Compare commits

...

11 Commits

Author SHA1 Message Date
mercury fe0414cc59 fix export ocserv users 2024-03-06 04:03:30 +04:00
mercury 48a1eba67e fix ocserv 2024-03-06 03:44:52 +04:00
mercury 714cff7d76 fix lib for short link 2024-03-06 02:10:11 +04:00
mercury 0e8bab5c4c fix service script 2024-03-06 01:45:31 +04:00
mercury 387e6e4986 short link for amnezia 2024-03-06 01:35:40 +04:00
mercury 6a7af1c30f fix import wg1 2024-03-05 00:14:36 +04:00
mercury 2a17b4f1f3 update version 2024-03-04 23:30:46 +04:00
mercury d005ccc919 fix start wg1 2024-03-04 23:26:09 +04:00
mercury 5df89e7f89 syncport fix 2024-03-04 16:51:18 +04:00
mercury f6d72800cb white ip 2024-03-04 16:38:37 +04:00
mercury 4ff1929a22 improve makefile 2024-03-03 19:53:52 +04:00
11 changed files with 136 additions and 40 deletions
+14
View File
@@ -0,0 +1,14 @@
import sys
from PyQt5.QtCore import *
def enc(s):
ba = qCompress(QByteArray(s.encode()))
ba = ba.toBase64(QByteArray.Base64Option.Base64UrlEncoding | QByteArray.Base64Option.OmitTrailingEquals)
print('vpn://' + str(ba, 'utf-8'))
s = ''
for line in sys.stdin:
s += line
s = s.strip()
enc(s)
+66 -9
View File
@@ -1005,6 +1005,7 @@ class Bot
'mtproto' => file_get_contents('/config/mtprotosecret'), 'mtproto' => file_get_contents('/config/mtprotosecret'),
'xray' => json_decode(file_get_contents('/config/xray.json'), true), 'xray' => json_decode(file_get_contents('/config/xray.json'), true),
'oc' => file_get_contents('/config/ocserv.conf'), 'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
]; ];
return json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES); return json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
@@ -1061,6 +1062,9 @@ class Bot
if ($this->getPacConf()['amnezia'] != $json['pac']['amnezia']) { if ($this->getPacConf()['amnezia'] != $json['pac']['amnezia']) {
$switch_amnezia = 1; $switch_amnezia = 1;
} }
if ($this->getPacConf()['wg1_amnezia'] != $json['pac']['wg1_amnezia']) {
$switch_wg1amnezia = 1;
}
$this->setPacConf($json['pac']); $this->setPacConf($json['pac']);
$out[] = 'update naiveproxy'; $out[] = 'update naiveproxy';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out)); $this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
@@ -1082,7 +1086,7 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out)); $this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->wg = 1; $this->wg = 1;
$this->saveClients($json['wg1']['clients']); $this->saveClients($json['wg1']['clients']);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_amnezia); $this->restartWG($this->createConfig($json['wg1']['server']), $switch_wg1amnezia);
$this->iptablesWG(); $this->iptablesWG();
} }
// ad // ad
@@ -1126,6 +1130,7 @@ class Bot
if (!empty($json['oc'])) { if (!empty($json['oc'])) {
$out[] = 'update ocserv'; $out[] = 'update ocserv';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out)); $this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
file_put_contents('/config/ocserv.passwd', $json['ocu']);
$this->restartOcserv($json['oc']); $this->restartOcserv($json['oc']);
} }
if (!empty($json['pac']['domain'])) { if (!empty($json['pac']['domain'])) {
@@ -2533,14 +2538,60 @@ DNS-over-HTTPS with IP:
$this->menu('client', "{$k}_$page"); $this->menu('client', "{$k}_$page");
} }
public function getAmneziaShortLink($client)
{
$dns = explode(',', $client['interface']['DNS']);
$c = json_encode([
"containers" => [
[
"awg" => [
"isThirdPartyConfig" => True,
"last_config" => json_encode([
"H1" => "{$client['interface']['H1']}",
"H2" => "{$client['interface']['H2']}",
"H3" => "{$client['interface']['H3']}",
"H4" => "{$client['interface']['H4']}",
"Jc" => "{$client['interface']['Jc']}",
"Jmax" => "{$client['interface']['Jmax']}",
"Jmin" => "{$client['interface']['Jmin']}",
"S1" => "{$client['interface']['S1']}",
"S2" => "{$client['interface']['S2']}",
"client_ip" => explode('/', $client['interface']['Address'])[0],
"client_priv_key" => $client['interface']['PrivateKey'],
"client_pub_key" => "0",
"config" => $this->createConfig($client),
"hostName" => $this->ip,
"port" => (int) getenv('WG1PORT'),
"psk_key" => $client['peers'][0]['PresharedKey'],
"server_pub_key" => $client['peers'][0]['PublicKey']
]),
"port" => (int) getenv('WG1PORT'),
"transport_proto" => "udp"
],
"container" => "amnezia-awg"
]
],
"defaultContainer" => "amnezia-awg",
"description" => $client['interface']['## name'],
"dns1" => $dns[0],
"dns2" => $dns[1] ?: '',
"hostName" => $this->ip
]);
exec("echo '$c' | python amnezia.py", $o);
return $o[0];
}
public function getClient($client, $page) public function getClient($client, $page)
{ {
$clients = $this->readClients(); $clients = $this->readClients();
if ($clients) { if ($clients) {
$name = $this->getName($clients[$client]['interface']); $name = $this->getName($clients[$client]['interface']);
$conf = $this->createConfig($clients[$client]); $conf = $this->createConfig($clients[$client]);
if ($this->getInstanceWG(1)) {
$sl = $this->getAmneziaShortLink($clients[$client]);
}
return [ return [
'text' => "<code>$conf</code>\n\n<b>$name</b> ({$this->getTitleWG()})", 'text' => "<pre>$conf</pre>\n\n<code>$sl</code>\n\n<b>$name</b> ({$this->getTitleWG()})",
'data' => [ 'data' => [
[ [
[ [
@@ -3829,7 +3880,6 @@ DNS-over-HTTPS with IP:
public function readStatus() public function readStatus()
{ {
// $this->sd([$this->getWGType(), $this->getInstanceWG()]);
$r = $this->ssh($this->getWGType(), $this->getInstanceWG()); $r = $this->ssh($this->getWGType(), $this->getInstanceWG());
$r = explode(PHP_EOL, $r); $r = explode(PHP_EOL, $r);
$r = array_filter($r); $r = array_filter($r);
@@ -4002,14 +4052,21 @@ DNS-over-HTTPS with IP:
public function syncPortClients() public function syncPortClients()
{ {
$endpoint = $this->ip . ':' . getenv('WGPORT'); $endpoint = [
$clients = $this->readClients(); $this->ip . ':' . getenv('WGPORT'),
foreach ($clients as $k => $v) { $this->ip . ':' . getenv('WG1PORT'),
foreach ($v['peers'] as $i => $j) { ];
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint; for ($i=0; $i < 2; $i++) {
$this->wg = $i;
$clients = $this->readClients();
foreach ($clients as $k => $v) {
foreach ($v['peers'] as $i => $j) {
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint[$i];
}
} }
$this->saveClients($clients);
} }
$this->saveClients($clients); unset($this->wg);
} }
public function saveClients(array $clients) public function saveClients(array $clients)
+1 -1
View File
@@ -243,7 +243,7 @@ $i = [
], ],
'backup' => [ 'backup' => [
'en' => 'auto backup', 'en' => 'auto backup',
'ru' => 'бэкап', 'ru' => 'автобэкап',
], ],
'logs' => [ 'logs' => [
'en' => 'logs', 'en' => 'logs',
+2 -2
View File
@@ -83,7 +83,7 @@ services:
ipv4_address: 10.10.0.2 ipv4_address: 10.10.0.2
logging: *default-logging logging: *default-logging
php: php:
image: mercurykd/vpnbot-php:1.1 image: mercurykd/vpnbot-php:1.2
build: build:
dockerfile: dockerfile/php.dockerfile dockerfile: dockerfile/php.dockerfile
args: args:
@@ -396,7 +396,7 @@ services:
ipv4_address: 10.10.0.9 ipv4_address: 10.10.0.9
logging: *default-logging logging: *default-logging
oc: oc:
image: mercurykd/vpnbot-oc:1.1 image: mercurykd/vpnbot-oc:1.2
build: build:
dockerfile: dockerfile/ocserv.dockerfile dockerfile: dockerfile/ocserv.dockerfile
args: args:
+10 -9
View File
@@ -1,21 +1,22 @@
ARG image ARG image
FROM $image FROM $image
RUN apk add --update openssh iptables \ RUN apk add --update openssh \
&& apk add --no-cache --virtual .build-deps \ iptables \
curl \
g++ \
gnutls-dev \ gnutls-dev \
gpgme \
libev-dev \ libev-dev \
libnl3-dev \
libseccomp-dev \
linux-headers \
linux-pam-dev \ linux-pam-dev \
lz4-dev \ lz4-dev \
libseccomp-dev \
&& apk add --no-cache --virtual .build-deps \
xz \
linux-headers \
libnl3-dev \
g++ \
gpgme \
curl \
make \ make \
readline-dev \ readline-dev \
tar \ tar \
xz \
autoconf \ autoconf \
automake \ automake \
gperf \ gperf \
+1
View File
@@ -19,6 +19,7 @@ RUN apk add --no-cache --update php81 \
openssh \ openssh \
openssl \ openssl \
curl \ curl \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \ && wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \ && tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
&& mv linux-amd64/dnslookup /usr/bin \ && mv linux-amd64/dnslookup /usr/bin \
+3 -2
View File
@@ -2,7 +2,7 @@ b:
docker compose build docker compose build
u: # запуск контейнеров u: # запуск контейнеров
bash ./update/update.sh & bash ./update/update.sh &
IP=$(shell ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$$|\1|p' | awk '{print $1}' | head -1) VER=$(shell git describe --tags) docker compose up -d --force-recreate IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose up -d --force-recreate
d: # остановка контейнеров d: # остановка контейнеров
-kill -9 $(shell cat ./update/update_pid) > /dev/null -kill -9 $(shell cat ./update/update_pid) > /dev/null
docker compose down --remove-orphans docker compose down --remove-orphans
@@ -54,4 +54,5 @@ s:
git status -su git status -su
c: c:
git add config/ git add config/
git checkout . git checkout .
git reset
+33 -14
View File
@@ -1,3 +1,7 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$') INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ] if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then then
@@ -13,21 +17,36 @@ fi
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
ln -s /etc/wireguard/wg0.conf /etc/amnezia/amneziawg/wg0.conf ln -s /etc/wireguard/wg0.conf /etc/amnezia/amneziawg/wg0.conf
if [ $(cat /pac.json | jq .amnezia) -eq 1 ] if [ "$HOSTNAME" = "wireguard1" ]
then then
awg-quick up wg0 if [ $(cat /pac.json | jq .wg1_amnezia) -eq 1 ]
then
awg-quick up wg0
else
wg-quick up wg0
fi
if [ $(cat /pac.json | jq .wg1_blocktorrent) -eq 1 ]
then
sh /block_torrent.sh
fi
if [ $(cat /pac.json | jq .wg1_exchange) -eq 1 ]
then
sh /block_exchange.sh
fi
else else
wg-quick up wg0 if [ $(cat /pac.json | jq .amnezia) -eq 1 ]
fi then
cat /ssh/key.pub > /root/.ssh/authorized_keys awg-quick up wg0
ssh-keygen -A else
exec /usr/sbin/sshd -D -e "$@" & wg-quick up wg0
if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ] fi
then if [ $(cat /pac.json | jq .blocktorrent) -eq 1 ]
sh /block_torrent.sh then
fi sh /block_torrent.sh
if [ $(cat /pac.json | jq .exchange) -eq 1 ] fi
then if [ $(cat /pac.json | jq .exchange) -eq 1 ]
sh /block_exchange.sh then
sh /block_exchange.sh
fi
fi fi
tail -f /dev/null tail -f /dev/null
+2 -2
View File
@@ -4,8 +4,8 @@ Requires=docker.service
After=docker.service After=docker.service
[Service] [Service]
WorkingDirectory=/root/vpnbot WorkingDirectory=/root/vpnbot
ExecStart=/bin/sh -c "IP=$(ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | awk '{print $1}' | head -1) docker compose up --build --force-recreate" ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate && bash ./update/update.sh &"
ExecStop=/usr/bin/docker compose down ExecStop=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null && docker compose down --remove-orphans"
TimeoutStartSec=0 TimeoutStartSec=0
Restart=on-failure Restart=on-failure
[Install] [Install]
+1 -1
View File
@@ -11,7 +11,7 @@ do
docker compose down --remove-orphans docker compose down --remove-orphans
git reset --hard git reset --hard
git pull > ./update/message git pull > ./update/message
IP=$(ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | awk '{print $1}' | head -1) VER=$(git describe --tags) docker compose up -d --force-recreate IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate
bash $pwd/update/update.sh & bash $pwd/update/update.sh &
exit 0 exit 0
fi fi
+3
View File
@@ -1,3 +1,6 @@
04.03.2024
- решение "серого айпи" при запуске
- фикс стартового скрипта второго контейнера wireguard
03.03.2024 возможность обновления бота по кнопке из самого бота 03.03.2024 возможность обновления бота по кнопке из самого бота
- <code>git pull && make r</code> - <code>git pull && make r</code>
02.03.2024 2 сервера wireguard, для возможности один запускать как wireguard а второй как amnezia 02.03.2024 2 сервера wireguard, для возможности один запускать как wireguard а второй как amnezia