Compare commits

...

24 Commits

Author SHA1 Message Date
mercury 7d12e5c972 improve update script 2024-03-21 01:36:11 +04:00
mercury 2efcea9dbe improve update script 2024-03-21 01:27:06 +04:00
mercury 5b1bf2b3d5 switch branches after update 2024-03-21 01:19:19 +04:00
mercury 9f1b3d84f4 XTLS-Reality steal from yourself 2024-03-20 22:36:06 +04:00
mercury e81c6a5dfb update version 2024-03-18 10:03:57 +04:00
mercury c00dafa6d1 fix port mtproto 2024-03-18 01:59:12 +04:00
mercury cab00f4aed fake tls mtproto 2024-03-18 01:53:22 +04:00
mercury 4082dac97b sslip.io 2024-03-17 17:50:09 +04:00
mercury 7317d418de update version 2024-03-13 22:59:39 +04:00
mercury b7a1f9bbd6 fix override.env in service 2024-03-10 16:57:42 +04:00
mercury fcc165b4be fix override.env 2024-03-10 16:49:19 +04:00
mercury a9d16eadce fix adguard menu 2024-03-10 15:31:40 +04:00
mercury 82b95ccb85 web app for donate 2024-03-10 13:10:35 +04:00
mercury e01ef61b62 protect adguard on backup restore 2024-03-10 13:01:32 +04:00
mercury 367bfc0fbc web panel config 2024-03-10 12:45:42 +04:00
mercury 524c52e326 web panel adguard 2024-03-10 12:39:30 +04:00
mercury 3bbb8290e5 improve settings menu 2024-03-07 19:27:40 +04:00
mercury 1e8ac34370 Merge branch 'master' into dev 2024-03-07 19:13:19 +04:00
Konstantin 2332e5ea71 Merge pull request #9 from 13f66cd22a80/master 2024-03-07 19:09:35 +04:00
mercury 796fa57330 improve status wg error 2024-03-07 19:00:33 +04:00
Jeff Scrum ce91b1152e Update readme.md 2024-03-07 14:44:29 +03:00
mercury 64d44428d0 update version 2024-03-07 14:34:48 +04:00
mercury 860fdc883f fix environment for wg 2024-03-07 14:32:52 +04:00
mercury f2f2066e99 update version 2024-03-07 13:21:46 +04:00
20 changed files with 500 additions and 66 deletions
+220 -31
View File
@@ -5,6 +5,7 @@ class Bot
public $input;
public $adguard;
public $update;
public $ip;
public function __construct($key, $i18n)
{
@@ -130,12 +131,21 @@ class Bot
case preg_match('~^/id$~', $this->input['message'], $m):
$this->send($this->input['chat'], $this->input['from'], $this->input['message_id']);
break;
case preg_match('~^/adguardChBr$~', $this->input['callback'], $m):
$this->adguardChBr();
break;
case preg_match('~^/mtproto$~', $this->input['callback'], $m):
$this->mtproto();
break;
case preg_match('~^/updatebot$~', $this->input['callback'], $m):
$this->updatebot();
break;
case preg_match('~^/branches$~', $this->input['callback'], $m):
$this->branches();
break;
case preg_match('~^/changeBranch (\d+)$~', $this->input['callback'], $m):
$this->changeBranch($m[1]);
break;
case preg_match('~^/getMirror$~', $this->input['callback'], $m):
$this->getMirror();
break;
@@ -332,6 +342,12 @@ class Bot
case preg_match('~^/changeFakeDomain$~', $this->input['callback'], $m):
$this->changeFakeDomain();
break;
case preg_match('~^/selfFakeDomain$~', $this->input['callback'], $m):
$this->selfFakeDomain();
break;
case preg_match('~^/changeTGDomain$~', $this->input['callback'], $m):
$this->changeTGDomain();
break;
case preg_match('~^/include (\d+)$~', $this->input['callback'], $m):
$this->include($m[1]);
break;
@@ -397,17 +413,26 @@ class Bot
public function secretSet($secret)
{
$this->restartTG($secret);
file_put_contents('/config/mtprotosecret', $secret);
$this->restartTG();
$this->mtproto();
}
public function restartTG($secret)
public function setTelegramDomain($domain)
{
file_put_contents('/config/mtprotosecret', $secret ?: '');
file_put_contents('/config/mtprotodomain', $domain);
$this->restartTG();
$this->mtproto();
}
public function restartTG()
{
$secret = file_get_contents('/config/mtprotosecret');
$fakedomain = file_get_contents('/config/mtprotodomain') ?: 'vk.com';
$this->ssh('pkill mtproto-proxy', 'tg');
if (preg_match('~^\w{32}$~', $secret)) {
$p = getenv('TGPORT');
$this->ssh("mtproto-proxy -u nobody -H $p --nat-info 10.10.0.8:{$this->ip} -S $secret --aes-pwd /proxy-secret /proxy-multi.conf -M 1 >/dev/null 2>&1 &", 'tg');
$this->ssh("mtproto-proxy --domain $fakedomain -u nobody -H $p --nat-info 10.10.0.8:{$this->ip} -S $secret --aes-pwd /proxy-secret /proxy-multi.conf -M 1 >/dev/null 2>&1 &", 'tg');
}
}
@@ -422,18 +447,22 @@ class Bot
{
$s = file_get_contents('/config/mtprotosecret');
$p = getenv('TGPORT');
$d = trim(file_get_contents('/config/mtprotodomain') ?: 'vk.com');
$d = exec("echo $d | tr -d '\\n' | xxd -ps -c 200");
$ip = $this->getPacConf()['domain'] ?: $this->ip;
return "https://t.me/proxy?server=$ip&port=$p&secret=$s";
return "https://t.me/proxy?server=$ip&port=$p&secret=ee$s$d";
}
public function mtproto()
{
$s = file_get_contents('/config/mtprotosecret');
$d = file_get_contents('/config/mtprotodomain') ?: 'vk.com';
$p = getenv('TGPORT');
$ip = $this->getPacConf()['domain'] ?: $this->ip;
$st = $this->ssh('pgrep mtproto-proxy', 'tg') ? 'on' : 'off';
$text[] = "Menu -> MTProto\n";
$text[] = "status: $st\n";
$text[] = "fake domain: <code>$d</code>\n";
if ($st == 'on') {
$text[] = $this->linkMtproto();
}
@@ -449,6 +478,12 @@ class Bot
'callback_data' => "/setSecret",
],
];
$data[] = [
[
'text' => $this->i18n('changeFakeDomain'),
'callback_data' => "/changeTGDomain",
],
];
$data[] = [
[
'text' => $this->i18n('show QR'),
@@ -1002,10 +1037,11 @@ class Bot
'private' => file_get_contents('/certs/cert_private'),
'public' => file_get_contents('/certs/cert_public'),
] : false,
'mtproto' => file_get_contents('/config/mtprotosecret'),
'xray' => json_decode(file_get_contents('/config/xray.json'), true),
'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
'mtproto' => file_get_contents('/config/mtprotosecret'),
'mtprotodomain' => file_get_contents('/config/mtprotodomain'),
'xray' => json_decode(file_get_contents('/config/xray.json'), true),
'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
];
return json_encode($conf, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
@@ -1117,7 +1153,9 @@ class Bot
if (!empty($json['mtproto'])) {
$out[] = 'update mtproto';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->restartTG($json['mtproto']);
file_put_contents('/config/mtprotosecret', $json['mtproto']);
file_put_contents('/config/mtprotodomain', $json['mtprotodomain'] ?: '');
$this->restartTG();
}
// xray
if (!empty($json['xray'])) {
@@ -1158,6 +1196,7 @@ class Bot
}
}
file_put_contents('/config/nginx.conf', $t);
$this->adguardProtect();
$out[] = $this->ssh("nginx -s reload 2>&1", 'ng');
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
@@ -1447,7 +1486,7 @@ class Bot
}
}
public function addDomain($domain)
public function addDomain($domain, $nomenu = false)
{
$domain = trim($domain);
if (!empty($domain)) {
@@ -1474,8 +1513,21 @@ class Bot
file_put_contents('/config/nginx.conf', $nginx);
}
}
sleep(3);
$this->menu('config');
if (empty($nomenu)) {
sleep(3);
$this->menu('config');
}
}
public function sslip()
{
$c = $this->getPacConf();
if (empty($c['domain'])) {
$this->addDomain(str_replace('.', '-', $this->ip) . '.sslip.io', 1);
$this->setSSL('letsencrypt');
} else {
$this->menu();
}
}
public function comment($text, $tag)
@@ -2181,6 +2233,17 @@ DNS-over-HTTPS with IP:
$c = $this->getPacConf();
$conf = $this->readConfig();
$status = $this->readStatus();
if (empty($status)) {
return [
'text' => "Menu -> " . $this->getTitleWG() . "\n\nerror status",
'data' => [[
[
'text' => $this->i18n('back'),
'callback_data' => "/menu",
],
]],
];
}
$clients = $this->getClients($page);
$bt = $c[$this->getInstanceWG(1) . 'blocktorrent'];
$ex = $c[$this->getInstanceWG(1) . 'exchange'];
@@ -3075,7 +3138,9 @@ DNS-over-HTTPS with IP:
],
[
'text' => $this->i18n('donate'),
'url' => "https://yoomoney.ru/to/410011827900450",
'web_app' => [
'url' => "https://www.donationalerts.com/r/mercurykd",
]
],
],
],
@@ -3333,6 +3398,10 @@ DNS-over-HTTPS with IP:
'text' => $this->i18n('changeFakeDomain'),
'callback_data' => "/changeFakeDomain",
],
[
'text' => $this->i18n('selfFakeDomain'),
'callback_data' => "/selfFakeDomain",
],
];
if ($c['inbounds'][0]['settings']['clients'][0]['id']) {
$data[] = [
@@ -3444,37 +3513,95 @@ DNS-over-HTTPS with IP:
];
}
public function adguardProtect()
{
$h = substr(hash('sha256', $this->key), 0, 8);
$s = empty($this->getPacConf()['adgbrowser']) ? '' : '#';
$a = $this->adguardBasicAuth();
$r = <<<CONF
location /adguard/ {
access_log /logs/nginx_adguard_access;
if (\$cookie_c != "$h") {
$s rewrite .* /webapp redirect;
}
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
proxy_set_header Authorization "Basic \$cookie_a";
}
location
CONF;
$f = '/config/nginx.conf';
$c = file_get_contents($f);
$t = preg_replace('~(location /adguard.+?})\s*location~s', $r, $c);
file_put_contents($f, $t);
}
public function adguardBasicAuth()
{
return base64_encode('admin:' . $this->getPacConf()['adpswd']);
}
public function adguardChBr()
{
$c = $this->getPacConf();
$c['adgbrowser'] = $c['adgbrowser'] ? 0 : 1;
$this->setPacConf($c);
$this->adguardProtect();
$this->ssh('nginx -s reload', 'ng');
$this->answer($this->input['callback_id'], $this->i18n($c['adgbrowser'] ? 'browser_notify_on' : 'browser_notify_off'), true);
$this->menu('adguard');
}
public function adguardMenu()
{
$conf = $this->getPacConf();
$ip = $this->ip;
$domain = $conf['domain'] ?: $ip;
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
if ($ssl) {
$text .= "DNS over HTTPS:\n<code>$ip</code>\n<code>$scheme://$domain/dns-query" . ($conf['adguardkey'] ? "/{$conf['adguardkey']}" : '') . "</code>\n\n";
$text .= "DNS over TLS:\n<code>tls://" . ($conf['adguardkey'] ? "{$conf['adguardkey']}." : '') . "$domain</code>";
}
$data = [
[
[
'text' => 'web panel',
'web_app' => [
"url" => "https://$domain/adguard"
],
],
[
'text' => $this->i18n('third party browser') . ': ' . $this->i18n($conf['adgbrowser'] ? 'on' : 'off'),
'callback_data' => '/adguardChBr'
],
],
[
[
'text' => $this->i18n('change password'),
'callback_data' => "/adguardpsswd",
],
[
'text' => $this->i18n('reset settings'),
'callback_data' => "/adguardreset",
'text' => 'ClientID' . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
'callback_data' => "/setAdguardKey",
],
],
];
$data[] = [
[
'text' => $this->i18n('reset settings'),
'callback_data' => "/adguardreset",
],
];
$data[] = [
[
'text' => $this->i18n('add upstream'),
'callback_data' => "/addupstream",
],
[
'text' => $this->i18n('setSecret') . ($conf['adguardkey'] ? ": {$conf['adguardkey']}" : ''),
'callback_data' => "/setAdguardKey",
'text' => $this->i18n('check DNS'),
'callback_data' => "/checkdns",
],
];
$upstreams = yaml_parse_file($this->adguard)['dns']['upstream_dns'];
@@ -3492,12 +3619,6 @@ DNS-over-HTTPS with IP:
];
}
}
$data[] = [
[
'text' => $this->i18n('check DNS'),
'callback_data' => "/checkdns",
],
];
$data[] = [
[
'text' => $this->i18n('back'),
@@ -3557,8 +3678,11 @@ DNS-over-HTTPS with IP:
public function configMenu()
{
$conf = $this->getPacConf();
$text = $this->i18n('domain explain');
$conf = $this->getPacConf();
$text[] = $conf['domain'] ? "Domains:\n{$conf['domain']}\nnp.{$conf['domain']}\noc.{$conf['domain']}" . ($conf['adguardkey'] ? "\n{$conf['adguardkey']}.{$conf['domain']}" : '') : $this->i18n('domain explain');
$ssl = $this->expireCert();
$text[] = $conf['domain'] ? "\nSSL: " . ($ssl ? date('Y-m-d H:i:s', $this->expireCert()) : 'none') : '';
$data = [
[
[
@@ -3573,7 +3697,7 @@ DNS-over-HTTPS with IP:
case 'letsencrypt':
$data[] = [
[
'text' => $this->i18n('renew SSL') . ': ' . date('Y-m-d H:i:s', $this->expireCert()),
'text' => $this->i18n('renew SSL'),
'callback_data' => "/setSSL letsencrypt",
],
[
@@ -3665,7 +3789,13 @@ DNS-over-HTTPS with IP:
'callback_data' => "/debug",
],
];
exec('git -C / branch', $m);
$track = trim(file_get_contents('/update/branch'));
$data[] = [
[
'text' => "{$m[0]} => $track",
'callback_data' => "/branches",
],
[
'text' => $this->i18n('update bot'),
'callback_data' => "/updatebot",
@@ -3678,11 +3808,44 @@ DNS-over-HTTPS with IP:
],
];
return [
'text' => $text,
'text' => implode("\n", $text),
'data' => $data,
];
}
public function branches()
{
exec('git -C / branch -r', $m);
array_shift($m);
foreach ($m as $k => $v) {
$data[] = [
[
'text' => $v,
'callback_data' => "/changeBranch $k",
]
];
}
$data[] = [
[
'text' => $this->i18n('back'),
'callback_data' => "/menu config",
]
];
$this->update($this->input['from'], $this->input['message_id'], 'branches', $data);
}
public function changeBranch($i)
{
exec('git -C / branch -r', $m);
array_shift($m);
foreach ($m as $k => $v) {
if ($i == $k) {
file_put_contents('/update/branch', trim(str_replace('origin/', '', $v)));
}
}
$this->menu('config');
}
public function logs()
{
foreach (scandir('/logs/') as $k => $v) {
@@ -3785,16 +3948,42 @@ DNS-over-HTTPS with IP:
];
}
public function setFakeDomain($domain)
public function changeTGDomain()
{
$r = $this->send(
$this->input['chat'],
"@{$this->input['username']} enter domain",
$this->input['message_id'],
reply: 'enter domain',
);
$_SESSION['reply'][$r['result']['message_id']] = [
'start_message' => $this->input['message_id'],
'start_callback' => $this->input['callback_id'],
'callback' => 'setTelegramDomain',
'args' => [],
];
}
public function setFakeDomain($domain, $self = false)
{
$c = $this->getXray();
$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] = $domain;
$c['inbounds'][0]['streamSettings']['realitySettings']['dest'] = "$domain:443";
$c['inbounds'][0]['streamSettings']['realitySettings']['dest'] = $self ? "10.10.1.2:443" : "$domain:443";
$this->restartXray($c);
$this->setUpstreamDomain($domain);
$this->xray();
}
public function selfFakeDomain()
{
$c = $this->getPacConf();
if (!empty($c['domain'])) {
$this->setFakeDomain($c['domain'], 1);
} else{
$this->answer($this->input['callback_id'], 'empty domain', true);
}
}
public function setBackup($text)
{
$text = trim($text);
+17 -1
View File
@@ -263,7 +263,11 @@ $i = [
],
'changeFakeDomain' => [
'en' => 'changeFakeDomain',
'ru' => 'установить фейковый домен',
'ru' => 'фейковый домен',
],
'selfFakeDomain' => [
'en' => 'selfFakeDomain',
'ru' => 'домен бота',
],
'page' => [
'en' => 'pagination',
@@ -305,4 +309,16 @@ $i = [
'en' => 'update bot',
'ru' => 'обновить бота',
],
'third party browser' => [
'en' => 'third party browser',
'ru' => 'сторонний браузер',
],
'browser_notify_on' => [
'en' => 'the web panel can be opened in any browser',
'ru' => 'веб панель может быть открыта в любом браузере',
],
'browser_notify_off' => [
'en' => 'web panel is only available from telegram',
'ru' => 'веб панель доступна только из телеграмма',
],
];
+18
View File
@@ -42,6 +42,24 @@ if ($hash == substr(md5($c['key']), 0, 8)) {
}
}
}
if (!empty($_GET['hash'])) {
$t = $_GET;
unset($t['hash']);
ksort($t);
foreach ($t as $k => $v) {
$s[] = "$k=$v";
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
die('ok');
}
}
header('500', true, 500);
exit;
+2 -1
View File
@@ -8,6 +8,7 @@ require __DIR__ . '/config.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
$bot->setwebhook();
$bot->adguardProtect();
$bot->setcommands();
$bot->syncPortClients();
$bot->setwebhook();
+2 -1
View File
@@ -35,4 +35,5 @@ if (!empty($c['admin'])) {
}
file_put_contents('/update/message', '');
file_put_contents('/update/reload_message', '');
$bot->menu();
$bot->restartTG();
$bot->sslip();
+24
View File
@@ -0,0 +1,24 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<script src="https://telegram.org/js/telegram-web-app.js"></script>
<script src="jquery-3.7.1.min.js"></script>
<title>Document</title>
</head>
<body>
<script>
var tg = window.Telegram.WebApp;
jQuery(function($) {
$.ajax({
'url': 'check?' + tg.initData,
}).done(function (r) {
location.replace('/adguard/');
}).fail(function (r) {
location.replace('/');
});
});
</script>
</body>
</html>
File diff suppressed because one or more lines are too long
+117
View File
@@ -0,0 +1,117 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Login</title>
<style>
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
body {
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
background-size: cover;
font-family: "Roboto";
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
&::before {
z-index: -1;
content: '';
position: fixed;
top: 0;
left: 0;
background: #44c4e7;
/* IE Fallback */
background: rgba(68, 196, 231, 0.8);
width: 100%;
height: 100%;
}
}
.form {
position: absolute;
top: 50%;
left: 50%;
background: #fff;
width: 285px;
margin: -140px 0 0 -182px;
padding: 40px;
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
h2 {
margin: 0 0 20px;
line-height: 1;
color: #44c4e7;
font-size: 18px;
font-weight: 400;
}
input {
outline: none;
display: block;
width: 100%;
margin: 0 0 20px;
padding: 10px 15px;
border: 1px solid #ccc;
color: #ccc;
font-family: "Roboto";
box-sizing: border-box;
font-size: 14px;
font-wieght: 400;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
transition: 0.2s linear;
&input:focus {
color: #333;
border: 1px solid #44c4e7;
}
}
button {
cursor: pointer;
background: #44c4e7;
width: 100%;
padding: 10px 15px;
border: 0;
color: #fff;
font-family: "Roboto";
font-size: 14px;
font-weight: 400;
&:hover {
background: #369cb8;
}
}
}
.error,
.valid {
display: none;
}
</style>
<script src="jquery-3.7.1.min.js"></script>
</head>
<body>
<section class="form animated flipInX">
<h2>Login To Your Account</h2>
<p class="valid">Valid. Please wait a moment.</p>
<p class="error">Error. Please enter correct Username &amp; password.</p>
<form class="loginbox" autocomplete="off">
<input placeholder="Username" type="text" id="username"></input>
<input placeholder="Password" type="password" id="password"></input>
<button id="submit">Login</button>
</form>
</section>
<script>
$(document).ready(function() {
$('#submit').click(function () {
event.preventDefault(); // prevent PageReLoad
$('.error').css('display', 'block'); // show error msg
});
});
</script>
</body>
</html>
View File
+23 -6
View File
@@ -22,15 +22,17 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_default_access;
location / {
return 444;
root /app;
index login.html;
try_files $uri $uri/ =404;
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
@@ -38,6 +40,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -67,11 +75,12 @@ http {
#-domain
# server {
# listen 80;
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 443 ssl http2 proxy_protocol;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
@@ -80,7 +89,9 @@ http {
# access_log /logs/nginx_domain_access;
# location / {
# return 444;
# root /app;
# index login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
@@ -88,6 +99,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
+23 -6
View File
@@ -22,15 +22,17 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_default_access;
location / {
return 444;
root /app;
index login.html;
try_files $uri $uri/ =404;
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
@@ -38,6 +40,12 @@ http {
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_pass http://php;
@@ -67,11 +75,12 @@ http {
#-domain
# server {
# listen 80;
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 443 ssl http2 proxy_protocol;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
@@ -80,7 +89,9 @@ http {
# access_log /logs/nginx_domain_access;
# location / {
# return 444;
# root /app;
# index login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
@@ -88,6 +99,12 @@ http {
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_pass http://php;
+15 -1
View File
@@ -12,6 +12,10 @@ networks:
ipam:
config:
- subnet: 10.10.0.0/24
xray:
ipam:
config:
- subnet: 10.10.1.0/24
volumes:
adguard:
@@ -69,6 +73,7 @@ services:
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./logs/:/logs/
- ./app/webapp:/app
ports:
- 80:80
hostname: nginx
@@ -86,9 +91,11 @@ services:
networks:
default:
ipv4_address: 10.10.0.2
xray:
ipv4_address: 10.10.1.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.2
image: mercurykd/vpnbot-php:1.3
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -109,6 +116,7 @@ services:
- ./mirror:/mirror
- ./.env:/mirror/.env
- ./update:/update
- ./.git:/.git
environment:
IP: ${IP}
VER: ${VER}
@@ -239,6 +247,8 @@ services:
required: true # default
- path: ./override.env
required: false
environment:
ADDRESS: ${WGADDRESS}
cap_add:
- NET_ADMIN
devices:
@@ -277,6 +287,8 @@ services:
required: true # default
- path: ./override.env
required: false
environment:
ADDRESS: ${WG1ADDRESS}
cap_add:
- NET_ADMIN
devices:
@@ -412,6 +424,8 @@ services:
networks:
default:
ipv4_address: 10.10.0.9
xray:
ipv4_address: 10.10.1.9
logging: *default-logging
oc:
image: mercurykd/vpnbot-oc:1.2
+1
View File
@@ -19,6 +19,7 @@ RUN apk add --no-cache --update php81 \
openssh \
openssl \
curl \
git \
py3-qt5 \
&& wget https://github.com/ameshkov/dnslookup/releases/download/v1.9.1/dnslookup-linux-amd64-v1.9.1.tar.gz \
&& tar -xf dnslookup-linux-amd64-v1.9.1.tar.gz \
+2 -1
View File
@@ -2,7 +2,8 @@ b:
docker compose build
u: # запуск контейнеров
bash ./update/update.sh &
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose up -d --force-recreate
touch ./override.env
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
d: # остановка контейнеров
-kill -9 $(shell cat ./update/update_pid) > /dev/null
docker compose down --remove-orphans
+8 -10
View File
@@ -62,19 +62,17 @@ telegram bot to manage servers (inside the bot)
<img src="https://github.com/mercurykd/vpnbot/assets/30900414/431ec09d-9c14-4c74-b8f6-e49c142132e8" width="200">
---
environment: ubuntu 18.04/20.04/22.04, debian 11
environment: ubuntu 18.04/20.04/22.04, debian 11/12
install:
`wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY`
---
additional options:
install as service(autoload on start):
### Install:
```shell
wget -O- https://raw.githubusercontent.com/mercurykd/vpnbot/master/scripts/init.sh | sh -s YOUR_TELEGRAM_BOT_KEY
```
### Install as service (autoload on start):
```shell
cd /root/vpnbot
bash scripts/install_as_service.sh
```
-5
View File
@@ -4,9 +4,4 @@ ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
curl -s https://core.telegram.org/getProxySecret -o proxy-secret
curl -s https://core.telegram.org/getProxyConfig -o proxy-multi.conf
if [ $(cat /mtprotosecret | wc -c) -gt 0 ]
then
SECRET=$(cat /mtprotosecret)
mtproto-proxy -u nobody -H $TGPORT --nat-info 10.10.0.8:$IP -S $SECRET --aes-pwd /proxy-secret /proxy-multi.conf -M 1
fi
tail -f /dev/null
+2 -1
View File
@@ -6,7 +6,8 @@ After=docker.service
Type=oneshot
RemainAfterExit=yes
WorkingDirectory=path
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate"
ExecStartPre=/bin/sh -c "touch ./override.env"
ExecStart=/bin/sh -c "IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate"
ExecStartPost=/bin/sh -c "bash ./update/update.sh &"
ExecStop=/bin/sh -c "docker compose down --remove-orphans"
ExecStopPost=/bin/sh -c "kill -9 $(cat ./update/update_pid) > /dev/null"
+1 -1
View File
@@ -3,4 +3,4 @@
GET {{url}}/status
###
GET {{url}}/config
GET {{url}}/config
+7 -1
View File
@@ -6,10 +6,16 @@ echo "$$" > $pwd/update/update_pid
while true
do
cmd=$(cat $pwd/update/pipe)
branch=$(cat $pwd/update/branch 2>/dev/null)
if [[ -n "$cmd" ]]
then
docker compose down --remove-orphans
git reset --hard
git reset --hard && git clean -fd
git fetch
if [[ -n "$branch" ]]
then
git checkout -t origin/$branch || git checkout $branch
fi
git pull > ./update/message
IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate
bash $pwd/update/update.sh &
+16
View File
@@ -1,3 +1,19 @@
20.03.2024 v1.11
- XTLS-Reality steal from yourself
18.03.2024 v1.10
- MTProto Fake-TLS
17.03.2024 v1.9
- автоматический технический домен sslip
13.03.2024 v1.8.10
- фикс override.env
10.03.2024 v1.8.9
- веб морда адгварда "встроена" в телеграм
- мелкие улучшения меню
07.03.2024 v1.8.8
- фикс не работающего wireguard
07.03.2024 v1.8.7
- фикс порта амнезии
- у кого ошибка запуска обновите докер и докер композ
07.03.2024 v1.8.6
- фикс синхронизации клиентов амнезии, бот падал после рестарта, клиенты пропадали
- возможность переназначить порты в override.env, файл не отслеживаемый, обновление не будет его сбрасывать