Compare commits
23 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7317d418de | |||
| b7a1f9bbd6 | |||
| fcc165b4be | |||
| a9d16eadce | |||
| 82b95ccb85 | |||
| e01ef61b62 | |||
| 367bfc0fbc | |||
| 524c52e326 | |||
| 3bbb8290e5 | |||
| 1e8ac34370 | |||
| 2332e5ea71 | |||
| 796fa57330 | |||
| ce91b1152e | |||
| 64d44428d0 | |||
| 860fdc883f | |||
| f2f2066e99 | |||
| 3e343ce2b7 | |||
| 3c16620a7d | |||
| b1efd9f400 | |||
| cbe0ef8a12 | |||
| 24026d3678 | |||
| dea46815c7 | |||
| 11e34d8c4e |
@@ -8,3 +8,4 @@ TGPORT=4443
|
|||||||
IMAGE=alpine:3.18.2
|
IMAGE=alpine:3.18.2
|
||||||
IP=
|
IP=
|
||||||
VER=
|
VER=
|
||||||
|
ENV=/root/.ashrc
|
||||||
@@ -18,3 +18,5 @@
|
|||||||
mirror/.env
|
mirror/.env
|
||||||
update/*
|
update/*
|
||||||
!update/update.sh
|
!update/update.sh
|
||||||
|
|
||||||
|
override.env
|
||||||
+90
-18
@@ -130,6 +130,9 @@ class Bot
|
|||||||
case preg_match('~^/id$~', $this->input['message'], $m):
|
case preg_match('~^/id$~', $this->input['message'], $m):
|
||||||
$this->send($this->input['chat'], $this->input['from'], $this->input['message_id']);
|
$this->send($this->input['chat'], $this->input['from'], $this->input['message_id']);
|
||||||
break;
|
break;
|
||||||
|
case preg_match('~^/adguardChBr$~', $this->input['callback'], $m):
|
||||||
|
$this->adguardChBr();
|
||||||
|
break;
|
||||||
case preg_match('~^/mtproto$~', $this->input['callback'], $m):
|
case preg_match('~^/mtproto$~', $this->input['callback'], $m):
|
||||||
$this->mtproto();
|
$this->mtproto();
|
||||||
break;
|
break;
|
||||||
@@ -1158,6 +1161,7 @@ class Bot
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
file_put_contents('/config/nginx.conf', $t);
|
file_put_contents('/config/nginx.conf', $t);
|
||||||
|
$this->adguardProtect();
|
||||||
$out[] = $this->ssh("nginx -s reload 2>&1", 'ng');
|
$out[] = $this->ssh("nginx -s reload 2>&1", 'ng');
|
||||||
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
|
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
|
||||||
|
|
||||||
@@ -2181,6 +2185,17 @@ DNS-over-HTTPS with IP:
|
|||||||
$c = $this->getPacConf();
|
$c = $this->getPacConf();
|
||||||
$conf = $this->readConfig();
|
$conf = $this->readConfig();
|
||||||
$status = $this->readStatus();
|
$status = $this->readStatus();
|
||||||
|
if (empty($status)) {
|
||||||
|
return [
|
||||||
|
'text' => "Menu -> " . $this->getTitleWG() . "\n\nerror status",
|
||||||
|
'data' => [[
|
||||||
|
[
|
||||||
|
'text' => $this->i18n('back'),
|
||||||
|
'callback_data' => "/menu",
|
||||||
|
],
|
||||||
|
]],
|
||||||
|
];
|
||||||
|
}
|
||||||
$clients = $this->getClients($page);
|
$clients = $this->getClients($page);
|
||||||
$bt = $c[$this->getInstanceWG(1) . 'blocktorrent'];
|
$bt = $c[$this->getInstanceWG(1) . 'blocktorrent'];
|
||||||
$ex = $c[$this->getInstanceWG(1) . 'exchange'];
|
$ex = $c[$this->getInstanceWG(1) . 'exchange'];
|
||||||
@@ -3075,7 +3090,9 @@ DNS-over-HTTPS with IP:
|
|||||||
],
|
],
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('donate'),
|
'text' => $this->i18n('donate'),
|
||||||
'url' => "https://yoomoney.ru/to/410011827900450",
|
'web_app' => [
|
||||||
|
'url' => "https://www.donationalerts.com/r/mercurykd",
|
||||||
|
]
|
||||||
],
|
],
|
||||||
],
|
],
|
||||||
],
|
],
|
||||||
@@ -3444,37 +3461,95 @@ DNS-over-HTTPS with IP:
|
|||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function adguardProtect()
|
||||||
|
{
|
||||||
|
$h = substr(hash('sha256', $this->key), 0, 8);
|
||||||
|
$s = empty($this->getPacConf()['adgbrowser']) ? '' : '#';
|
||||||
|
$a = $this->adguardBasicAuth();
|
||||||
|
$r = <<<CONF
|
||||||
|
location /adguard/ {
|
||||||
|
access_log /logs/nginx_adguard_access;
|
||||||
|
if (\$cookie_c != "$h") {
|
||||||
|
$s rewrite .* /webapp redirect;
|
||||||
|
}
|
||||||
|
proxy_pass http://ad:80/;
|
||||||
|
proxy_redirect / /adguard/;
|
||||||
|
proxy_cookie_path / /adguard/;
|
||||||
|
proxy_set_header Authorization "Basic \$cookie_a";
|
||||||
|
}
|
||||||
|
location
|
||||||
|
CONF;
|
||||||
|
$f = '/config/nginx.conf';
|
||||||
|
$c = file_get_contents($f);
|
||||||
|
$t = preg_replace('~(location /adguard.+?})\s*location~s', $r, $c);
|
||||||
|
file_put_contents($f, $t);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function adguardBasicAuth()
|
||||||
|
{
|
||||||
|
return base64_encode('admin:' . $this->getPacConf()['adpswd']);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function adguardChBr()
|
||||||
|
{
|
||||||
|
$c = $this->getPacConf();
|
||||||
|
$c['adgbrowser'] = $c['adgbrowser'] ? 0 : 1;
|
||||||
|
$this->setPacConf($c);
|
||||||
|
$this->adguardProtect();
|
||||||
|
$this->ssh('nginx -s reload', 'ng');
|
||||||
|
$this->answer($this->input['callback_id'], $this->i18n($c['adgbrowser'] ? 'browser_notify_on' : 'browser_notify_off'), true);
|
||||||
|
$this->menu('adguard');
|
||||||
|
}
|
||||||
|
|
||||||
public function adguardMenu()
|
public function adguardMenu()
|
||||||
{
|
{
|
||||||
$conf = $this->getPacConf();
|
$conf = $this->getPacConf();
|
||||||
$ip = $this->ip;
|
$ip = $this->ip;
|
||||||
$domain = $conf['domain'] ?: $ip;
|
$domain = $conf['domain'] ?: $ip;
|
||||||
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
|
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||||
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
|
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
|
||||||
if ($ssl) {
|
if ($ssl) {
|
||||||
$text .= "DNS over HTTPS:\n<code>$ip</code>\n<code>$scheme://$domain/dns-query" . ($conf['adguardkey'] ? "/{$conf['adguardkey']}" : '') . "</code>\n\n";
|
$text .= "DNS over HTTPS:\n<code>$ip</code>\n<code>$scheme://$domain/dns-query" . ($conf['adguardkey'] ? "/{$conf['adguardkey']}" : '') . "</code>\n\n";
|
||||||
$text .= "DNS over TLS:\n<code>tls://" . ($conf['adguardkey'] ? "{$conf['adguardkey']}." : '') . "$domain</code>";
|
$text .= "DNS over TLS:\n<code>tls://" . ($conf['adguardkey'] ? "{$conf['adguardkey']}." : '') . "$domain</code>";
|
||||||
}
|
}
|
||||||
$data = [
|
$data = [
|
||||||
|
[
|
||||||
|
[
|
||||||
|
'text' => 'web panel',
|
||||||
|
'web_app' => [
|
||||||
|
"url" => "https://$domain/adguard"
|
||||||
|
],
|
||||||
|
],
|
||||||
|
[
|
||||||
|
'text' => $this->i18n('third party browser') . ': ' . $this->i18n($conf['adgbrowser'] ? 'on' : 'off'),
|
||||||
|
'callback_data' => '/adguardChBr'
|
||||||
|
],
|
||||||
|
],
|
||||||
[
|
[
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('change password'),
|
'text' => $this->i18n('change password'),
|
||||||
'callback_data' => "/adguardpsswd",
|
'callback_data' => "/adguardpsswd",
|
||||||
],
|
],
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('reset settings'),
|
'text' => 'ClientID' . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
|
||||||
'callback_data' => "/adguardreset",
|
'callback_data' => "/setAdguardKey",
|
||||||
],
|
],
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
|
$data[] = [
|
||||||
|
[
|
||||||
|
'text' => $this->i18n('reset settings'),
|
||||||
|
'callback_data' => "/adguardreset",
|
||||||
|
],
|
||||||
|
];
|
||||||
$data[] = [
|
$data[] = [
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('add upstream'),
|
'text' => $this->i18n('add upstream'),
|
||||||
'callback_data' => "/addupstream",
|
'callback_data' => "/addupstream",
|
||||||
],
|
],
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('setSecret') . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
|
'text' => $this->i18n('check DNS'),
|
||||||
'callback_data' => "/setAdguardKey",
|
'callback_data' => "/checkdns",
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
$upstreams = yaml_parse_file($this->adguard)['dns']['upstream_dns'];
|
$upstreams = yaml_parse_file($this->adguard)['dns']['upstream_dns'];
|
||||||
@@ -3492,12 +3567,6 @@ DNS-over-HTTPS with IP:
|
|||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
$data[] = [
|
|
||||||
[
|
|
||||||
'text' => $this->i18n('check DNS'),
|
|
||||||
'callback_data' => "/checkdns",
|
|
||||||
],
|
|
||||||
];
|
|
||||||
$data[] = [
|
$data[] = [
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('back'),
|
'text' => $this->i18n('back'),
|
||||||
@@ -3557,8 +3626,11 @@ DNS-over-HTTPS with IP:
|
|||||||
|
|
||||||
public function configMenu()
|
public function configMenu()
|
||||||
{
|
{
|
||||||
$conf = $this->getPacConf();
|
$conf = $this->getPacConf();
|
||||||
$text = $this->i18n('domain explain');
|
$text[] = $conf['domain'] ? "Domains:\n{$conf['domain']}\nnp.{$conf['domain']}\noc.{$conf['domain']}" . ($conf['adguardkey'] ? "\n{$conf['adguardkey']}.{$conf['domain']}" : '') : $this->i18n('domain explain');
|
||||||
|
$ssl = $this->expireCert();
|
||||||
|
$text[] = $conf['domain'] ? "\nSSL: " . ($ssl ? date('Y-m-d H:i:s', $this->expireCert()) : 'none') : '';
|
||||||
|
|
||||||
$data = [
|
$data = [
|
||||||
[
|
[
|
||||||
[
|
[
|
||||||
@@ -3573,7 +3645,7 @@ DNS-over-HTTPS with IP:
|
|||||||
case 'letsencrypt':
|
case 'letsencrypt':
|
||||||
$data[] = [
|
$data[] = [
|
||||||
[
|
[
|
||||||
'text' => $this->i18n('renew SSL') . ': ' . date('Y-m-d H:i:s', $this->expireCert()),
|
'text' => $this->i18n('renew SSL'),
|
||||||
'callback_data' => "/setSSL letsencrypt",
|
'callback_data' => "/setSSL letsencrypt",
|
||||||
],
|
],
|
||||||
[
|
[
|
||||||
@@ -3678,7 +3750,7 @@ DNS-over-HTTPS with IP:
|
|||||||
],
|
],
|
||||||
];
|
];
|
||||||
return [
|
return [
|
||||||
'text' => $text,
|
'text' => implode("\n", $text),
|
||||||
'data' => $data,
|
'data' => $data,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
@@ -4060,8 +4132,8 @@ DNS-over-HTTPS with IP:
|
|||||||
$this->wg = $i;
|
$this->wg = $i;
|
||||||
$clients = $this->readClients();
|
$clients = $this->readClients();
|
||||||
foreach ($clients as $k => $v) {
|
foreach ($clients as $k => $v) {
|
||||||
foreach ($v['peers'] as $i => $j) {
|
foreach ($v['peers'] as $n => $j) {
|
||||||
$clients[$k]['peers'][$i]['Endpoint'] = $endpoint[$i];
|
$clients[$k]['peers'][$n]['Endpoint'] = $endpoint[$i];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
$this->saveClients($clients);
|
$this->saveClients($clients);
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
require './config.php';
|
||||||
|
|
||||||
|
$ch = curl_init();
|
||||||
|
curl_setopt_array($ch, [
|
||||||
|
CURLOPT_URL => "https://api.telegram.org/bot{$c['key']}/getWebhookInfo",
|
||||||
|
CURLOPT_RETURNTRANSFER => true,
|
||||||
|
]);
|
||||||
|
$res = curl_exec($ch);
|
||||||
|
die(var_dump($res));
|
||||||
@@ -305,4 +305,16 @@ $i = [
|
|||||||
'en' => 'update bot',
|
'en' => 'update bot',
|
||||||
'ru' => 'обновить бота',
|
'ru' => 'обновить бота',
|
||||||
],
|
],
|
||||||
|
'third party browser' => [
|
||||||
|
'en' => 'third party browser',
|
||||||
|
'ru' => 'сторонний браузер',
|
||||||
|
],
|
||||||
|
'browser_notify_on' => [
|
||||||
|
'en' => 'the web panel can now be opened in any browser',
|
||||||
|
'ru' => 'веб панель теперь может быть открыта в любом браузере',
|
||||||
|
],
|
||||||
|
'browser_notify_off' => [
|
||||||
|
'en' => 'the web panel can no longer be opened in any browser',
|
||||||
|
'ru' => 'веб панель теперь не может быть открыта в любом браузере',
|
||||||
|
],
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -42,6 +42,24 @@ if ($hash == substr(md5($c['key']), 0, 8)) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (!empty($_GET['hash'])) {
|
||||||
|
$t = $_GET;
|
||||||
|
unset($t['hash']);
|
||||||
|
ksort($t);
|
||||||
|
foreach ($t as $k => $v) {
|
||||||
|
$s[] = "$k=$v";
|
||||||
|
}
|
||||||
|
$s = implode("\n", $s);
|
||||||
|
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
|
||||||
|
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
|
||||||
|
require __DIR__ . '/bot.php';
|
||||||
|
require __DIR__ . '/i18n.php';
|
||||||
|
$bot = new Bot($c['key'], $i);
|
||||||
|
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
|
||||||
|
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
|
||||||
|
die('ok');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
header('500', true, 500);
|
header('500', true, 500);
|
||||||
exit;
|
exit;
|
||||||
|
|||||||
+2
-1
@@ -8,6 +8,7 @@ require __DIR__ . '/config.php';
|
|||||||
require __DIR__ . '/i18n.php';
|
require __DIR__ . '/i18n.php';
|
||||||
|
|
||||||
$bot = new Bot($c['key'], $i);
|
$bot = new Bot($c['key'], $i);
|
||||||
$bot->setwebhook();
|
$bot->adguardProtect();
|
||||||
$bot->setcommands();
|
$bot->setcommands();
|
||||||
$bot->syncPortClients();
|
$bot->syncPortClients();
|
||||||
|
$bot->setwebhook();
|
||||||
|
|||||||
@@ -0,0 +1,24 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<script src="https://telegram.org/js/telegram-web-app.js"></script>
|
||||||
|
<script src="jquery-3.7.1.min.js"></script>
|
||||||
|
<title>Document</title>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<script>
|
||||||
|
var tg = window.Telegram.WebApp;
|
||||||
|
jQuery(function($) {
|
||||||
|
$.ajax({
|
||||||
|
'url': 'check?' + tg.initData,
|
||||||
|
}).done(function (r) {
|
||||||
|
location.replace('/adguard/');
|
||||||
|
}).fail(function (r) {
|
||||||
|
location.replace('/');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
</script>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
Vendored
+2
File diff suppressed because one or more lines are too long
@@ -38,6 +38,12 @@ http {
|
|||||||
proxy_redirect / /adguard/;
|
proxy_redirect / /adguard/;
|
||||||
proxy_cookie_path / /adguard/;
|
proxy_cookie_path / /adguard/;
|
||||||
}
|
}
|
||||||
|
location /webapp {
|
||||||
|
access_log /logs/nginx_webapp_access;
|
||||||
|
alias /app;
|
||||||
|
index index.html;
|
||||||
|
try_files $uri $uri/ /pac?$query_string;
|
||||||
|
}
|
||||||
location /pac {
|
location /pac {
|
||||||
access_log /logs/nginx_pac_access;
|
access_log /logs/nginx_pac_access;
|
||||||
proxy_pass http://php;
|
proxy_pass http://php;
|
||||||
@@ -88,6 +94,12 @@ http {
|
|||||||
# proxy_redirect / /adguard/;
|
# proxy_redirect / /adguard/;
|
||||||
# proxy_cookie_path / /adguard/;
|
# proxy_cookie_path / /adguard/;
|
||||||
# }
|
# }
|
||||||
|
# location /webapp {
|
||||||
|
# access_log /logs/nginx_webapp_access;
|
||||||
|
# alias /app;
|
||||||
|
# index index.html;
|
||||||
|
# try_files $uri $uri/ /pac?$query_string;
|
||||||
|
# }
|
||||||
# location /pac {
|
# location /pac {
|
||||||
# access_log /logs/nginx_pac_access;
|
# access_log /logs/nginx_pac_access;
|
||||||
# proxy_pass http://php;
|
# proxy_pass http://php;
|
||||||
|
|||||||
@@ -38,6 +38,12 @@ http {
|
|||||||
proxy_redirect / /adguard/;
|
proxy_redirect / /adguard/;
|
||||||
proxy_cookie_path / /adguard/;
|
proxy_cookie_path / /adguard/;
|
||||||
}
|
}
|
||||||
|
location /webapp {
|
||||||
|
access_log /logs/nginx_webapp_access;
|
||||||
|
alias /app;
|
||||||
|
index index.html;
|
||||||
|
try_files $uri $uri/ /pac?$query_string;
|
||||||
|
}
|
||||||
location /pac {
|
location /pac {
|
||||||
access_log /logs/nginx_pac_access;
|
access_log /logs/nginx_pac_access;
|
||||||
proxy_pass http://php;
|
proxy_pass http://php;
|
||||||
@@ -88,6 +94,12 @@ http {
|
|||||||
# proxy_redirect / /adguard/;
|
# proxy_redirect / /adguard/;
|
||||||
# proxy_cookie_path / /adguard/;
|
# proxy_cookie_path / /adguard/;
|
||||||
# }
|
# }
|
||||||
|
# location /webapp {
|
||||||
|
# access_log /logs/nginx_webapp_access;
|
||||||
|
# alias /app;
|
||||||
|
# index index.html;
|
||||||
|
# try_files $uri $uri/ /pac?$query_string;
|
||||||
|
# }
|
||||||
# location /pac {
|
# location /pac {
|
||||||
# access_log /logs/nginx_pac_access;
|
# access_log /logs/nginx_pac_access;
|
||||||
# proxy_pass http://php;
|
# proxy_pass http://php;
|
||||||
|
|||||||
+69
-42
@@ -41,8 +41,11 @@ services:
|
|||||||
condition: service_started
|
condition: service_started
|
||||||
ss:
|
ss:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_upstream.sh"]
|
command: ["/bin/sh", "/start_upstream.sh"]
|
||||||
networks:
|
networks:
|
||||||
@@ -66,6 +69,7 @@ services:
|
|||||||
- ./ssh:/ssh
|
- ./ssh:/ssh
|
||||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||||
- ./logs/:/logs/
|
- ./logs/:/logs/
|
||||||
|
- ./app/webapp:/app
|
||||||
ports:
|
ports:
|
||||||
- 80:80
|
- 80:80
|
||||||
hostname: nginx
|
hostname: nginx
|
||||||
@@ -73,9 +77,11 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
up:
|
up:
|
||||||
condition: service_started
|
condition: service_started
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
SSPORT: ${SSPORT}
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_ng.sh"]
|
command: ["/bin/sh", "/start_ng.sh"]
|
||||||
networks:
|
networks:
|
||||||
@@ -88,6 +94,8 @@ services:
|
|||||||
dockerfile: dockerfile/php.dockerfile
|
dockerfile: dockerfile/php.dockerfile
|
||||||
args:
|
args:
|
||||||
image: ${IMAGE}
|
image: ${IMAGE}
|
||||||
|
ports:
|
||||||
|
- 127.0.0.1:8081:8080
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/.profile:/root/.ashrc:ro
|
- ./config/.profile:/root/.ashrc:ro
|
||||||
- ./config/php.ini:/etc/php81/php.ini
|
- ./config/php.ini:/etc/php81/php.ini
|
||||||
@@ -103,15 +111,13 @@ services:
|
|||||||
- ./.env:/mirror/.env
|
- ./.env:/mirror/.env
|
||||||
- ./update:/update
|
- ./update:/update
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
|
||||||
IP: ${IP}
|
IP: ${IP}
|
||||||
ADDRESS: ${WGADDRESS}
|
|
||||||
WGPORT: ${WGPORT}
|
|
||||||
WG1ADDRESS: ${WG1ADDRESS}
|
|
||||||
WG1PORT: ${WG1PORT}
|
|
||||||
SSPORT: ${SSPORT}
|
|
||||||
TGPORT: ${TGPORT}
|
|
||||||
VER: ${VER}
|
VER: ${VER}
|
||||||
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
hostname: php
|
hostname: php
|
||||||
container_name: php-${VER}
|
container_name: php-${VER}
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
@@ -130,7 +136,7 @@ services:
|
|||||||
timeout: 5s
|
timeout: 5s
|
||||||
retries: 5
|
retries: 5
|
||||||
service:
|
service:
|
||||||
image: mercurykd/vpnbot-php:1.1
|
image: mercurykd/vpnbot-php:1.2
|
||||||
build:
|
build:
|
||||||
dockerfile: dockerfile/php.dockerfile
|
dockerfile: dockerfile/php.dockerfile
|
||||||
args:
|
args:
|
||||||
@@ -146,15 +152,13 @@ services:
|
|||||||
- ./update:/update
|
- ./update:/update
|
||||||
- ./scripts/start_service.sh:/start_service.sh
|
- ./scripts/start_service.sh:/start_service.sh
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
|
||||||
IP: ${IP}
|
IP: ${IP}
|
||||||
ADDRESS: ${WGADDRESS}
|
|
||||||
WGPORT: ${WGPORT}
|
|
||||||
WG1ADDRESS: ${WG1ADDRESS}
|
|
||||||
WG1PORT: ${WG1PORT}
|
|
||||||
SSPORT: ${SSPORT}
|
|
||||||
TGPORT: ${TGPORT}
|
|
||||||
VER: ${VER}
|
VER: ${VER}
|
||||||
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
hostname: service
|
hostname: service
|
||||||
container_name: service-${VER}
|
container_name: service-${VER}
|
||||||
# restart: unless-stopped
|
# restart: unless-stopped
|
||||||
@@ -200,7 +204,11 @@ services:
|
|||||||
ipv4_address: 10.10.0.3
|
ipv4_address: 10.10.0.3
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
TZ: ${TZ}
|
||||||
SSPORT: ${SSPORT}
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_proxy.sh"]
|
command: ["/bin/sh", "/start_proxy.sh"]
|
||||||
logging: *default-logging
|
logging: *default-logging
|
||||||
@@ -227,11 +235,13 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
ports:
|
||||||
- ${WGPORT}:${WGPORT}/udp
|
- ${WGPORT}:${WGPORT}/udp
|
||||||
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
|
||||||
WGPORT: ${WGPORT}
|
|
||||||
ADDRESS: ${WGADDRESS}
|
ADDRESS: ${WGADDRESS}
|
||||||
ENV: /root/.ashrc
|
|
||||||
cap_add:
|
cap_add:
|
||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
devices:
|
devices:
|
||||||
@@ -265,11 +275,13 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
ports:
|
ports:
|
||||||
- ${WG1PORT}:${WG1PORT}/udp
|
- ${WG1PORT}:${WG1PORT}/udp
|
||||||
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
|
||||||
WGPORT: ${WG1PORT}
|
|
||||||
ADDRESS: ${WG1ADDRESS}
|
ADDRESS: ${WG1ADDRESS}
|
||||||
ENV: /root/.ashrc
|
|
||||||
cap_add:
|
cap_add:
|
||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
devices:
|
devices:
|
||||||
@@ -304,8 +316,11 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
networks:
|
networks:
|
||||||
default:
|
default:
|
||||||
@@ -334,9 +349,11 @@ services:
|
|||||||
ports:
|
ports:
|
||||||
- ${SSPORT}:${SSPORT}/tcp
|
- ${SSPORT}:${SSPORT}/tcp
|
||||||
- ${SSPORT}:${SSPORT}/udp
|
- ${SSPORT}:${SSPORT}/udp
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
SSPORT: ${SSPORT}
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_ss.sh"]
|
command: ["/bin/sh", "/start_ss.sh"]
|
||||||
networks:
|
networks:
|
||||||
@@ -361,9 +378,12 @@ services:
|
|||||||
ports:
|
ports:
|
||||||
- ${TGPORT}:${TGPORT}
|
- ${TGPORT}:${TGPORT}
|
||||||
environment:
|
environment:
|
||||||
TZ: ${TZ}
|
|
||||||
IP: ${IP}
|
IP: ${IP}
|
||||||
TGPORT: ${TGPORT}
|
env_file:
|
||||||
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_tg.sh"]
|
command: ["/bin/sh", "/start_tg.sh"]
|
||||||
networks:
|
networks:
|
||||||
@@ -387,8 +407,11 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_xray.sh"]
|
command: ["/bin/sh", "/start_xray.sh"]
|
||||||
networks:
|
networks:
|
||||||
@@ -413,9 +436,11 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
ENV: /root/.ashrc
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_oc.sh"]
|
command: ["/bin/sh", "/start_oc.sh"]
|
||||||
cap_add:
|
cap_add:
|
||||||
@@ -444,9 +469,11 @@ services:
|
|||||||
depends_on:
|
depends_on:
|
||||||
php:
|
php:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
environment:
|
env_file:
|
||||||
TZ: ${TZ}
|
- path: ./.env
|
||||||
ENV: /root/.ashrc
|
required: true # default
|
||||||
|
- path: ./override.env
|
||||||
|
required: false
|
||||||
stop_grace_period: 1s
|
stop_grace_period: 1s
|
||||||
command: ["/bin/sh", "/start_np.sh"]
|
command: ["/bin/sh", "/start_np.sh"]
|
||||||
cap_add:
|
cap_add:
|
||||||
|
|||||||
@@ -2,7 +2,8 @@ b:
|
|||||||
docker compose build
|
docker compose build
|
||||||
u: # запуск контейнеров
|
u: # запуск контейнеров
|
||||||
bash ./update/update.sh &
|
bash ./update/update.sh &
|
||||||
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose up -d --force-recreate
|
touch ./override.env
|
||||||
|
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||||
d: # остановка контейнеров
|
d: # остановка контейнеров
|
||||||
-kill -9 $(shell cat ./update/update_pid) > /dev/null
|
-kill -9 $(shell cat ./update/update_pid) > /dev/null
|
||||||
docker compose down --remove-orphans
|
docker compose down --remove-orphans
|
||||||
@@ -55,4 +56,6 @@ s:
|
|||||||
c:
|
c:
|
||||||
git add config/
|
git add config/
|
||||||
git checkout .
|
git checkout .
|
||||||
git reset
|
git reset
|
||||||
|
webhook:
|
||||||
|
docker compose exec php php checkwebhook.php
|
||||||
@@ -62,19 +62,17 @@ telegram bot to manage servers (inside the bot)
|
|||||||
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
|
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
|
||||||
|
|
||||||
---
|
---
|
||||||
environment: ubuntu 18.04/20.04/22.04, debian 11
|
environment: ubuntu 18.04/20.04/22.04, debian 11/12
|
||||||
|
|
||||||
install:
|
### Install:
|
||||||
|
|
||||||
`wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY`
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
additional options:
|
|
||||||
|
|
||||||
install as service(autoload on start):
|
|
||||||
|
|
||||||
|
```shell
|
||||||
|
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Install as service (autoload on start):
|
||||||
|
|
||||||
|
```shell
|
||||||
cd /root/vpnbot
|
cd /root/vpnbot
|
||||||
bash scripts/install_as_service.sh
|
bash scripts/install_as_service.sh
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
cp scripts/vpnbot.service /etc/systemd/system/vpnbot.service
|
path=`pwd`
|
||||||
|
sed "s|path|$path|g" "$path/scripts/vpnbot.service" > /etc/systemd/system/vpnbot.service
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
systemctl enable vpnbot
|
systemctl enable vpnbot
|
||||||
|
|||||||
@@ -6,4 +6,4 @@ php cron.php &
|
|||||||
unitd --log /logs/unit_error
|
unitd --log /logs/unit_error
|
||||||
curl -X PUT --data-binary @/config/unit.json --unix-socket /var/run/control.unit.sock http://localhost/config
|
curl -X PUT --data-binary @/config/unit.json --unix-socket /var/run/control.unit.sock http://localhost/config
|
||||||
pkill unitd
|
pkill unitd
|
||||||
unitd --no-daemon --log /logs/unit_error
|
unitd --no-daemon --control 0.0.0.0:8080 --log /logs/unit_error
|
||||||
|
|||||||
+23
-8
@@ -3,16 +3,31 @@ ssh-keygen -A
|
|||||||
exec /usr/sbin/sshd -D -e "$@" &
|
exec /usr/sbin/sshd -D -e "$@" &
|
||||||
|
|
||||||
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
|
INTERFACE=$(route | grep '^default' | grep -o '[^ ]*$')
|
||||||
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
|
if [ "$HOSTNAME" = "wireguard1" ]
|
||||||
then
|
then
|
||||||
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
|
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
|
||||||
echo "[Interface]" > /etc/wireguard/wg0.conf
|
then
|
||||||
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
|
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
|
||||||
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
|
echo "[Interface]" > /etc/wireguard/wg0.conf
|
||||||
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
|
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
|
||||||
|
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
|
||||||
|
echo "ListenPort = $WG1PORT" >> /etc/wireguard/wg0.conf
|
||||||
|
else
|
||||||
|
sed "s/ListenPort = [0-9]\+/ListenPort = $WG1PORT/" /etc/wireguard/wg0.conf > change_port
|
||||||
|
cat change_port > /etc/wireguard/wg0.conf
|
||||||
|
fi
|
||||||
else
|
else
|
||||||
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
|
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
|
||||||
cat change_port > /etc/wireguard/wg0.conf
|
then
|
||||||
|
PRIVATEKEY=$(wg genkey | tee /etc/wireguard/privatekey)
|
||||||
|
echo "[Interface]" > /etc/wireguard/wg0.conf
|
||||||
|
echo "PrivateKey = $PRIVATEKEY" >> /etc/wireguard/wg0.conf
|
||||||
|
echo "Address = $ADDRESS" >> /etc/wireguard/wg0.conf
|
||||||
|
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
|
||||||
|
else
|
||||||
|
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
|
||||||
|
cat change_port > /etc/wireguard/wg0.conf
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
|
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
|
||||||
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
|
iptables -t nat -A POSTROUTING -o $INTERFACE -j MASQUERADE
|
||||||
|
|||||||
@@ -5,8 +5,9 @@ After=docker.service
|
|||||||
[Service]
|
[Service]
|
||||||
Type=oneshot
|
Type=oneshot
|
||||||
RemainAfterExit=yes
|
RemainAfterExit=yes
|
||||||
WorkingDirectory=/root/vpnbot
|
WorkingDirectory=path
|
||||||
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate"
|
ExecStartPre=/bin/sh -c "touch ./override.env"
|
||||||
|
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate"
|
||||||
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
|
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
|
||||||
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
|
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
|
||||||
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
|
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
@url = http://127.0.0.1:8081
|
||||||
|
###
|
||||||
|
|
||||||
|
GET {{url}}/status
|
||||||
|
###
|
||||||
|
GET {{url}}/config
|
||||||
@@ -1,3 +1,17 @@
|
|||||||
|
13.03.2024 v1.8.10
|
||||||
|
- фикс override.env
|
||||||
|
10.03.2024 v1.8.9
|
||||||
|
- веб морда адгварда "встроена" в телеграм
|
||||||
|
- мелкие улучшения меню
|
||||||
|
07.03.2024 v1.8.8
|
||||||
|
- фикс не работающего wireguard
|
||||||
|
07.03.2024 v1.8.7
|
||||||
|
- фикс порта амнезии
|
||||||
|
- у кого ошибка запуска обновите докер и докер композ
|
||||||
|
07.03.2024 v1.8.6
|
||||||
|
- фикс синхронизации клиентов амнезии, бот падал после рестарта, клиенты пропадали
|
||||||
|
- возможность переназначить порты в override.env, файл не отслеживаемый, обновление не будет его сбрасывать
|
||||||
|
- убрал дублирование образа php
|
||||||
06.03.2024
|
06.03.2024
|
||||||
- короткие ссылки для амнезии
|
- короткие ссылки для амнезии
|
||||||
- фикс работы openconnect
|
- фикс работы openconnect
|
||||||
|
|||||||
Reference in New Issue
Block a user