Compare commits
29 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9932ee1e00 | |||
| 1a6e9f43e8 | |||
| 76373ffcf2 | |||
| 43c59a9ed6 | |||
| 8b3c6ca547 | |||
| 63654e7ad7 | |||
| dcb4f72f07 | |||
| 90afbbedb0 | |||
| 1964ed0079 | |||
| 2525181655 | |||
| ef690349fd | |||
| 2c1db5f233 | |||
| 554d7f3a25 | |||
| f2a1ec1b71 | |||
| 04f1bf564c | |||
| 1116f8ec75 | |||
| f8e5b54a98 | |||
| 3929032e7a | |||
| 057917a24a | |||
| 941fc05e21 | |||
| 797088a328 | |||
| 45614eaf3b | |||
| 47113b4940 | |||
| 3febfe1d3d | |||
| 90084c37ff | |||
| b49f088256 | |||
| b3366edb6e | |||
| 1edc9e8608 | |||
| 8a3d9c1007 |
+307
-358
File diff suppressed because it is too large
Load Diff
+3
-3
@@ -2,8 +2,8 @@
|
|||||||
|
|
||||||
$i = [
|
$i = [
|
||||||
'warp' => [
|
'warp' => [
|
||||||
'en' => 'warp',
|
'en' => 'Warp',
|
||||||
'ru' => 'warp',
|
'ru' => 'Warp',
|
||||||
],
|
],
|
||||||
'wg_title' => [
|
'wg_title' => [
|
||||||
'en' => 'Wireguard',
|
'en' => 'Wireguard',
|
||||||
@@ -22,7 +22,7 @@ $i = [
|
|||||||
'ru' => 'AdGuard',
|
'ru' => 'AdGuard',
|
||||||
],
|
],
|
||||||
'config' => [
|
'config' => [
|
||||||
'en' => 'config',
|
'en' => 'Settings',
|
||||||
'ru' => 'настройки',
|
'ru' => 'настройки',
|
||||||
],
|
],
|
||||||
'pac' => [
|
'pac' => [
|
||||||
|
|||||||
+131
-137
@@ -1,129 +1,18 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
require __DIR__ . '/timezone.php';
|
require __DIR__ . '/timezone.php';
|
||||||
|
|
||||||
// bot
|
|
||||||
require __DIR__ . '/config.php';
|
require __DIR__ . '/config.php';
|
||||||
if ('POST' == $_SERVER['REQUEST_METHOD'] && $_GET['k'] == $c['key']) {
|
if ($c['debug']) {
|
||||||
if ($c['debug']) {
|
require __DIR__ . '/debug.php';
|
||||||
require __DIR__ . '/debug.php';
|
|
||||||
}
|
|
||||||
require __DIR__ . '/calc.php';
|
|
||||||
require __DIR__ . '/bot.php';
|
|
||||||
require __DIR__ . '/i18n.php';
|
|
||||||
if (file_exists(__DIR__ . '/override.php')) {
|
|
||||||
include __DIR__ . '/override.php';
|
|
||||||
}
|
|
||||||
$bot = new Bot($c['key'], $i);
|
|
||||||
$bot->input();
|
|
||||||
exit;
|
|
||||||
}
|
}
|
||||||
|
require __DIR__ . '/calc.php';
|
||||||
// pac
|
require __DIR__ . '/bot.php';
|
||||||
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
|
require __DIR__ . '/i18n.php';
|
||||||
$_GET = array_merge($_GET, $t);
|
if (file_exists(__DIR__ . '/override.php')) {
|
||||||
}
|
include __DIR__ . '/override.php';
|
||||||
$type = $_GET['t'] ?? 'pac';
|
|
||||||
$address = $_GET['a'] ?: '127.0.0.1';
|
|
||||||
$port = $_GET['p'] ?: '1080';
|
|
||||||
$hash = $_GET['h'];
|
|
||||||
if ($hash == substr(md5($c['key']), 0, 8)) {
|
|
||||||
require __DIR__ . '/bot.php';
|
|
||||||
require __DIR__ . '/i18n.php';
|
|
||||||
$bot = new Bot($c['key'], $i);
|
|
||||||
switch ($type) {
|
|
||||||
case 'mirror':
|
|
||||||
$bot->getMirror();
|
|
||||||
break;
|
|
||||||
case 's':
|
|
||||||
case 'si':
|
|
||||||
case 'cl':
|
|
||||||
$bot->subscription();
|
|
||||||
exit;
|
|
||||||
|
|
||||||
case 'te':
|
|
||||||
if (!empty($_GET['te'])) {
|
|
||||||
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
|
|
||||||
} else {
|
|
||||||
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
|
|
||||||
}
|
|
||||||
if ($t) {
|
|
||||||
header('Content-Type: text/html');
|
|
||||||
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
|
||||||
$name = $_GET['te'] ?: 'origin';
|
|
||||||
$type = $_GET['ty'];
|
|
||||||
echo <<<HTML
|
|
||||||
<!DOCTYPE HTML>
|
|
||||||
<html lang="en" style="height:100%">
|
|
||||||
<head>
|
|
||||||
<!-- when using the mode "code", it's important to specify charset utf-8 -->
|
|
||||||
<meta charset="utf-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
|
|
||||||
<link href="jsoneditor.min.css" rel="stylesheet" type="text/css">
|
|
||||||
<script src="jsoneditor.min.js"></script>
|
|
||||||
<script src="jquery-3.7.1.min.js"></script>
|
|
||||||
<script src="https://telegram.org/js/telegram-web-app.js"></script>
|
|
||||||
</head>
|
|
||||||
<body style="height:100%">
|
|
||||||
<div id="jsoneditor" style="height:100%"></div>
|
|
||||||
|
|
||||||
<script>
|
|
||||||
jQuery(function($) {
|
|
||||||
var tg = window.Telegram.WebApp;
|
|
||||||
// create the editor
|
|
||||||
const container = document.getElementById("jsoneditor")
|
|
||||||
const options = {}
|
|
||||||
const editor = new JSONEditor(container, options)
|
|
||||||
editor.set({$t})
|
|
||||||
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
|
|
||||||
var self = this;
|
|
||||||
$.ajax({
|
|
||||||
url: '/webapp/save?' + tg.initData,
|
|
||||||
method: 'POST',
|
|
||||||
data: {
|
|
||||||
name: '$name',
|
|
||||||
type: '$type',
|
|
||||||
json: editor.getText()
|
|
||||||
},
|
|
||||||
dataType: 'json'
|
|
||||||
}).done(function (r) {
|
|
||||||
if (r.status == true) {
|
|
||||||
tg.MainButton.setText('{$bot->i18n('success')}')
|
|
||||||
setTimeout(() => {
|
|
||||||
tg.close();
|
|
||||||
}, 500);
|
|
||||||
} else {
|
|
||||||
tg.MainButton.setText(r.message);
|
|
||||||
}
|
|
||||||
}).fail(function (r) {
|
|
||||||
tg.MainButton.setText('{$bot->i18n('error')}')
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
</script>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
HTML;
|
|
||||||
exit;
|
|
||||||
}
|
|
||||||
|
|
||||||
default:
|
|
||||||
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
|
|
||||||
$pac = file_get_contents($file);
|
|
||||||
header('Content-Type: text/plain');
|
|
||||||
echo str_replace([
|
|
||||||
'~address~',
|
|
||||||
'~port~',
|
|
||||||
], [
|
|
||||||
$address,
|
|
||||||
$port,
|
|
||||||
], $pac);
|
|
||||||
exit;
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
$bot = new Bot($c['key'], $i);
|
||||||
|
$hash = $bot->getHashBot();
|
||||||
if (!empty($_GET['hash'])) {
|
if (!empty($_GET['hash'])) {
|
||||||
$t = $_GET;
|
$t = $_GET;
|
||||||
unset($t['hash']);
|
unset($t['hash']);
|
||||||
@@ -131,22 +20,127 @@ if (!empty($_GET['hash'])) {
|
|||||||
foreach ($t as $k => $v) {
|
foreach ($t as $k => $v) {
|
||||||
$s[] = "$k=$v";
|
$s[] = "$k=$v";
|
||||||
}
|
}
|
||||||
$s = implode("\n", $s);
|
$s = implode("\n", $s);
|
||||||
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
|
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
|
||||||
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
|
$webapp = hash_hmac('sha256', $s, $sk) == $_GET['hash'];
|
||||||
require __DIR__ . '/bot.php';
|
|
||||||
require __DIR__ . '/i18n.php';
|
|
||||||
$bot = new Bot($c['key'], $i);
|
|
||||||
if (!empty($_POST['json'])) {
|
|
||||||
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
|
|
||||||
die();
|
|
||||||
} else {
|
|
||||||
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
|
|
||||||
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
|
|
||||||
}
|
|
||||||
die('ok');
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
header('500', true, 500);
|
switch (true) {
|
||||||
exit;
|
// tlgrm
|
||||||
|
case 'POST' == $_SERVER['REQUEST_METHOD'] && preg_match('~^/tlgrm~', $_SERVER['REQUEST_URI']) && $_GET['k'] == $c['key']:
|
||||||
|
$bot->input();
|
||||||
|
break;
|
||||||
|
|
||||||
|
// save template
|
||||||
|
case preg_match('~^' . preg_quote("/webapp$hash/save") . '~', $_SERVER['REQUEST_URI']) && $webapp && !empty($_POST['json']):
|
||||||
|
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
|
||||||
|
break;
|
||||||
|
|
||||||
|
// adguard cookie
|
||||||
|
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
|
||||||
|
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
|
||||||
|
echo "/adguard$hash/";
|
||||||
|
break;
|
||||||
|
|
||||||
|
// subs & pac
|
||||||
|
case preg_match('~^' . preg_quote("/pac$hash") . '~', $_SERVER['REQUEST_URI']):
|
||||||
|
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
|
||||||
|
$_GET = array_merge($_GET, $t);
|
||||||
|
}
|
||||||
|
$type = $_GET['t'] ?? 'pac';
|
||||||
|
$address = $_GET['a'] ?: '127.0.0.1';
|
||||||
|
$port = $_GET['p'] ?: '1080';
|
||||||
|
switch ($type) {
|
||||||
|
case 's':
|
||||||
|
case 'si':
|
||||||
|
case 'cl':
|
||||||
|
$bot->subscription();
|
||||||
|
exit;
|
||||||
|
|
||||||
|
case 'te':
|
||||||
|
if (!empty($_GET['te'])) {
|
||||||
|
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
|
||||||
|
} else {
|
||||||
|
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
|
||||||
|
}
|
||||||
|
if ($t) {
|
||||||
|
header('Content-Type: text/html');
|
||||||
|
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
||||||
|
$name = $_GET['te'] ?: 'origin';
|
||||||
|
$type = $_GET['ty'];
|
||||||
|
echo <<<HTML
|
||||||
|
<!DOCTYPE HTML>
|
||||||
|
<html lang="en" style="height:100%">
|
||||||
|
<head>
|
||||||
|
<!-- when using the mode "code", it's important to specify charset utf-8 -->
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
|
||||||
|
<link href="/webapp$hash/jsoneditor.min.css" rel="stylesheet" type="text/css">
|
||||||
|
<script src="/webapp$hash/jsoneditor.min.js"></script>
|
||||||
|
<script src="/webapp$hash/jquery-3.7.1.min.js"></script>
|
||||||
|
<script src="https://telegram.org/js/telegram-web-app.js"></script>
|
||||||
|
</head>
|
||||||
|
<body style="height:100%">
|
||||||
|
<div id="jsoneditor" style="height:100%"></div>
|
||||||
|
|
||||||
|
<script>
|
||||||
|
jQuery(function($) {
|
||||||
|
var tg = window.Telegram.WebApp;
|
||||||
|
// create the editor
|
||||||
|
const container = document.getElementById("jsoneditor")
|
||||||
|
const options = {}
|
||||||
|
const editor = new JSONEditor(container, options)
|
||||||
|
editor.set({$t})
|
||||||
|
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
|
||||||
|
var self = this;
|
||||||
|
$.ajax({
|
||||||
|
url: '/webapp$hash/save?' + tg.initData,
|
||||||
|
method: 'POST',
|
||||||
|
data: {
|
||||||
|
name: '$name',
|
||||||
|
type: '$type',
|
||||||
|
json: editor.getText()
|
||||||
|
},
|
||||||
|
dataType: 'json'
|
||||||
|
}).done(function (r) {
|
||||||
|
if (r.status == true) {
|
||||||
|
tg.MainButton.setText('{$bot->i18n('success')}')
|
||||||
|
setTimeout(() => {
|
||||||
|
tg.close();
|
||||||
|
}, 500);
|
||||||
|
} else {
|
||||||
|
tg.MainButton.setText(r.message);
|
||||||
|
}
|
||||||
|
}).fail(function (r) {
|
||||||
|
tg.MainButton.setText('{$bot->i18n('error')}')
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
</script>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
|
HTML;
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
|
||||||
|
default:
|
||||||
|
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
|
||||||
|
$pac = file_get_contents($file);
|
||||||
|
header('Content-Type: text/plain');
|
||||||
|
echo str_replace([
|
||||||
|
'~address~',
|
||||||
|
'~port~',
|
||||||
|
], [
|
||||||
|
$address,
|
||||||
|
$port,
|
||||||
|
], $pac);
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
|
||||||
|
default:
|
||||||
|
header('500', true, 500);
|
||||||
|
}
|
||||||
|
|||||||
@@ -20,5 +20,6 @@ if (!empty($bot->selfupdate)) {
|
|||||||
$bot->dontshowcron = 1;
|
$bot->dontshowcron = 1;
|
||||||
$bot->sslip();
|
$bot->sslip();
|
||||||
$bot->adguardSync();
|
$bot->adguardSync();
|
||||||
|
$bot->cloakNginx();
|
||||||
$bot->syncDeny();
|
$bot->syncDeny();
|
||||||
$bot->cleanDocker();
|
$bot->cleanDocker();
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
$.ajax({
|
$.ajax({
|
||||||
'url': 'check?' + tg.initData,
|
'url': 'check?' + tg.initData,
|
||||||
}).done(function (r) {
|
}).done(function (r) {
|
||||||
location.replace('/adguard/');
|
location.replace(r);
|
||||||
}).fail(function (r) {
|
}).fail(function (r) {
|
||||||
location.replace('/');
|
location.replace('/');
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,117 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>Login</title>
|
|
||||||
<style>
|
|
||||||
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
|
|
||||||
|
|
||||||
body {
|
|
||||||
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
|
|
||||||
background-size: cover;
|
|
||||||
font-family: "Roboto";
|
|
||||||
-webkit-font-smoothing: antialiased;
|
|
||||||
-moz-osx-font-smoothing: grayscale;
|
|
||||||
|
|
||||||
&::before {
|
|
||||||
z-index: -1;
|
|
||||||
content: '';
|
|
||||||
position: fixed;
|
|
||||||
top: 0;
|
|
||||||
left: 0;
|
|
||||||
background: #44c4e7;
|
|
||||||
/* IE Fallback */
|
|
||||||
background: rgba(68, 196, 231, 0.8);
|
|
||||||
width: 100%;
|
|
||||||
height: 100%;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
.form {
|
|
||||||
position: absolute;
|
|
||||||
top: 50%;
|
|
||||||
left: 50%;
|
|
||||||
background: #fff;
|
|
||||||
width: 285px;
|
|
||||||
margin: -140px 0 0 -182px;
|
|
||||||
padding: 40px;
|
|
||||||
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
margin: 0 0 20px;
|
|
||||||
line-height: 1;
|
|
||||||
color: #44c4e7;
|
|
||||||
font-size: 18px;
|
|
||||||
font-weight: 400;
|
|
||||||
}
|
|
||||||
|
|
||||||
input {
|
|
||||||
outline: none;
|
|
||||||
display: block;
|
|
||||||
width: 100%;
|
|
||||||
margin: 0 0 20px;
|
|
||||||
padding: 10px 15px;
|
|
||||||
border: 1px solid #ccc;
|
|
||||||
color: #ccc;
|
|
||||||
font-family: "Roboto";
|
|
||||||
box-sizing: border-box;
|
|
||||||
font-size: 14px;
|
|
||||||
font-wieght: 400;
|
|
||||||
-webkit-font-smoothing: antialiased;
|
|
||||||
-moz-osx-font-smoothing: grayscale;
|
|
||||||
transition: 0.2s linear;
|
|
||||||
|
|
||||||
&input:focus {
|
|
||||||
color: #333;
|
|
||||||
border: 1px solid #44c4e7;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
button {
|
|
||||||
cursor: pointer;
|
|
||||||
background: #44c4e7;
|
|
||||||
width: 100%;
|
|
||||||
padding: 10px 15px;
|
|
||||||
border: 0;
|
|
||||||
color: #fff;
|
|
||||||
font-family: "Roboto";
|
|
||||||
font-size: 14px;
|
|
||||||
font-weight: 400;
|
|
||||||
|
|
||||||
&:hover {
|
|
||||||
background: #369cb8;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
.error,
|
|
||||||
.valid {
|
|
||||||
display: none;
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
<script src="jquery-3.7.1.min.js"></script>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
<section class="form animated flipInX">
|
|
||||||
<h2>Login To Your Account</h2>
|
|
||||||
<p class="valid">Valid. Please wait a moment.</p>
|
|
||||||
<p class="error">Error. Please enter correct Username & password.</p>
|
|
||||||
<form class="loginbox" autocomplete="off">
|
|
||||||
<input placeholder="Username" type="text" id="username"></input>
|
|
||||||
<input placeholder="Password" type="password" id="password"></input>
|
|
||||||
<button id="submit">Login</button>
|
|
||||||
</form>
|
|
||||||
</section>
|
|
||||||
<script>
|
|
||||||
$(document).ready(function() {
|
|
||||||
$('#submit').click(function () {
|
|
||||||
event.preventDefault(); // prevent PageReLoad
|
|
||||||
$('.error').css('display', 'block'); // show error msg
|
|
||||||
});
|
|
||||||
});
|
|
||||||
</script>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
+170
-176
@@ -1,197 +1,191 @@
|
|||||||
user nginx;
|
user nginx;
|
||||||
worker_processes auto;
|
worker_processes auto;
|
||||||
|
|
||||||
error_log /logs/nginx_error;
|
error_log /logs/nginx_error;
|
||||||
pid /var/run/nginx.pid;
|
pid /var/run/nginx.pid;
|
||||||
|
|
||||||
events {
|
events {
|
||||||
worker_connections 1024;
|
worker_connections 1024;
|
||||||
}
|
}
|
||||||
|
|
||||||
http {
|
http {
|
||||||
server_names_hash_bucket_size 64;
|
server_names_hash_bucket_size 64;
|
||||||
include include.conf;
|
server_tokens off;
|
||||||
include /etc/nginx/mime.types;
|
include include.conf;
|
||||||
default_type application/octet-stream;
|
include /etc/nginx/mime.types;
|
||||||
|
default_type application/octet-stream;
|
||||||
|
|
||||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||||
|
|
||||||
real_ip_header proxy_protocol;
|
real_ip_header proxy_protocol;
|
||||||
real_ip_recursive on;
|
real_ip_recursive on;
|
||||||
set_real_ip_from 10.10.0.10;
|
set_real_ip_from 10.10.0.10;
|
||||||
|
|
||||||
server {
|
server {
|
||||||
listen 10.10.0.2:80 default_server;
|
listen 80 default_server;
|
||||||
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
|
|
||||||
ssl_certificate /certs/self_public;
|
|
||||||
ssl_certificate_key /certs/self_private;
|
|
||||||
|
|
||||||
access_log /logs/nginx_default_access;
|
location / {
|
||||||
|
return 301 https://$host$request_uri;
|
||||||
location / {
|
}
|
||||||
root /app;
|
location ~\.well-known {
|
||||||
index override.html login.html;
|
access_log /logs/nginx_certbot_access;
|
||||||
try_files $uri $uri/ =404;
|
root /certs/;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
location /adguard/ {
|
|
||||||
access_log /logs/nginx_adguard_access;
|
server {
|
||||||
proxy_pass http://ad:80/;
|
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
|
||||||
proxy_redirect / /adguard/;
|
listen 10.10.1.2:443 ssl http2 default_server;
|
||||||
proxy_cookie_path / /adguard/;
|
ssl_certificate /certs/self_public;
|
||||||
|
ssl_certificate_key /certs/self_private;
|
||||||
|
|
||||||
|
access_log /logs/nginx_ip_access;
|
||||||
|
|
||||||
|
location = / {
|
||||||
|
root /app;
|
||||||
|
try_files $uri /override.html @auth;
|
||||||
|
}
|
||||||
|
|
||||||
|
location / {
|
||||||
|
root /app;
|
||||||
|
auth_basic "Restricted Content";
|
||||||
|
auth_basic_user_file /app/.htpasswd;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
location @auth {
|
||||||
|
root /app;
|
||||||
|
auth_basic "Restricted Content";
|
||||||
|
auth_basic_user_file /app/.htpasswd;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /tlgrm {
|
||||||
|
access_log /logs/nginx_tlgrm_access;
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location @php {
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /adguard/ {
|
||||||
|
}
|
||||||
|
|
||||||
|
location /webapp {
|
||||||
|
access_log /logs/nginx_webapp_access;
|
||||||
|
alias /app;
|
||||||
|
index index.html;
|
||||||
|
try_files $uri $uri/ @php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /pac {
|
||||||
|
access_log /logs/nginx_pac_access;
|
||||||
|
proxy_set_header Host $http_host;
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /ws {
|
||||||
|
proxy_pass http://xr:443;
|
||||||
|
proxy_redirect off;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection "upgrade";
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_read_timeout 5d;
|
||||||
|
}
|
||||||
|
location /dns-query {
|
||||||
|
access_log /logs/nginx_doh_access;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Connection "";
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-Proto https;
|
||||||
|
proxy_set_header X-Forwarded-For $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-Host $remote_addr;
|
||||||
|
proxy_cache doh_cache;
|
||||||
|
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||||
|
proxy_pass https://ad/dns-query;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
location /webapp {
|
|
||||||
access_log /logs/nginx_webapp_access;
|
|
||||||
alias /app;
|
|
||||||
index index.html;
|
|
||||||
try_files $uri $uri/ /pac?$query_string;
|
|
||||||
}
|
|
||||||
location /pac {
|
|
||||||
access_log /logs/nginx_pac_access;
|
|
||||||
proxy_set_header Host $http_host;
|
|
||||||
proxy_pass http://php;
|
|
||||||
}
|
|
||||||
location /tlgrm {
|
|
||||||
access_log /logs/nginx_tlgrm_access;
|
|
||||||
proxy_pass http://php;
|
|
||||||
}
|
|
||||||
location /v2ray {
|
|
||||||
access_log /logs/nginx_v2ray_access;
|
|
||||||
proxy_redirect off;
|
|
||||||
proxy_buffering off;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_pass http://ss:8388/;
|
|
||||||
proxy_set_header Host $http_host;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection "upgrade";
|
|
||||||
}
|
|
||||||
location /ws {
|
|
||||||
proxy_pass http://xr:443;
|
|
||||||
proxy_redirect off;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection "upgrade";
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_read_timeout 5d;
|
|
||||||
}
|
|
||||||
#-ssl
|
|
||||||
# # The DoH server block
|
|
||||||
# location /dns-query {
|
|
||||||
# access_log /logs/nginx_doh_access;
|
|
||||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Connection "";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Proto https;
|
|
||||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
|
||||||
|
|
||||||
# # Enable Cache, and set the cache_key to include the request_body
|
#~
|
||||||
# proxy_cache doh_cache;
|
|
||||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
|
||||||
|
|
||||||
# # proxy pass to the dohloop upstream
|
#-domain
|
||||||
# proxy_pass https://ad/dns-query;
|
# server {
|
||||||
# }
|
# server_name domain;
|
||||||
#-ssl
|
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||||
location ~\.well-known {
|
# listen 10.10.1.2:443 ssl http2;
|
||||||
access_log /logs/nginx_certbot_access;
|
# ssl_certificate /certs/cert_public;
|
||||||
root /certs/;
|
# ssl_certificate_key /certs/cert_private;
|
||||||
try_files $uri =404;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#~
|
# access_log /logs/nginx_domain_access;
|
||||||
|
|
||||||
#-domain
|
# location = / {
|
||||||
# server {
|
# root /app;
|
||||||
# listen 10.10.0.2:80;
|
# try_files $uri /override.html @auth;
|
||||||
# server_name ;
|
# }
|
||||||
#-domain
|
|
||||||
#-ssl
|
|
||||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
|
||||||
# listen 10.10.1.2:443 ssl http2;
|
|
||||||
# ssl_certificate /certs/cert_public;
|
|
||||||
# ssl_certificate_key /certs/cert_private;
|
|
||||||
#-ssl
|
|
||||||
|
|
||||||
#-domain
|
# location / {
|
||||||
# access_log /logs/nginx_domain_access;
|
# root /app;
|
||||||
|
# auth_basic "Restricted Content";
|
||||||
|
# auth_basic_user_file /app/.htpasswd;
|
||||||
|
# try_files $uri =404;
|
||||||
|
# }
|
||||||
|
# location @auth {
|
||||||
|
# root /app;
|
||||||
|
# auth_basic "Restricted Content";
|
||||||
|
# auth_basic_user_file /app/.htpasswd;
|
||||||
|
# try_files $uri =404;
|
||||||
|
# }
|
||||||
|
|
||||||
# location / {
|
# location @php {
|
||||||
# root /app;
|
# proxy_pass http://php;
|
||||||
# index override.html login.html;
|
# }
|
||||||
# try_files $uri $uri/ =404;
|
|
||||||
# }
|
|
||||||
# location /adguard/ {
|
|
||||||
# access_log /logs/nginx_adguard_access;
|
|
||||||
# proxy_pass http://ad:80/;
|
|
||||||
# proxy_redirect / /adguard/;
|
|
||||||
# proxy_cookie_path / /adguard/;
|
|
||||||
# }
|
|
||||||
# location /webapp {
|
|
||||||
# access_log /logs/nginx_webapp_access;
|
|
||||||
# alias /app;
|
|
||||||
# index index.html;
|
|
||||||
# try_files $uri $uri/ /pac?$query_string;
|
|
||||||
# }
|
|
||||||
# location /pac {
|
|
||||||
# access_log /logs/nginx_pac_access;
|
|
||||||
# proxy_set_header Host $http_host;
|
|
||||||
# proxy_pass http://php;
|
|
||||||
# }
|
|
||||||
# location ~\.well-known {
|
|
||||||
# access_log /logs/nginx_certbot_access;
|
|
||||||
# root /certs/;
|
|
||||||
# try_files $uri =404;
|
|
||||||
# }
|
|
||||||
# location /v2ray {
|
|
||||||
# access_log /logs/nginx_v2ray_access;
|
|
||||||
# proxy_redirect off;
|
|
||||||
# proxy_buffering off;
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_pass http://ss:8388/;
|
|
||||||
# proxy_set_header Host $http_host;
|
|
||||||
# proxy_set_header Upgrade $http_upgrade;
|
|
||||||
# proxy_set_header Connection "upgrade";
|
|
||||||
# }
|
|
||||||
# location /ws {
|
|
||||||
# proxy_pass http://xr:443;
|
|
||||||
# proxy_redirect off;
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Upgrade $http_upgrade;
|
|
||||||
# proxy_set_header Connection "upgrade";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
# proxy_read_timeout 5d;
|
|
||||||
# }
|
|
||||||
#-domain
|
|
||||||
#-ssl
|
|
||||||
# # The DoH server block
|
|
||||||
# location /dns-query {
|
|
||||||
# access_log /logs/nginx_doh_access;
|
|
||||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Connection "";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Proto https;
|
|
||||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
|
||||||
|
|
||||||
# # Enable Cache, and set the cache_key to include the request_body
|
# location /adguard/ {
|
||||||
# proxy_cache doh_cache;
|
# }
|
||||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
|
||||||
|
|
||||||
# # proxy pass to the dohloop upstream
|
# location /webapp {
|
||||||
# proxy_pass https://ad/dns-query;
|
# access_log /logs/nginx_webapp_access;
|
||||||
# }
|
# alias /app;
|
||||||
#-ssl
|
# index index.html;
|
||||||
#-domain
|
# try_files $uri $uri/ @php;
|
||||||
# }
|
# }
|
||||||
#-domain
|
|
||||||
|
# location /pac {
|
||||||
|
# access_log /logs/nginx_pac_access;
|
||||||
|
# proxy_set_header Host $http_host;
|
||||||
|
# proxy_pass http://php;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location /ws {
|
||||||
|
# proxy_pass http://xr:443;
|
||||||
|
# proxy_redirect off;
|
||||||
|
# proxy_http_version 1.1;
|
||||||
|
# proxy_set_header Upgrade $http_upgrade;
|
||||||
|
# proxy_set_header Connection "upgrade";
|
||||||
|
# proxy_set_header Host $host;
|
||||||
|
# proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
# proxy_read_timeout 5d;
|
||||||
|
# }
|
||||||
|
# location /dns-query {
|
||||||
|
# access_log /logs/nginx_doh_access;
|
||||||
|
# proxy_http_version 1.1;
|
||||||
|
# proxy_set_header Connection "";
|
||||||
|
# proxy_set_header Host $host;
|
||||||
|
# proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-Proto https;
|
||||||
|
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||||
|
# proxy_cache doh_cache;
|
||||||
|
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||||
|
# proxy_pass https://ad/dns-query;
|
||||||
|
# }
|
||||||
|
# }
|
||||||
|
#-domain
|
||||||
}
|
}
|
||||||
|
|||||||
+170
-176
@@ -1,197 +1,191 @@
|
|||||||
user nginx;
|
user nginx;
|
||||||
worker_processes auto;
|
worker_processes auto;
|
||||||
|
|
||||||
error_log /logs/nginx_error;
|
error_log /logs/nginx_error;
|
||||||
pid /var/run/nginx.pid;
|
pid /var/run/nginx.pid;
|
||||||
|
|
||||||
events {
|
events {
|
||||||
worker_connections 1024;
|
worker_connections 1024;
|
||||||
}
|
}
|
||||||
|
|
||||||
http {
|
http {
|
||||||
server_names_hash_bucket_size 64;
|
server_names_hash_bucket_size 64;
|
||||||
include include.conf;
|
server_tokens off;
|
||||||
include /etc/nginx/mime.types;
|
include include.conf;
|
||||||
default_type application/octet-stream;
|
include /etc/nginx/mime.types;
|
||||||
|
default_type application/octet-stream;
|
||||||
|
|
||||||
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
# Proxy Cache storage - so we can cache the DoH response from the upstream
|
||||||
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
|
||||||
|
|
||||||
real_ip_header proxy_protocol;
|
real_ip_header proxy_protocol;
|
||||||
real_ip_recursive on;
|
real_ip_recursive on;
|
||||||
set_real_ip_from 10.10.0.10;
|
set_real_ip_from 10.10.0.10;
|
||||||
|
|
||||||
server {
|
server {
|
||||||
listen 10.10.0.2:80 default_server;
|
listen 80 default_server;
|
||||||
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
|
|
||||||
ssl_certificate /certs/self_public;
|
|
||||||
ssl_certificate_key /certs/self_private;
|
|
||||||
|
|
||||||
access_log /logs/nginx_default_access;
|
location / {
|
||||||
|
return 301 https://$host$request_uri;
|
||||||
location / {
|
}
|
||||||
root /app;
|
location ~\.well-known {
|
||||||
index override.html login.html;
|
access_log /logs/nginx_certbot_access;
|
||||||
try_files $uri $uri/ =404;
|
root /certs/;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
location /adguard/ {
|
|
||||||
access_log /logs/nginx_adguard_access;
|
server {
|
||||||
proxy_pass http://ad:80/;
|
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
|
||||||
proxy_redirect / /adguard/;
|
listen 10.10.1.2:443 ssl http2 default_server;
|
||||||
proxy_cookie_path / /adguard/;
|
ssl_certificate /certs/self_public;
|
||||||
|
ssl_certificate_key /certs/self_private;
|
||||||
|
|
||||||
|
access_log /logs/nginx_ip_access;
|
||||||
|
|
||||||
|
location = / {
|
||||||
|
root /app;
|
||||||
|
try_files $uri /override.html @auth;
|
||||||
|
}
|
||||||
|
|
||||||
|
location / {
|
||||||
|
root /app;
|
||||||
|
auth_basic "Restricted Content";
|
||||||
|
auth_basic_user_file /app/.htpasswd;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
location @auth {
|
||||||
|
root /app;
|
||||||
|
auth_basic "Restricted Content";
|
||||||
|
auth_basic_user_file /app/.htpasswd;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /tlgrm {
|
||||||
|
access_log /logs/nginx_tlgrm_access;
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location @php {
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /adguard/ {
|
||||||
|
}
|
||||||
|
|
||||||
|
location /webapp {
|
||||||
|
access_log /logs/nginx_webapp_access;
|
||||||
|
alias /app;
|
||||||
|
index index.html;
|
||||||
|
try_files $uri $uri/ @php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /pac {
|
||||||
|
access_log /logs/nginx_pac_access;
|
||||||
|
proxy_set_header Host $http_host;
|
||||||
|
proxy_pass http://php;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /ws {
|
||||||
|
proxy_pass http://xr:443;
|
||||||
|
proxy_redirect off;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection "upgrade";
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_read_timeout 5d;
|
||||||
|
}
|
||||||
|
location /dns-query {
|
||||||
|
access_log /logs/nginx_doh_access;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Connection "";
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-Proto https;
|
||||||
|
proxy_set_header X-Forwarded-For $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-Host $remote_addr;
|
||||||
|
proxy_cache doh_cache;
|
||||||
|
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||||
|
proxy_pass https://ad/dns-query;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
location /webapp {
|
|
||||||
access_log /logs/nginx_webapp_access;
|
|
||||||
alias /app;
|
|
||||||
index index.html;
|
|
||||||
try_files $uri $uri/ /pac?$query_string;
|
|
||||||
}
|
|
||||||
location /pac {
|
|
||||||
access_log /logs/nginx_pac_access;
|
|
||||||
proxy_set_header Host $http_host;
|
|
||||||
proxy_pass http://php;
|
|
||||||
}
|
|
||||||
location /tlgrm {
|
|
||||||
access_log /logs/nginx_tlgrm_access;
|
|
||||||
proxy_pass http://php;
|
|
||||||
}
|
|
||||||
location /v2ray {
|
|
||||||
access_log /logs/nginx_v2ray_access;
|
|
||||||
proxy_redirect off;
|
|
||||||
proxy_buffering off;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_pass http://ss:8388/;
|
|
||||||
proxy_set_header Host $http_host;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection "upgrade";
|
|
||||||
}
|
|
||||||
location /ws {
|
|
||||||
proxy_pass http://xr:443;
|
|
||||||
proxy_redirect off;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection "upgrade";
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_read_timeout 5d;
|
|
||||||
}
|
|
||||||
#-ssl
|
|
||||||
# # The DoH server block
|
|
||||||
# location /dns-query {
|
|
||||||
# access_log /logs/nginx_doh_access;
|
|
||||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Connection "";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Proto https;
|
|
||||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
|
||||||
|
|
||||||
# # Enable Cache, and set the cache_key to include the request_body
|
#~
|
||||||
# proxy_cache doh_cache;
|
|
||||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
|
||||||
|
|
||||||
# # proxy pass to the dohloop upstream
|
#-domain
|
||||||
# proxy_pass https://ad/dns-query;
|
# server {
|
||||||
# }
|
# server_name domain;
|
||||||
#-ssl
|
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
||||||
location ~\.well-known {
|
# listen 10.10.1.2:443 ssl http2;
|
||||||
access_log /logs/nginx_certbot_access;
|
# ssl_certificate /certs/cert_public;
|
||||||
root /certs/;
|
# ssl_certificate_key /certs/cert_private;
|
||||||
try_files $uri =404;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#~
|
# access_log /logs/nginx_domain_access;
|
||||||
|
|
||||||
#-domain
|
# location = / {
|
||||||
# server {
|
# root /app;
|
||||||
# listen 10.10.0.2:80;
|
# try_files $uri /override.html @auth;
|
||||||
# server_name ;
|
# }
|
||||||
#-domain
|
|
||||||
#-ssl
|
|
||||||
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
|
|
||||||
# listen 10.10.1.2:443 ssl http2;
|
|
||||||
# ssl_certificate /certs/cert_public;
|
|
||||||
# ssl_certificate_key /certs/cert_private;
|
|
||||||
#-ssl
|
|
||||||
|
|
||||||
#-domain
|
# location / {
|
||||||
# access_log /logs/nginx_domain_access;
|
# root /app;
|
||||||
|
# auth_basic "Restricted Content";
|
||||||
|
# auth_basic_user_file /app/.htpasswd;
|
||||||
|
# try_files $uri =404;
|
||||||
|
# }
|
||||||
|
# location @auth {
|
||||||
|
# root /app;
|
||||||
|
# auth_basic "Restricted Content";
|
||||||
|
# auth_basic_user_file /app/.htpasswd;
|
||||||
|
# try_files $uri =404;
|
||||||
|
# }
|
||||||
|
|
||||||
# location / {
|
# location @php {
|
||||||
# root /app;
|
# proxy_pass http://php;
|
||||||
# index override.html login.html;
|
# }
|
||||||
# try_files $uri $uri/ =404;
|
|
||||||
# }
|
|
||||||
# location /adguard/ {
|
|
||||||
# access_log /logs/nginx_adguard_access;
|
|
||||||
# proxy_pass http://ad:80/;
|
|
||||||
# proxy_redirect / /adguard/;
|
|
||||||
# proxy_cookie_path / /adguard/;
|
|
||||||
# }
|
|
||||||
# location /webapp {
|
|
||||||
# access_log /logs/nginx_webapp_access;
|
|
||||||
# alias /app;
|
|
||||||
# index index.html;
|
|
||||||
# try_files $uri $uri/ /pac?$query_string;
|
|
||||||
# }
|
|
||||||
# location /pac {
|
|
||||||
# access_log /logs/nginx_pac_access;
|
|
||||||
# proxy_set_header Host $http_host;
|
|
||||||
# proxy_pass http://php;
|
|
||||||
# }
|
|
||||||
# location ~\.well-known {
|
|
||||||
# access_log /logs/nginx_certbot_access;
|
|
||||||
# root /certs/;
|
|
||||||
# try_files $uri =404;
|
|
||||||
# }
|
|
||||||
# location /v2ray {
|
|
||||||
# access_log /logs/nginx_v2ray_access;
|
|
||||||
# proxy_redirect off;
|
|
||||||
# proxy_buffering off;
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_pass http://ss:8388/;
|
|
||||||
# proxy_set_header Host $http_host;
|
|
||||||
# proxy_set_header Upgrade $http_upgrade;
|
|
||||||
# proxy_set_header Connection "upgrade";
|
|
||||||
# }
|
|
||||||
# location /ws {
|
|
||||||
# proxy_pass http://xr:443;
|
|
||||||
# proxy_redirect off;
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Upgrade $http_upgrade;
|
|
||||||
# proxy_set_header Connection "upgrade";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
# proxy_read_timeout 5d;
|
|
||||||
# }
|
|
||||||
#-domain
|
|
||||||
#-ssl
|
|
||||||
# # The DoH server block
|
|
||||||
# location /dns-query {
|
|
||||||
# access_log /logs/nginx_doh_access;
|
|
||||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_set_header Connection "";
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Proto https;
|
|
||||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
|
||||||
|
|
||||||
# # Enable Cache, and set the cache_key to include the request_body
|
# location /adguard/ {
|
||||||
# proxy_cache doh_cache;
|
# }
|
||||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
|
||||||
|
|
||||||
# # proxy pass to the dohloop upstream
|
# location /webapp {
|
||||||
# proxy_pass https://ad/dns-query;
|
# access_log /logs/nginx_webapp_access;
|
||||||
# }
|
# alias /app;
|
||||||
#-ssl
|
# index index.html;
|
||||||
#-domain
|
# try_files $uri $uri/ @php;
|
||||||
# }
|
# }
|
||||||
#-domain
|
|
||||||
|
# location /pac {
|
||||||
|
# access_log /logs/nginx_pac_access;
|
||||||
|
# proxy_set_header Host $http_host;
|
||||||
|
# proxy_pass http://php;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location /ws {
|
||||||
|
# proxy_pass http://xr:443;
|
||||||
|
# proxy_redirect off;
|
||||||
|
# proxy_http_version 1.1;
|
||||||
|
# proxy_set_header Upgrade $http_upgrade;
|
||||||
|
# proxy_set_header Connection "upgrade";
|
||||||
|
# proxy_set_header Host $host;
|
||||||
|
# proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
# proxy_read_timeout 5d;
|
||||||
|
# }
|
||||||
|
# location /dns-query {
|
||||||
|
# access_log /logs/nginx_doh_access;
|
||||||
|
# proxy_http_version 1.1;
|
||||||
|
# proxy_set_header Connection "";
|
||||||
|
# proxy_set_header Host $host;
|
||||||
|
# proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-Proto https;
|
||||||
|
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||||
|
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||||
|
# proxy_cache doh_cache;
|
||||||
|
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||||
|
# proxy_pass https://ad/dns-query;
|
||||||
|
# }
|
||||||
|
# }
|
||||||
|
#-domain
|
||||||
}
|
}
|
||||||
|
|||||||
+1
-3
@@ -397,7 +397,7 @@ zend.exception_string_param_max_len = 0
|
|||||||
; threat in any way, but it makes it possible to determine whether you use PHP
|
; threat in any way, but it makes it possible to determine whether you use PHP
|
||||||
; on your server or not.
|
; on your server or not.
|
||||||
; https://php.net/expose-php
|
; https://php.net/expose-php
|
||||||
expose_php = On
|
expose_php = Off
|
||||||
|
|
||||||
;;;;;;;;;;;;;;;;;;;
|
;;;;;;;;;;;;;;;;;;;
|
||||||
; Resource Limits ;
|
; Resource Limits ;
|
||||||
@@ -1955,5 +1955,3 @@ opcache.enable=1
|
|||||||
opcache.jit_buffer_size=128M
|
opcache.jit_buffer_size=128M
|
||||||
opcache.enable_cli=1
|
opcache.enable_cli=1
|
||||||
pcre.jit=1
|
pcre.jit=1
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -110,6 +110,10 @@
|
|||||||
"protocol": "dns",
|
"protocol": "dns",
|
||||||
"outbound": "dns-out"
|
"outbound": "dns-out"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"addruleset": true,
|
||||||
|
"outbound": "direct"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"addruleset": true,
|
"addruleset": true,
|
||||||
"createruleset": [
|
"createruleset": [
|
||||||
|
|||||||
+1
-1
@@ -3,7 +3,7 @@
|
|||||||
"server_port": 8388,
|
"server_port": 8388,
|
||||||
"local_address": "0.0.0.0",
|
"local_address": "0.0.0.0",
|
||||||
"local_port": 1080,
|
"local_port": 1080,
|
||||||
"password": "test",
|
"password": "",
|
||||||
"timeout": 120,
|
"timeout": 120,
|
||||||
"method": "chacha20-ietf-poly1305",
|
"method": "chacha20-ietf-poly1305",
|
||||||
"no_delay": true,
|
"no_delay": true,
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"server": "0.0.0.0",
|
"server": "0.0.0.0",
|
||||||
"server_port": 8388,
|
"server_port": 8388,
|
||||||
"password": "test",
|
"password": "",
|
||||||
"timeout": 120,
|
"timeout": 120,
|
||||||
"method": "chacha20-ietf-poly1305",
|
"method": "chacha20-ietf-poly1305",
|
||||||
"no_delay": true,
|
"no_delay": true,
|
||||||
|
|||||||
@@ -35,7 +35,7 @@ stream {
|
|||||||
map_hash_bucket_size 128;
|
map_hash_bucket_size 128;
|
||||||
map $ssl_preread_server_name $sni_name {
|
map $ssl_preread_server_name $sni_name {
|
||||||
#domain
|
#domain
|
||||||
telegram.org reality;
|
t reality;
|
||||||
#domain
|
#domain
|
||||||
|
|
||||||
#ocserv
|
#ocserv
|
||||||
|
|||||||
+5
-22
@@ -16,27 +16,10 @@
|
|||||||
"enabled": true
|
"enabled": true
|
||||||
},
|
},
|
||||||
"streamSettings": {
|
"streamSettings": {
|
||||||
"network": "tcp",
|
"network": "ws",
|
||||||
"realitySettings": {
|
"wsSettings": {
|
||||||
"dest": "telegram.org:443",
|
"path": "/ws"
|
||||||
"maxClientVer": "",
|
}
|
||||||
"maxTimeDiff": 0,
|
|
||||||
"minClientVer": "",
|
|
||||||
"privateKey": "",
|
|
||||||
"serverNames": [
|
|
||||||
"telegram.org"
|
|
||||||
],
|
|
||||||
"shortIds": [],
|
|
||||||
"show": false,
|
|
||||||
"xver": 0
|
|
||||||
},
|
|
||||||
"tcpSettings": {
|
|
||||||
"acceptProxyProtocol": true
|
|
||||||
},
|
|
||||||
"sockopt": {
|
|
||||||
"acceptProxyProtocol": true
|
|
||||||
},
|
|
||||||
"security": "reality"
|
|
||||||
},
|
},
|
||||||
"tag": "vless_tls"
|
"tag": "vless_tls"
|
||||||
}
|
}
|
||||||
@@ -59,4 +42,4 @@
|
|||||||
"domainStrategy": "AsIs",
|
"domainStrategy": "AsIs",
|
||||||
"rules": []
|
"rules": []
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -44,8 +44,6 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ad:
|
ad:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
ss:
|
|
||||||
condition: service_started
|
|
||||||
env_file:
|
env_file:
|
||||||
- path: ./.env
|
- path: ./.env
|
||||||
required: true # default
|
required: true # default
|
||||||
@@ -187,45 +185,13 @@ services:
|
|||||||
- up
|
- up
|
||||||
- ng
|
- ng
|
||||||
- php
|
- php
|
||||||
- proxy
|
|
||||||
- wg
|
- wg
|
||||||
- wg1
|
- wg1
|
||||||
- ad
|
- ad
|
||||||
- ss
|
|
||||||
- tg
|
- tg
|
||||||
- xr
|
- xr
|
||||||
- oc
|
- oc
|
||||||
- np
|
- np
|
||||||
proxy:
|
|
||||||
image: mercurykd/vpnbot-ss:1.2
|
|
||||||
build:
|
|
||||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
|
||||||
args:
|
|
||||||
image: ${IMAGE}
|
|
||||||
volumes:
|
|
||||||
- ./config/.profile:/root/.ashrc:ro
|
|
||||||
- ./config/sslocal.json:/config.json
|
|
||||||
- ./ssh:/ssh
|
|
||||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
|
||||||
- ./scripts/start_proxy.sh:/start_proxy.sh
|
|
||||||
hostname: proxy
|
|
||||||
container_name: proxy-${VER}
|
|
||||||
depends_on:
|
|
||||||
php:
|
|
||||||
condition: service_healthy
|
|
||||||
networks:
|
|
||||||
default:
|
|
||||||
ipv4_address: 10.10.0.3
|
|
||||||
environment:
|
|
||||||
TZ: ${TZ}
|
|
||||||
env_file:
|
|
||||||
- path: ./.env
|
|
||||||
required: true # default
|
|
||||||
- path: ./override.env
|
|
||||||
required: false
|
|
||||||
stop_grace_period: 1s
|
|
||||||
command: ["/bin/sh", "/start_proxy.sh"]
|
|
||||||
logging: *default-logging
|
|
||||||
wg:
|
wg:
|
||||||
image: mercurykd/vpnbot-wg:1.1
|
image: mercurykd/vpnbot-wg:1.1
|
||||||
build:
|
build:
|
||||||
@@ -247,8 +213,6 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
|
||||||
- ${WGPORT}:${WGPORT}/udp
|
|
||||||
env_file:
|
env_file:
|
||||||
- path: ./.env
|
- path: ./.env
|
||||||
required: true # default
|
required: true # default
|
||||||
@@ -287,8 +251,6 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
|
||||||
- ${WG1PORT}:${WG1PORT}/udp
|
|
||||||
env_file:
|
env_file:
|
||||||
- path: ./.env
|
- path: ./.env
|
||||||
required: true # default
|
required: true # default
|
||||||
@@ -312,8 +274,6 @@ services:
|
|||||||
dockerfile: dockerfile/adguard.dockerfile
|
dockerfile: dockerfile/adguard.dockerfile
|
||||||
args:
|
args:
|
||||||
image: ${IMAGE}
|
image: ${IMAGE}
|
||||||
ports:
|
|
||||||
- 853:853
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/.profile:/root/.ashrc:ro
|
- ./config/.profile:/root/.ashrc:ro
|
||||||
- type: volume
|
- type: volume
|
||||||
@@ -343,37 +303,6 @@ services:
|
|||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
entrypoint: ["/bin/sh", "/start_ad.sh"]
|
entrypoint: ["/bin/sh", "/start_ad.sh"]
|
||||||
logging: *default-logging
|
logging: *default-logging
|
||||||
ss:
|
|
||||||
image: mercurykd/vpnbot-ss:1.2
|
|
||||||
build:
|
|
||||||
dockerfile: dockerfile/shadowsocks.dockerfile
|
|
||||||
args:
|
|
||||||
image: ${IMAGE}
|
|
||||||
volumes:
|
|
||||||
- ./config/.profile:/root/.ashrc:ro
|
|
||||||
- ./config/ssserver.json:/config.json
|
|
||||||
- ./ssh:/ssh
|
|
||||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
|
||||||
- ./scripts/start_ss.sh:/start_ss.sh
|
|
||||||
hostname: shadowsocks
|
|
||||||
container_name: shadowsocks-${VER}
|
|
||||||
depends_on:
|
|
||||||
php:
|
|
||||||
condition: service_healthy
|
|
||||||
ports:
|
|
||||||
- ${SSPORT}:${SSPORT}/tcp
|
|
||||||
- ${SSPORT}:${SSPORT}/udp
|
|
||||||
env_file:
|
|
||||||
- path: ./.env
|
|
||||||
required: true # default
|
|
||||||
- path: ./override.env
|
|
||||||
required: false
|
|
||||||
stop_grace_period: 1s
|
|
||||||
command: ["/bin/sh", "/start_ss.sh"]
|
|
||||||
networks:
|
|
||||||
default:
|
|
||||||
ipv4_address: 10.10.0.6
|
|
||||||
logging: *default-logging
|
|
||||||
tg:
|
tg:
|
||||||
image: mercurykd/vpnbot-tg:1.1
|
image: mercurykd/vpnbot-tg:1.1
|
||||||
build:
|
build:
|
||||||
@@ -389,8 +318,6 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
|
||||||
- ${TGPORT}:${TGPORT}
|
|
||||||
environment:
|
environment:
|
||||||
IP: ${IP}
|
IP: ${IP}
|
||||||
env_file:
|
env_file:
|
||||||
|
|||||||
@@ -1,3 +1,30 @@
|
|||||||
|
22.12.2024 v2.0
|
||||||
|
!!! версия не совместима с предыдущими, возможно прийдется накатывать руками. старые конфиги (кроме вг) не будут работать! перед обновлением:
|
||||||
|
- включить все порты или удалить docker-compose.override.yml
|
||||||
|
- переключить vless на вебсокет
|
||||||
|
- запустить обновление, если бот запуститься:
|
||||||
|
- перевыпустить сертификаты
|
||||||
|
- все ссылки на конфиги будут новыми (старые не будут работать)
|
||||||
|
- переключить vless на нужный режим (передернуть тумблер)
|
||||||
|
- включить нужные вам порты (по умолчанию включено только 80 и 443)
|
||||||
|
|
||||||
|
что нового:
|
||||||
|
- по умолчанию включены только 80, 443 порты
|
||||||
|
- у каждого инстанса бота теперь индивидуальные ссылки и поддомены
|
||||||
|
- отключены заголовки в ответах по которым можно было идентифицировать бота
|
||||||
|
- стандартная заглушка на главной заменена на basic auth. если есть override.html - то покажет его
|
||||||
|
- любая ссылка 'не по адресам бота' выдает непроходимый basic auth
|
||||||
|
- поддомены np и oc теперь у каждого индивидуальные
|
||||||
|
- выпилен shadowsocks (10.10.0.3 прокси теперь нет)
|
||||||
|
- добавлен direct rule в origin-singbox шаблон
|
||||||
|
- заменены значки для silence mode анализатора логов
|
||||||
|
- переработано главное меню аля дашбоард
|
||||||
|
- куча отрефакторенного кода - возможны баги
|
||||||
|
|
||||||
|
19.12.2024 v1.115
|
||||||
|
- генерация устойчивого пароля shadowsocks, если он равен test или пуст
|
||||||
|
19.12.2024 v1.114
|
||||||
|
- убран дефолтный пароль у shadowsocks
|
||||||
13.12.2024 v1.113
|
13.12.2024 v1.113
|
||||||
- обновлен adguardHome
|
- обновлен adguardHome
|
||||||
- фикс краша adg при удалении dns-upstream из бота
|
- фикс краша adg при удалении dns-upstream из бота
|
||||||
|
|||||||
Reference in New Issue
Block a user