. If this value is left blank, connections will be
|
||||
; accepted from any ip address.
|
||||
; Default Value: any
|
||||
;listen.allowed_clients = 127.0.0.1
|
||||
|
||||
; Specify the nice(2) priority to apply to the pool processes (only if set)
|
||||
; The value can vary from -19 (highest priority) to 20 (lower priority)
|
||||
; Note: - It will only work if the FPM master process is launched as root
|
||||
; - The pool processes will inherit the master process priority
|
||||
; unless it specified otherwise
|
||||
; Default Value: no set
|
||||
; process.priority = -19
|
||||
|
||||
; Set the process dumpable flag (PR_SET_DUMPABLE prctl) even if the process user
|
||||
; or group is different than the master process user. It allows to create process
|
||||
; core dump and ptrace the process for the pool user.
|
||||
; Default Value: no
|
||||
; process.dumpable = yes
|
||||
|
||||
; Choose how the process manager will control the number of child processes.
|
||||
; Possible Values:
|
||||
; static - a fixed number (pm.max_children) of child processes;
|
||||
; dynamic - the number of child processes are set dynamically based on the
|
||||
; following directives. With this process management, there will be
|
||||
; always at least 1 children.
|
||||
; pm.max_children - the maximum number of children that can
|
||||
; be alive at the same time.
|
||||
; pm.start_servers - the number of children created on startup.
|
||||
; pm.min_spare_servers - the minimum number of children in 'idle'
|
||||
; state (waiting to process). If the number
|
||||
; of 'idle' processes is less than this
|
||||
; number then some children will be created.
|
||||
; pm.max_spare_servers - the maximum number of children in 'idle'
|
||||
; state (waiting to process). If the number
|
||||
; of 'idle' processes is greater than this
|
||||
; number then some children will be killed.
|
||||
; pm.max_spawn_rate - the maximum number of rate to spawn child
|
||||
; processes at once.
|
||||
; ondemand - no children are created at startup. Children will be forked when
|
||||
; new requests will connect. The following parameter are used:
|
||||
; pm.max_children - the maximum number of children that
|
||||
; can be alive at the same time.
|
||||
; pm.process_idle_timeout - The number of seconds after which
|
||||
; an idle process will be killed.
|
||||
; Note: This value is mandatory.
|
||||
pm = dynamic
|
||||
|
||||
; The number of child processes to be created when pm is set to 'static' and the
|
||||
; maximum number of child processes when pm is set to 'dynamic' or 'ondemand'.
|
||||
; This value sets the limit on the number of simultaneous requests that will be
|
||||
; served. Equivalent to the ApacheMaxClients directive with mpm_prefork.
|
||||
; Equivalent to the PHP_FCGI_CHILDREN environment variable in the original PHP
|
||||
; CGI. The below defaults are based on a server without much resources. Don't
|
||||
; forget to tweak pm.* to fit your needs.
|
||||
; Note: Used when pm is set to 'static', 'dynamic' or 'ondemand'
|
||||
; Note: This value is mandatory.
|
||||
pm.max_children = 5
|
||||
|
||||
; The number of child processes created on startup.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Default Value: (min_spare_servers + max_spare_servers) / 2
|
||||
pm.start_servers = 2
|
||||
|
||||
; The desired minimum number of idle server processes.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
pm.min_spare_servers = 1
|
||||
|
||||
; The desired maximum number of idle server processes.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
pm.max_spare_servers = 3
|
||||
|
||||
; The number of rate to spawn child processes at once.
|
||||
; Note: Used only when pm is set to 'dynamic'
|
||||
; Note: Mandatory when pm is set to 'dynamic'
|
||||
; Default Value: 32
|
||||
;pm.max_spawn_rate = 32
|
||||
|
||||
; The number of seconds after which an idle process will be killed.
|
||||
; Note: Used only when pm is set to 'ondemand'
|
||||
; Default Value: 10s
|
||||
;pm.process_idle_timeout = 10s;
|
||||
|
||||
; The number of requests each child process should execute before respawning.
|
||||
; This can be useful to work around memory leaks in 3rd party libraries. For
|
||||
; endless request processing specify '0'. Equivalent to PHP_FCGI_MAX_REQUESTS.
|
||||
; Default Value: 0
|
||||
;pm.max_requests = 500
|
||||
|
||||
; The URI to view the FPM status page. If this value is not set, no URI will be
|
||||
; recognized as a status page. It shows the following information:
|
||||
; pool - the name of the pool;
|
||||
; process manager - static, dynamic or ondemand;
|
||||
; start time - the date and time FPM has started;
|
||||
; start since - number of seconds since FPM has started;
|
||||
; accepted conn - the number of request accepted by the pool;
|
||||
; listen queue - the number of request in the queue of pending
|
||||
; connections (see backlog in listen(2));
|
||||
; max listen queue - the maximum number of requests in the queue
|
||||
; of pending connections since FPM has started;
|
||||
; listen queue len - the size of the socket queue of pending connections;
|
||||
; idle processes - the number of idle processes;
|
||||
; active processes - the number of active processes;
|
||||
; total processes - the number of idle + active processes;
|
||||
; max active processes - the maximum number of active processes since FPM
|
||||
; has started;
|
||||
; max children reached - number of times, the process limit has been reached,
|
||||
; when pm tries to start more children (works only for
|
||||
; pm 'dynamic' and 'ondemand');
|
||||
; Value are updated in real time.
|
||||
; Example output:
|
||||
; pool: www
|
||||
; process manager: static
|
||||
; start time: 01/Jul/2011:17:53:49 +0200
|
||||
; start since: 62636
|
||||
; accepted conn: 190460
|
||||
; listen queue: 0
|
||||
; max listen queue: 1
|
||||
; listen queue len: 42
|
||||
; idle processes: 4
|
||||
; active processes: 11
|
||||
; total processes: 15
|
||||
; max active processes: 12
|
||||
; max children reached: 0
|
||||
;
|
||||
; By default the status page output is formatted as text/plain. Passing either
|
||||
; 'html', 'xml' or 'json' in the query string will return the corresponding
|
||||
; output syntax. Example:
|
||||
; http://www.foo.bar/status
|
||||
; http://www.foo.bar/status?json
|
||||
; http://www.foo.bar/status?html
|
||||
; http://www.foo.bar/status?xml
|
||||
;
|
||||
; By default the status page only outputs short status. Passing 'full' in the
|
||||
; query string will also return status for each pool process.
|
||||
; Example:
|
||||
; http://www.foo.bar/status?full
|
||||
; http://www.foo.bar/status?json&full
|
||||
; http://www.foo.bar/status?html&full
|
||||
; http://www.foo.bar/status?xml&full
|
||||
; The Full status returns for each process:
|
||||
; pid - the PID of the process;
|
||||
; state - the state of the process (Idle, Running, ...);
|
||||
; start time - the date and time the process has started;
|
||||
; start since - the number of seconds since the process has started;
|
||||
; requests - the number of requests the process has served;
|
||||
; request duration - the duration in µs of the requests;
|
||||
; request method - the request method (GET, POST, ...);
|
||||
; request URI - the request URI with the query string;
|
||||
; content length - the content length of the request (only with POST);
|
||||
; user - the user (PHP_AUTH_USER) (or '-' if not set);
|
||||
; script - the main script called (or '-' if not set);
|
||||
; last request cpu - the %cpu the last request consumed
|
||||
; it's always 0 if the process is not in Idle state
|
||||
; because CPU calculation is done when the request
|
||||
; processing has terminated;
|
||||
; last request memory - the max amount of memory the last request consumed
|
||||
; it's always 0 if the process is not in Idle state
|
||||
; because memory calculation is done when the request
|
||||
; processing has terminated;
|
||||
; If the process is in Idle state, then informations are related to the
|
||||
; last request the process has served. Otherwise informations are related to
|
||||
; the current request being served.
|
||||
; Example output:
|
||||
; ************************
|
||||
; pid: 31330
|
||||
; state: Running
|
||||
; start time: 01/Jul/2011:17:53:49 +0200
|
||||
; start since: 63087
|
||||
; requests: 12808
|
||||
; request duration: 1250261
|
||||
; request method: GET
|
||||
; request URI: /test_mem.php?N=10000
|
||||
; content length: 0
|
||||
; user: -
|
||||
; script: /home/fat/web/docs/php/test_mem.php
|
||||
; last request cpu: 0.00
|
||||
; last request memory: 0
|
||||
;
|
||||
; Note: There is a real-time FPM status monitoring sample web page available
|
||||
; It's available in: /usr/local/share/php/fpm/status.html
|
||||
;
|
||||
; Note: The value must start with a leading slash (/). The value can be
|
||||
; anything, but it may not be a good idea to use the .php extension or it
|
||||
; may conflict with a real PHP file.
|
||||
; Default Value: not set
|
||||
;pm.status_path = /status
|
||||
|
||||
; The address on which to accept FastCGI status request. This creates a new
|
||||
; invisible pool that can handle requests independently. This is useful
|
||||
; if the main pool is busy with long running requests because it is still possible
|
||||
; to get the status before finishing the long running requests.
|
||||
;
|
||||
; Valid syntaxes are:
|
||||
; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
|
||||
; a specific port;
|
||||
; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
|
||||
; a specific port;
|
||||
; 'port' - to listen on a TCP socket to all addresses
|
||||
; (IPv6 and IPv4-mapped) on a specific port;
|
||||
; '/path/to/unix/socket' - to listen on a unix socket.
|
||||
; Default Value: value of the listen option
|
||||
;pm.status_listen = 127.0.0.1:9001
|
||||
|
||||
; The ping URI to call the monitoring page of FPM. If this value is not set, no
|
||||
; URI will be recognized as a ping page. This could be used to test from outside
|
||||
; that FPM is alive and responding, or to
|
||||
; - create a graph of FPM availability (rrd or such);
|
||||
; - remove a server from a group if it is not responding (load balancing);
|
||||
; - trigger alerts for the operating team (24/7).
|
||||
; Note: The value must start with a leading slash (/). The value can be
|
||||
; anything, but it may not be a good idea to use the .php extension or it
|
||||
; may conflict with a real PHP file.
|
||||
; Default Value: not set
|
||||
;ping.path = /ping
|
||||
|
||||
; This directive may be used to customize the response of a ping request. The
|
||||
; response is formatted as text/plain with a 200 response code.
|
||||
; Default Value: pong
|
||||
;ping.response = pong
|
||||
|
||||
; The access log file
|
||||
; Default: not set
|
||||
;access.log = log/$pool.access.log
|
||||
|
||||
; The access log format.
|
||||
; The following syntax is allowed
|
||||
; %%: the '%' character
|
||||
; %C: %CPU used by the request
|
||||
; it can accept the following format:
|
||||
; - %{user}C for user CPU only
|
||||
; - %{system}C for system CPU only
|
||||
; - %{total}C for user + system CPU (default)
|
||||
; %d: time taken to serve the request
|
||||
; it can accept the following format:
|
||||
; - %{seconds}d (default)
|
||||
; - %{milliseconds}d
|
||||
; - %{milli}d
|
||||
; - %{microseconds}d
|
||||
; - %{micro}d
|
||||
; %e: an environment variable (same as $_ENV or $_SERVER)
|
||||
; it must be associated with embraces to specify the name of the env
|
||||
; variable. Some examples:
|
||||
; - server specifics like: %{REQUEST_METHOD}e or %{SERVER_PROTOCOL}e
|
||||
; - HTTP headers like: %{HTTP_HOST}e or %{HTTP_USER_AGENT}e
|
||||
; %f: script filename
|
||||
; %l: content-length of the request (for POST request only)
|
||||
; %m: request method
|
||||
; %M: peak of memory allocated by PHP
|
||||
; it can accept the following format:
|
||||
; - %{bytes}M (default)
|
||||
; - %{kilobytes}M
|
||||
; - %{kilo}M
|
||||
; - %{megabytes}M
|
||||
; - %{mega}M
|
||||
; %n: pool name
|
||||
; %o: output header
|
||||
; it must be associated with embraces to specify the name of the header:
|
||||
; - %{Content-Type}o
|
||||
; - %{X-Powered-By}o
|
||||
; - %{Transfert-Encoding}o
|
||||
; - ....
|
||||
; %p: PID of the child that serviced the request
|
||||
; %P: PID of the parent of the child that serviced the request
|
||||
; %q: the query string
|
||||
; %Q: the '?' character if query string exists
|
||||
; %r: the request URI (without the query string, see %q and %Q)
|
||||
; %R: remote IP address
|
||||
; %s: status (response code)
|
||||
; %t: server time the request was received
|
||||
; it can accept a strftime(3) format:
|
||||
; %d/%b/%Y:%H:%M:%S %z (default)
|
||||
; The strftime(3) format must be encapsulated in a %{<strftime_format>}t tag
|
||||
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
|
||||
; %T: time the log has been written (the request has finished)
|
||||
; it can accept a strftime(3) format:
|
||||
; %d/%b/%Y:%H:%M:%S %z (default)
|
||||
; The strftime(3) format must be encapsulated in a %{<strftime_format>}t tag
|
||||
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
|
||||
; %u: remote user
|
||||
;
|
||||
; Default: "%R - %u %t \"%m %r\" %s"
|
||||
;access.format = "%R - %u %t \"%m %r%Q%q\" %s %f %{milli}d %{kilo}M %C%%"
|
||||
|
||||
; The log file for slow requests
|
||||
; Default Value: not set
|
||||
; Note: slowlog is mandatory if request_slowlog_timeout is set
|
||||
;slowlog = log/$pool.log.slow
|
||||
|
||||
; The timeout for serving a single request after which a PHP backtrace will be
|
||||
; dumped to the 'slowlog' file. A value of '0s' means 'off'.
|
||||
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
|
||||
; Default Value: 0
|
||||
;request_slowlog_timeout = 0
|
||||
|
||||
; Depth of slow log stack trace.
|
||||
; Default Value: 20
|
||||
;request_slowlog_trace_depth = 20
|
||||
|
||||
; The timeout for serving a single request after which the worker process will
|
||||
; be killed. This option should be used when the 'max_execution_time' ini option
|
||||
; does not stop script execution for some reason. A value of '0' means 'off'.
|
||||
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
|
||||
; Default Value: 0
|
||||
;request_terminate_timeout = 0
|
||||
|
||||
; The timeout set by 'request_terminate_timeout' ini option is not engaged after
|
||||
; application calls 'fastcgi_finish_request' or when application has finished and
|
||||
; shutdown functions are being called (registered via register_shutdown_function).
|
||||
; This option will enable timeout limit to be applied unconditionally
|
||||
; even in such cases.
|
||||
; Default Value: no
|
||||
;request_terminate_timeout_track_finished = no
|
||||
|
||||
; Set open file descriptor rlimit.
|
||||
; Default Value: system defined value
|
||||
;rlimit_files = 1024
|
||||
|
||||
; Set max core size rlimit.
|
||||
; Possible Values: 'unlimited' or an integer greater or equal to 0
|
||||
; Default Value: system defined value
|
||||
;rlimit_core = 0
|
||||
|
||||
; Chroot to this directory at the start. This value must be defined as an
|
||||
; absolute path. When this value is not set, chroot is not used.
|
||||
; Note: you can prefix with '$prefix' to chroot to the pool prefix or one
|
||||
; of its subdirectories. If the pool prefix is not set, the global prefix
|
||||
; will be used instead.
|
||||
; Note: chrooting is a great security feature and should be used whenever
|
||||
; possible. However, all PHP paths will be relative to the chroot
|
||||
; (error_log, sessions.save_path, ...).
|
||||
; Default Value: not set
|
||||
;chroot =
|
||||
|
||||
; Chdir to this directory at the start.
|
||||
; Note: relative path can be used.
|
||||
; Default Value: current directory or / when chroot
|
||||
;chdir = /var/www
|
||||
|
||||
; Redirect worker stdout and stderr into main error log. If not set, stdout and
|
||||
; stderr will be redirected to /dev/null according to FastCGI specs.
|
||||
; Note: on highloaded environment, this can cause some delay in the page
|
||||
; process time (several ms).
|
||||
; Default Value: no
|
||||
;catch_workers_output = yes
|
||||
|
||||
; Decorate worker output with prefix and suffix containing information about
|
||||
; the child that writes to the log and if stdout or stderr is used as well as
|
||||
; log level and time. This options is used only if catch_workers_output is yes.
|
||||
; Settings to "no" will output data as written to the stdout or stderr.
|
||||
; Default value: yes
|
||||
;decorate_workers_output = no
|
||||
|
||||
; Clear environment in FPM workers
|
||||
; Prevents arbitrary environment variables from reaching FPM worker processes
|
||||
; by clearing the environment in workers before env vars specified in this
|
||||
; pool configuration are added.
|
||||
; Setting to "no" will make all environment variables available to PHP code
|
||||
; via getenv(), $_ENV and $_SERVER.
|
||||
; Default Value: yes
|
||||
;clear_env = no
|
||||
|
||||
; Limits the extensions of the main script FPM will allow to parse. This can
|
||||
; prevent configuration mistakes on the web server side. You should only limit
|
||||
; FPM to .php extensions to prevent malicious users to use other extensions to
|
||||
; execute php code.
|
||||
; Note: set an empty value to allow all extensions.
|
||||
; Default Value: .php
|
||||
;security.limit_extensions = .php .php3 .php4 .php5 .php7
|
||||
|
||||
; Pass environment variables like LD_LIBRARY_PATH. All $VARIABLEs are taken from
|
||||
; the current environment.
|
||||
; Default Value: clean env
|
||||
;env[HOSTNAME] = $HOSTNAME
|
||||
;env[PATH] = /usr/local/bin:/usr/bin:/bin
|
||||
;env[TMP] = /tmp
|
||||
;env[TMPDIR] = /tmp
|
||||
;env[TEMP] = /tmp
|
||||
|
||||
; Additional php.ini defines, specific to this pool of workers. These settings
|
||||
; overwrite the values previously defined in the php.ini. The directives are the
|
||||
; same as the PHP SAPI:
|
||||
; php_value/php_flag - you can set classic ini defines which can
|
||||
; be overwritten from PHP call 'ini_set'.
|
||||
; php_admin_value/php_admin_flag - these directives won't be overwritten by
|
||||
; PHP call 'ini_set'
|
||||
; For php_*flag, valid values are on, off, 1, 0, true, false, yes or no.
|
||||
|
||||
; Defining 'extension' will load the corresponding shared extension from
|
||||
; extension_dir. Defining 'disable_functions' or 'disable_classes' will not
|
||||
; overwrite previously defined php.ini values, but will append the new value
|
||||
; instead.
|
||||
|
||||
; Note: path INI options can be relative and will be expanded with the prefix
|
||||
; (pool, global or /usr/local)
|
||||
|
||||
; Default Value: nothing is defined by default except the values in php.ini and
|
||||
; specified at startup with the -d argument
|
||||
;php_admin_value[sendmail_path] = /usr/sbin/sendmail -t -i -f www@my.domain.com
|
||||
;php_flag[display_errors] = off
|
||||
;php_admin_value[error_log] = /var/log/fpm-php.www.log
|
||||
;php_admin_flag[log_errors] = on
|
||||
;php_admin_value[memory_limit] = 32M
|
||||
@@ -0,0 +1,5 @@
|
||||
[global]
|
||||
daemonize = no
|
||||
|
||||
[www]
|
||||
listen = 9000
|
||||
@@ -0,0 +1 @@
|
||||
extension=sodium
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,16 @@
|
||||
server {
|
||||
# listen 80 default_server;
|
||||
listen 443 ssl http2 default_server;
|
||||
|
||||
ssl_certificate /cert/nginx_public.pem;
|
||||
ssl_certificate_key /cert/nginx_private.key;
|
||||
|
||||
root /app;
|
||||
location / {
|
||||
fastcgi_pass fpm:9000;
|
||||
fastcgi_index index.php;
|
||||
include fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
logoutput: stderr
|
||||
internal: eth0 port = 1080
|
||||
external: eth0
|
||||
socksmethod: none
|
||||
user.privileged: root
|
||||
user.unprivileged: nobody
|
||||
|
||||
client pass {
|
||||
from: 0/0 to: 0/0
|
||||
log: connect disconnect error ioop
|
||||
}
|
||||
|
||||
socks pass {
|
||||
from: 0/0 to: 0/0
|
||||
log: connect disconnect error ioop
|
||||
}
|
||||
@@ -0,0 +1,91 @@
|
||||
version: "3.7"
|
||||
|
||||
volumes:
|
||||
nginxkey:
|
||||
sshkey:
|
||||
|
||||
networks:
|
||||
default:
|
||||
ipam:
|
||||
config:
|
||||
- subnet: 10.10.0.0/24
|
||||
|
||||
services:
|
||||
nginx:
|
||||
image: nginx
|
||||
ports:
|
||||
- 443:443
|
||||
volumes:
|
||||
- ./config/nginx/:/etc/nginx/conf.d/
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- type: volume
|
||||
target: /cert
|
||||
source: nginxkey
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
hostname: nginx
|
||||
restart: always
|
||||
depends_on:
|
||||
- fpm
|
||||
stop_grace_period: 1s
|
||||
fpm:
|
||||
build:
|
||||
dockerfile: dockerfile/php.dockerfile
|
||||
args:
|
||||
IP: ${IP}
|
||||
volumes:
|
||||
- ./config/fpm/:/usr/local/etc/
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./app:/app
|
||||
- ./logs:/app/logs/
|
||||
- ./config/clients.json:/app/clients.json
|
||||
- type: volume
|
||||
target: /ssh
|
||||
source: sshkey
|
||||
- type: volume
|
||||
target: /cert
|
||||
source: nginxkey
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
ADDRESS: ${ADDRESS}
|
||||
PORT_WG: ${PORT}
|
||||
working_dir: /app
|
||||
hostname: fpm
|
||||
restart: always
|
||||
depends_on:
|
||||
- wg
|
||||
command: bash -c 'chown -R www-data:www-data /app/logs && chown www-data:www-data /app/clients.json && php init.php && php-fpm'
|
||||
stop_grace_period: 1s
|
||||
proxy:
|
||||
build:
|
||||
dockerfile: dockerfile/proxy.dockerfile
|
||||
volumes:
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./config/sockd.conf:/etc/sockd.conf
|
||||
hostname: proxy
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.3
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
wg:
|
||||
build:
|
||||
dockerfile: dockerfile/wireguard.dockerfile
|
||||
volumes:
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./config/wg0.conf:/etc/wireguard/wg0.conf
|
||||
- ./scripts/start_wg.sh:/start_wg.sh
|
||||
- ./scripts/reset_wg.sh:/reset_wg.sh
|
||||
- type: volume
|
||||
target: /ssh
|
||||
source: sshkey
|
||||
hostname: wireguard
|
||||
ports:
|
||||
- ${PORT}:${PORT}/udp
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
PORT_WG: ${PORT}
|
||||
ADDRESS: ${ADDRESS}
|
||||
cap_add:
|
||||
- NET_ADMIN
|
||||
stop_grace_period: 1s
|
||||
@@ -0,0 +1,8 @@
|
||||
from php:8.1-fpm
|
||||
run apt update && apt install -y libssh2-1-dev && pecl install https://pecl.php.net/get/ssh2-1.3.1.tgz
|
||||
ARG IP
|
||||
run mkdir /cert && \
|
||||
openssl req -newkey rsa:2048 -sha256 -nodes \
|
||||
-keyout /cert/nginx_private.key -x509 -days 365 -out /cert/nginx_public.pem \
|
||||
-subj "/C=US/ST=New York/L=Brooklyn/O=Example Brooklyn Company/CN=$IP"
|
||||
workdir /app
|
||||
@@ -0,0 +1,11 @@
|
||||
from ubuntu:18.04
|
||||
run apt update && \
|
||||
apt install -y build-essential gcc make wget && \
|
||||
wget https://www.inet.no/dante/files/dante-1.4.3.tar.gz && \
|
||||
tar -xf dante-1.4.3.tar.gz && \
|
||||
cd dante-1.4.3 && \
|
||||
./configure --prefix=/usr --sysconfdir=/etc --localstatedir=/var --disable-client --without-libwrap --without-bsdauth --without-gssapi --without-krb5 --without-upnp --without-pam && \
|
||||
make && \
|
||||
make install
|
||||
expose 1080
|
||||
cmd ["sockd"]
|
||||
@@ -0,0 +1,17 @@
|
||||
from ubuntu:18.04
|
||||
run apt update && \
|
||||
apt install -y wireguard \
|
||||
iproute2 \
|
||||
net-tools \
|
||||
iptables \
|
||||
linux-headers-$(uname -r) \
|
||||
ssh
|
||||
run mkdir /root/.ssh && \
|
||||
mkdir /ssh && \
|
||||
touch /root/.ssh/authorized_keys && \
|
||||
ssh-keygen -t rsa -f /ssh/key -N '' && \
|
||||
chmod 644 /ssh/key && \
|
||||
wg genkey > /etc/wireguard/privatekey
|
||||
copy ./scripts/start_wg.sh /start_wg.sh
|
||||
copy ./scripts/reset_wg.sh /reset_wg.sh
|
||||
cmd ["/bin/sh", "/start_wg.sh"]
|
||||
@@ -0,0 +1,30 @@
|
||||
IP ?= 127.0.0.1
|
||||
SERVICE ?= fpm
|
||||
hosts: unhosts # маппинг доменов на локалку
|
||||
echo "$(IP) test.ru" >> /mnt/c/Windows/System32/drivers/etc/hosts
|
||||
unhosts:
|
||||
sed -i '/test.ru/d' /mnt/c/Windows/System32/drivers/etc/hosts
|
||||
u: # запуск контейнеров
|
||||
IP=$(shell curl https://ipinfo.io/ip) docker compose up -d --build --force-recreate
|
||||
sleep 1
|
||||
docker compose logs wg fpm proxy
|
||||
d: # остановка контейнеров
|
||||
docker compose down -v
|
||||
ps: # список контейнеров
|
||||
docker compose ps
|
||||
l: # логи из контейнеров
|
||||
docker compose logs $(SERVICE)
|
||||
nginx: # консоль сервиса
|
||||
docker compose exec nginx bash
|
||||
fpm: # консоль сервиса
|
||||
docker compose exec fpm bash
|
||||
proxy: # консоль сервиса
|
||||
docker compose exec proxy bash
|
||||
wg: # консоль сервиса
|
||||
docker compose exec wg bash
|
||||
r-fpm: # рестарт сервиса
|
||||
docker compose restart fpm
|
||||
r-nginx: # рестарт сервиса
|
||||
docker compose restart nginx
|
||||
r-wg: # рестарт сервиса
|
||||
docker compose restart wg
|
||||
@@ -0,0 +1,19 @@
|
||||
apt update
|
||||
apt install -y \
|
||||
ca-certificates \
|
||||
curl \
|
||||
gnupg \
|
||||
lsb-release \
|
||||
make \
|
||||
git
|
||||
mkdir -p /etc/apt/keyrings
|
||||
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg
|
||||
echo \
|
||||
"deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu \
|
||||
$(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
|
||||
apt update
|
||||
apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin
|
||||
git clone https://github.com/mercurykd/vpnbot.git
|
||||
cd ./vpnbot
|
||||
echo "<?php \$key='$1';" > ./app/config.php
|
||||
make u
|
||||
@@ -0,0 +1,10 @@
|
||||
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
|
||||
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
|
||||
echo "[Interface]" > /etc/wireguard/wg0.conf
|
||||
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
|
||||
echo "Address = $1" >> /etc/wireguard/wg0.conf
|
||||
echo "ListenPort = $2" >> /etc/wireguard/wg0.conf
|
||||
echo "PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE" >> /etc/wireguard/wg0.conf
|
||||
echo "PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o $INTERFACE -j MASQUERADE" >> /etc/wireguard/wg0.conf
|
||||
wg-quick down wg0
|
||||
wg-quick up wg0
|
||||
@@ -0,0 +1,15 @@
|
||||
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
|
||||
PRIVATEKEY=$(cat /etc/wireguard/privatekey)
|
||||
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
|
||||
then
|
||||
echo "[Interface]" > /etc/wireguard/wg0.conf
|
||||
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
|
||||
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
|
||||
echo "ListenPort = $PORT_WG" >> /etc/wireguard/wg0.conf
|
||||
echo "PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE" >> /etc/wireguard/wg0.conf
|
||||
echo "PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o $INTERFACE -j MASQUERADE" >> /etc/wireguard/wg0.conf
|
||||
fi
|
||||
wg-quick up wg0
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
service ssh start
|
||||
tail -f /dev/null
|
||||
Reference in New Issue
Block a user