Compare commits
254 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 3f1e80c641 | |||
| 5afe6a4777 | |||
| c2cf0bff98 | |||
| 60241aaffb | |||
| 96ff868b10 | |||
| f58c29a66b | |||
| ca922f4612 | |||
| 5a5b1b62b1 | |||
| 0ef34f818d | |||
| d1960d6acb | |||
| 95cba4c8d1 | |||
| 18e2dd53ff | |||
| 3e5b131c16 | |||
| e07d1505e4 | |||
| c140f292e8 | |||
| 7cc100ace5 | |||
| 4938ada85d | |||
| c5b9886470 | |||
| 61d8b899e7 | |||
| 7d81eeeddd | |||
| 3bdebd95ab | |||
| eb4641a58d | |||
| 61900daafd | |||
| 364dbd6408 | |||
| 57ee403070 | |||
| b5ab8fb4eb | |||
| 95c6a023d0 | |||
| 9f196ca58e | |||
| 665b4007eb | |||
| 9c9f42e9e4 | |||
| 30c260bf02 | |||
| a3c59991ce | |||
| 288435e2a0 | |||
| 1b1acee59f | |||
| a8d121b7e1 | |||
| f6d2c89e8d | |||
| e4863eb645 | |||
| bc28be571b | |||
| 34f5f32a82 | |||
| fc4c28edfb | |||
| c352270b39 | |||
| 2ee6c3392b | |||
| 9bd85c9e05 | |||
| 82e51c0d9c | |||
| 9051b214c5 | |||
| 0710ef51fd | |||
| 597763f80a | |||
| 8398ecf736 | |||
| 0d14061edb | |||
| 03218b974d | |||
| 84ac1200dc | |||
| aa64a48db2 | |||
| 70c83da66a | |||
| 52ff056474 | |||
| 225260044a | |||
| 050d1ee3eb | |||
| 6979cca602 | |||
| 7fc24ea4f4 | |||
| 3dff9e039f | |||
| e2441eb9fd | |||
| 269d0e9956 | |||
| 8ba85164aa | |||
| e7cc7b66e2 | |||
| 54fa8d35b1 | |||
| ffe6bb4ba8 | |||
| 6be95533c4 | |||
| 8d13bee021 | |||
| db6a18f498 | |||
| 6954a16fa2 | |||
| ca7a9c955d | |||
| 852fbd55c6 | |||
| 3a8a843d8c | |||
| 90828d1117 | |||
| 37e8b96bcf | |||
| 306bc41813 | |||
| f6e5da382b | |||
| d7ed7042ec | |||
| 4496a30552 | |||
| ca1a596f85 | |||
| b3edf1bdcc | |||
| c6306aa918 | |||
| d5bbc9a564 | |||
| d2aab8ee4b | |||
| 304217d36e | |||
| 2622397542 | |||
| 702123e39c | |||
| 01ef7707c4 | |||
| 064d39d80b | |||
| 1b93d41421 | |||
| e41c8e30a4 | |||
| 260f988360 | |||
| ca4905220d | |||
| 08c5ff136e | |||
| 8709531717 | |||
| 71f53c3575 | |||
| 2607f1f264 | |||
| a94cab7dc1 | |||
| 694d446402 | |||
| 6074d40643 | |||
| 4b1df94325 | |||
| 232c75d5bf | |||
| 5e860a4896 | |||
| 5b05486b98 | |||
| fb22744fa7 | |||
| af812b7c93 | |||
| 3302ca8871 | |||
| 2c5eff03d5 | |||
| a8a203041f | |||
| a21c9b5fe9 | |||
| 696779450f | |||
| 7c5b3dfa3a | |||
| 74404559f9 | |||
| 11e8fb468b | |||
| ca92ca703f | |||
| f527888db8 | |||
| 0e47a771cc | |||
| ff10cbefc8 | |||
| 3371ba4bae | |||
| 621fb08467 | |||
| 5153b2c94a | |||
| 1e9461cc49 | |||
| 88f48a036c | |||
| b40e052d3f | |||
| a43082ae27 | |||
| c2cd945991 | |||
| 0737327e4b | |||
| f620bf12cd | |||
| 8b3730c61f | |||
| c6d9dcd47b | |||
| d83ba51d81 | |||
| 1a593100b7 | |||
| 414a67c10d | |||
| f92b484011 | |||
| 7af0276944 | |||
| 24aaa8756c | |||
| 07e2beff9b | |||
| 86261e6b76 | |||
| d816582e6f | |||
| 6d1ab0cb3a | |||
| 284b025881 | |||
| 0ca93b56a3 | |||
| 7bcd8de007 | |||
| 34eb950852 | |||
| 46021855a5 | |||
| 29c18ceb9d | |||
| 49d0827b9e | |||
| 07e04c384a | |||
| 579457b4f4 | |||
| 3dac9416ca | |||
| 5b4d3b5627 | |||
| 658e125cd8 | |||
| 1840555573 | |||
| ecdc028226 | |||
| d432bf82f2 | |||
| 211e2c079d | |||
| 1696c4da7b | |||
| b8d5700eba | |||
| 7e20c14299 | |||
| b9155cf674 | |||
| 159f775e12 | |||
| ae672439be | |||
| 6dafba5618 | |||
| 7daf61a4f5 | |||
| f9266827c9 | |||
| 9e22c64771 | |||
| a2026a4436 | |||
| 95c5b5b8fd | |||
| efbe20485a | |||
| 475eea1f47 | |||
| 02d9cdcccc | |||
| d633799f11 | |||
| ead66c3951 | |||
| bd7742d8b2 | |||
| ac593629a8 | |||
| 9932ee1e00 | |||
| 1a6e9f43e8 | |||
| 76373ffcf2 | |||
| 43c59a9ed6 | |||
| 8b3c6ca547 | |||
| 63654e7ad7 | |||
| dcb4f72f07 | |||
| 90afbbedb0 | |||
| 1964ed0079 | |||
| 2525181655 | |||
| ef690349fd | |||
| 2c1db5f233 | |||
| 554d7f3a25 | |||
| f2a1ec1b71 | |||
| 04f1bf564c | |||
| 1116f8ec75 | |||
| f8e5b54a98 | |||
| 3929032e7a | |||
| 057917a24a | |||
| 941fc05e21 | |||
| 797088a328 | |||
| 45614eaf3b | |||
| 47113b4940 | |||
| 3febfe1d3d | |||
| 90084c37ff | |||
| b49f088256 | |||
| 09a0f77863 | |||
| 8c65f8e538 | |||
| 32e49088c2 | |||
| f666762dfa | |||
| a1778e6be8 | |||
| 4b61e38b6b | |||
| 270968e4ac | |||
| 3349e3b306 | |||
| 3e53000065 | |||
| 18ceb51f4e | |||
| 99bce7a988 | |||
| 446a5d7150 | |||
| 855f516936 | |||
| e1c13480d1 | |||
| bd5e10fa23 | |||
| 3627b389b4 | |||
| f3f9cb5348 | |||
| 1527b9f856 | |||
| f896b307ea | |||
| 8ba7ddedee | |||
| 19ef567873 | |||
| 4f4e36e1cb | |||
| 6267931475 | |||
| 7e2d90e7da | |||
| 28906176f5 | |||
| 968d72ce81 | |||
| 66e204e5ba | |||
| 36e8acd2aa | |||
| cdc20adccd | |||
| 8ad00bc47a | |||
| 4902eb53ce | |||
| 253cceb44c | |||
| 9d53f2896c | |||
| 550a8ad3b7 | |||
| e2f84b0ee7 | |||
| b394e769c6 | |||
| 7d8dc1dd2d | |||
| 34b1de5132 | |||
| 12b5d84afc | |||
| c3d90ada83 | |||
| dbe3f290ea | |||
| b56b48e080 | |||
| 21b7a4816f | |||
| 51ecb815ba | |||
| 66cee61d41 | |||
| 66225917fe | |||
| be227f6a33 | |||
| 37d392a240 | |||
| 565573cfc2 | |||
| 3813f43b92 | |||
| f34427c13c | |||
| b3366edb6e | |||
| 1edc9e8608 | |||
| 8a3d9c1007 |
+10
-1
@@ -10,6 +10,7 @@
|
||||
/sftp-config.json
|
||||
/tg.pyr
|
||||
/config/wg0.conf
|
||||
/config/hwid.json
|
||||
/todo.todo
|
||||
/app/zapretlists/*
|
||||
!/app/zapretlists/.gitkeep
|
||||
@@ -22,4 +23,12 @@ update/*
|
||||
override.env
|
||||
override.html
|
||||
override.php
|
||||
docker-compose.override.yml
|
||||
docker-compose.override.yml
|
||||
backup.json
|
||||
app/webapp/override/
|
||||
.rest
|
||||
|
||||
subscription.php
|
||||
location.conf
|
||||
override.conf
|
||||
i18n.override.php
|
||||
@@ -0,0 +1,13 @@
|
||||
<?php
|
||||
|
||||
require __DIR__ . '/timezone.php';
|
||||
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/config.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
if ($c['debug']) {
|
||||
require __DIR__ . '/debug.php';
|
||||
}
|
||||
|
||||
$bot = new Bot($c['key'], $i);
|
||||
echo $bot->export();
|
||||
+3142
-812
File diff suppressed because it is too large
Load Diff
+38
-6
@@ -2,8 +2,8 @@
|
||||
|
||||
$i = [
|
||||
'warp' => [
|
||||
'en' => 'warp',
|
||||
'ru' => 'warp',
|
||||
'en' => 'Warp',
|
||||
'ru' => 'Warp',
|
||||
],
|
||||
'wg_title' => [
|
||||
'en' => 'Wireguard',
|
||||
@@ -22,7 +22,7 @@ $i = [
|
||||
'ru' => 'AdGuard',
|
||||
],
|
||||
'config' => [
|
||||
'en' => 'config',
|
||||
'en' => 'Settings',
|
||||
'ru' => 'настройки',
|
||||
],
|
||||
'pac' => [
|
||||
@@ -30,7 +30,7 @@ $i = [
|
||||
'ru' => 'PAC',
|
||||
],
|
||||
'chat' => [
|
||||
'en' => 'discussion group',
|
||||
'en' => 'chat',
|
||||
'ru' => 'чат поддержки',
|
||||
],
|
||||
'back' => [
|
||||
@@ -193,6 +193,30 @@ $i = [
|
||||
'en' => 'delete internal dns',
|
||||
'ru' => 'удалить внутренний dns',
|
||||
],
|
||||
'hwid limit' => [
|
||||
'en' => 'HWID limit',
|
||||
'ru' => 'HWID лимит',
|
||||
],
|
||||
'hwid devices' => [
|
||||
'en' => 'HWID devices',
|
||||
'ru' => 'Устройства HWID',
|
||||
],
|
||||
'set hwid devices count' => [
|
||||
'en' => 'set HWID devices count',
|
||||
'ru' => 'установить количество HWID устройств',
|
||||
],
|
||||
'use default hwid limit' => [
|
||||
'en' => 'use default limit',
|
||||
'ru' => 'использовать лимит по умолчанию',
|
||||
],
|
||||
'no devices' => [
|
||||
'en' => 'no devices',
|
||||
'ru' => 'нет устройств',
|
||||
],
|
||||
'hwid notice' => [
|
||||
'en' => 'HWID limit works only when subscription is refreshed or added',
|
||||
'ru' => 'HWID лимит срабатывает только в момент обновления и добавления подписки',
|
||||
],
|
||||
'on' => [
|
||||
'en' => '🟢',
|
||||
'ru' => '🟢',
|
||||
@@ -262,8 +286,12 @@ $i = [
|
||||
'ru' => 'очистить',
|
||||
],
|
||||
'xray' => [
|
||||
'en' => 'Xray',
|
||||
'ru' => 'Xray',
|
||||
'en' => 'Vless',
|
||||
'ru' => 'Vless',
|
||||
],
|
||||
'clash' => [
|
||||
'en' => 'mihomo',
|
||||
'ru' => 'mihomo',
|
||||
],
|
||||
'geodb' => [
|
||||
'en' => 'GeoIp/GeoSite',
|
||||
@@ -374,3 +402,7 @@ $i = [
|
||||
'ru' => 'перезагрузка',
|
||||
],
|
||||
];
|
||||
|
||||
if (file_exists(__DIR__ . '/i18n.override.php')) {
|
||||
include __DIR__ . '/i18n.override.php';
|
||||
}
|
||||
|
||||
+135
-136
@@ -1,128 +1,18 @@
|
||||
<?php
|
||||
|
||||
require __DIR__ . '/timezone.php';
|
||||
|
||||
// bot
|
||||
require __DIR__ . '/config.php';
|
||||
if ('POST' == $_SERVER['REQUEST_METHOD'] && $_GET['k'] == $c['key']) {
|
||||
if ($c['debug']) {
|
||||
require __DIR__ . '/debug.php';
|
||||
}
|
||||
require __DIR__ . '/calc.php';
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
if (file_exists(__DIR__ . '/override.php')) {
|
||||
include __DIR__ . '/override.php';
|
||||
}
|
||||
$bot = new Bot($c['key'], $i);
|
||||
$bot->input();
|
||||
exit;
|
||||
if ($c['debug']) {
|
||||
require __DIR__ . '/debug.php';
|
||||
}
|
||||
|
||||
// pac
|
||||
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
|
||||
$_GET = array_merge($_GET, $t);
|
||||
}
|
||||
$type = $_GET['t'] ?? 'pac';
|
||||
$address = $_GET['a'] ?: '127.0.0.1';
|
||||
$port = $_GET['p'] ?: '1080';
|
||||
$hash = $_GET['h'];
|
||||
if ($hash == substr(md5($c['key']), 0, 8)) {
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
$bot = new Bot($c['key'], $i);
|
||||
switch ($type) {
|
||||
case 'mirror':
|
||||
$bot->getMirror();
|
||||
break;
|
||||
case 's':
|
||||
case 'si':
|
||||
$bot->subscription();
|
||||
exit;
|
||||
|
||||
case 'te':
|
||||
if (!empty($_GET['te'])) {
|
||||
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
|
||||
} else {
|
||||
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
|
||||
}
|
||||
if ($t) {
|
||||
header('Content-Type: text/html');
|
||||
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
||||
$name = $_GET['te'] ?: 'origin';
|
||||
$type = $_GET['ty'];
|
||||
echo <<<HTML
|
||||
<!DOCTYPE HTML>
|
||||
<html lang="en" style="height:100%">
|
||||
<head>
|
||||
<!-- when using the mode "code", it's important to specify charset utf-8 -->
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<link href="jsoneditor.min.css" rel="stylesheet" type="text/css">
|
||||
<script src="jsoneditor.min.js"></script>
|
||||
<script src="jquery-3.7.1.min.js"></script>
|
||||
<script src="https://telegram.org/js/telegram-web-app.js"></script>
|
||||
</head>
|
||||
<body style="height:100%">
|
||||
<div id="jsoneditor" style="height:100%"></div>
|
||||
|
||||
<script>
|
||||
jQuery(function($) {
|
||||
var tg = window.Telegram.WebApp;
|
||||
// create the editor
|
||||
const container = document.getElementById("jsoneditor")
|
||||
const options = {}
|
||||
const editor = new JSONEditor(container, options)
|
||||
editor.set({$t})
|
||||
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
|
||||
var self = this;
|
||||
$.ajax({
|
||||
url: '/webapp/save?' + tg.initData,
|
||||
method: 'POST',
|
||||
data: {
|
||||
name: '$name',
|
||||
type: '$type',
|
||||
json: editor.getText()
|
||||
},
|
||||
dataType: 'json'
|
||||
}).done(function (r) {
|
||||
if (r.status == true) {
|
||||
tg.MainButton.setText('{$bot->i18n('success')}')
|
||||
setTimeout(() => {
|
||||
tg.close();
|
||||
}, 500);
|
||||
} else {
|
||||
tg.MainButton.setText(r.message);
|
||||
}
|
||||
}).fail(function (r) {
|
||||
tg.MainButton.setText('{$bot->i18n('error')}')
|
||||
});
|
||||
});
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
HTML;
|
||||
exit;
|
||||
}
|
||||
|
||||
default:
|
||||
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
|
||||
$pac = file_get_contents($file);
|
||||
header('Content-Type: text/plain');
|
||||
echo str_replace([
|
||||
'~address~',
|
||||
'~port~',
|
||||
], [
|
||||
$address,
|
||||
$port,
|
||||
], $pac);
|
||||
exit;
|
||||
}
|
||||
break;
|
||||
}
|
||||
require __DIR__ . '/calc.php';
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
if (file_exists(__DIR__ . '/override.php')) {
|
||||
include __DIR__ . '/override.php';
|
||||
}
|
||||
$bot = new Bot($c['key'], $i);
|
||||
$hash = $bot->getHashBot();
|
||||
if (!empty($_GET['hash'])) {
|
||||
$t = $_GET;
|
||||
unset($t['hash']);
|
||||
@@ -130,22 +20,131 @@ if (!empty($_GET['hash'])) {
|
||||
foreach ($t as $k => $v) {
|
||||
$s[] = "$k=$v";
|
||||
}
|
||||
$s = implode("\n", $s);
|
||||
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
|
||||
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
$bot = new Bot($c['key'], $i);
|
||||
if (!empty($_POST['json'])) {
|
||||
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
|
||||
die();
|
||||
} else {
|
||||
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
|
||||
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
|
||||
}
|
||||
die('ok');
|
||||
}
|
||||
$s = implode("\n", $s);
|
||||
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
|
||||
$webapp = hash_hmac('sha256', $s, $sk) == $_GET['hash'];
|
||||
}
|
||||
|
||||
header('500', true, 500);
|
||||
exit;
|
||||
switch (true) {
|
||||
// tlgrm
|
||||
case 'POST' == $_SERVER['REQUEST_METHOD'] && preg_match('~^/tlgrm~', $_SERVER['REQUEST_URI']) && $_GET['k'] == $c['key']:
|
||||
$bot->input();
|
||||
break;
|
||||
|
||||
// save template
|
||||
case preg_match('~^' . preg_quote("/webapp$hash/save") . '~', $_SERVER['REQUEST_URI']) && $webapp && !empty($_POST['json']):
|
||||
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
|
||||
break;
|
||||
|
||||
// adguard cookie
|
||||
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
|
||||
setcookie('c', $hash, 0, '/');
|
||||
echo "/adguard$hash/";
|
||||
break;
|
||||
|
||||
case preg_match('~^' . preg_quote("/pac$hash/sub") . '~', $_SERVER['REQUEST_URI']) && file_exists(__DIR__ . '/subscription.php'):
|
||||
$bot->sub();
|
||||
exit;
|
||||
|
||||
// subs & pac
|
||||
case preg_match('~^' . preg_quote("/pac$hash") . '~', $_SERVER['REQUEST_URI']):
|
||||
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
|
||||
$_GET = array_merge($_GET, $t);
|
||||
}
|
||||
$type = $_GET['t'] ?? 'pac';
|
||||
$address = $_GET['a'] ?: '127.0.0.1';
|
||||
$port = $_GET['p'] ?: '1080';
|
||||
switch ($type) {
|
||||
case 's':
|
||||
case 'si':
|
||||
case 'cl':
|
||||
$bot->subscription();
|
||||
exit;
|
||||
|
||||
case 'te':
|
||||
if (!empty($_GET['te'])) {
|
||||
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
|
||||
} else {
|
||||
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
|
||||
}
|
||||
if ($t) {
|
||||
header('Content-Type: text/html');
|
||||
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
||||
$name = $_GET['te'] ?: 'origin';
|
||||
$type = $_GET['ty'];
|
||||
echo <<<HTML
|
||||
<!DOCTYPE HTML>
|
||||
<html lang="en" style="height:100%">
|
||||
<head>
|
||||
<!-- when using the mode "code", it's important to specify charset utf-8 -->
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<link href="/webapp$hash/jsoneditor.min.css" rel="stylesheet" type="text/css">
|
||||
<script src="/webapp$hash/jsoneditor.min.js"></script>
|
||||
<script src="/webapp$hash/jquery-3.7.1.min.js"></script>
|
||||
<script src="https://telegram.org/js/telegram-web-app.js"></script>
|
||||
</head>
|
||||
<body style="height:100%">
|
||||
<div id="jsoneditor" style="height:100%"></div>
|
||||
|
||||
<script>
|
||||
jQuery(function($) {
|
||||
var tg = window.Telegram.WebApp;
|
||||
// create the editor
|
||||
const container = document.getElementById("jsoneditor")
|
||||
const options = {}
|
||||
const editor = new JSONEditor(container, options)
|
||||
editor.set({$t})
|
||||
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
|
||||
var self = this;
|
||||
$.ajax({
|
||||
url: '/webapp$hash/save?' + tg.initData,
|
||||
method: 'POST',
|
||||
data: {
|
||||
name: '$name',
|
||||
type: '$type',
|
||||
json: editor.getText()
|
||||
},
|
||||
dataType: 'json'
|
||||
}).done(function (r) {
|
||||
if (r.status == true) {
|
||||
tg.MainButton.setText('{$bot->i18n('success')}')
|
||||
setTimeout(() => {
|
||||
tg.close();
|
||||
}, 500);
|
||||
} else {
|
||||
tg.MainButton.setText(r.message);
|
||||
}
|
||||
}).fail(function (r) {
|
||||
tg.MainButton.setText('{$bot->i18n('error')}')
|
||||
});
|
||||
});
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
HTML;
|
||||
exit;
|
||||
}
|
||||
|
||||
default:
|
||||
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
|
||||
$pac = file_get_contents($file);
|
||||
header('Content-Type: text/plain');
|
||||
echo str_replace([
|
||||
'~address~',
|
||||
'~port~',
|
||||
], [
|
||||
$address,
|
||||
$port,
|
||||
], $pac);
|
||||
exit;
|
||||
}
|
||||
break;
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
header('500', true, 500);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
<?php
|
||||
|
||||
require __DIR__ . '/timezone.php';
|
||||
|
||||
// require __DIR__ . '/debug.php';
|
||||
require __DIR__ . '/bot.php';
|
||||
require __DIR__ . '/config.php';
|
||||
require __DIR__ . '/i18n.php';
|
||||
|
||||
(new Bot($c['key'], $i))->analyzeXray();
|
||||
+9
-1
@@ -13,12 +13,20 @@ if ($c['debug']) {
|
||||
$bot = new Bot($c['key'], $i);
|
||||
|
||||
$bot->selfUpdate();
|
||||
$bot->ssPswdCheck();
|
||||
$bot->restartTG();
|
||||
if (!empty($bot->selfupdate)) {
|
||||
$bot->offWarp();
|
||||
}
|
||||
$bot->dontshowcron = 1;
|
||||
$bot->adguardSync();
|
||||
$bot->sslip();
|
||||
$bot->adguardSync();
|
||||
$bot->cloakNginx();
|
||||
$bot->syncDeny();
|
||||
$bot->cleanDocker();
|
||||
$bot->dnsttStart();
|
||||
$bot->restartHysteria();
|
||||
$c = $bot->getPacConf();
|
||||
$bot->setUpstreamDomain($c['transport'] != 'Reality' ? 't' : $c['reality']['domain']);
|
||||
$bot->setUpstreamDomainNaive($c['domain']);
|
||||
$bot->setUpstreamDomainOcserv($c['domain']);
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
$.ajax({
|
||||
'url': 'check?' + tg.initData,
|
||||
}).done(function (r) {
|
||||
location.replace('/adguard/');
|
||||
location.replace(r);
|
||||
}).fail(function (r) {
|
||||
location.replace('/');
|
||||
});
|
||||
|
||||
@@ -1,117 +0,0 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Login</title>
|
||||
<style>
|
||||
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
|
||||
|
||||
body {
|
||||
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
|
||||
background-size: cover;
|
||||
font-family: "Roboto";
|
||||
-webkit-font-smoothing: antialiased;
|
||||
-moz-osx-font-smoothing: grayscale;
|
||||
|
||||
&::before {
|
||||
z-index: -1;
|
||||
content: '';
|
||||
position: fixed;
|
||||
top: 0;
|
||||
left: 0;
|
||||
background: #44c4e7;
|
||||
/* IE Fallback */
|
||||
background: rgba(68, 196, 231, 0.8);
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
}
|
||||
}
|
||||
|
||||
.form {
|
||||
position: absolute;
|
||||
top: 50%;
|
||||
left: 50%;
|
||||
background: #fff;
|
||||
width: 285px;
|
||||
margin: -140px 0 0 -182px;
|
||||
padding: 40px;
|
||||
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
|
||||
|
||||
h2 {
|
||||
margin: 0 0 20px;
|
||||
line-height: 1;
|
||||
color: #44c4e7;
|
||||
font-size: 18px;
|
||||
font-weight: 400;
|
||||
}
|
||||
|
||||
input {
|
||||
outline: none;
|
||||
display: block;
|
||||
width: 100%;
|
||||
margin: 0 0 20px;
|
||||
padding: 10px 15px;
|
||||
border: 1px solid #ccc;
|
||||
color: #ccc;
|
||||
font-family: "Roboto";
|
||||
box-sizing: border-box;
|
||||
font-size: 14px;
|
||||
font-wieght: 400;
|
||||
-webkit-font-smoothing: antialiased;
|
||||
-moz-osx-font-smoothing: grayscale;
|
||||
transition: 0.2s linear;
|
||||
|
||||
&input:focus {
|
||||
color: #333;
|
||||
border: 1px solid #44c4e7;
|
||||
}
|
||||
}
|
||||
|
||||
button {
|
||||
cursor: pointer;
|
||||
background: #44c4e7;
|
||||
width: 100%;
|
||||
padding: 10px 15px;
|
||||
border: 0;
|
||||
color: #fff;
|
||||
font-family: "Roboto";
|
||||
font-size: 14px;
|
||||
font-weight: 400;
|
||||
|
||||
&:hover {
|
||||
background: #369cb8;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
.error,
|
||||
.valid {
|
||||
display: none;
|
||||
}
|
||||
</style>
|
||||
<script src="jquery-3.7.1.min.js"></script>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<section class="form animated flipInX">
|
||||
<h2>Login To Your Account</h2>
|
||||
<p class="valid">Valid. Please wait a moment.</p>
|
||||
<p class="error">Error. Please enter correct Username & password.</p>
|
||||
<form class="loginbox" autocomplete="off">
|
||||
<input placeholder="Username" type="text" id="username"></input>
|
||||
<input placeholder="Password" type="password" id="password"></input>
|
||||
<button id="submit">Login</button>
|
||||
</form>
|
||||
</section>
|
||||
<script>
|
||||
$(document).ready(function() {
|
||||
$('#submit').click(function () {
|
||||
event.preventDefault(); // prevent PageReLoad
|
||||
$('.error').css('display', 'block'); // show error msg
|
||||
});
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,150 @@
|
||||
{
|
||||
"mixed-port": 2080,
|
||||
"allow-lan": true,
|
||||
"tcp-concurrent": true,
|
||||
"enable-process": true,
|
||||
"find-process-mode": "strict",
|
||||
"global-client-fingerprint": "chrome",
|
||||
"mode": "rule",
|
||||
"log-level": "info",
|
||||
"ipv6": false,
|
||||
"keep-alive-interval": 60,
|
||||
"unified-delay": false,
|
||||
"profile": {
|
||||
"store-selected": true,
|
||||
"store-fake-ip": true
|
||||
},
|
||||
"sniffer": {
|
||||
"enable": true,
|
||||
"sniff": {
|
||||
"HTTP": {
|
||||
"ports": [
|
||||
80,
|
||||
"8080-8880"
|
||||
],
|
||||
"override-destination": true
|
||||
},
|
||||
"TLS": {
|
||||
"ports": [
|
||||
443,
|
||||
8443
|
||||
]
|
||||
},
|
||||
"QUIC": {
|
||||
"ports": [
|
||||
443,
|
||||
8443
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"tun": {
|
||||
"enable": true,
|
||||
"stack": "mixed",
|
||||
"dns-hijack": [
|
||||
"any:53"
|
||||
],
|
||||
"auto-route": true,
|
||||
"auto-detect-interface": true,
|
||||
"strict-route": true
|
||||
},
|
||||
"dns": {
|
||||
"enable": true,
|
||||
"listen": ":1053",
|
||||
"prefer-h3": false,
|
||||
"ipv6": false,
|
||||
"enhanced-mode": "fake-ip",
|
||||
"fake-ip-filter": [
|
||||
"~domain~",
|
||||
"+.lan",
|
||||
"+.local"
|
||||
],
|
||||
"nameserver": [
|
||||
"~dns~"
|
||||
]
|
||||
},
|
||||
"proxies": [
|
||||
{
|
||||
"name": "~outbound~",
|
||||
"type": "vless",
|
||||
"server": "~domain~",
|
||||
"port": 443,
|
||||
"uuid": "~uid~",
|
||||
"network": "tcp",
|
||||
"flow": "xtls-rprx-vision",
|
||||
"udp": true,
|
||||
"tls": true,
|
||||
"reality-opts": {
|
||||
"public-key": "~public_key~",
|
||||
"short-id": "~short_id~"
|
||||
},
|
||||
"servername": "~server_name~",
|
||||
"client-fingerprint": "chrome"
|
||||
}
|
||||
],
|
||||
"proxy-groups": [
|
||||
{
|
||||
"name": "PROXY",
|
||||
"type": "select",
|
||||
"proxies": [
|
||||
"~outbound~"
|
||||
]
|
||||
}
|
||||
],
|
||||
"add-rule-providers": true,
|
||||
"rule-providers": {},
|
||||
"rules": [
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~block~",
|
||||
"action": "REJECT",
|
||||
"interval": 60,
|
||||
"behavior": "domain",
|
||||
"name": "block"
|
||||
},
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~process~",
|
||||
"action": "PROXY",
|
||||
"interval": 60,
|
||||
"behavior": "classical",
|
||||
"name": "process"
|
||||
},
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~package~",
|
||||
"action": "PROXY",
|
||||
"interval": 60,
|
||||
"behavior": "classical",
|
||||
"name": "package"
|
||||
},
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~warp~",
|
||||
"action": "PROXY",
|
||||
"interval": 60,
|
||||
"behavior": "classical",
|
||||
"name": "warp"
|
||||
},
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~pac~",
|
||||
"action": "PROXY",
|
||||
"interval": 60,
|
||||
"behavior": "domain",
|
||||
"name": "pac"
|
||||
},
|
||||
{
|
||||
"type": "RULE-SET",
|
||||
"list": "~subnet~",
|
||||
"action": "PROXY",
|
||||
"interval": 60,
|
||||
"behavior": "ipcidr",
|
||||
"name": "subnet"
|
||||
},
|
||||
{
|
||||
"type": "MATCH",
|
||||
"action": "DIRECT"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
{}
|
||||
@@ -0,0 +1,9 @@
|
||||
listen: :443
|
||||
proxy_protocol: true
|
||||
|
||||
tls:
|
||||
cert: /certs/cert_public
|
||||
key: /certs/cert_private
|
||||
auth:
|
||||
type: password
|
||||
password:
|
||||
+207
-176
@@ -1,197 +1,228 @@
|
||||
user nginx;
|
||||
worker_processes auto;
|
||||
user nginx;
|
||||
worker_processes auto;
|
||||
|
||||
error_log /logs/nginx_error;
|
||||
pid /var/run/nginx.pid;
|
||||
error_log /logs/nginx_error;
|
||||
pid /var/run/nginx.pid;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
worker_connections 1024;
|
||||
}
|
||||
|
||||
http {
|
||||
server_names_hash_bucket_size 64;
|
||||
include include.conf;
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
server_names_hash_bucket_size 64;
|
||||
server_tokens off;
|
||||
include override.conf;
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||
|
||||
real_ip_header proxy_protocol;
|
||||
real_ip_recursive on;
|
||||
set_real_ip_from 10.10.0.10;
|
||||
real_ip_header proxy_protocol;
|
||||
real_ip_recursive on;
|
||||
set_real_ip_from 10.10.0.10;
|
||||
|
||||
server {
|
||||
listen 10.10.0.2:80 default_server;
|
||||
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
|
||||
ssl_certificate /certs/self_public;
|
||||
ssl_certificate_key /certs/self_private;
|
||||
server {
|
||||
listen 80 default_server;
|
||||
|
||||
access_log /logs/nginx_default_access;
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
index override.html login.html;
|
||||
try_files $uri $uri/ =404;
|
||||
location / {
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
}
|
||||
location /adguard/ {
|
||||
access_log /logs/nginx_adguard_access;
|
||||
proxy_pass http://ad:80/;
|
||||
proxy_redirect / /adguard/;
|
||||
proxy_cookie_path / /adguard/;
|
||||
|
||||
server {
|
||||
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
|
||||
listen 10.10.1.2:443 ssl http2 default_server;
|
||||
ssl_certificate /certs/self_public;
|
||||
ssl_certificate_key /certs/self_private;
|
||||
|
||||
access_log /logs/nginx_ip_access;
|
||||
|
||||
location = / {
|
||||
root /app;
|
||||
try_files $uri /override.html @auth;
|
||||
}
|
||||
|
||||
location /override/ {
|
||||
alias /app/override/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
auth_basic "Restricted Content";
|
||||
auth_basic_user_file /app/.htpasswd;
|
||||
try_files $uri =404;
|
||||
}
|
||||
location @auth {
|
||||
root /app;
|
||||
auth_basic "Restricted Content";
|
||||
auth_basic_user_file /app/.htpasswd;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location /tlgrm {
|
||||
access_log /logs/nginx_tlgrm_access;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location @php {
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location /adguard/ {
|
||||
}
|
||||
|
||||
location /webapp {
|
||||
access_log /logs/nginx_webapp_access;
|
||||
alias /app;
|
||||
index index.html;
|
||||
try_files $uri $uri/ @php;
|
||||
}
|
||||
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
|
||||
location /v2ray {
|
||||
access_log /logs/nginx_v2ray_access;
|
||||
proxy_redirect off;
|
||||
proxy_buffering off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_pass http://ss:8388/;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
|
||||
location /dns-query {
|
||||
access_log /logs/nginx_doh_access;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Connection "";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto https;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
proxy_cache doh_cache;
|
||||
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
proxy_pass https://ad/dns-query;
|
||||
}
|
||||
include location.conf;
|
||||
}
|
||||
location /webapp {
|
||||
access_log /logs/nginx_webapp_access;
|
||||
alias /app;
|
||||
index index.html;
|
||||
try_files $uri $uri/ /pac?$query_string;
|
||||
}
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /tlgrm {
|
||||
access_log /logs/nginx_tlgrm_access;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /v2ray {
|
||||
access_log /logs/nginx_v2ray_access;
|
||||
proxy_redirect off;
|
||||
proxy_buffering off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_pass http://ss:8388/;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
#~
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
}
|
||||
#-domain
|
||||
# server {
|
||||
# server_name domain;
|
||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||
# listen 10.10.1.2:443 ssl http2;
|
||||
# ssl_certificate /certs/cert_public;
|
||||
# ssl_certificate_key /certs/cert_private;
|
||||
|
||||
#~
|
||||
# access_log /logs/nginx_domain_access;
|
||||
|
||||
#-domain
|
||||
# server {
|
||||
# listen 10.10.0.2:80;
|
||||
# server_name ;
|
||||
#-domain
|
||||
#-ssl
|
||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||
# listen 10.10.1.2:443 ssl http2;
|
||||
# ssl_certificate /certs/cert_public;
|
||||
# ssl_certificate_key /certs/cert_private;
|
||||
#-ssl
|
||||
# location = / {
|
||||
# root /app;
|
||||
# try_files $uri /override.html @auth;
|
||||
# }
|
||||
|
||||
#-domain
|
||||
# access_log /logs/nginx_domain_access;
|
||||
# location /override/ {
|
||||
# alias /app/override/;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
|
||||
# location / {
|
||||
# root /app;
|
||||
# index override.html login.html;
|
||||
# try_files $uri $uri/ =404;
|
||||
# }
|
||||
# location /adguard/ {
|
||||
# access_log /logs/nginx_adguard_access;
|
||||
# proxy_pass http://ad:80/;
|
||||
# proxy_redirect / /adguard/;
|
||||
# proxy_cookie_path / /adguard/;
|
||||
# }
|
||||
# location /webapp {
|
||||
# access_log /logs/nginx_webapp_access;
|
||||
# alias /app;
|
||||
# index index.html;
|
||||
# try_files $uri $uri/ /pac?$query_string;
|
||||
# }
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
# location ~\.well-known {
|
||||
# access_log /logs/nginx_certbot_access;
|
||||
# root /certs/;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
# location /v2ray {
|
||||
# access_log /logs/nginx_v2ray_access;
|
||||
# proxy_redirect off;
|
||||
# proxy_buffering off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_pass http://ss:8388/;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
#-domain
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
# location / {
|
||||
# root /app;
|
||||
# auth_basic "Restricted Content";
|
||||
# auth_basic_user_file /app/.htpasswd;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
# location @auth {
|
||||
# root /app;
|
||||
# auth_basic "Restricted Content";
|
||||
# auth_basic_user_file /app/.htpasswd;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
# location @php {
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
#-domain
|
||||
# }
|
||||
#-domain
|
||||
# location /adguard/ {
|
||||
# }
|
||||
|
||||
# location /webapp {
|
||||
# access_log /logs/nginx_webapp_access;
|
||||
# alias /app;
|
||||
# index index.html;
|
||||
# try_files $uri $uri/ @php;
|
||||
# }
|
||||
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
|
||||
# location /v2ray {
|
||||
# access_log /logs/nginx_v2ray_access;
|
||||
# proxy_redirect off;
|
||||
# proxy_buffering off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_pass http://ss:8388/;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
|
||||
# include location.conf;
|
||||
# }
|
||||
#-domain
|
||||
}
|
||||
|
||||
+207
-176
@@ -1,197 +1,228 @@
|
||||
user nginx;
|
||||
worker_processes auto;
|
||||
user nginx;
|
||||
worker_processes auto;
|
||||
|
||||
error_log /logs/nginx_error;
|
||||
pid /var/run/nginx.pid;
|
||||
error_log /logs/nginx_error;
|
||||
pid /var/run/nginx.pid;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
worker_connections 1024;
|
||||
}
|
||||
|
||||
http {
|
||||
server_names_hash_bucket_size 64;
|
||||
include include.conf;
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
server_names_hash_bucket_size 64;
|
||||
server_tokens off;
|
||||
include override.conf;
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||
|
||||
real_ip_header proxy_protocol;
|
||||
real_ip_recursive on;
|
||||
set_real_ip_from 10.10.0.10;
|
||||
real_ip_header proxy_protocol;
|
||||
real_ip_recursive on;
|
||||
set_real_ip_from 10.10.0.10;
|
||||
|
||||
server {
|
||||
listen 10.10.0.2:80 default_server;
|
||||
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
|
||||
ssl_certificate /certs/self_public;
|
||||
ssl_certificate_key /certs/self_private;
|
||||
server {
|
||||
listen 80 default_server;
|
||||
|
||||
access_log /logs/nginx_default_access;
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
index override.html login.html;
|
||||
try_files $uri $uri/ =404;
|
||||
location / {
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
}
|
||||
location /adguard/ {
|
||||
access_log /logs/nginx_adguard_access;
|
||||
proxy_pass http://ad:80/;
|
||||
proxy_redirect / /adguard/;
|
||||
proxy_cookie_path / /adguard/;
|
||||
|
||||
server {
|
||||
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
|
||||
listen 10.10.1.2:443 ssl http2 default_server;
|
||||
ssl_certificate /certs/self_public;
|
||||
ssl_certificate_key /certs/self_private;
|
||||
|
||||
access_log /logs/nginx_ip_access;
|
||||
|
||||
location = / {
|
||||
root /app;
|
||||
try_files $uri /override.html @auth;
|
||||
}
|
||||
|
||||
location /override/ {
|
||||
alias /app/override/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
auth_basic "Restricted Content";
|
||||
auth_basic_user_file /app/.htpasswd;
|
||||
try_files $uri =404;
|
||||
}
|
||||
location @auth {
|
||||
root /app;
|
||||
auth_basic "Restricted Content";
|
||||
auth_basic_user_file /app/.htpasswd;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location /tlgrm {
|
||||
access_log /logs/nginx_tlgrm_access;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location @php {
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location /adguard/ {
|
||||
}
|
||||
|
||||
location /webapp {
|
||||
access_log /logs/nginx_webapp_access;
|
||||
alias /app;
|
||||
index index.html;
|
||||
try_files $uri $uri/ @php;
|
||||
}
|
||||
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
|
||||
location /v2ray {
|
||||
access_log /logs/nginx_v2ray_access;
|
||||
proxy_redirect off;
|
||||
proxy_buffering off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_pass http://ss:8388/;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
|
||||
location /dns-query {
|
||||
access_log /logs/nginx_doh_access;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Connection "";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto https;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
proxy_cache doh_cache;
|
||||
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
proxy_pass https://ad/dns-query;
|
||||
}
|
||||
include location.conf;
|
||||
}
|
||||
location /webapp {
|
||||
access_log /logs/nginx_webapp_access;
|
||||
alias /app;
|
||||
index index.html;
|
||||
try_files $uri $uri/ /pac?$query_string;
|
||||
}
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /tlgrm {
|
||||
access_log /logs/nginx_tlgrm_access;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /v2ray {
|
||||
access_log /logs/nginx_v2ray_access;
|
||||
proxy_redirect off;
|
||||
proxy_buffering off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_pass http://ss:8388/;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
#~
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
try_files $uri =404;
|
||||
}
|
||||
}
|
||||
#-domain
|
||||
# server {
|
||||
# server_name domain;
|
||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||
# listen 10.10.1.2:443 ssl http2;
|
||||
# ssl_certificate /certs/cert_public;
|
||||
# ssl_certificate_key /certs/cert_private;
|
||||
|
||||
#~
|
||||
# access_log /logs/nginx_domain_access;
|
||||
|
||||
#-domain
|
||||
# server {
|
||||
# listen 10.10.0.2:80;
|
||||
# server_name ;
|
||||
#-domain
|
||||
#-ssl
|
||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||
# listen 10.10.1.2:443 ssl http2;
|
||||
# ssl_certificate /certs/cert_public;
|
||||
# ssl_certificate_key /certs/cert_private;
|
||||
#-ssl
|
||||
# location = / {
|
||||
# root /app;
|
||||
# try_files $uri /override.html @auth;
|
||||
# }
|
||||
|
||||
#-domain
|
||||
# access_log /logs/nginx_domain_access;
|
||||
# location /override/ {
|
||||
# alias /app/override/;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
|
||||
# location / {
|
||||
# root /app;
|
||||
# index override.html login.html;
|
||||
# try_files $uri $uri/ =404;
|
||||
# }
|
||||
# location /adguard/ {
|
||||
# access_log /logs/nginx_adguard_access;
|
||||
# proxy_pass http://ad:80/;
|
||||
# proxy_redirect / /adguard/;
|
||||
# proxy_cookie_path / /adguard/;
|
||||
# }
|
||||
# location /webapp {
|
||||
# access_log /logs/nginx_webapp_access;
|
||||
# alias /app;
|
||||
# index index.html;
|
||||
# try_files $uri $uri/ /pac?$query_string;
|
||||
# }
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
# location ~\.well-known {
|
||||
# access_log /logs/nginx_certbot_access;
|
||||
# root /certs/;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
# location /v2ray {
|
||||
# access_log /logs/nginx_v2ray_access;
|
||||
# proxy_redirect off;
|
||||
# proxy_buffering off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_pass http://ss:8388/;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
#-domain
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
# location / {
|
||||
# root /app;
|
||||
# auth_basic "Restricted Content";
|
||||
# auth_basic_user_file /app/.htpasswd;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
# location @auth {
|
||||
# root /app;
|
||||
# auth_basic "Restricted Content";
|
||||
# auth_basic_user_file /app/.htpasswd;
|
||||
# try_files $uri =404;
|
||||
# }
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
# location @php {
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
#-domain
|
||||
# }
|
||||
#-domain
|
||||
# location /adguard/ {
|
||||
# }
|
||||
|
||||
# location /webapp {
|
||||
# access_log /logs/nginx_webapp_access;
|
||||
# alias /app;
|
||||
# index index.html;
|
||||
# try_files $uri $uri/ @php;
|
||||
# }
|
||||
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
|
||||
# location /v2ray {
|
||||
# access_log /logs/nginx_v2ray_access;
|
||||
# proxy_redirect off;
|
||||
# proxy_buffering off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_pass http://ss:8388/;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
|
||||
# include location.conf;
|
||||
# }
|
||||
#-domain
|
||||
}
|
||||
|
||||
+1
-1
@@ -505,7 +505,7 @@ ipv4-netmask = 255.255.255.0
|
||||
|
||||
# Whether to tunnel all DNS queries via the VPN. This is the default
|
||||
# when a default route is set.
|
||||
#tunnel-all-dns = true
|
||||
tunnel-all-dns = true
|
||||
|
||||
# The advertised DNS server. Use multiple lines for
|
||||
# multiple servers.
|
||||
|
||||
+1
-3
@@ -397,7 +397,7 @@ zend.exception_string_param_max_len = 0
|
||||
; threat in any way, but it makes it possible to determine whether you use PHP
|
||||
; on your server or not.
|
||||
; https://php.net/expose-php
|
||||
expose_php = On
|
||||
expose_php = Off
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;
|
||||
; Resource Limits ;
|
||||
@@ -1955,5 +1955,3 @@ opcache.enable=1
|
||||
opcache.jit_buffer_size=128M
|
||||
opcache.enable_cli=1
|
||||
pcre.jit=1
|
||||
|
||||
|
||||
|
||||
+54
-33
@@ -9,12 +9,12 @@
|
||||
"tag": "tun-in",
|
||||
"domain_strategy": "prefer_ipv4",
|
||||
"interface_name": "sing-tun",
|
||||
"inet4_address": "172.19.0.1\/30",
|
||||
"address": [
|
||||
"172.19.0.1\/30"
|
||||
],
|
||||
"mtu": 1400,
|
||||
"gso": true,
|
||||
"auto_route": true,
|
||||
"strict_route": true,
|
||||
"sniff": true,
|
||||
"endpoint_independent_nat": false,
|
||||
"stack": "mixed",
|
||||
"platform": {
|
||||
@@ -27,14 +27,9 @@
|
||||
},
|
||||
{
|
||||
"type": "mixed",
|
||||
"tag": "mixed-in",
|
||||
"domain_strategy": "prefer_ipv4",
|
||||
"tag": "in",
|
||||
"listen": "127.0.0.1",
|
||||
"listen_port": 2080,
|
||||
"tcp_fast_open": true,
|
||||
"sniff": true,
|
||||
"sniff_override_destination": false,
|
||||
"users": []
|
||||
"listen_port": 2080
|
||||
}
|
||||
],
|
||||
"dns": {
|
||||
@@ -92,14 +87,6 @@
|
||||
{
|
||||
"type": "direct",
|
||||
"tag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "block",
|
||||
"tag": "block"
|
||||
},
|
||||
{
|
||||
"type": "dns",
|
||||
"tag": "dns-out"
|
||||
}
|
||||
],
|
||||
"route": {
|
||||
@@ -107,14 +94,32 @@
|
||||
"override_android_vpn": true,
|
||||
"rules": [
|
||||
{
|
||||
"protocol": "dns",
|
||||
"outbound": "dns-out"
|
||||
"action": "sniff"
|
||||
},
|
||||
{
|
||||
"protocol": "dns",
|
||||
"action": "hijack-dns"
|
||||
},
|
||||
{
|
||||
"inbound": "in",
|
||||
"action": "resolve",
|
||||
"strategy": "prefer_ipv4"
|
||||
},
|
||||
{
|
||||
"inbound": "in",
|
||||
"action": "sniff",
|
||||
"timeout": "1s"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"outbound": "direct"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "pac",
|
||||
"interval": "15s",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"domain_suffix": "~pac~"
|
||||
@@ -122,13 +127,29 @@
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "~domains_outbound~"
|
||||
"outbound": "~outbound~"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "subnet",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"ip_cidr": "~subnet~"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "~outbound~"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "package",
|
||||
"interval": "15s",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"package_name": "~package~"
|
||||
@@ -136,13 +157,14 @@
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "~app_outbound~"
|
||||
"outbound": "~outbound~"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "process",
|
||||
"interval": "15s",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"process_name": "~process~"
|
||||
@@ -150,13 +172,14 @@
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "~process_outbound~"
|
||||
"outbound": "~outbound~"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "block",
|
||||
"interval": "15s",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"domain_suffix": "~block~"
|
||||
@@ -164,13 +187,14 @@
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "block"
|
||||
"action": "reject"
|
||||
},
|
||||
{
|
||||
"addruleset": true,
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "warp",
|
||||
"interval": "15s",
|
||||
"interval": "60s",
|
||||
"rules": [
|
||||
{
|
||||
"domain_suffix": "~warp~"
|
||||
@@ -179,11 +203,8 @@
|
||||
}
|
||||
],
|
||||
"outbound": "~outbound~"
|
||||
},
|
||||
{
|
||||
"outbound": "direct"
|
||||
}
|
||||
],
|
||||
"final": "~final_outbound~"
|
||||
"final": "direct"
|
||||
}
|
||||
}
|
||||
+9
-4
@@ -83,9 +83,9 @@ AuthorizedKeysFile .ssh/authorized_keys
|
||||
|
||||
#AllowAgentForwarding yes
|
||||
# Feel free to re-enable these if your use case requires them.
|
||||
AllowTcpForwarding no
|
||||
GatewayPorts no
|
||||
X11Forwarding no
|
||||
# AllowTcpForwarding no
|
||||
# GatewayPorts no
|
||||
# X11Forwarding no
|
||||
#X11DisplayOffset 10
|
||||
#X11UseLocalhost yes
|
||||
#PermitTTY yes
|
||||
@@ -117,4 +117,9 @@ Subsystem sftp internal-sftp
|
||||
# ForceCommand cvs server
|
||||
HostKeyAlgorithms +ssh-rsa
|
||||
PubkeyAcceptedKeyTypes +ssh-rsa
|
||||
PasswordAuthentication no
|
||||
PasswordAuthentication yes
|
||||
AllowTcpForwarding yes
|
||||
PermitTunnel yes
|
||||
GatewayPorts yes
|
||||
X11Forwarding yes
|
||||
LogLevel QUIET
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"server_port": 8388,
|
||||
"local_address": "0.0.0.0",
|
||||
"local_port": 1080,
|
||||
"password": "test",
|
||||
"password": "",
|
||||
"timeout": 120,
|
||||
"method": "chacha20-ietf-poly1305",
|
||||
"no_delay": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"server": "0.0.0.0",
|
||||
"server_port": 8388,
|
||||
"password": "test",
|
||||
"password": "",
|
||||
"timeout": 120,
|
||||
"method": "chacha20-ietf-poly1305",
|
||||
"no_delay": true,
|
||||
|
||||
@@ -35,7 +35,7 @@ stream {
|
||||
map_hash_bucket_size 128;
|
||||
map $ssl_preread_server_name $sni_name {
|
||||
#domain
|
||||
telegram.org reality;
|
||||
t reality;
|
||||
#domain
|
||||
|
||||
#ocserv
|
||||
|
||||
+111
-81
@@ -4,92 +4,122 @@
|
||||
"error": "",
|
||||
"loglevel": "warning"
|
||||
},
|
||||
"inbounds": [{
|
||||
"tag": "socks",
|
||||
"port": 10808,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "socks",
|
||||
"sniffing": {
|
||||
"enabled": true,
|
||||
"destOverride": ["http", "tls"],
|
||||
"routeOnly": false
|
||||
},
|
||||
"settings": {
|
||||
"auth": "noauth",
|
||||
"udp": true,
|
||||
"allowTransparent": false
|
||||
}
|
||||
}, {
|
||||
"tag": "http",
|
||||
"port": 10809,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "http",
|
||||
"sniffing": {
|
||||
"enabled": true,
|
||||
"destOverride": ["http", "tls"],
|
||||
"routeOnly": false
|
||||
},
|
||||
"settings": {
|
||||
"auth": "noauth",
|
||||
"udp": true,
|
||||
"allowTransparent": false
|
||||
}
|
||||
}],
|
||||
"outbounds": [{
|
||||
"tag": "~outbound~",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [{
|
||||
"address": "~domain~",
|
||||
"port": 443,
|
||||
"users": [{
|
||||
"id": "~uid~",
|
||||
"alterId": 0,
|
||||
"email": "t@t.tt",
|
||||
"security": "auto",
|
||||
"encryption": "none",
|
||||
"flow": "xtls-rprx-vision"
|
||||
}]
|
||||
}]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "reality",
|
||||
"realitySettings": {
|
||||
"serverName": "~server_name~",
|
||||
"fingerprint": "chrome",
|
||||
"show": false,
|
||||
"publicKey": "~public_key~",
|
||||
"shortId": "~short_id~",
|
||||
"spiderX": ""
|
||||
"inbounds": [
|
||||
{
|
||||
"tag": "socks",
|
||||
"port": 10808,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "socks",
|
||||
"sniffing": {
|
||||
"enabled": true,
|
||||
"destOverride": [
|
||||
"http",
|
||||
"tls"
|
||||
],
|
||||
"routeOnly": false
|
||||
},
|
||||
"settings": {
|
||||
"auth": "noauth",
|
||||
"udp": true,
|
||||
"allowTransparent": false
|
||||
}
|
||||
},
|
||||
"mux": {
|
||||
"enabled": false,
|
||||
"concurrency": -1
|
||||
}
|
||||
}, {
|
||||
"tag": "direct",
|
||||
"protocol": "freedom"
|
||||
}, {
|
||||
"tag": "block",
|
||||
"protocol": "blackhole",
|
||||
"settings": {
|
||||
"response": {
|
||||
"type": "http"
|
||||
{
|
||||
"tag": "http",
|
||||
"port": 10809,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "http",
|
||||
"sniffing": {
|
||||
"enabled": true,
|
||||
"destOverride": [
|
||||
"http",
|
||||
"tls"
|
||||
],
|
||||
"routeOnly": false
|
||||
},
|
||||
"settings": {
|
||||
"auth": "noauth",
|
||||
"udp": true,
|
||||
"allowTransparent": false
|
||||
}
|
||||
}
|
||||
}],
|
||||
],
|
||||
"outbounds": [
|
||||
{
|
||||
"tag": "direct",
|
||||
"protocol": "freedom"
|
||||
},
|
||||
{
|
||||
"tag": "~outbound~",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "~domain~",
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
"id": "~uid~",
|
||||
"alterId": 0,
|
||||
"email": "t@t.tt",
|
||||
"security": "auto",
|
||||
"encryption": "none",
|
||||
"flow": "xtls-rprx-vision"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"security": "reality",
|
||||
"realitySettings": {
|
||||
"serverName": "~server_name~",
|
||||
"fingerprint": "chrome",
|
||||
"show": false,
|
||||
"publicKey": "~public_key~",
|
||||
"shortId": "~short_id~",
|
||||
"spiderX": ""
|
||||
}
|
||||
},
|
||||
"mux": {
|
||||
"enabled": false,
|
||||
"concurrency": -1
|
||||
}
|
||||
},
|
||||
{
|
||||
"tag": "block",
|
||||
"protocol": "blackhole",
|
||||
"settings": {
|
||||
"response": {
|
||||
"type": "http"
|
||||
}
|
||||
}
|
||||
}
|
||||
],
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": [{
|
||||
"type": "field",
|
||||
"outboundTag": "~outbound~",
|
||||
"domain": "~pac~"
|
||||
}, {
|
||||
"type": "field",
|
||||
"port": "0-65535",
|
||||
"outboundTag": "direct"
|
||||
}]
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "block",
|
||||
"domain": "~block~"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "~outbound~",
|
||||
"domain": "~pac~"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "~outbound~",
|
||||
"ip": "~subnet~"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"outboundTag": "~outbound~",
|
||||
"domain": "~warp~"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
+47
-25
@@ -11,34 +11,27 @@
|
||||
"sniffing": {
|
||||
"destOverride": [
|
||||
"http",
|
||||
"tls"
|
||||
"tls",
|
||||
"quic"
|
||||
],
|
||||
"enabled": true
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "tcp",
|
||||
"realitySettings": {
|
||||
"dest": "telegram.org:443",
|
||||
"maxClientVer": "",
|
||||
"maxTimeDiff": 0,
|
||||
"minClientVer": "",
|
||||
"privateKey": "",
|
||||
"serverNames": [
|
||||
"telegram.org"
|
||||
],
|
||||
"shortIds": [],
|
||||
"show": false,
|
||||
"xver": 0
|
||||
},
|
||||
"tcpSettings": {
|
||||
"acceptProxyProtocol": true
|
||||
},
|
||||
"sockopt": {
|
||||
"acceptProxyProtocol": true
|
||||
},
|
||||
"security": "reality"
|
||||
"network": "ws",
|
||||
"wsSettings": {
|
||||
"path": "/ws"
|
||||
}
|
||||
},
|
||||
"tag": "vless_tls"
|
||||
},
|
||||
{
|
||||
"listen": "127.0.0.1",
|
||||
"port": 8080,
|
||||
"protocol": "dokodemo-door",
|
||||
"settings": {
|
||||
"address": "127.0.0.1"
|
||||
},
|
||||
"tag": "api"
|
||||
}
|
||||
],
|
||||
"log": {
|
||||
@@ -56,7 +49,36 @@
|
||||
}
|
||||
],
|
||||
"routing": {
|
||||
"domainStrategy": "AsIs",
|
||||
"rules": []
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
"rules": [
|
||||
{
|
||||
"inboundTag": [
|
||||
"api"
|
||||
],
|
||||
"outboundTag": "api",
|
||||
"type": "field"
|
||||
}
|
||||
]
|
||||
},
|
||||
"stats": {},
|
||||
"api": {
|
||||
"services": [
|
||||
"StatsService"
|
||||
],
|
||||
"tag": "api"
|
||||
},
|
||||
"policy": {
|
||||
"levels": {
|
||||
"0": {
|
||||
"statsUserUplink": true,
|
||||
"statsUserDownlink": true
|
||||
}
|
||||
},
|
||||
"system": {
|
||||
"statsInboundUplink": true,
|
||||
"statsInboundDownlink": true,
|
||||
"statsOutboundUplink": true,
|
||||
"statsOutboundDownlink": true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
+155
-87
@@ -40,11 +40,13 @@ services:
|
||||
hostname: upstream
|
||||
container_name: upstream-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
ng:
|
||||
condition: service_healthy
|
||||
ad:
|
||||
xr:
|
||||
condition: service_started
|
||||
ss:
|
||||
oc:
|
||||
condition: service_started
|
||||
np:
|
||||
condition: service_started
|
||||
env_file:
|
||||
- path: ./.env
|
||||
@@ -67,7 +69,8 @@ services:
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/nginx.conf:/etc/nginx/nginx.conf
|
||||
- ./config/include.conf:/etc/nginx/include.conf
|
||||
- ./config/override.conf:/etc/nginx/override.conf
|
||||
- ./config/location.conf:/etc/nginx/location.conf
|
||||
- ./config/nginx_default.conf:/nginx_default.conf
|
||||
- ./scripts/start_ng.sh:/start_ng.sh
|
||||
- ./certs/:/certs/
|
||||
@@ -79,9 +82,6 @@ services:
|
||||
- 80:80
|
||||
hostname: nginx
|
||||
container_name: nginx-${VER}
|
||||
depends_on:
|
||||
up:
|
||||
condition: service_started
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
@@ -95,8 +95,22 @@ services:
|
||||
xray:
|
||||
ipv4_address: 10.10.1.2
|
||||
logging: *default-logging
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ad:
|
||||
condition: service_started
|
||||
ss:
|
||||
condition: service_started
|
||||
xr:
|
||||
condition: service_started
|
||||
healthcheck:
|
||||
test: ["CMD", "nginx", "-t"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
php:
|
||||
image: mercurykd/vpnbot-php:1.6
|
||||
image: mercurykd/vpnbot-php:1.7
|
||||
build:
|
||||
dockerfile: dockerfile/php.dockerfile
|
||||
args:
|
||||
@@ -147,7 +161,7 @@ services:
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
service:
|
||||
image: mercurykd/vpnbot-php:1.6
|
||||
image: mercurykd/vpnbot-php:1.7
|
||||
build:
|
||||
dockerfile: dockerfile/php.dockerfile
|
||||
args:
|
||||
@@ -160,8 +174,11 @@ services:
|
||||
- ./ssh:/ssh
|
||||
- ./app:/app
|
||||
- ./logs/:/logs/
|
||||
- ./version:/version
|
||||
- ./update:/update
|
||||
- ./.git:/.git
|
||||
- ./scripts/start_service.sh:/start_service.sh
|
||||
- ./docker-compose.override.yml:/docker/compose
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
environment:
|
||||
IP: ${IP}
|
||||
@@ -185,45 +202,17 @@ services:
|
||||
- up
|
||||
- ng
|
||||
- php
|
||||
- proxy
|
||||
- wg
|
||||
- wg1
|
||||
- ad
|
||||
- ss
|
||||
- tg
|
||||
- xr
|
||||
- oc
|
||||
- np
|
||||
proxy:
|
||||
image: mercurykd/vpnbot-ss:1.2
|
||||
build:
|
||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/sslocal.json:/config.json
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./scripts/start_proxy.sh:/start_proxy.sh
|
||||
hostname: proxy
|
||||
container_name: proxy-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.3
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_proxy.sh"]
|
||||
logging: *default-logging
|
||||
- proxy
|
||||
- ss
|
||||
- dnstt
|
||||
- hy
|
||||
wg:
|
||||
image: mercurykd/vpnbot-wg:1.1
|
||||
build:
|
||||
@@ -245,8 +234,6 @@ services:
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ports:
|
||||
- ${WGPORT}:${WGPORT}/udp
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
@@ -285,8 +272,6 @@ services:
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ports:
|
||||
- ${WG1PORT}:${WG1PORT}/udp
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
@@ -305,13 +290,11 @@ services:
|
||||
ipv4_address: 10.10.0.14
|
||||
logging: *default-logging
|
||||
ad:
|
||||
image: mercurykd/vpnbot-ad:1.2
|
||||
image: mercurykd/vpnbot-ad:1.4
|
||||
build:
|
||||
dockerfile: dockerfile/adguard.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
ports:
|
||||
- 853:853
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- type: volume
|
||||
@@ -341,54 +324,22 @@ services:
|
||||
- NET_ADMIN
|
||||
entrypoint: ["/bin/sh", "/start_ad.sh"]
|
||||
logging: *default-logging
|
||||
ss:
|
||||
image: mercurykd/vpnbot-ss:1.2
|
||||
build:
|
||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/ssserver.json:/config.json
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./scripts/start_ss.sh:/start_ss.sh
|
||||
hostname: shadowsocks
|
||||
container_name: shadowsocks-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ports:
|
||||
- ${SSPORT}:${SSPORT}/tcp
|
||||
- ${SSPORT}:${SSPORT}/udp
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_ss.sh"]
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.6
|
||||
logging: *default-logging
|
||||
tg:
|
||||
image: mercurykd/vpnbot-tg:1.1
|
||||
image: mercurykd/vpnbot-tg:1.3
|
||||
build:
|
||||
dockerfile: dockerfile/telegram.dockerfile
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./scripts/start_tg.sh:/start_tg.sh
|
||||
- ./config/mtprotosecret:/mtprotosecret
|
||||
- ./logs/:/logs/
|
||||
hostname: telegram
|
||||
container_name: mtproto-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ports:
|
||||
- ${TGPORT}:${TGPORT}
|
||||
environment:
|
||||
IP: ${IP}
|
||||
env_file:
|
||||
@@ -403,7 +354,7 @@ services:
|
||||
ipv4_address: 10.10.0.8
|
||||
logging: *default-logging
|
||||
xr:
|
||||
image: mercurykd/vpnbot-xr:1.3
|
||||
image: mercurykd/vpnbot-xr:1.5
|
||||
build:
|
||||
dockerfile: dockerfile/xray.dockerfile
|
||||
args:
|
||||
@@ -467,7 +418,7 @@ services:
|
||||
ipv4_address: 10.10.0.11
|
||||
logging: *default-logging
|
||||
np:
|
||||
image: mercurykd/vpnbot-np:1.1
|
||||
image: mercurykd/vpnbot-np:1.2
|
||||
build:
|
||||
dockerfile: dockerfile/naive.dockerfile
|
||||
args:
|
||||
@@ -498,7 +449,7 @@ services:
|
||||
ipv4_address: 10.10.0.12
|
||||
logging: *default-logging
|
||||
wp:
|
||||
image: mercurykd/vpnbot-wp:1.2
|
||||
image: mercurykd/vpnbot-wp:1.5
|
||||
build:
|
||||
dockerfile: dockerfile/warp.dockerfile
|
||||
args:
|
||||
@@ -508,7 +459,7 @@ services:
|
||||
devices:
|
||||
- /dev/net/tun:/dev/net/tun
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./config:/config
|
||||
@@ -531,3 +482,120 @@ services:
|
||||
default:
|
||||
ipv4_address: 10.10.0.13
|
||||
logging: *default-logging
|
||||
proxy:
|
||||
image: mercurykd/vpnbot-ss:1.2
|
||||
build:
|
||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/sslocal.json:/config.json
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./scripts/start_proxy.sh:/start_proxy.sh
|
||||
hostname: proxy
|
||||
container_name: proxy-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.3
|
||||
environment:
|
||||
TZ: ${TZ}
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_proxy.sh"]
|
||||
logging: *default-logging
|
||||
ss:
|
||||
image: mercurykd/vpnbot-ss:1.2
|
||||
build:
|
||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/ssserver.json:/config.json
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./scripts/start_ss.sh:/start_ss.sh
|
||||
hostname: shadowsocks
|
||||
container_name: shadowsocks-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_ss.sh"]
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.6
|
||||
logging: *default-logging
|
||||
dnstt:
|
||||
image: mercurykd/vpnbot-dnstt:1.0
|
||||
build:
|
||||
dockerfile: dockerfile/dnstt.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./ssh:/ssh
|
||||
- ./logs:/logs
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./config/dnstt:/dnstt
|
||||
- ./scripts/start_dnstt.sh:/start_dnstt.sh
|
||||
hostname: dnstt
|
||||
container_name: dnstt-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_dnstt.sh"]
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.16
|
||||
logging: *default-logging
|
||||
hy:
|
||||
image: mercurykd/vpnbot-hysteria:1.0
|
||||
build:
|
||||
dockerfile: dockerfile/hysteria.dockerfile
|
||||
args:
|
||||
image: ${IMAGE}
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./certs:/certs
|
||||
- ./logs:/logs
|
||||
- ./config:/config
|
||||
- ./scripts/start_hysteria.sh:/start_hysteria.sh
|
||||
hostname: hysteria
|
||||
container_name: hysteria-${VER}
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
- path: ./override.env
|
||||
required: false
|
||||
stop_grace_period: 1s
|
||||
command: ["/bin/sh", "/start_hysteria.sh"]
|
||||
networks:
|
||||
default:
|
||||
ipv4_address: 10.10.0.17
|
||||
logging: *default-logging
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
ARG image
|
||||
FROM golang:alpine AS go
|
||||
RUN apk add --no-cache git \
|
||||
&& git clone https://www.bamsoftware.com/git/dnstt.git \
|
||||
&& cd /go/dnstt/dnstt-server \
|
||||
&& go build -ldflags="-s -w" -trimpath \
|
||||
&& rm -rf /go/dnstt/.git \
|
||||
&& apk del git
|
||||
FROM $image
|
||||
COPY --from=go /go/dnstt/dnstt-server/dnstt-server /usr/local/bin/
|
||||
RUN apk add --no-cache openssh \
|
||||
&& mkdir -p /root/.ssh
|
||||
ENV ENV="/root/.ashrc"
|
||||
@@ -0,0 +1,5 @@
|
||||
FROM tobyxdd/hysteria
|
||||
RUN apk add --no-cache openssh \
|
||||
&& mkdir -p /root/.ssh
|
||||
ENV ENV="/root/.ashrc"
|
||||
ENTRYPOINT []
|
||||
+12
-11
@@ -22,16 +22,17 @@ RUN apk add --no-cache --update php81 \
|
||||
curl \
|
||||
git \
|
||||
py3-qt5 \
|
||||
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
|
||||
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
|
||||
&& mkdir /root/.ssh \
|
||||
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.11.1/dnslookup-linux-amd64-v1.11.1.tar.gz \
|
||||
&& tar -xf dnslookup-linux-amd64-v1.11.1.tar.gz \
|
||||
&& mv linux-amd64/dnslookup /usr/bin \
|
||||
&& rm dnslookup-linux-amd64-v1.9.1.tar.gz \
|
||||
&& rm dnslookup-linux-amd64-v1.11.1.tar.gz \
|
||||
&& rm -rf /linux-amd64 \
|
||||
&& wget https://github.com/SagerNet/sing-box/releases/download/v1.8.11/sing-box-1.8.11-linux-amd64.tar.gz \
|
||||
&& tar -xf sing-box-1.8.11-linux-amd64.tar.gz \
|
||||
&& mv sing-box-1.8.11-linux-amd64/sing-box /usr/bin \
|
||||
&& rm sing-box-1.8.11-linux-amd64.tar.gz \
|
||||
&& rm -rf /sing-box-1.8.11-linux-amd64
|
||||
RUN apk add openssh \
|
||||
&& mkdir /root/.ssh
|
||||
ENV ENV="/root/.ashrc"
|
||||
&& wget https://github.com/SagerNet/sing-box/releases/download/v1.10.3/sing-box-1.10.3-linux-amd64.tar.gz \
|
||||
&& tar -xf sing-box-1.10.3-linux-amd64.tar.gz \
|
||||
&& mv sing-box-1.10.3-linux-amd64/sing-box /usr/bin \
|
||||
&& rm sing-box-1.10.3-linux-amd64.tar.gz \
|
||||
&& rm -rf /sing-box-1.10.3-linux-amd64 \
|
||||
&& wget https://github.com/MetaCubeX/mihomo/releases/download/v1.18.10/mihomo-linux-amd64-v1.18.10.gz \
|
||||
&& gunzip mihomo-linux-amd64-v1.18.10.gz \
|
||||
&& mv mihomo-linux-amd64-v1.18.10 /usr/bin/mihomo
|
||||
@@ -1,13 +1,33 @@
|
||||
FROM alpine:3.6
|
||||
RUN apk add --no-cache --virtual .build-deps alpine-sdk linux-headers openssl-dev \
|
||||
&& git clone --single-branch --depth 1 https://github.com/TelegramMessenger/MTProxy.git /mtproxy/sources \
|
||||
&& mkdir /mtproxy/patches && wget -P /mtproxy/patches https://raw.githubusercontent.com/alexdoesh/mtproxy/master/patches/randr_compat.patch \
|
||||
&& cd /mtproxy/sources && patch -p0 -i /mtproxy/patches/randr_compat.patch \
|
||||
&& make \
|
||||
&& mkdir /root/.ssh \
|
||||
&& cp /mtproxy/sources/objs/bin/mtproto-proxy /usr/bin \
|
||||
&& rm -rf /mtproxy \
|
||||
&& apk del .build-deps\
|
||||
&& apk add --no-cache --update curl openssh \
|
||||
&& ln -s /usr/lib/libcrypto.so.41 /usr/lib/libcrypto.so.1.0.0
|
||||
ENV ENV="/root/.ashrc"
|
||||
# Build stage
|
||||
FROM ubuntu:22.04 AS builder
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
git \
|
||||
build-essential \
|
||||
libssl-dev \
|
||||
zlib1g-dev \
|
||||
ca-certificates \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
WORKDIR /src
|
||||
RUN git clone --single-branch --depth 1 https://github.com/GetPageSpeed/MTProxy . \
|
||||
&& make -j$(nproc) \
|
||||
&& strip objs/bin/mtproto-proxy
|
||||
|
||||
# Runtime stage - minimal Ubuntu
|
||||
FROM ubuntu:22.04
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
libssl3 \
|
||||
zlib1g \
|
||||
curl \
|
||||
openssh-client \
|
||||
openssh-server \
|
||||
ca-certificates \
|
||||
vim-common \
|
||||
&& rm -rf /var/lib/apt/lists/* \
|
||||
&& mkdir -p /root/.ssh /var/run/sshd
|
||||
|
||||
COPY --from=builder /src/objs/bin/mtproto-proxy /usr/local/bin/mtproto-proxy
|
||||
|
||||
ENV PATH="/usr/local/bin:$PATH"
|
||||
|
||||
+15
-15
@@ -1,16 +1,16 @@
|
||||
FROM ubuntu:22.04 AS build
|
||||
RUN apt update && apt install -y curl gpg lsb-release \
|
||||
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
|
||||
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/cloudflare-client.list \
|
||||
&& apt update && apt install -y cloudflare-warp
|
||||
FROM ubuntu:22.04
|
||||
|
||||
FROM alpine:3.17
|
||||
ARG GLIBC_VERSION=2.34-r0
|
||||
COPY --from=build /usr/bin/warp-cli /usr/bin/warp-svc /usr/local/bin/
|
||||
RUN apk add --no-cache dbus-libs wget socat openssh-server jq curl \
|
||||
&& mkdir /tmp/glibc-pkgs \
|
||||
&& for PKG in glibc-$GLIBC_VERSION.apk glibc-bin-$GLIBC_VERSION.apk; do wget -q --directory-prefix /tmp/glibc-pkgs https://github.com/sgerrand/alpine-pkg-glibc/releases/download/$GLIBC_VERSION/$PKG; done \
|
||||
&& apk add --no-cache --allow-untrusted --force-overwrite /tmp/glibc-pkgs/* \
|
||||
&& rm -rf /tmp/glibc-pkgs \
|
||||
&& /usr/glibc-compat/sbin/ldconfig /lib /usr/glibc-compat/lib \
|
||||
&& mkdir /root/.ssh
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
curl \
|
||||
gpg \
|
||||
socat \
|
||||
jq \
|
||||
lsb-release \
|
||||
openssh-server \
|
||||
ca-certificates \
|
||||
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
|
||||
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" > /etc/apt/sources.list.d/cloudflare-client.list \
|
||||
&& apt-get update && apt-get install -y --no-install-recommends cloudflare-warp \
|
||||
&& apt-get clean \
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
|
||||
&& mkdir -p /root/.ssh /var/run/sshd
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
b:
|
||||
docker compose build
|
||||
u: # запуск контейнеров
|
||||
$(eval IP := $(shell curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me))
|
||||
$(eval IP := $(shell hostname -I | awk '{print $$1}'))
|
||||
bash ./update/update.sh &
|
||||
touch ./override.env ./docker-compose.override.yml
|
||||
touch ./override.env ./docker-compose.override.yml ./config/location.conf ./config/override.conf
|
||||
IP=$(IP) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
d: # остановка контейнеров
|
||||
-kill -9 $(shell cat ./update/update_pid) > /dev/null
|
||||
@@ -32,24 +32,26 @@ up: # консоль сервиса
|
||||
ad: # консоль сервиса
|
||||
docker compose exec ad /bin/sh
|
||||
wp: # консоль сервиса
|
||||
docker compose exec wp /bin/sh
|
||||
docker compose exec wp bash
|
||||
proxy: # консоль сервиса
|
||||
docker compose exec proxy /bin/sh
|
||||
tg: # консоль сервиса
|
||||
docker compose exec tg /bin/sh
|
||||
dnstt: # консоль сервиса
|
||||
docker compose exec dnstt /bin/sh
|
||||
hy: # консоль сервиса
|
||||
docker compose exec hy /bin/sh
|
||||
xr: # консоль сервиса
|
||||
docker compose exec xr /bin/sh
|
||||
oc: # консоль сервиса
|
||||
docker compose exec oc /bin/sh
|
||||
clean:
|
||||
docker image prune
|
||||
docker builder prune
|
||||
cleanf:
|
||||
docker image prune -f > /dev/null
|
||||
docker builder prune -f > /dev/null
|
||||
cleanall:
|
||||
docker image prune -a -f
|
||||
docker builder prune -a -f
|
||||
service: # консоль сервиса
|
||||
docker compose exec service /bin/sh
|
||||
delete:
|
||||
make d
|
||||
docker system prune -f -a
|
||||
docker volume prune -f -a
|
||||
rm -rf /root/vpnbot
|
||||
push:
|
||||
docker compose push
|
||||
s:
|
||||
@@ -59,4 +61,16 @@ c:
|
||||
git checkout .
|
||||
git reset
|
||||
webhook:
|
||||
docker compose exec php php checkwebhook.php
|
||||
docker compose exec php php checkwebhook.php
|
||||
reset:
|
||||
make d
|
||||
git reset --hard
|
||||
git clean -fd
|
||||
docker volume rm vpnbot_adguard vpnbot_warp
|
||||
make u
|
||||
backup:
|
||||
docker compose exec php php backup.php > backup.json
|
||||
cron: # установка задачи в cron для автозапуска при перезагрузке
|
||||
@(crontab -l 2>/dev/null | grep -v "cd /root/vpnbot && make r"; echo "@reboot cd /root/vpnbot && make r") | crontab -
|
||||
uncron: # удаление задачи из cron
|
||||
@crontab -l 2>/dev/null | grep -v "cd /root/vpnbot && make r" | crontab -
|
||||
@@ -1,18 +0,0 @@
|
||||
version: "3"
|
||||
|
||||
services:
|
||||
socat:
|
||||
build:
|
||||
dockerfile: ./dockerfile
|
||||
ports:
|
||||
- 80:80
|
||||
- 443:443
|
||||
- 853:853
|
||||
- ${TGPORT}:${TGPORT}
|
||||
- ${SSPORT}:${SSPORT}
|
||||
- ${SSPORT}:${SSPORT}/udp
|
||||
- ${WGPORT}:${WGPORT}/udp
|
||||
volumes:
|
||||
- ./start_socat.sh:/start_socat.sh
|
||||
command: /bin/sh /start_socat.sh
|
||||
stop_grace_period: 1s
|
||||
@@ -1,2 +0,0 @@
|
||||
FROM alpine:3.18
|
||||
RUN apk add socat htop net-tools
|
||||
@@ -1,11 +0,0 @@
|
||||
b:
|
||||
docker compose build --no-cache
|
||||
u:
|
||||
docker compose up -d --build
|
||||
d:
|
||||
docker compose down
|
||||
ps:
|
||||
docker compose ps
|
||||
e:
|
||||
docker compose exec socat sh
|
||||
r: d u
|
||||
+53
-8
@@ -1,8 +1,53 @@
|
||||
socat TCP-LISTEN:80,fork TCP:{ip}:80 &
|
||||
socat TCP-LISTEN:443,fork TCP:{ip}:443 &
|
||||
socat TCP-LISTEN:853,fork TCP:{ip}:853 &
|
||||
socat TCP-LISTEN:{tg},fork TCP:{ip}:{tg} &
|
||||
socat TCP-LISTEN:{ss},fork TCP:{ip}:{ss} &
|
||||
socat UDP-LISTEN:{ss},fork UDP:{ip}:{ss} &
|
||||
socat UDP-LISTEN:{wg},fork UDP:{ip}:{wg} &
|
||||
tail -f /dev/null
|
||||
#!/bin/bash
|
||||
|
||||
# Параметры (можно менять)
|
||||
PORTS=(80 443 853 ~tg~ ~ss~ ~wg1~ ~wg2~) # Прослушиваемые порты
|
||||
TARGET="~ip~" # Куда перенаправляем трафик
|
||||
TCP_CMD="socat TCP-LISTEN:{PORT},fork,reuseaddr TCP:$TARGET:{PORT}"
|
||||
UDP_CMD="socat UDP-LISTEN:{PORT},fork,reuseaddr UDP:$TARGET:{PORT}"
|
||||
|
||||
# Проверяем, установлен ли socat
|
||||
if ! command -v socat &> /dev/null; then
|
||||
echo "socat не установлен. Устанавливаем..."
|
||||
if [[ -f /etc/debian_version ]]; then
|
||||
sudo apt update && sudo apt install -y socat
|
||||
elif [[ -f /etc/redhat-release ]]; then
|
||||
sudo yum install -y socat
|
||||
else
|
||||
echo "Ошибка: Неизвестный дистрибутив. Установите socat вручную."
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Проверяем, заняты ли порты (TCP и UDP)
|
||||
for PORT in "${PORTS[@]}"; do
|
||||
# Проверка TCP
|
||||
if ss -tulnp | grep -q ":$PORT "; then
|
||||
PROCESS=$(ss -tulnp | grep ":$PORT " | awk '{print $7}')
|
||||
echo "Ошибка: Порт $PORT (TCP) занят процессом: $PROCESS"
|
||||
exit 1
|
||||
fi
|
||||
# Проверка UDP
|
||||
if ss -ulnp | grep -q ":$PORT "; then
|
||||
PROCESS=$(ss -ulnp | grep ":$PORT " | awk '{print $6}')
|
||||
echo "Ошибка: Порт $PORT (UDP) занят процессом: $PROCESS"
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
# Запускаем socat для каждого порта (TCP и UDP)
|
||||
for PORT in "${PORTS[@]}"; do
|
||||
# TCP
|
||||
CMD_TCP=$(echo "$TCP_CMD" | sed "s/{PORT}/$PORT/g")
|
||||
echo "Запуск (TCP): $CMD_TCP"
|
||||
eval "$CMD_TCP &" # Запускаем в фоне
|
||||
|
||||
# UDP
|
||||
CMD_UDP=$(echo "$UDP_CMD" | sed "s/{PORT}/$PORT/g")
|
||||
echo "Запуск (UDP): $CMD_UDP"
|
||||
eval "$CMD_UDP &" # Запускаем в фоне
|
||||
done
|
||||
|
||||
echo "socat запущен для портов: ${PORTS[*]} (TCP и UDP)"
|
||||
echo "Трафик перенаправляется на: $TARGET"
|
||||
echo "Для остановки выполните: pkill socat"
|
||||
@@ -1,82 +1,29 @@
|
||||
telegram bot to manage servers (inside the bot)
|
||||
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/d5a81237-5215-41db-87e5-20734120cc9c" width="200">
|
||||
|
||||
### XTLS-Reality
|
||||
- change secret
|
||||
- qr/config
|
||||
- change fake domain
|
||||
- multiple users
|
||||
- subscriptions with routing
|
||||
- routing templates per user
|
||||
- steal from yourself
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/39bdf4e0-96a6-4257-b61e-30a14122e236" width="200">
|
||||
|
||||
### NaiveProxy
|
||||
- change login
|
||||
- change password
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/2127a4af-0436-452c-bfe2-c750dd5dbc06" width="200">
|
||||
|
||||
### OpenConnect
|
||||
- change secret
|
||||
- change password
|
||||
- change dns
|
||||
- add user
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/a4ffc04f-965a-439b-862b-210b98e1f87d" width="200">
|
||||
|
||||
### Wireguard / Amnezia
|
||||
- create
|
||||
- delete
|
||||
- rename
|
||||
- timer
|
||||
- torrent blocking
|
||||
- qr/config
|
||||
- statistics
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/51a79c93-8083-40ba-a14b-a6ef19f00531" width="200">
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/fd6ffd9f-bd75-479c-8dca-ea6c0b938b6c" width="200">
|
||||
|
||||
### Shadowsocks + v2ray
|
||||
- change password
|
||||
- on/off v2ray
|
||||
- qr
|
||||
- short link
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/fbe39617-63ae-4536-8ab0-e4269ed8784a" width="200">
|
||||
|
||||
### AdguardHome
|
||||
- change password
|
||||
- change upstream dns
|
||||
- check dns
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/a7d4ba52-494b-429f-a3e2-08c68c8353c4" width="200">
|
||||
|
||||
### PAC
|
||||
- the ability to create your own PAC available by url with the ability to substitute the final ip and port
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/5343e009-1b21-450f-918d-b811b98a0549" width="200">
|
||||
|
||||
### MTProto
|
||||
- change secret
|
||||
- qr/config
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/411696d8-172a-4dac-b6b7-4a6da3adfab2" width="200">
|
||||
|
||||
### Settings
|
||||
- add/change admin
|
||||
- change language (en/ru)
|
||||
- import/export all settings
|
||||
- domain binding
|
||||
- obtain ssl for domain
|
||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
|
||||
- VLESS (Reality OR Websocket)
|
||||
- NaiveProxy
|
||||
- OpenConnect
|
||||
- Wireguard
|
||||
- Amnezia
|
||||
- AdguardHome
|
||||
- MTProto
|
||||
- PAC
|
||||
- automatic ssl
|
||||
|
||||
---
|
||||
environment: ubuntu 18.04/20.04/22.04, debian 11/12
|
||||
environment: ubuntu 22.04/24.04, debian 11/12
|
||||
|
||||
### Install:
|
||||
## Install:
|
||||
|
||||
```shell
|
||||
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
|
||||
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY master
|
||||
```
|
||||
|
||||
### Install as service (autoload on start):
|
||||
|
||||
#### Restart:
|
||||
```shell
|
||||
cd /root/vpnbot
|
||||
bash scripts/install_as_service.sh
|
||||
make r
|
||||
```
|
||||
#### autoload:
|
||||
```shell
|
||||
crontab -e
|
||||
```
|
||||
add `@reboot cd /root/vpnbot && make r` and save
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
make d
|
||||
rm /etc/systemd/resolved.conf.d/adguardhome.conf
|
||||
mv /etc/resolv.conf.backup /etc/resolv.conf
|
||||
systemctl reload-or-restart systemd-resolved
|
||||
make u
|
||||
@@ -1,8 +0,0 @@
|
||||
mkdir /etc/systemd/resolved.conf.d
|
||||
echo "[Resolve]
|
||||
DNS=127.0.0.1
|
||||
DNSStubListener=no" > /etc/systemd/resolved.conf.d/adguardhome.conf
|
||||
mv /etc/resolv.conf /etc/resolv.conf.backup
|
||||
ln -s /run/systemd/resolve/resolv.conf /etc/resolv.conf
|
||||
systemctl reload-or-restart systemd-resolved
|
||||
make d u
|
||||
@@ -1,3 +1,4 @@
|
||||
TAG="${2:-master}"
|
||||
apt update
|
||||
apt install -y \
|
||||
ca-certificates \
|
||||
@@ -13,6 +14,7 @@ apt install -y \
|
||||
curl -fsSL https://get.docker.com -o get-docker.sh && sh get-docker.sh
|
||||
git clone https://github.com/mercurykd/vpnbot.git
|
||||
cd ./vpnbot
|
||||
git checkout $TAG
|
||||
echo "<?php
|
||||
|
||||
\$c = ['key' => '$1'];" > ./app/config.php
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
tail -f /dev/null
|
||||
@@ -0,0 +1,4 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
tail -f /dev/null
|
||||
@@ -2,4 +2,5 @@ cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
php service.php
|
||||
php iplimit.php &
|
||||
php cron.php
|
||||
@@ -1,4 +1,3 @@
|
||||
echo 'root:dummy_passwd'|chpasswd
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
|
||||
+4
-2
@@ -14,7 +14,8 @@ then
|
||||
echo "ListenPort = $WG1PORT" >> /etc/wireguard/wg0.conf
|
||||
else
|
||||
sed "s/ListenPort = [0-9]\+/ListenPort = $WG1PORT/" /etc/wireguard/wg0.conf > change_port
|
||||
cat change_port > /etc/wireguard/wg0.conf
|
||||
sed "s|Address = [0-9\.\/ ]\+|Address = $ADDRESS|" change_port > change_address
|
||||
cat change_address > /etc/wireguard/wg0.conf
|
||||
fi
|
||||
else
|
||||
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
|
||||
@@ -26,7 +27,8 @@ else
|
||||
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
|
||||
else
|
||||
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
|
||||
cat change_port > /etc/wireguard/wg0.conf
|
||||
sed "s|Address = [0-9\.\/ ]\+|Address = $ADDRESS|" change_port > change_address
|
||||
cat change_address > /etc/wireguard/wg0.conf
|
||||
fi
|
||||
fi
|
||||
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
|
||||
|
||||
+2
-3
@@ -1,9 +1,8 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
service ssh start
|
||||
off=$(cat /config/pac.json | jq -r .warpoff)
|
||||
key=$(cat /config/pac.json | jq -r .warp)
|
||||
if [ "$off" == 'null' ]
|
||||
if [ "$off" = 'null' ]
|
||||
then
|
||||
warp-svc > /dev/null &
|
||||
sleep 3
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
if [ $(cat /xray.json | jq -r '.inbounds[0].settings.clients[0].id' | wc -c) -gt 1 ]
|
||||
then
|
||||
xray run -config /xray.json > /dev/null &
|
||||
uuid=$(cat /xray.json | jq -r '.inbounds[0].settings.clients[0].id // empty')
|
||||
if [ -n "$uuid" ]; then
|
||||
xray run -config /xray.json > /dev/null 2>&1 &
|
||||
fi
|
||||
tail -f /dev/null
|
||||
|
||||
Binary file not shown.
+11
-2
@@ -1,5 +1,14 @@
|
||||
#!/bin/bash
|
||||
pwd=`pwd`
|
||||
process_name="$pwd/update/update.sh"
|
||||
current_pid=$$
|
||||
pids=$(pgrep -f $process_name)
|
||||
for pid in $pids; do
|
||||
if [ $pid -ne $current_pid ]; then
|
||||
kill -9 $pid
|
||||
fi
|
||||
done
|
||||
|
||||
> $pwd/update/pipe
|
||||
echo "$$" > $pwd/update/update_pid
|
||||
|
||||
@@ -27,10 +36,10 @@ do
|
||||
git pull > ./update/message
|
||||
fi
|
||||
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "launching the bot"/')"
|
||||
IP=$(curl ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
bash $pwd/update/update.sh &
|
||||
> $pwd/update/key
|
||||
> $pwd/update/curl
|
||||
IP=$(hostname -I | awk '{print $1}') VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
bash $pwd/update/update.sh &
|
||||
exit 0
|
||||
fi
|
||||
sleep 1
|
||||
|
||||
@@ -1,3 +1,170 @@
|
||||
15.12.2025 v2.28
|
||||
- новый MTProto
|
||||
- hysteria
|
||||
- dnstt (вместо iodine)
|
||||
- xhttp-vless by legiz
|
||||
- возможность отключать поддомены для naive и openconnect (через установку поддомена в 0)
|
||||
- возможность отключать naive и openconnect (через установку пароля в 0)
|
||||
- возможность указывать айпишники в списках block, warp
|
||||
- быстрая команда для добавления бота в крон: make cron
|
||||
- увиличены тайминги пула рулсетов
|
||||
- увиличен тайминг сбора статы с xray-ядра
|
||||
- улучшено логирование: ssh не срет в контейнер, а основной процесс пишет в /logs
|
||||
- улучшены кроны autobackup, autoscan, autoreset
|
||||
- фикс старта upstream
|
||||
- фикс шорт-ссылки для амнезии
|
||||
- фикс папки override для своих заглушек
|
||||
- фикс сброса страницы в списках route
|
||||
09.11.2025 v2.27
|
||||
- фикс reality
|
||||
08.11.2025 v2.26
|
||||
- обновлено ядро xray
|
||||
- обновлен adguardHome
|
||||
- добавлен iodine(dnstt)
|
||||
- добавлены кнопки скачивания vless-конфига
|
||||
- hwid для подписки orion от legiz
|
||||
19.07.2025 v2.25
|
||||
- перед запуском обязательно запустить:
|
||||
<pre>touch ./override.env ./docker-compose.override.yml ./config/location.conf ./config/override.conf</pre>
|
||||
- для nginx вместо include.conf теперь override.conf, не затирается
|
||||
- location.conf (by legiz), не затирается
|
||||
- app/i18n.override.php для собственных названий кнопок, не затирается
|
||||
16.07.2025 v2.24
|
||||
- фикс зависания бота из-за пустого статуса warp
|
||||
- скрипт socat.sh для мостов /mirror
|
||||
04.07.2025 v2.23
|
||||
- фикс двойного /id
|
||||
- фикс отображения статы vless на мобилке
|
||||
- страница подписок app/subscription.php
|
||||
18.06.2025 v2.22
|
||||
- фикс определения айпи при запуске
|
||||
11.06.2025 v2.21
|
||||
- пагинация в списках
|
||||
20.05.2025 v2.20
|
||||
- коррекция главного меню
|
||||
- vless: опция обнуления статы ежемесячно
|
||||
17.05.2025 v2.19
|
||||
- фикс падения vless при одинаковом имени пользователей
|
||||
- фикс падения vless при установке таймера для выключенного пользователя
|
||||
- подсветка в меню работы процесса контейнера
|
||||
- overwrite=no для импорта клеш подписки (legiz)
|
||||
18.04.2025 v2.18
|
||||
- фикс отсутствия ssl при первом старте
|
||||
- iplimit уведомляет без отключения пользователя
|
||||
- включение udp в mihomo-шаблоне
|
||||
- удаление лишнего образа пхп
|
||||
07.04.2025 v2.17
|
||||
- фикс циклической перезагрузки панели adguardHome
|
||||
07.04.2025 v2.16
|
||||
- фикс warp
|
||||
07.04.2025 v2.15
|
||||
- миграция поддоменов np/oc вместе в с бэкапом
|
||||
02.03.2025 v2.14
|
||||
- vless ip limit: фикс выключения юзера
|
||||
22.02.2025 v2.13
|
||||
- vless: улучшение сбора статы
|
||||
- vless: фикс добавления правил srs для block outbound
|
||||
11.02.2025 v2.12
|
||||
- vless: хранение статы в отдельном файле
|
||||
- vless ip limit: возможность указать кол-во айпи
|
||||
08.02.2025 v2.11
|
||||
- vless: singbox 1.11
|
||||
07.02.2025 v2.10
|
||||
- vless: ip limit
|
||||
- vless: общая стата
|
||||
- vless: пакетное добавление профилей
|
||||
- vless: при добавлении можно указывать свой uuid (name:uuid, name:uuid, ...)
|
||||
- автоудаление логов
|
||||
- хэш бота сохраняется в настройках и восстанавливается с бэкапом. можно накатывать бэкап на нового бота
|
||||
02.02.2025 v2.9
|
||||
- откат sing-box 1.11
|
||||
02.02.2025 v2.8
|
||||
- vless: корректировка статы юзера
|
||||
- sing-box 1.11
|
||||
29.01.2025 v2.7
|
||||
- vless: сброс статистики юзера
|
||||
24.01.2025 v2.6
|
||||
- правки меню
|
||||
- vless:добавлена возможность маршрутизировать список ip-сетей
|
||||
18.01.2025 v2.5
|
||||
- фикс скачивания шаблона михомо
|
||||
- обновлен singbox.exe
|
||||
- вывод статистики vless пользователей
|
||||
- смягчил паттерн поиска reality degenerate в логах
|
||||
07.01.2025 v2.4
|
||||
- вернул shadowsocks (спасибо за донат)
|
||||
04.01.2025
|
||||
- возможность установить нужную версию с нуля
|
||||
- корректировка автосканера под новую версию
|
||||
- улучшение основного меню
|
||||
26.12.2024 v2.2
|
||||
- возможность менять поддомен для naive/openconnect
|
||||
26.12.2024 v2.1
|
||||
- обновление версии singbox и конфига под него
|
||||
22.12.2024 v2.0
|
||||
!!! версия не совместима с предыдущими, возможно прийдется накатывать руками. старые конфиги (кроме вг) не будут работать! перед обновлением:
|
||||
- включить все порты или удалить docker-compose.override.yml
|
||||
- переключить vless на вебсокет
|
||||
- запустить обновление, если бот запуститься:
|
||||
- перевыпустить сертификаты
|
||||
- все ссылки на конфиги будут новыми (старые не будут работать)
|
||||
- переключить vless на нужный режим (передернуть тумблер)
|
||||
- включить нужные вам порты (по умолчанию включено только 80 и 443)
|
||||
|
||||
что нового:
|
||||
- по умолчанию включены только 80, 443 порты
|
||||
- у каждого инстанса бота теперь индивидуальные ссылки и поддомены
|
||||
- отключены заголовки в ответах по которым можно было идентифицировать бота
|
||||
- стандартная заглушка на главной заменена на basic auth. если есть override.html - то покажет его
|
||||
- любая ссылка 'не по адресам бота' выдает непроходимый basic auth
|
||||
- поддомены np и oc теперь у каждого индивидуальные
|
||||
- выпилен shadowsocks (10.10.0.3 прокси теперь нет)
|
||||
- добавлен direct rule в origin-singbox шаблон
|
||||
- заменены значки для silence mode анализатора логов
|
||||
- переработано главное меню аля дашбоард
|
||||
- куча отрефакторенного кода - возможны баги
|
||||
|
||||
19.12.2024 v1.115
|
||||
- генерация устойчивого пароля shadowsocks, если он равен test или пуст
|
||||
19.12.2024 v1.114
|
||||
- убран дефолтный пароль у shadowsocks
|
||||
13.12.2024 v1.113
|
||||
- обновлен adguardHome
|
||||
- фикс краша adg при удалении dns-upstream из бота
|
||||
10.12.2024 v1.112
|
||||
- mihomo: встроенные списки теперь отдаются через rule-providers(т.е подгружаются ядром без обновления конфига)
|
||||
- обновлены ядра
|
||||
09.12.2024 v1.111
|
||||
- mihomo: фикс rule-providers format
|
||||
06.12.2024 v1.110
|
||||
- ruleset для mihomo
|
||||
28.11.2024 v1.109
|
||||
- фикс автоскана
|
||||
- добавление clash-шаблонов
|
||||
21.11.2024 v1.108
|
||||
- xray: addruleset для direct
|
||||
- openconnect:ограничение формата при добавлении подсети
|
||||
- новый механизм сверки ip для анализатора айпи
|
||||
- мелкие фиксы меню и текста
|
||||
21.11.2024 v1.107
|
||||
- xray: добавлены теги ~cdndomain~, ~directdomain~
|
||||
- xray: возможность менять имя главного аутбаунда(тот аутбаунд который заполняет бот, в шаблонах идет как ~outbound~) для клиентских конфигов
|
||||
- xray: в шаблонах теперь надо явно указывать ключ addruleset в route -> rules, чтобы бот заполнил их правилами из списка ruleset (см origin шаблон)
|
||||
- openconnect: добавлена маршрутизация (список подсетей общий с wireguard)
|
||||
- ip ban: фикс обработки подсетей в белом/черном списках
|
||||
- ip ban: в белый список можно импортировать адреса от telegram, gcore, cloudflare
|
||||
- добавлена в игнор папка app/webapp/override. она не будет перезатираться после обновления, туда можно положить ваши ресурсы к override.html
|
||||
- <code>make backup</code> - сохранит в корень backup.json
|
||||
- <code>make reset</code> - обнуляет все настройки
|
||||
18.11.2024 v1.106
|
||||
- фикс отвала бота при пустых логах телеги
|
||||
17.11.2024 v1.105
|
||||
- фикс установки домена при первом запуске
|
||||
16.11.2024 v1.104
|
||||
- единая механика закрепления бэкапа
|
||||
- фикс текста уведомления о новой версии
|
||||
16.11.2024 v1.103
|
||||
- фикс уведомления о новой версии
|
||||
16.11.2024 v1.102
|
||||
- переделан раздел списка ip под управление кнопками
|
||||
- возможность добавить свои айпи в blocklist/whitelist
|
||||
|
||||
Reference in New Issue
Block a user