Compare commits

...

29 Commits

Author SHA1 Message Date
mercury 82b95ccb85 web app for donate 2024-03-10 13:10:35 +04:00
mercury e01ef61b62 protect adguard on backup restore 2024-03-10 13:01:32 +04:00
mercury 367bfc0fbc web panel config 2024-03-10 12:45:42 +04:00
mercury 524c52e326 web panel adguard 2024-03-10 12:39:30 +04:00
mercury 3bbb8290e5 improve settings menu 2024-03-07 19:27:40 +04:00
mercury 1e8ac34370 Merge branch 'master' into dev 2024-03-07 19:13:19 +04:00
Konstantin 2332e5ea71 Merge pull request #9 from 13f66cd22a80/master 2024-03-07 19:09:35 +04:00
mercury 796fa57330 improve status wg error 2024-03-07 19:00:33 +04:00
Jeff Scrum ce91b1152e Update readme.md 2024-03-07 14:44:29 +03:00
mercury 64d44428d0 update version 2024-03-07 14:34:48 +04:00
mercury 860fdc883f fix environment for wg 2024-03-07 14:32:52 +04:00
mercury f2f2066e99 update version 2024-03-07 13:21:46 +04:00
mercury 3e343ce2b7 fix port amnezia 2024-03-07 13:10:09 +04:00
mercury 3c16620a7d update version 2024-03-07 11:58:25 +04:00
mercury b1efd9f400 fix syncports 2024-03-07 11:52:34 +04:00
mercury cbe0ef8a12 check webhook 2024-03-07 10:46:55 +04:00
mercury 24026d3678 optimize images 2024-03-07 10:23:13 +04:00
mercury dea46815c7 override environment 2024-03-07 10:20:43 +04:00
mercury 11e34d8c4e unversary path for vpnbot.service 2024-03-06 15:15:45 +04:00
mercury 3e3684eb34 fix service for systemd 2024-03-06 14:46:02 +04:00
mercury 7ee47db8e2 fix short link type 2024-03-06 11:52:09 +04:00
mercury b390fe7dd8 update version 2024-03-06 04:08:45 +04:00
mercury fe0414cc59 fix export ocserv users 2024-03-06 04:03:30 +04:00
mercury 48a1eba67e fix ocserv 2024-03-06 03:44:52 +04:00
mercury 714cff7d76 fix lib for short link 2024-03-06 02:10:11 +04:00
mercury 0e8bab5c4c fix service script 2024-03-06 01:45:31 +04:00
mercury 387e6e4986 short link for amnezia 2024-03-06 01:35:40 +04:00
mercury 6a7af1c30f fix import wg1 2024-03-05 00:14:36 +04:00
mercury 2a17b4f1f3 update version 2024-03-04 23:30:46 +04:00
23 changed files with 407 additions and 101 deletions
+1
View File
@@ -8,3 +8,4 @@ TGPORT=4443
IMAGE=alpine:3.18.2
IP=
VER=
ENV=/root/.ashrc
+2
View File
@@ -18,3 +18,5 @@
mirror/.env
update/*
!update/update.sh
override.env
+14
View File
@@ -0,0 +1,14 @@
import sys
from PyQt5.QtCore import *
def enc(s):
ba = qCompress(QByteArray(s.encode()))
ba = ba.toBase64(QByteArray.Base64Option.Base64UrlEncoding | QByteArray.Base64Option.OmitTrailingEquals)
print('vpn://' + str(ba, 'utf-8'))
s = ''
for line in sys.stdin:
s += line
s = s.strip()
enc(s)
+144 -21
View File
@@ -130,6 +130,9 @@ class Bot
case preg_match('~^/id$~', $this->input['message'], $m):
$this->send($this->input['chat'], $this->input['from'], $this->input['message_id']);
break;
case preg_match('~^/adguardChBr$~', $this->input['callback'], $m):
$this->adguardChBr();
break;
case preg_match('~^/mtproto$~', $this->input['callback'], $m):
$this->mtproto();
break;
@@ -1005,6 +1008,7 @@ class Bot
'mtproto' => file_get_contents('/config/mtprotosecret'),
'xray' => json_decode(file_get_contents('/config/xray.json'), true),
'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
];
return json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
@@ -1061,6 +1065,9 @@ class Bot
if ($this->getPacConf()['amnezia'] != $json['pac']['amnezia']) {
$switch_amnezia = 1;
}
if ($this->getPacConf()['wg1_amnezia'] != $json['pac']['wg1_amnezia']) {
$switch_wg1amnezia = 1;
}
$this->setPacConf($json['pac']);
$out[] = 'update naiveproxy';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
@@ -1082,7 +1089,7 @@ class Bot
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->wg = 1;
$this->saveClients($json['wg1']['clients']);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_amnezia);
$this->restartWG($this->createConfig($json['wg1']['server']), $switch_wg1amnezia);
$this->iptablesWG();
}
// ad
@@ -1126,6 +1133,7 @@ class Bot
if (!empty($json['oc'])) {
$out[] = 'update ocserv';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
file_put_contents('/config/ocserv.passwd', $json['ocu']);
$this->restartOcserv($json['oc']);
}
if (!empty($json['pac']['domain'])) {
@@ -1153,6 +1161,7 @@ class Bot
}
}
file_put_contents('/config/nginx.conf', $t);
$this->adguardProtect();
$out[] = $this->ssh("nginx -s reload 2>&1", 'ng');
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
@@ -2176,6 +2185,17 @@ DNS-over-HTTPS with IP:
$c = $this->getPacConf();
$conf = $this->readConfig();
$status = $this->readStatus();
if (empty($status)) {
return [
'text' => "Menu -> " . $this->getTitleWG() . "\n\nerror status",
'data' => [[
[
'text' => $this->i18n('back'),
'callback_data' => "/menu",
],
]],
];
}
$clients = $this->getClients($page);
$bt = $c[$this->getInstanceWG(1) . 'blocktorrent'];
$ex = $c[$this->getInstanceWG(1) . 'exchange'];
@@ -2227,7 +2247,7 @@ DNS-over-HTTPS with IP:
if (!empty($v['# PublicKey'])) {
$conf['peers'][$k]['online'] = 'off';
} else {
$conf['peers'][$k]['status'] = $this->getStatusPeer($v['PublicKey'], $status['peers']);
$conf['peers'][$k]['status'] = $status ? $this->getStatusPeer($v['PublicKey'], $status['peers']) : 'error';
$conf['peers'][$k]['online'] = preg_match('~^(\d+ seconds|[12] minute)~', $conf['peers'][$k]['status']['latest handshake']) ? 'online' : '';
}
}
@@ -2533,14 +2553,60 @@ DNS-over-HTTPS with IP:
$this->menu('client', "{$k}_$page");
}
public function getAmneziaShortLink($client)
{
$dns = explode(',', $client['interface']['DNS']);
$c = json_encode([
"containers" => [
[
"awg" => [
"isThirdPartyConfig" => True,
"last_config" => json_encode([
"H1" => "{$client['interface']['H1']}",
"H2" => "{$client['interface']['H2']}",
"H3" => "{$client['interface']['H3']}",
"H4" => "{$client['interface']['H4']}",
"Jc" => "{$client['interface']['Jc']}",
"Jmax" => "{$client['interface']['Jmax']}",
"Jmin" => "{$client['interface']['Jmin']}",
"S1" => "{$client['interface']['S1']}",
"S2" => "{$client['interface']['S2']}",
"client_ip" => explode('/', $client['interface']['Address'])[0],
"client_priv_key" => $client['interface']['PrivateKey'],
"client_pub_key" => "0",
"config" => $this->createConfig($client),
"hostName" => $this->ip,
"port" => (int) getenv('WG1PORT'),
"psk_key" => $client['peers'][0]['PresharedKey'],
"server_pub_key" => $client['peers'][0]['PublicKey']
]),
"port" => (int) getenv('WG1PORT'),
"transport_proto" => "udp"
],
"container" => "amnezia-awg"
]
],
"defaultContainer" => "amnezia-awg",
"description" => $client['interface']['## name'],
"dns1" => $dns[0],
"dns2" => $dns[1] ?: '',
"hostName" => $this->ip
]);
exec("echo '$c' | python amnezia.py", $o);
return $o[0];
}
public function getClient($client, $page)
{
$clients = $this->readClients();
if ($clients) {
$name = $this->getName($clients[$client]['interface']);
$conf = $this->createConfig($clients[$client]);
if ($this->getWGType() == 'awg') {
$sl = $this->getAmneziaShortLink($clients[$client]);
}
return [
'text' => "<code>$conf</code>\n\n<b>$name</b> ({$this->getTitleWG()})",
'text' => "<pre>$conf</pre>\n\n<code>$sl</code>\n\n<b>$name</b> ({$this->getTitleWG()})",
'data' => [
[
[
@@ -3024,7 +3090,9 @@ DNS-over-HTTPS with IP:
],
[
'text' => $this->i18n('donate'),
'url' => "https://yoomoney.ru/to/410011827900450",
'web_app' => [
'url' => "https://yoomoney.ru/to/410011827900450",
]
],
],
],
@@ -3393,37 +3461,95 @@ DNS-over-HTTPS with IP:
];
}
public function adguardProtect()
{
$h = substr(hash('sha256', $this->key), 0, 8);
$s = empty($this->getPacConf()['adgbrowser']) ? '' : '#';
$a = $this->adguardBasicAuth();
$r = <<<CONF
location /adguard/ {
access_log /logs/nginx_adguard_access;
if (\$cookie_c != "$h") {
$s rewrite .* /webapp redirect;
}
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
proxy_set_header Authorization "Basic \$cookie_a";
}
location
CONF;
$f = '/config/nginx.conf';
$c = file_get_contents($f);
$t = preg_replace('~(location /adguard.+?})\s*location~s', $r, $c);
file_put_contents($f, $t);
}
public function adguardBasicAuth()
{
return base64_encode('admin:' . $this->getPacConf()['adpswd']);
}
public function adguardChBr()
{
$c = $this->getPacConf();
$c['adgbrowser'] = $c['adgbrowser'] ? 0 : 1;
$this->setPacConf($c);
$this->adguardProtect();
$this->ssh('nginx -s reload', 'ng');
$this->answer($this->input['callback_id'], $this->i18n($c['adgbrowser'] ? 'browser_notify_on' : 'browser_notify_off'), true);
$this->menu('adguard');
}
public function adguardMenu()
{
$conf = $this->getPacConf();
$ip = $this->ip;
$domain = $conf['domain'] ?: $ip;
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
$text = $conf['adgbrowser'] ? "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n" : '';
if ($ssl) {
$text .= "DNS over HTTPS:\n<code>$ip</code>\n<code>$scheme://$domain/dns-query" . ($conf['adguardkey'] ? "/{$conf['adguardkey']}" : '') . "</code>\n\n";
$text .= "DNS over TLS:\n<code>tls://" . ($conf['adguardkey'] ? "{$conf['adguardkey']}." : '') . "$domain</code>";
}
$data = [
[
[
'text' => 'web panel',
'web_app' => [
"url" => "https://$domain/adguard"
],
],
[
'text' => $this->i18n('third party browser') . ': ' . $this->i18n($conf['adgbrowser'] ? 'on' : 'off'),
'callback_data' => '/adguardChBr'
],
],
[
[
'text' => $this->i18n('change password'),
'callback_data' => "/adguardpsswd",
],
[
'text' => $this->i18n('reset settings'),
'callback_data' => "/adguardreset",
'text' => 'ClientID' . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
'callback_data' => "/setAdguardKey",
],
],
];
$data[] = [
[
'text' => $this->i18n('reset settings'),
'callback_data' => "/adguardreset",
],
];
$data[] = [
[
'text' => $this->i18n('add upstream'),
'callback_data' => "/addupstream",
],
[
'text' => $this->i18n('setSecret') . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
'callback_data' => "/setAdguardKey",
'text' => $this->i18n('check DNS'),
'callback_data' => "/checkdns",
],
];
$upstreams = yaml_parse_file($this->adguard)['dns']['upstream_dns'];
@@ -3441,12 +3567,6 @@ DNS-over-HTTPS with IP:
];
}
}
$data[] = [
[
'text' => $this->i18n('check DNS'),
'callback_data' => "/checkdns",
],
];
$data[] = [
[
'text' => $this->i18n('back'),
@@ -3506,8 +3626,11 @@ DNS-over-HTTPS with IP:
public function configMenu()
{
$conf = $this->getPacConf();
$text = $this->i18n('domain explain');
$conf = $this->getPacConf();
$text[] = $conf['domain'] ? "Domains:\n{$conf['domain']}\nnp.{$conf['domain']}\noc.{$conf['domain']}" . ($conf['adguardkey'] ? "\n{$conf['adguardkey']}.{$conf['domain']}" : '') : $this->i18n('domain explain');
$ssl = $this->expireCert();
$text[] = $conf['domain'] ? "\nSSL: " . ($ssl ? date('Y-m-d H:i:s', $this->expireCert()) : 'none') : '';
$data = [
[
[
@@ -3522,7 +3645,7 @@ DNS-over-HTTPS with IP:
case 'letsencrypt':
$data[] = [
[
'text' => $this->i18n('renew SSL') . ': ' . date('Y-m-d H:i:s', $this->expireCert()),
'text' => $this->i18n('renew SSL'),
'callback_data' => "/setSSL letsencrypt",
],
[
@@ -3627,7 +3750,7 @@ DNS-over-HTTPS with IP:
],
];
return [
'text' => $text,
'text' => implode("\n", $text),
'data' => $data,
];
}
@@ -4009,8 +4132,8 @@ DNS-over-HTTPS with IP:
$this->wg = $i;
$clients = $this->readClients();
foreach ($clients as $k => $v) {
foreach ($v['peers'] as $i => $j) {
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint[$i];
foreach ($v['peers'] as $n => $j) {
$clients[$k]['peers'][$n]['Endpoint'] = $endpoint[$i];
}
}
$this->saveClients($clients);
+11
View File
@@ -0,0 +1,11 @@
<?php
require './config.php';
$ch = curl_init();
curl_setopt_array($ch, [
CURLOPT_URL => "https://api.telegram.org/bot{$c['key']}/getWebhookInfo",
CURLOPT_RETURNTRANSFER => true,
]);
$res = curl_exec($ch);
die(var_dump($res));
+13 -1
View File
@@ -243,7 +243,7 @@ $i = [
],
'backup' => [
'en' => 'auto backup',
'ru' => 'бэкап',
'ru' => 'автобэкап',
],
'logs' => [
'en' => 'logs',
@@ -305,4 +305,16 @@ $i = [
'en' => 'update bot',
'ru' => 'обновить бота',
],
'third party browser' => [
'en' => 'third party browser',
'ru' => 'сторонний браузер',
],
'browser_notify_on' => [
'en' => 'the web panel can now be opened in any browser',
'ru' => 'веб панель теперь может быть открыта в любом браузере',
],
'browser_notify_off' => [
'en' => 'the web panel can no longer be opened in any browser',
'ru' => 'веб панель теперь не может быть открыта в любом браузере',
],
];
+18
View File
@@ -42,6 +42,24 @@ if ($hash == substr(md5($c['key']), 0, 8)) {
}
}
}
if (!empty($_GET['hash'])) {
$t = $_GET;
unset($t['hash']);
ksort($t);
foreach ($t as $k => $v) {
$s[] = "$k=$v";
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
die('ok');
}
}
header('500', true, 500);
exit;
+2 -1
View File
@@ -8,6 +8,7 @@ require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
$bot->setwebhook();
$bot->adguardProtect();
$bot->setcommands();
$bot->syncPortClients();
$bot->setwebhook();
+24
View File
@@ -0,0 +1,24 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<script src="https://telegram.org/js/telegram-web-app.js"></script>
<script src="jquery-3.7.1.min.js"></script>
<title>Document</title>
</head>
<body>
<script>
var tg = window.Telegram.WebApp;
jQuery(function($) {
$.ajax({
'url': 'check?' + tg.initData,
}).done(function (r) {
location.replace('/adguard/');
}).fail(function (r) {
location.replace('/');
});
});
</script>
</body>
</html>
File diff suppressed because one or more lines are too long
+12
View File
@@ -38,6 +38,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -88,6 +94,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
+12
View File
@@ -38,6 +38,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -88,6 +94,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
+71 -44
View File
@@ -41,8 +41,11 @@ services:
condition: service_started
ss:
condition: service_started
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_upstream.sh"]
networks:
@@ -66,6 +69,7 @@ services:
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./logs/:/logs/
- ./app/webapp:/app
ports:
- 80:80
hostname: nginx
@@ -73,9 +77,11 @@ services:
depends_on:
up:
condition: service_started
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ng.sh"]
networks:
@@ -83,11 +89,13 @@ services:
ipv4_address: 10.10.0.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.1
image: mercurykd/vpnbot-php:1.2
build:
dockerfile: dockerfile/php.dockerfile
args:
image: ${IMAGE}
ports:
- 127.0.0.1:8081:8080
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/php.ini:/etc/php81/php.ini
@@ -103,15 +111,13 @@ services:
- ./.env:/mirror/.env
- ./update:/update
environment:
TZ: ${TZ}
IP: ${IP}
ADDRESS: ${WGADDRESS}
WGPORT: ${WGPORT}
WG1ADDRESS: ${WG1ADDRESS}
WG1PORT: ${WG1PORT}
SSPORT: ${SSPORT}
TGPORT: ${TGPORT}
VER: ${VER}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
hostname: php
container_name: php-${VER}
restart: unless-stopped
@@ -130,7 +136,7 @@ services:
timeout: 5s
retries: 5
service:
image: mercurykd/vpnbot-php:1.1
image: mercurykd/vpnbot-php:1.2
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -146,15 +152,13 @@ services:
- ./update:/update
- ./scripts/start_service.sh:/start_service.sh
environment:
TZ: ${TZ}
IP: ${IP}
ADDRESS: ${WGADDRESS}
WGPORT: ${WGPORT}
WG1ADDRESS: ${WG1ADDRESS}
WG1PORT: ${WG1PORT}
SSPORT: ${SSPORT}
TGPORT: ${TGPORT}
VER: ${VER}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
hostname: service
container_name: service-${VER}
# restart: unless-stopped
@@ -200,7 +204,11 @@ services:
ipv4_address: 10.10.0.3
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_proxy.sh"]
logging: *default-logging
@@ -227,11 +235,13 @@ services:
condition: service_healthy
ports:
- ${WGPORT}:${WGPORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
environment:
TZ: ${TZ}
WGPORT: ${WGPORT}
ADDRESS: ${WGADDRESS}
ENV: /root/.ashrc
cap_add:
- NET_ADMIN
devices:
@@ -265,11 +275,13 @@ services:
condition: service_healthy
ports:
- ${WG1PORT}:${WG1PORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
environment:
TZ: ${TZ}
WGPORT: ${WG1PORT}
ADDRESS: ${WG1ADDRESS}
ENV: /root/.ashrc
cap_add:
- NET_ADMIN
devices:
@@ -304,8 +316,11 @@ services:
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
networks:
default:
@@ -334,9 +349,11 @@ services:
ports:
- ${SSPORT}:${SSPORT}/tcp
- ${SSPORT}:${SSPORT}/udp
environment:
TZ: ${TZ}
SSPORT: ${SSPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ss.sh"]
networks:
@@ -361,9 +378,12 @@ services:
ports:
- ${TGPORT}:${TGPORT}
environment:
TZ: ${TZ}
IP: ${IP}
TGPORT: ${TGPORT}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_tg.sh"]
networks:
@@ -387,8 +407,11 @@ services:
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_xray.sh"]
networks:
@@ -396,7 +419,7 @@ services:
ipv4_address: 10.10.0.9
logging: *default-logging
oc:
image: mercurykd/vpnbot-oc:1.1
image: mercurykd/vpnbot-oc:1.2
build:
dockerfile: dockerfile/ocserv.dockerfile
args:
@@ -413,9 +436,11 @@ services:
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
ENV: /root/.ashrc
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_oc.sh"]
cap_add:
@@ -444,9 +469,11 @@ services:
depends_on:
php:
condition: service_healthy
environment:
TZ: ${TZ}
ENV: /root/.ashrc
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_np.sh"]
cap_add:
+10 -9
View File
@@ -1,21 +1,22 @@
ARG image
FROM $image
RUN apk add --update openssh iptables \
&& apk add --no-cache --virtual .build-deps \
curl \
g++ \
RUN apk add --update openssh \
iptables \
gnutls-dev \
gpgme \
libev-dev \
libnl3-dev \
libseccomp-dev \
linux-headers \
linux-pam-dev \
lz4-dev \
libseccomp-dev \
&& apk add --no-cache --virtual .build-deps \
xz \
linux-headers \
libnl3-dev \
g++ \
gpgme \
curl \
make \
readline-dev \
tar \
xz \
autoconf \
automake \
gperf \
+1
View File
@@ -19,6 +19,7 @@ RUN apk add --no-cache --update php81 \
openssh \
openssl \
curl \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
&& mv linux-amd64/dnslookup /usr/bin \
+3 -1
View File
@@ -55,4 +55,6 @@ s:
c:
git add config/
git checkout .
git reset
git reset
webhook:
docker compose exec php php checkwebhook.php
+8 -10
View File
@@ -62,19 +62,17 @@ telegram bot to manage servers (inside the bot)
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
---
environment: ubuntu 18.04/20.04/22.04, debian 11
environment: ubuntu 18.04/20.04/22.04, debian 11/12
install:
`wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY`
---
additional options:
install as service(autoload on start):
### Install:
```shell
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
```
### Install as service (autoload on start):
```shell
cd /root/vpnbot
bash scripts/install_as_service.sh
```
+2 -1
View File
@@ -1,3 +1,4 @@
cp scripts/vpnbot.service /etc/systemd/system/vpnbot.service
path=`pwd`
sed "s|path|$path|g" "$path/scripts/vpnbot.service" > /etc/systemd/system/vpnbot.service
systemctl daemon-reload
systemctl enable vpnbot
+1 -1
View File
@@ -6,4 +6,4 @@ php cron.php &
unitd --log /logs/unit_error
curl -X PUT --data-binary @/config/unit.json --unix-socket /var/run/control.unit.sock http://localhost/config
pkill unitd
unitd --no-daemon --log /logs/unit_error
unitd --no-daemon --control 0.0.0.0:8080 --log /logs/unit_error
+23 -8
View File
@@ -3,16 +3,31 @@ ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
if [ "$HOSTNAME" = "wireguard1" ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WG1PORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WG1PORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
fi
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
then
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
echo "[Interface]" > /etc/wireguard/wg0.conf
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
fi
fi
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
+7 -4
View File
@@ -3,10 +3,13 @@ Description=VPN: Docker Compose Application Service
Requires=docker.service
After=docker.service
[Service]
WorkingDirectory=/root/vpnbot
ExecStart=/bin/sh -c "IP=$(ip -4 addr | sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | awk '{print $1}' | head -1) docker compose up --build --force-recreate"
ExecStop=/usr/bin/docker compose down
Type=oneshot
RemainAfterExit=yes
WorkingDirectory=path
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate"
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
TimeoutStartSec=0
Restart=on-failure
[Install]
WantedBy=multi-user.target
+6
View File
@@ -0,0 +1,6 @@
@url = http://127.0.0.1:8081
###
GET {{url}}/status
###
GET {{url}}/config
+20
View File
@@ -1,3 +1,23 @@
10.03.2024 v1.8.9
- веб морда адгварда "встроена" в телеграм
- мелкие улучшения меню
07.03.2024 v1.8.8
- фикс не работающего wireguard
07.03.2024 v1.8.7
- фикс порта амнезии
- у кого ошибка запуска обновите докер и докер композ
07.03.2024 v1.8.6
- фикс синхронизации клиентов амнезии, бот падал после рестарта, клиенты пропадали
- возможность переназначить порты в override.env, файл не отслеживаемый, обновление не будет его сбрасывать
- убрал дублирование образа php
06.03.2024
- короткие ссылки для амнезии
- фикс работы openconnect
- фикс экспорта пользователей openconnect
- фикс скрипта установки бота как сервиса
04.03.2024
- решение "серого айпи" при запуске
- фикс стартового скрипта второго контейнера wireguard
03.03.2024 возможность обновления бота по кнопке из самого бота
- <code>git pull && make r</code>
02.03.2024 2 сервера wireguard, для возможности один запускать как wireguard а второй как amnezia