Compare commits

..

56 Commits

Author SHA1 Message Date
mercury 9f1b3d84f4 XTLS-Reality steal from yourself 2024-03-20 22:36:06 +04:00
mercury e81c6a5dfb update version 2024-03-18 10:03:57 +04:00
mercury c00dafa6d1 fix port mtproto 2024-03-18 01:59:12 +04:00
mercury cab00f4aed fake tls mtproto 2024-03-18 01:53:22 +04:00
mercury 4082dac97b sslip.io 2024-03-17 17:50:09 +04:00
mercury 7317d418de update version 2024-03-13 22:59:39 +04:00
mercury b7a1f9bbd6 fix override.env in service 2024-03-10 16:57:42 +04:00
mercury fcc165b4be fix override.env 2024-03-10 16:49:19 +04:00
mercury a9d16eadce fix adguard menu 2024-03-10 15:31:40 +04:00
mercury 82b95ccb85 web app for donate 2024-03-10 13:10:35 +04:00
mercury e01ef61b62 protect adguard on backup restore 2024-03-10 13:01:32 +04:00
mercury 367bfc0fbc web panel config 2024-03-10 12:45:42 +04:00
mercury 524c52e326 web panel adguard 2024-03-10 12:39:30 +04:00
mercury 3bbb8290e5 improve settings menu 2024-03-07 19:27:40 +04:00
mercury 1e8ac34370 Merge branch 'master' into dev 2024-03-07 19:13:19 +04:00
Konstantin 2332e5ea71 Merge pull request #9 from 13f66cd22a80/master 2024-03-07 19:09:35 +04:00
mercury 796fa57330 improve status wg error 2024-03-07 19:00:33 +04:00
Jeff Scrum ce91b1152e Update readme.md 2024-03-07 14:44:29 +03:00
mercury 64d44428d0 update version 2024-03-07 14:34:48 +04:00
mercury 860fdc883f fix environment for wg 2024-03-07 14:32:52 +04:00
mercury f2f2066e99 update version 2024-03-07 13:21:46 +04:00
mercury 3e343ce2b7 fix port amnezia 2024-03-07 13:10:09 +04:00
mercury 3c16620a7d update version 2024-03-07 11:58:25 +04:00
mercury b1efd9f400 fix syncports 2024-03-07 11:52:34 +04:00
mercury cbe0ef8a12 check webhook 2024-03-07 10:46:55 +04:00
mercury 24026d3678 optimize images 2024-03-07 10:23:13 +04:00
mercury dea46815c7 override environment 2024-03-07 10:20:43 +04:00
mercury 11e34d8c4e unversary path for vpnbot.service 2024-03-06 15:15:45 +04:00
mercury 3e3684eb34 fix service for systemd 2024-03-06 14:46:02 +04:00
mercury 7ee47db8e2 fix short link type 2024-03-06 11:52:09 +04:00
mercury b390fe7dd8 update version 2024-03-06 04:08:45 +04:00
mercury fe0414cc59 fix export ocserv users 2024-03-06 04:03:30 +04:00
mercury 48a1eba67e fix ocserv 2024-03-06 03:44:52 +04:00
mercury 714cff7d76 fix lib for short link 2024-03-06 02:10:11 +04:00
mercury 0e8bab5c4c fix service script 2024-03-06 01:45:31 +04:00
mercury 387e6e4986 short link for amnezia 2024-03-06 01:35:40 +04:00
mercury 6a7af1c30f fix import wg1 2024-03-05 00:14:36 +04:00
mercury 2a17b4f1f3 update version 2024-03-04 23:30:46 +04:00
mercury d005ccc919 fix start wg1 2024-03-04 23:26:09 +04:00
mercury 5df89e7f89 syncport fix 2024-03-04 16:51:18 +04:00
mercury f6d72800cb white ip 2024-03-04 16:38:37 +04:00
mercury 4ff1929a22 improve makefile 2024-03-03 19:53:52 +04:00
mercury 46d54ffeee fix gitignore 2024-03-03 19:45:57 +04:00
mercury 20cde272dd update self 2024-03-03 19:29:21 +04:00
mercury 4270ee5b23 update version 2024-03-02 15:56:18 +04:00
mercury cdcd6a7931 check webhook 2024-03-02 15:05:21 +04:00
mercury f360091c1a improve makefile 2024-03-02 00:30:12 +04:00
mercury 3e52c3650e two instance wireguard 2024-03-02 00:14:13 +04:00
mercury 757c704d38 update version 2024-03-01 11:50:51 +04:00
mercury 7c9f4d9815 fix iptables wg 2024-03-01 11:27:36 +04:00
mercury 9bfa7bd0c7 fix import 2024-03-01 02:48:24 +04:00
mercury d8620ef4f2 update version 2024-03-01 02:37:22 +04:00
mercury d4b9c4af48 fix long domain set 2024-03-01 02:17:29 +04:00
mercury c115661529 images from hub 2024-02-29 00:10:00 +04:00
mercury e0ee25127f update version 2024-02-28 15:22:16 +04:00
mercury ae2e9c0205 mirror 2024-02-28 14:53:11 +04:00
38 changed files with 1230 additions and 269 deletions
+5 -2
View File
@@ -1,8 +1,11 @@
TZ=Europe/Samara
WGADDRESS=10.0.1.1/24
WGPORT=51820
WG1ADDRESS=10.0.3.1/24
WG1PORT=51821
SSPORT=8388
TGPORT=4443
SYSTEM=ubuntu
RELEASE=18.04
IMAGE=alpine:3.18.2
IP=
VER=
ENV=/root/.ashrc
+5
View File
@@ -15,3 +15,8 @@
!/app/zapretlists/.gitkeep
.vscode/
.idea/
mirror/.env
update/*
!update/update.sh
override.env
+14
View File
@@ -0,0 +1,14 @@
import sys
from PyQt5.QtCore import *
def enc(s):
ba = qCompress(QByteArray(s.encode()))
ba = ba.toBase64(QByteArray.Base64Option.Base64UrlEncoding | QByteArray.Base64Option.OmitTrailingEquals)
print('vpn://' + str(ba, 'utf-8'))
s = ''
for line in sys.stdin:
s += line
s = s.strip()
enc(s)
+499 -126
View File
File diff suppressed because it is too large Load Diff
+11
View File
@@ -0,0 +1,11 @@
<?php
require './config.php';
$ch = curl_init();
curl_setopt_array($ch, [
CURLOPT_URL => "https://api.telegram.org/bot{$c['key']}/getWebhookInfo",
CURLOPT_RETURNTRANSFER => true,
]);
$res = curl_exec($ch);
die(var_dump($res));
+30 -2
View File
@@ -243,7 +243,7 @@ $i = [
],
'backup' => [
'en' => 'auto backup',
'ru' => 'бэкап',
'ru' => 'автобэкап',
],
'logs' => [
'en' => 'logs',
@@ -263,7 +263,11 @@ $i = [
],
'changeFakeDomain' => [
'en' => 'changeFakeDomain',
'ru' => 'установить фейковый домен',
'ru' => 'фейковый домен',
],
'selfFakeDomain' => [
'en' => 'selfFakeDomain',
'ru' => 'домен бота',
],
'page' => [
'en' => 'pagination',
@@ -293,4 +297,28 @@ $i = [
'en' => 'dns',
'ru' => 'днс',
],
'mirror' => [
'en' => 'mirror',
'ru' => 'зеркало',
],
'download' => [
'en' => 'download',
'ru' => 'скачать',
],
'update bot' => [
'en' => 'update bot',
'ru' => 'обновить бота',
],
'third party browser' => [
'en' => 'third party browser',
'ru' => 'сторонний браузер',
],
'browser_notify_on' => [
'en' => 'the web panel can be opened in any browser',
'ru' => 'веб панель может быть открыта в любом браузере',
],
'browser_notify_off' => [
'en' => 'web panel is only available from telegram',
'ru' => 'веб панель доступна только из телеграмма',
],
];
+36 -11
View File
@@ -22,17 +22,42 @@ $address = $_GET['a'] ?: '127.0.0.1';
$port = $_GET['p'] ?: '1080';
$hash = $_GET['h'];
if ($hash == substr(md5($c['key']), 0, 8)) {
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
if ($type == 'mirror') {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
$bot->getMirror();
} else {
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
}
}
}
if (!empty($_GET['hash'])) {
$t = $_GET;
unset($t['hash']);
ksort($t);
foreach ($t as $k => $v) {
$s[] = "$k=$v";
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
die('ok');
}
}
+2 -7
View File
@@ -8,12 +8,7 @@ require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
$bot->setwebhook();
$bot->adguardProtect();
$bot->setcommands();
$bot->syncPortClients();
if (!empty($c['admin'])) {
$ip = getenv('IP');
foreach ($c['admin'] as $k => $v) {
$bot->send($v, "start $ip");
}
}
$bot->setwebhook();
+117
View File
@@ -0,0 +1,117 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Login</title>
<style>
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
body {
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
background-size: cover;
font-family: "Roboto";
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
&::before {
z-index: -1;
content: '';
position: fixed;
top: 0;
left: 0;
background: #44c4e7;
/* IE Fallback */
background: rgba(68, 196, 231, 0.8);
width: 100%;
height: 100%;
}
}
.form {
position: absolute;
top: 50%;
left: 50%;
background: #fff;
width: 285px;
margin: -140px 0 0 -182px;
padding: 40px;
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
h2 {
margin: 0 0 20px;
line-height: 1;
color: #44c4e7;
font-size: 18px;
font-weight: 400;
}
input {
outline: none;
display: block;
width: 100%;
margin: 0 0 20px;
padding: 10px 15px;
border: 1px solid #ccc;
color: #ccc;
font-family: "Roboto";
box-sizing: border-box;
font-size: 14px;
font-wieght: 400;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
transition: 0.2s linear;
&input:focus {
color: #333;
border: 1px solid #44c4e7;
}
}
button {
cursor: pointer;
background: #44c4e7;
width: 100%;
padding: 10px 15px;
border: 0;
color: #fff;
font-family: "Roboto";
font-size: 14px;
font-weight: 400;
&:hover {
background: #369cb8;
}
}
}
.error,
.valid {
display: none;
}
</style>
<script src="jquery-3.7.1.min.js"></script>
</head>
<body>
<section class="form animated flipInX">
<h2>Login To Your Account</h2>
<p class="valid">Valid. Please wait a moment.</p>
<p class="error">Error. Please enter correct Username &amp; password.</p>
<form class="loginbox" autocomplete="off">
<input placeholder="Username" type="text" id="username"></input>
<input placeholder="Password" type="password" id="password"></input>
<button id="submit">Login</button>
</form>
</section>
<script>
$(document).ready(function() {
$('#submit').click(function () {
event.preventDefault(); // prevent PageReLoad
$('.error').css('display', 'block'); // show error msg
});
});
</script>
</body>
</html>
+39
View File
@@ -0,0 +1,39 @@
<?php
require __DIR__ . '/timezone.php';
// require __DIR__ . '/debug.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
if (!empty($c['admin'])) {
$ip = getenv('IP');
$rm = explode(':', trim(file_get_contents('/update/reload_message')));
$m = file_get_contents('/update/message');
foreach ($c['admin'] as $k => $v) {
$r = $bot->send($v, "start $ip");
$bot->input['chat'] = $v;
$bot->input['message_id'] = $r['result']['message_id'];
if (file_exists($bot->update)) {
if (!empty($m)) {
$bot->send($v, "<pre>$m</pre>", $v == $rm[0] ? $rm[1] : 0);
}
$r = $bot->send($v, "import settings");
$bot->input['chat'] = $v;
$bot->input['message_id'] = $r['result']['message_id'];
$bot->input['callback_id'] = $r['result']['message_id'];
if (empty($flag)) {
$bot->importFile($bot->update);
unlink($bot->update);
$flag = true;
}
}
}
}
file_put_contents('/update/message', '');
file_put_contents('/update/reload_message', '');
$bot->restartTG();
$bot->sslip();
+24
View File
@@ -0,0 +1,24 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<script src="https://telegram.org/js/telegram-web-app.js"></script>
<script src="jquery-3.7.1.min.js"></script>
<title>Document</title>
</head>
<body>
<script>
var tg = window.Telegram.WebApp;
jQuery(function($) {
$.ajax({
'url': 'check?' + tg.initData,
}).done(function (r) {
location.replace('/adguard/');
}).fail(function (r) {
location.replace('/');
});
});
</script>
</body>
</html>
File diff suppressed because one or more lines are too long
+1
View File
@@ -0,0 +1 @@
[]
+24 -6
View File
@@ -9,6 +9,7 @@ events {
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
@@ -21,15 +22,17 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_default_access;
location / {
return 444;
root /app;
index login.html;
try_files $uri $uri/ =404;
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
@@ -37,6 +40,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -66,11 +75,12 @@ http {
#-domain
# server {
# listen 80;
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 443 ssl http2 proxy_protocol;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
@@ -79,7 +89,9 @@ http {
# access_log /logs/nginx_domain_access;
# location / {
# return 444;
# root /app;
# index login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
@@ -87,6 +99,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
+24 -6
View File
@@ -9,6 +9,7 @@ events {
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
@@ -21,15 +22,17 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_default_access;
location / {
return 444;
root /app;
index login.html;
try_files $uri $uri/ =404;
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
@@ -37,6 +40,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -66,11 +75,12 @@ http {
#-domain
# server {
# listen 80;
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 443 ssl http2 proxy_protocol;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
@@ -79,7 +89,9 @@ http {
# access_log /logs/nginx_domain_access;
# location / {
# return 444;
# root /app;
# index login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
@@ -87,6 +99,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
View File
+180 -30
View File
@@ -12,11 +12,16 @@ networks:
ipam:
config:
- subnet: 10.10.0.0/24
xray:
ipam:
config:
- subnet: 10.10.1.0/24
volumes:
adguard:
services:
up:
image: mercurykd/vpnbot-up:1.1
build:
context: dockerfile
dockerfile: nginx.dockerfile
@@ -32,6 +37,7 @@ services:
ports:
- 443:443
hostname: upstream
container_name: upstream-${VER}
depends_on:
php:
condition: service_healthy
@@ -39,8 +45,11 @@ services:
condition: service_started
ss:
condition: service_started
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_upstream.sh"]
networks:
@@ -48,6 +57,7 @@ services:
ipv4_address: 10.10.0.10
logging: *default-logging
ng:
image: mercurykd/vpnbot-ng:1.1
build:
context: dockerfile
dockerfile: nginx.dockerfile
@@ -63,26 +73,36 @@ services:
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./logs/:/logs/
- ./app/webapp:/app
- ./app/login.html:/app/login.html
ports:
- 80:80
hostname: nginx
container_name: nginx-${VER}
depends_on:
up:
condition: service_started
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ng.sh"]
networks:
default:
ipv4_address: 10.10.0.2
xray:
ipv4_address: 10.10.1.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.2
build:
dockerfile: dockerfile/php.dockerfile
args:
image: ${IMAGE}
ports:
- 127.0.0.1:8081:8080
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/php.ini:/etc/php81/php.ini
@@ -94,14 +114,19 @@ services:
- ./scripts/start_php.sh:/start_php.sh
- ./scripts/check_file.sh:/check_file.sh
- ./version:/version
- ./mirror:/mirror
- ./.env:/mirror/.env
- ./update:/update
environment:
TZ: ${TZ}
IP: ${IP}
ADDRESS: ${WGADDRESS}
WGPORT: ${WGPORT}
SSPORT: ${SSPORT}
TGPORT: ${TGPORT}
VER: ${VER}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
hostname: php
container_name: php-${VER}
restart: unless-stopped
stop_grace_period: 1s
command: ["/bin/sh", "/start_php.sh"]
@@ -117,7 +142,55 @@ services:
interval: 5s
timeout: 5s
retries: 5
service:
image: mercurykd/vpnbot-php:1.2
build:
dockerfile: dockerfile/php.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/php.ini:/etc/php81/php.ini
- ./config/:/config/
- ./certs/:/certs/
- ./ssh:/ssh
- ./app:/app
- ./logs/:/logs/
- ./update:/update
- ./scripts/start_service.sh:/start_service.sh
environment:
IP: ${IP}
VER: ${VER}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
hostname: service
container_name: service-${VER}
# restart: unless-stopped
stop_grace_period: 1s
command: ["/bin/sh", "/start_service.sh"]
working_dir: /app
networks:
default:
ipv4_address: 10.10.0.15
logging: *default-logging
depends_on:
- up
- ng
- php
- proxy
- wg
- wg1
- ad
- ss
- tg
- xr
- oc
- np
proxy:
image: mercurykd/vpnbot-ss:1.1
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
@@ -129,6 +202,7 @@ services:
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_proxy.sh:/start_proxy.sh
hostname: proxy
container_name: proxy-${VER}
depends_on:
php:
condition: service_healthy
@@ -137,11 +211,16 @@ services:
ipv4_address: 10.10.0.3
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_proxy.sh"]
logging: *default-logging
wg:
image: mercurykd/vpnbot-wg:1.1
build:
dockerfile: dockerfile/wireguard.dockerfile
args:
@@ -153,20 +232,22 @@ services:
- ./scripts/start_wg.sh:/start_wg.sh
- ./scripts/reset_wg.sh:/reset_wg.sh
- ./scripts/block_torrent.sh:/block_torrent.sh
- ./scripts/unblock_torrent.sh:/unblock_torrent.sh
- ./scripts/block_exchange.sh:/block_exchange.sh
- ./scripts/unblock_exchange.sh:/unblock_exchange.sh
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
hostname: wireguard
container_name: wireguard-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${WGPORT}:${WGPORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
environment:
TZ: ${TZ}
WGPORT: ${WGPORT}
ADDRESS: ${WGADDRESS}
cap_add:
- NET_ADMIN
@@ -178,7 +259,48 @@ services:
default:
ipv4_address: 10.10.0.4
logging: *default-logging
wg1:
image: mercurykd/vpnbot-wg:1.1
build:
dockerfile: dockerfile/wireguard.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/wg1.conf:/etc/wireguard/wg0.conf
- ./config/pac.json:/pac.json
- ./scripts/start_wg.sh:/start_wg.sh
- ./scripts/reset_wg.sh:/reset_wg.sh
- ./scripts/block_torrent.sh:/block_torrent.sh
- ./scripts/block_exchange.sh:/block_exchange.sh
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
hostname: wireguard1
container_name: wireguard1-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${WG1PORT}:${WG1PORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
environment:
ADDRESS: ${WG1ADDRESS}
cap_add:
- NET_ADMIN
devices:
- /dev/net/tun:/dev/net/tun
stop_grace_period: 1s
command: ["/bin/sh", "/start_wg.sh"]
networks:
default:
ipv4_address: 10.10.0.14
logging: *default-logging
ad:
image: mercurykd/vpnbot-ad:1.1
build:
dockerfile: dockerfile/adguard.dockerfile
args:
@@ -197,11 +319,15 @@ services:
- ./logs/:/logs/
- ./scripts/start_ad.sh:/start_ad.sh
hostname: adguard
container_name: adguard-${VER}
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
networks:
default:
@@ -211,6 +337,7 @@ services:
entrypoint: ["/bin/sh", "/start_ad.sh"]
logging: *default-logging
ss:
image: mercurykd/vpnbot-ss:1.1
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
@@ -222,15 +349,18 @@ services:
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_ss.sh:/start_ss.sh
hostname: shadowsocks
container_name: shadowsocks-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${SSPORT}:${SSPORT}/tcp
- ${SSPORT}:${SSPORT}/udp
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ss.sh"]
networks:
@@ -238,6 +368,7 @@ services:
ipv4_address: 10.10.0.6
logging: *default-logging
tg:
image: mercurykd/vpnbot-tg:1.1
build:
dockerfile: dockerfile/telegram.dockerfile
volumes:
@@ -247,15 +378,19 @@ services:
- ./scripts/start_tg.sh:/start_tg.sh
- ./config/mtprotosecret:/mtprotosecret
hostname: telegram
container_name: mtproto-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${TGPORT}:${TGPORT}
environment:
TZ: ${TZ}
IP: ${IP}
TGPORT: ${TGPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_tg.sh"]
networks:
@@ -263,6 +398,7 @@ services:
ipv4_address: 10.10.0.8
logging: *default-logging
xr:
image: mercurykd/vpnbot-xr:1.1
build:
dockerfile: dockerfile/xray.dockerfile
args:
@@ -274,18 +410,25 @@ services:
- ./config/xray.json:/xray.json
- ./scripts/start_xray.sh:/start_xray.sh
hostname: xray
container_name: xray-${VER}
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_xray.sh"]
networks:
default:
ipv4_address: 10.10.0.9
xray:
ipv4_address: 10.10.1.9
logging: *default-logging
oc:
image: mercurykd/vpnbot-oc:1.2
build:
dockerfile: dockerfile/ocserv.dockerfile
args:
@@ -298,12 +441,15 @@ services:
- ./certs:/certs
- ./scripts/start_oc.sh:/start_oc.sh
hostname: ocserv
container_name: openconnect-${VER}
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
ENV: /root/.ashrc
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_oc.sh"]
cap_add:
@@ -315,6 +461,7 @@ services:
ipv4_address: 10.10.0.11
logging: *default-logging
np:
image: mercurykd/vpnbot-np:1.1
build:
dockerfile: dockerfile/naive.dockerfile
args:
@@ -327,12 +474,15 @@ services:
- ./certs:/certs
- ./scripts/start_np.sh:/start_np.sh
hostname: naive
container_name: naive-${VER}
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
ENV: /root/.ashrc
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_np.sh"]
cap_add:
+10 -9
View File
@@ -1,21 +1,22 @@
ARG image
FROM $image
RUN apk add --update openssh iptables \
&& apk add --no-cache --virtual .build-deps \
curl \
g++ \
RUN apk add --update openssh \
iptables \
gnutls-dev \
gpgme \
libev-dev \
libnl3-dev \
libseccomp-dev \
linux-headers \
linux-pam-dev \
lz4-dev \
libseccomp-dev \
&& apk add --no-cache --virtual .build-deps \
xz \
linux-headers \
libnl3-dev \
g++ \
gpgme \
curl \
make \
readline-dev \
tar \
xz \
autoconf \
automake \
gperf \
+2
View File
@@ -3,6 +3,7 @@ FROM $image
RUN apk add --no-cache --update php81 \
php81-mbstring \
php81-session \
php81-phar \
php81-curl \
php81-opcache \
php81-openssl \
@@ -18,6 +19,7 @@ RUN apk add --no-cache --update php81 \
openssh \
openssl \
curl \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
&& mv linux-amd64/dnslookup /usr/bin \
+23 -13
View File
@@ -1,12 +1,15 @@
b:
docker compose build
u: # запуск контейнеров
IP=$(shell ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$$|\1|p' | awk '{print $1}' | head -1) docker compose up -d --build --force-recreate
bash ./update/update.sh &
touch ./override.env
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
d: # остановка контейнеров
docker compose down
-kill -9 $(shell cat ./update/update_pid) > /dev/null
docker compose down --remove-orphans
dv: # остановка контейнеров
docker compose down -v
r: cleanf d u cleanf
r: d cleanf u cleanf
ps: # список контейнеров
docker compose ps
l: # логи из контейнеров
@@ -15,6 +18,8 @@ php: # консоль сервиса
docker compose exec php /bin/sh
wg: # консоль сервиса
docker compose exec wg /bin/sh
wg1: # консоль сервиса
docker compose exec wg1 /bin/sh
ss: # консоль сервиса
docker compose exec ss /bin/sh
ng: # консоль сервиса
@@ -25,12 +30,14 @@ up: # консоль сервиса
docker compose exec up /bin/sh
ad: # консоль сервиса
docker compose exec ad /bin/sh
wp: # консоль сервиса
docker compose exec wp bash
proxy: # консоль сервиса
docker compose exec proxy /bin/sh
tg: # консоль сервиса
docker compose exec tg /bin/sh
xr: # консоль сервиса
docker compose exec xr /bin/shec tg /bin/sh
docker compose exec xr /bin/sh
oc: # консоль сервиса
docker compose exec oc /bin/sh
clean:
@@ -40,12 +47,15 @@ cleanf:
docker image prune -f > /dev/null
docker builder prune -f > /dev/null
cleanall:
docker image prune -a
docker builder prune -a
p:
git stash
git pull
git stash pop stash@{0}
update: p r
cn:
docker compose exec ng nginx -t
docker image prune -a -f
docker builder prune -a -f
push:
docker compose push
s:
git status -su
c:
git add config/
git checkout .
git reset
webhook:
docker compose exec php php checkwebhook.php
+18
View File
@@ -0,0 +1,18 @@
version: "3"
services:
socat:
build:
dockerfile: ./dockerfile
ports:
- 80:80
- 443:443
- 853:853
- ${TGPORT}:${TGPORT}
- ${SSPORT}:${SSPORT}
- ${SSPORT}:${SSPORT}/udp
- ${WGPORT}:${WGPORT}/udp
volumes:
- ./start_socat.sh:/start_socat.sh
command: /bin/sh /start_socat.sh
stop_grace_period: 1s
+2
View File
@@ -0,0 +1,2 @@
FROM alpine:3.18
RUN apk add socat htop net-tools
+11
View File
@@ -0,0 +1,11 @@
b:
docker compose build --no-cache
u:
docker compose up -d --build
d:
docker compose down
ps:
docker compose ps
e:
docker compose exec socat sh
r: d u
+8
View File
@@ -0,0 +1,8 @@
socat TCP-LISTEN:80,fork TCP:{ip}:80 &
socat TCP-LISTEN:443,fork TCP:{ip}:443 &
socat TCP-LISTEN:853,fork TCP:{ip}:853 &
socat TCP-LISTEN:{tg},fork TCP:{ip}:{tg} &
socat TCP-LISTEN:{ss},fork TCP:{ip}:{ss} &
socat UDP-LISTEN:{ss},fork UDP:{ip}:{ss} &
socat UDP-LISTEN:{wg},fork UDP:{ip}:{wg} &
tail -f /dev/null
+8 -10
View File
@@ -62,19 +62,17 @@ telegram bot to manage servers (inside the bot)
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
---
environment: ubuntu 18.04/20.04/22.04, debian 11
environment: ubuntu 18.04/20.04/22.04, debian 11/12
install:
`wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY`
---
additional options:
install as service(autoload on start):
### Install:
```shell
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
```
### Install as service (autoload on start):
```shell
cd /root/vpnbot
bash scripts/install_as_service.sh
```
+1 -1
View File
@@ -1,4 +1,4 @@
if [[ -f "/ssh/key.pub" && -s "/ssh/key.pub" ]]; then
if [[ -f "/start" && -f "/ssh/key.pub" && -s "/ssh/key.pub" ]]; then
exit 0;
else
exit 1;
+2 -1
View File
@@ -1,3 +1,4 @@
cp scripts/vpnbot.service /etc/systemd/system/vpnbot.service
path=`pwd`
sed "s|path|$path|g" "$path/scripts/vpnbot.service" > /etc/systemd/system/vpnbot.service
systemctl daemon-reload
systemctl enable vpnbot
+1
View File
@@ -1,4 +1,5 @@
route add -net 10.0.1.0 netmask 255.255.255.0 gw wg
route add -net 10.0.3.0 netmask 255.255.255.0 gw wg1
route add -net 10.0.2.0 netmask 255.255.255.0 gw oc
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
+1 -1
View File
@@ -6,4 +6,4 @@ php cron.php &
unitd --log /logs/unit_error
curl -X PUT --data-binary @/config/unit.json --unix-socket /var/run/control.unit.sock http://localhost/config
pkill unitd
unitd --no-daemon --log /logs/unit_error
unitd --no-daemon --control 0.0.0.0:8080 --log /logs/unit_error
+1
View File
@@ -0,0 +1 @@
php service.php
-5
View File
@@ -4,9 +4,4 @@ ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
curl -s https://core.telegram.org/getProxySecret -o proxy-secret
curl -s https://core.telegram.org/getProxyConfig -o proxy-multi.conf
if [ $(cat /mtprotosecret | wc -c) -gt 0 ]
then
SECRET=$(cat /mtprotosecret)
mtproto-proxy -u nobody -H $TGPORT --nat-info 10.10.0.8:$IP -S $SECRET --aes-pwd /proxy-secret /proxy-multi.conf -M 1
fi
tail -f /dev/null
+56 -22
View File
@@ -1,33 +1,67 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
if [ "$HOSTNAME" = "wireguard1" ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WG1PORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WG1PORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
fi
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
fi
fi
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
ln -s /etc/wireguard/wg0.conf /etc/amnezia/amneziawg/wg0.conf
if [ $(cat /pac.json | jq .amnezia) -eq 1 ]
if [ "$HOSTNAME" = "wireguard1" ]
then
awg-quick up wg0
if [ $(cat /pac.json | jq .wg1_amnezia) -eq 1 ]
then
awg-quick up wg0
else
wg-quick up wg0
fi
if [ $(cat /pac.json | jq .wg1_blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .wg1_exchange) -eq 1 ]
then
sh /block_exchange.sh
fi
else
wg-quick up wg0
fi
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .exchange) -eq 1 ]
then
sh /block_exchange.sh
if [ $(cat /pac.json | jq .amnezia) -eq 1 ]
then
awg-quick up wg0
else
wg-quick up wg0
fi
if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .exchange) -eq 1 ]
then
sh /block_exchange.sh
fi
fi
tail -f /dev/null
-1
View File
@@ -1 +0,0 @@
iptables -D FORWARD -i wg0 -o wg0 -j REJECT
-12
View File
@@ -1,12 +0,0 @@
iptables -D FORWARD -p tcp -m ipp2p --bit -j DROP
iptables -D FORWARD -p udp -m ipp2p --bit -j DROP
iptables -D FORWARD -m string --algo bm --string "BitTorrent" -j DROP
iptables -D FORWARD -m string --algo bm --string "BitTorrent protocol" -j DROP
iptables -D FORWARD -m string --algo bm --string "peer_id=" -j DROP
iptables -D FORWARD -m string --algo bm --string ".torrent" -j DROP
iptables -D FORWARD -m string --algo bm --string "announce.php?passkey=" -j DROP
iptables -D FORWARD -m string --algo bm --string "torrent" -j DROP
iptables -D FORWARD -m string --algo bm --string "announce" -j DROP
iptables -D FORWARD -m string --algo bm --string "info_hash" -j DROP
iptables -D OUTPUT -p tcp -m ipp2p --bit -j DROP
iptables -D OUTPUT -p udp -m ipp2p --bit -j DROP
+8 -4
View File
@@ -3,10 +3,14 @@ Description=VPN: Docker Compose Application Service
Requires=docker.service
After=docker.service
[Service]
WorkingDirectory=/root/vpnbot
ExecStart=/bin/sh -c "IP=$(ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | awk '{print $1}' | head -1) docker compose up --build --force-recreate"
ExecStop=/usr/bin/docker compose down
Type=oneshot
RemainAfterExit=yes
WorkingDirectory=path
ExecStartPre=/bin/sh -c "touch ./override.env"
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate"
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
TimeoutStartSec=0
Restart=on-failure
[Install]
WantedBy=multi-user.target
+6
View File
@@ -0,0 +1,6 @@
@url = http://127.0.0.1:8081
###
GET {{url}}/status
###
GET {{url}}/config
+19
View File
@@ -0,0 +1,19 @@
#!/bin/bash
pwd=`pwd`
> $pwd/update/pipe
echo "$$" > $pwd/update/update_pid
while true
do
cmd=$(cat $pwd/update/pipe)
if [[ -n "$cmd" ]]
then
docker compose down --remove-orphans
git reset --hard
git pull > ./update/message
IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate
bash $pwd/update/update.sh &
exit 0
fi
sleep 1
done
+40
View File
@@ -1,3 +1,43 @@
20.03.2024 v1.11
- XTLS-Reality steal from yourself
18.03.2024 v1.10
- MTProto Fake-TLS
17.03.2024 v1.9
- автоматический технический домен sslip
13.03.2024 v1.8.10
- фикс override.env
10.03.2024 v1.8.9
- веб морда адгварда "встроена" в телеграм
- мелкие улучшения меню
07.03.2024 v1.8.8
- фикс не работающего wireguard
07.03.2024 v1.8.7
- фикс порта амнезии
- у кого ошибка запуска обновите докер и докер композ
07.03.2024 v1.8.6
- фикс синхронизации клиентов амнезии, бот падал после рестарта, клиенты пропадали
- возможность переназначить порты в override.env, файл не отслеживаемый, обновление не будет его сбрасывать
- убрал дублирование образа php
06.03.2024
- короткие ссылки для амнезии
- фикс работы openconnect
- фикс экспорта пользователей openconnect
- фикс скрипта установки бота как сервиса
04.03.2024
- решение "серого айпи" при запуске
- фикс стартового скрипта второго контейнера wireguard
03.03.2024 возможность обновления бота по кнопке из самого бота
- <code>git pull && make r</code>
02.03.2024 2 сервера wireguard, для возможности один запускать как wireguard а второй как amnezia
- <code>git pull && make r</code>
01.03.2024 фикс блокировок торрентов и обмена между пользователями
- <code>git pull && make r</code>
01.03.2024 фикс установки домена с длинным названием
- <code>make update</code>
29.02.2024 образы теперь будут скачиваться с docker hub
- <code>git pull && make d cleanall u</code>
28.02.2024 v1.1 добавлен раздел "зеркало"
- <code>git pull && make r</code>
27.02.2024 оптимизация размеров образов, сборка naive из исходников
- <code>git pull && make r</code>
19.02.2024 добавлен NaiveProxy