Compare commits

..

120 Commits

Author SHA1 Message Date
mercury 8effb72cdc update version 2026-03-10 10:05:12 +04:00
mercury bec8f5488e reset amnezia keys fix 2026-03-08 01:23:12 +04:00
mercury f97b0f9228 amneziawg2.0 2026-03-08 01:12:09 +04:00
mercury 8e8babe1a6 update version 2025-12-16 00:58:02 +04:00
mercury 238c380f23 fix clash template rules behavior 2025-12-16 00:55:44 +04:00
mercury abc2e7c587 setting up dnstt display in menu 2025-12-16 00:38:34 +04:00
mercury 3f99d9fbf0 hide dnstt 2025-12-15 17:06:19 +04:00
mercury 3f1e80c641 update version 2025-12-15 16:48:24 +04:00
mercury 5afe6a4777 lightweight warp image 2025-12-15 00:44:54 +04:00
mercury c2cf0bff98 delete bot command 2025-12-15 00:34:41 +04:00
mercury 60241aaffb new mtproto image 2025-12-15 00:18:08 +04:00
mercury 96ff868b10 improve dnstt menu 2025-12-14 22:49:28 +04:00
mercury f58c29a66b fix reality start 2025-12-14 22:48:58 +04:00
mercury ca922f4612 change address for wg on start 2025-12-14 22:04:22 +04:00
mercury 5a5b1b62b1 domain for shortlink amnezia 2025-12-14 21:55:30 +04:00
mercury 0ef34f818d changing dependencies when starting containers 2025-12-11 00:44:32 +04:00
mercury d1960d6acb change of strategy for server xray domain resolution 2025-12-10 01:34:44 +04:00
mercury 95cba4c8d1 improved issuance of routing rules vless: ip or domains 2025-12-10 01:33:21 +04:00
mercury 18e2dd53ff changing dependencies when starting containers 2025-12-10 00:40:45 +04:00
mercury 3e5b131c16 delete hysteria upstream 2025-12-10 00:40:15 +04:00
mercury e07d1505e4 attempt to save page when changing domain list 2025-12-10 00:01:02 +04:00
mercury c140f292e8 fix port for first amnezia container 2025-12-09 21:57:10 +04:00
mercury 7cc100ace5 dnstt menu improve 2025-12-09 21:31:12 +04:00
mercury 4938ada85d Merge branch 'xhttp' into dev 2025-12-04 02:24:43 +04:00
mercury c5b9886470 hysteria: logging, correct port 2025-12-04 02:23:00 +04:00
mercury 61d8b899e7 improved docker-compose.override.yml rewrite algorithm 2025-12-04 01:08:14 +04:00
mercury 7d81eeeddd improved process logging 2025-12-03 01:25:53 +04:00
mercury 3bdebd95ab backup dnstt keys 2025-12-03 00:16:19 +04:00
mercury eb4641a58d ability to disable naive and openconnect subdomains 2025-12-03 00:10:47 +04:00
mercury 61900daafd custom hysteria port 2025-12-03 00:08:49 +04:00
mercury 364dbd6408 xhttp from legiz 2025-12-02 22:41:08 +04:00
mercury 57ee403070 added hysteria 2025-12-01 00:13:19 +04:00
mercury b5ab8fb4eb command to add to cron to restart the bot when restarting the vps 2025-11-30 21:06:16 +04:00
mercury 95c6a023d0 iodine -> dnstt 2025-11-30 20:46:31 +04:00
mercury 9f196ca58e issue #36 fix 2025-11-29 22:32:50 +04:00
mercury 665b4007eb improve cron handlers 2025-11-28 02:43:29 +04:00
mercury 9c9f42e9e4 update mtproto image 2025-11-28 02:06:19 +04:00
mercury 30c260bf02 fix override html 2025-11-27 21:41:59 +04:00
mercury a3c59991ce fix override html 2025-11-27 21:35:09 +04:00
mercury 288435e2a0 support quic destination override 2025-11-27 14:29:41 +04:00
mercury 1b1acee59f Ruleset polling timeout increased to 60 seconds 2025-11-27 02:16:59 +04:00
mercury a8d121b7e1 adaptation of the warp, block list to the presence of ipcidr for all kernel configs 2025-11-27 02:15:22 +04:00
mercury f6d2c89e8d xray statistics are collected once per minute 2025-11-27 02:12:22 +04:00
mercury e4863eb645 update warp image 2025-11-26 11:54:13 +04:00
mercury bc28be571b fix warp rules for xray 2025-11-26 10:22:35 +04:00
mercury 34f5f32a82 warp list create classical ruleset for mihomo 2025-11-26 10:03:29 +04:00
mercury fc4c28edfb naiveproxy image update 2025-11-26 01:10:06 +04:00
mercury c352270b39 Fix overwriting fingerprint for vray 2025-11-26 01:03:55 +04:00
mercury 2ee6c3392b ability to add IPs and subnets to warplist 2025-11-26 00:50:43 +04:00
mercury 9bd85c9e05 empty password stoped openconnect and naive, fix 2025-11-10 00:24:35 +04:00
mercury 82e51c0d9c empty password stoped openconnect and naive 2025-11-10 00:14:04 +04:00
mercury 9051b214c5 fix reality 2025-11-09 23:52:51 +04:00
mercury 0710ef51fd fix domain in download config vless 2025-11-08 22:54:18 +04:00
mercury 597763f80a update group link 2025-11-08 19:44:38 +04:00
mercury 8398ecf736 edit announce 2025-11-08 19:24:39 +04:00
mercury 0d14061edb Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-11-08 19:23:05 +04:00
mercury 03218b974d download vless button 2025-11-08 19:20:50 +04:00
Konstantin 84ac1200dc Merge pull request #41 from legiz-ru/dev
Add HWID device limit support for sub page
2025-09-25 11:00:13 +04:00
legiz-ru aa64a48db2 delete overhead mkdir0777 2025-09-25 09:52:17 +03:00
legiz-ru 70c83da66a add hwid to backup 2025-09-23 20:44:42 +03:00
legiz-ru 52ff056474 fix: hwid ignore for browsers 2025-09-23 14:21:41 +03:00
legiz-ru 225260044a Add HWID device limit support for sub page
based on standart by remnawave: https://remna.st/docs/features/hwid-device-limit
2025-09-23 13:50:03 +03:00
mercury 050d1ee3eb fix start_io 2025-09-11 16:46:12 +04:00
mercury 6979cca602 iodine 2025-09-11 16:22:27 +04:00
mercury 7fc24ea4f4 add suburl, expire to subs page 2025-08-31 00:18:00 +04:00
mercury 3dff9e039f non-wiped additional nginx configurations 2025-07-19 22:48:28 +04:00
mercury e2441eb9fd update version 2025-07-16 17:18:18 +04:00
mercury 269d0e9956 mirror shell-script 2025-07-13 23:34:11 +04:00
mercury 8ba85164aa fix empty warp status 2025-07-11 20:55:38 +04:00
mercury e7cc7b66e2 add configs to subs page 2025-07-04 18:33:04 +04:00
mercury 54fa8d35b1 update version 2025-07-04 17:48:15 +04:00
mercury ffe6bb4ba8 subscription page 2025-07-04 17:45:50 +04:00
mercury 6be95533c4 improve vless menu 2025-07-04 16:42:47 +04:00
mercury 8d13bee021 improve /id 2025-07-04 16:38:39 +04:00
mercury db6a18f498 update version 2025-06-18 00:56:49 +04:00
mercury 6954a16fa2 get ip from host 2025-06-18 00:47:48 +04:00
mercury ca7a9c955d update version 2025-06-11 14:09:51 +04:00
mercury 852fbd55c6 Pagination number 2025-05-27 23:42:02 +04:00
mercury 3a8a843d8c update version 2025-05-20 21:39:34 +04:00
mercury 90828d1117 improve main menu 2025-05-18 19:23:42 +04:00
mercury 37e8b96bcf improve main menu 2025-05-18 11:30:59 +04:00
mercury 306bc41813 improve main menu 2025-05-18 03:29:15 +04:00
mercury f6e5da382b reset vless stats monthly 2025-05-17 16:18:46 +04:00
mercury d7ed7042ec update version 2025-05-17 14:54:58 +04:00
mercury 4496a30552 add status process container 2025-05-17 14:49:32 +04:00
mercury ca1a596f85 fix crash vless when enable timer user 2025-05-17 14:24:22 +04:00
mercury b3edf1bdcc Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-05-17 13:55:28 +04:00
mercury c6306aa918 vless: check already exists user 2025-05-17 13:52:45 +04:00
Konstantin d5bbc9a564 Merge pull request #39 from legiz-ru/dev
add no overwrite key for Clash Mi
2025-05-10 12:22:57 +04:00
legiz-ru d2aab8ee4b add no overwrite key for Clash Mi 2025-05-09 22:18:30 +03:00
mercury 304217d36e Периодическое падение upstream при запуске сервисов 2025-04-26 23:37:37 +04:00
mercury 2622397542 mihomo: udp true 2025-04-18 23:40:33 +04:00
mercury 702123e39c vless: ip limit only notifies 2025-04-17 00:58:13 +04:00
mercury 01ef7707c4 fix first start 2025-04-14 11:36:26 +04:00
mercury 064d39d80b Excess image php 2025-04-09 18:12:18 +04:00
mercury 1b93d41421 cyclical rebooting panel adguardhome fix 2025-04-07 00:22:50 +04:00
mercury e41c8e30a4 fix warp 2025-04-06 23:57:46 +04:00
mercury 260f988360 Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-04-05 00:38:54 +04:00
mercury ca4905220d np/oc the domain is preserved when transferring 2025-04-05 00:36:08 +04:00
Konstantin 08c5ff136e Merge pull request #38 from legiz-ru/dev
new variable ~dnspath~
2025-03-04 15:45:18 +04:00
legiz-ru 8709531717 new variable ~dnspath~
new variable ~dnspath~ for client templates (required for future release sing-box 1.12)
2025-03-04 12:41:23 +03:00
Konstantin 71f53c3575 Merge pull request #37 from legiz-ru/dev
update singbox 1.11.4 windows x64
2025-03-04 12:16:19 +04:00
legiz-ru 2607f1f264 update singbox 1.11.4 windows x64 2025-03-04 10:46:56 +03:00
mercury a94cab7dc1 fix ip limit user off 2025-03-02 18:41:18 +04:00
mercury 694d446402 update version 2025-02-22 18:56:42 +04:00
mercury 6074d40643 update version 2025-02-22 18:52:17 +04:00
mercury 4b1df94325 Revert "add clash mode selector for sing-box clients"
This reverts commit fb22744fa7.
2025-02-22 18:51:49 +04:00
mercury 232c75d5bf Merge branch 'dev' of github.com:mercurykd/vpnbot into dev 2025-02-22 18:50:32 +04:00
mercury 5e860a4896 fix addruleset for block outbound 2025-02-22 18:47:36 +04:00
Konstantin 5b05486b98 Merge pull request #35 from legiz-ru/dev
add clash mode selector for sing-box clients
2025-02-13 10:13:38 +04:00
legiz-ru fb22744fa7 add clash mode selector for sing-box clients 2025-02-13 08:11:20 +03:00
mercury af812b7c93 vless: stats collect improve 2025-02-12 13:29:08 +04:00
mercury 3302ca8871 vless stats: fix delete user 2025-02-12 12:50:39 +04:00
mercury 2c5eff03d5 vless stats: fix reset user stats 2025-02-12 00:25:23 +04:00
mercury a8a203041f vless stats: fix reset user stats 2025-02-11 22:48:47 +04:00
mercury a21c9b5fe9 update version 2025-02-11 00:14:07 +04:00
mercury 696779450f ip limit: count ip 2025-02-11 00:12:21 +04:00
mercury 7c5b3dfa3a xray: fix stats user 2025-02-10 23:58:17 +04:00
mercury 74404559f9 xray: stats to separate file 2025-02-10 23:33:38 +04:00
mercury 11e8fb468b singbox: return mixed-in port 2025-02-10 10:03:27 +04:00
32 changed files with 2588 additions and 671 deletions
+6
View File
@@ -10,6 +10,7 @@
/sftp-config.json
/tg.pyr
/config/wg0.conf
/config/hwid.json
/todo.todo
/app/zapretlists/*
!/app/zapretlists/.gitkeep
@@ -26,3 +27,8 @@ docker-compose.override.yml
backup.json
app/webapp/override/
.rest
subscription.php
location.conf
override.conf
i18n.override.php
+2150 -537
View File
File diff suppressed because it is too large Load Diff
+28
View File
@@ -193,6 +193,30 @@ $i = [
'en' => 'delete internal dns',
'ru' => 'удалить внутренний dns',
],
'hwid limit' => [
'en' => 'HWID limit',
'ru' => 'HWID лимит',
],
'hwid devices' => [
'en' => 'HWID devices',
'ru' => 'Устройства HWID',
],
'set hwid devices count' => [
'en' => 'set HWID devices count',
'ru' => 'установить количество HWID устройств',
],
'use default hwid limit' => [
'en' => 'use default limit',
'ru' => 'использовать лимит по умолчанию',
],
'no devices' => [
'en' => 'no devices',
'ru' => 'нет устройств',
],
'hwid notice' => [
'en' => 'HWID limit works only when subscription is refreshed or added',
'ru' => 'HWID лимит срабатывает только в момент обновления и добавления подписки',
],
'on' => [
'en' => '🟢',
'ru' => '🟢',
@@ -378,3 +402,7 @@ $i = [
'ru' => 'перезагрузка',
],
];
if (file_exists(__DIR__ . '/i18n.override.php')) {
include __DIR__ . '/i18n.override.php';
}
+5 -1
View File
@@ -38,10 +38,14 @@ switch (true) {
// adguard cookie
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('c', $hash, 0, '/');
echo "/adguard$hash/";
break;
case preg_match('~^' . preg_quote("/pac$hash/sub") . '~', $_SERVER['REQUEST_URI']) && file_exists(__DIR__ . '/subscription.php'):
$bot->sub();
exit;
// subs & pac
case preg_match('~^' . preg_quote("/pac$hash") . '~', $_SERVER['REQUEST_URI']):
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
+6
View File
@@ -24,3 +24,9 @@ $bot->adguardSync();
$bot->cloakNginx();
$bot->syncDeny();
$bot->cleanDocker();
$bot->dnsttStart();
$bot->restartHysteria();
$c = $bot->getPacConf();
$bot->setUpstreamDomain($c['transport'] != 'Reality' ? 't' : $c['reality']['domain']);
$bot->setUpstreamDomainNaive($c['domain']);
$bot->setUpstreamDomainOcserv($c['domain']);
+12 -11
View File
@@ -8,7 +8,7 @@
"mode": "rule",
"log-level": "info",
"ipv6": false,
"keep-alive-interval": 30,
"keep-alive-interval": 60,
"unified-delay": false,
"profile": {
"store-selected": true,
@@ -72,6 +72,7 @@
"uuid": "~uid~",
"network": "tcp",
"flow": "xtls-rprx-vision",
"udp": true,
"tls": true,
"reality-opts": {
"public-key": "~public_key~",
@@ -97,15 +98,15 @@
"type": "RULE-SET",
"list": "~block~",
"action": "REJECT",
"interval": 30,
"behavior": "domain",
"interval": 60,
"behavior": "classical",
"name": "block"
},
{
"type": "RULE-SET",
"list": "~process~",
"action": "PROXY",
"interval": 30,
"interval": 60,
"behavior": "classical",
"name": "process"
},
@@ -113,7 +114,7 @@
"type": "RULE-SET",
"list": "~package~",
"action": "PROXY",
"interval": 30,
"interval": 60,
"behavior": "classical",
"name": "package"
},
@@ -121,24 +122,24 @@
"type": "RULE-SET",
"list": "~warp~",
"action": "PROXY",
"interval": 30,
"behavior": "domain",
"interval": 60,
"behavior": "classical",
"name": "warp"
},
{
"type": "RULE-SET",
"list": "~pac~",
"action": "PROXY",
"interval": 30,
"behavior": "domain",
"interval": 60,
"behavior": "classical",
"name": "pac"
},
{
"type": "RULE-SET",
"list": "~subnet~",
"action": "PROXY",
"interval": 30,
"behavior": "ipcidr",
"interval": 60,
"behavior": "classical",
"name": "subnet"
},
{
+1
View File
@@ -0,0 +1 @@
{}
+9
View File
@@ -0,0 +1,9 @@
listen: :443
proxy_protocol: true
tls:
cert: /certs/cert_public
key: /certs/cert_private
auth:
type: password
password:
+14 -1
View File
@@ -11,7 +11,7 @@ events {
http {
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include override.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
@@ -48,6 +48,11 @@ http {
try_files $uri /override.html @auth;
}
location /override/ {
alias /app/override/;
try_files $uri =404;
}
location / {
root /app;
auth_basic "Restricted Content";
@@ -122,6 +127,7 @@ http {
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
include location.conf;
}
#~
@@ -141,6 +147,11 @@ http {
# try_files $uri /override.html @auth;
# }
# location /override/ {
# alias /app/override/;
# try_files $uri =404;
# }
# location / {
# root /app;
# auth_basic "Restricted Content";
@@ -210,6 +221,8 @@ http {
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# include location.conf;
# }
#-domain
}
+14 -1
View File
@@ -11,7 +11,7 @@ events {
http {
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include override.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
@@ -48,6 +48,11 @@ http {
try_files $uri /override.html @auth;
}
location /override/ {
alias /app/override/;
try_files $uri =404;
}
location / {
root /app;
auth_basic "Restricted Content";
@@ -122,6 +127,7 @@ http {
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
include location.conf;
}
#~
@@ -141,6 +147,11 @@ http {
# try_files $uri /override.html @auth;
# }
# location /override/ {
# alias /app/override/;
# try_files $uri =404;
# }
# location / {
# root /app;
# auth_basic "Restricted Content";
@@ -210,6 +221,8 @@ http {
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# include location.conf;
# }
#-domain
}
+9 -7
View File
@@ -27,7 +27,9 @@
},
{
"type": "mixed",
"tag": "in"
"tag": "in",
"listen": "127.0.0.1",
"listen_port": 2080
}
],
"dns": {
@@ -117,7 +119,7 @@
"createruleset": [
{
"name": "pac",
"interval": "30s",
"interval": "60s",
"rules": [
{
"domain_suffix": "~pac~"
@@ -132,7 +134,7 @@
"createruleset": [
{
"name": "subnet",
"interval": "30s",
"interval": "60s",
"rules": [
{
"ip_cidr": "~subnet~"
@@ -147,7 +149,7 @@
"createruleset": [
{
"name": "package",
"interval": "30s",
"interval": "60s",
"rules": [
{
"package_name": "~package~"
@@ -162,7 +164,7 @@
"createruleset": [
{
"name": "process",
"interval": "30s",
"interval": "60s",
"rules": [
{
"process_name": "~process~"
@@ -177,7 +179,7 @@
"createruleset": [
{
"name": "block",
"interval": "30s",
"interval": "60s",
"rules": [
{
"domain_suffix": "~block~"
@@ -192,7 +194,7 @@
"createruleset": [
{
"name": "warp",
"interval": "30s",
"interval": "60s",
"rules": [
{
"domain_suffix": "~warp~"
+9 -4
View File
@@ -83,9 +83,9 @@ AuthorizedKeysFile .ssh/authorized_keys
#AllowAgentForwarding yes
# Feel free to re-enable these if your use case requires them.
AllowTcpForwarding no
GatewayPorts no
X11Forwarding no
# AllowTcpForwarding no
# GatewayPorts no
# X11Forwarding no
#X11DisplayOffset 10
#X11UseLocalhost yes
#PermitTTY yes
@@ -117,4 +117,9 @@ Subsystem sftp internal-sftp
# ForceCommand cvs server
HostKeyAlgorithms +ssh-rsa
PubkeyAcceptedKeyTypes +ssh-rsa
PasswordAuthentication no
PasswordAuthentication yes
AllowTcpForwarding yes
PermitTunnel yes
GatewayPorts yes
X11Forwarding yes
LogLevel QUIET
+3 -2
View File
@@ -11,7 +11,8 @@
"sniffing": {
"destOverride": [
"http",
"tls"
"tls",
"quic"
],
"enabled": true
},
@@ -48,7 +49,7 @@
}
],
"routing": {
"domainStrategy": "AsIs",
"domainStrategy": "IPIfNonMatch",
"rules": [
{
"inboundTag": [
+93 -17
View File
@@ -40,11 +40,13 @@ services:
hostname: upstream
container_name: upstream-${VER}
depends_on:
php:
ng:
condition: service_healthy
ad:
xr:
condition: service_started
ss:
oc:
condition: service_started
np:
condition: service_started
env_file:
- path: ./.env
@@ -67,7 +69,8 @@ services:
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/nginx.conf:/etc/nginx/nginx.conf
- ./config/include.conf:/etc/nginx/include.conf
- ./config/override.conf:/etc/nginx/override.conf
- ./config/location.conf:/etc/nginx/location.conf
- ./config/nginx_default.conf:/nginx_default.conf
- ./scripts/start_ng.sh:/start_ng.sh
- ./certs/:/certs/
@@ -79,9 +82,6 @@ services:
- 80:80
hostname: nginx
container_name: nginx-${VER}
depends_on:
up:
condition: service_started
env_file:
- path: ./.env
required: true # default
@@ -95,6 +95,20 @@ services:
xray:
ipv4_address: 10.10.1.2
logging: *default-logging
depends_on:
php:
condition: service_healthy
ad:
condition: service_started
ss:
condition: service_started
xr:
condition: service_started
healthcheck:
test: ["CMD", "nginx", "-t"]
interval: 10s
timeout: 5s
retries: 3
php:
image: mercurykd/vpnbot-php:1.7
build:
@@ -147,7 +161,7 @@ services:
timeout: 5s
retries: 5
service:
image: mercurykd/vpnbot-php:1.6
image: mercurykd/vpnbot-php:1.7
build:
dockerfile: dockerfile/php.dockerfile
args:
@@ -197,8 +211,10 @@ services:
- np
- proxy
- ss
- dnstt
- hy
wg:
image: mercurykd/vpnbot-wg:1.1
image: mercurykd/vpnbot-wg:1.2
build:
dockerfile: dockerfile/wireguard.dockerfile
args:
@@ -236,7 +252,7 @@ services:
ipv4_address: 10.10.0.4
logging: *default-logging
wg1:
image: mercurykd/vpnbot-wg:1.1
image: mercurykd/vpnbot-wg:1.2
build:
dockerfile: dockerfile/wireguard.dockerfile
args:
@@ -274,7 +290,7 @@ services:
ipv4_address: 10.10.0.14
logging: *default-logging
ad:
image: mercurykd/vpnbot-ad:1.3
image: mercurykd/vpnbot-ad:1.4
build:
dockerfile: dockerfile/adguard.dockerfile
args:
@@ -309,15 +325,16 @@ services:
entrypoint: ["/bin/sh", "/start_ad.sh"]
logging: *default-logging
tg:
image: mercurykd/vpnbot-tg:1.1
image: mercurykd/vpnbot-tg:1.3
build:
dockerfile: dockerfile/telegram.dockerfile
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/.profile:/root/.bashrc:ro
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_tg.sh:/start_tg.sh
- ./config/mtprotosecret:/mtprotosecret
- ./logs/:/logs/
hostname: telegram
container_name: mtproto-${VER}
depends_on:
@@ -337,7 +354,7 @@ services:
ipv4_address: 10.10.0.8
logging: *default-logging
xr:
image: mercurykd/vpnbot-xr:1.4
image: mercurykd/vpnbot-xr:1.5
build:
dockerfile: dockerfile/xray.dockerfile
args:
@@ -401,7 +418,7 @@ services:
ipv4_address: 10.10.0.11
logging: *default-logging
np:
image: mercurykd/vpnbot-np:1.1
image: mercurykd/vpnbot-np:1.2
build:
dockerfile: dockerfile/naive.dockerfile
args:
@@ -432,7 +449,7 @@ services:
ipv4_address: 10.10.0.12
logging: *default-logging
wp:
image: mercurykd/vpnbot-wp:1.2
image: mercurykd/vpnbot-wp:1.5
build:
dockerfile: dockerfile/warp.dockerfile
args:
@@ -442,7 +459,7 @@ services:
devices:
- /dev/net/tun:/dev/net/tun
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/.profile:/root/.bashrc:ro
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./config:/config
@@ -523,3 +540,62 @@ services:
default:
ipv4_address: 10.10.0.6
logging: *default-logging
dnstt:
image: mercurykd/vpnbot-dnstt:1.0
build:
dockerfile: dockerfile/dnstt.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./ssh:/ssh
- ./logs:/logs
- ./config/sshd_config:/etc/ssh/sshd_config
- ./config/dnstt:/dnstt
- ./scripts/start_dnstt.sh:/start_dnstt.sh
hostname: dnstt
container_name: dnstt-${VER}
depends_on:
php:
condition: service_healthy
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_dnstt.sh"]
networks:
default:
ipv4_address: 10.10.0.16
logging: *default-logging
hy:
image: mercurykd/vpnbot-hysteria:1.0
build:
dockerfile: dockerfile/hysteria.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./certs:/certs
- ./logs:/logs
- ./config:/config
- ./scripts/start_hysteria.sh:/start_hysteria.sh
hostname: hysteria
container_name: hysteria-${VER}
depends_on:
php:
condition: service_healthy
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_hysteria.sh"]
networks:
default:
ipv4_address: 10.10.0.17
logging: *default-logging
+13
View File
@@ -0,0 +1,13 @@
ARG image
FROM golang:alpine AS go
RUN apk add --no-cache git \
&& git clone https://www.bamsoftware.com/git/dnstt.git \
&& cd /go/dnstt/dnstt-server \
&& go build -ldflags="-s -w" -trimpath \
&& rm -rf /go/dnstt/.git \
&& apk del git
FROM $image
COPY --from=go /go/dnstt/dnstt-server/dnstt-server /usr/local/bin/
RUN apk add --no-cache openssh \
&& mkdir -p /root/.ssh
ENV ENV="/root/.ashrc"
+5
View File
@@ -0,0 +1,5 @@
FROM tobyxdd/hysteria
RUN apk add --no-cache openssh \
&& mkdir -p /root/.ssh
ENV ENV="/root/.ashrc"
ENTRYPOINT []
+33 -13
View File
@@ -1,13 +1,33 @@
FROM alpine:3.6
RUN apk add --no-cache --virtual .build-deps alpine-sdk linux-headers openssl-dev \
&& git clone --single-branch --depth 1 https://github.com/TelegramMessenger/MTProxy.git /mtproxy/sources \
&& mkdir /mtproxy/patches && wget -P /mtproxy/patches https://raw.githubusercontent.com/alexdoesh/mtproxy/master/patches/randr_compat.patch \
&& cd /mtproxy/sources && patch -p0 -i /mtproxy/patches/randr_compat.patch \
&& make \
&& mkdir /root/.ssh \
&& cp /mtproxy/sources/objs/bin/mtproto-proxy /usr/bin \
&& rm -rf /mtproxy \
&& apk del .build-deps\
&& apk add --no-cache --update curl openssh \
&& ln -s /usr/lib/libcrypto.so.41 /usr/lib/libcrypto.so.1.0.0
ENV ENV="/root/.ashrc"
# Build stage
FROM ubuntu:22.04 AS builder
RUN apt-get update && apt-get install -y --no-install-recommends \
git \
build-essential \
libssl-dev \
zlib1g-dev \
ca-certificates \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
RUN git clone --single-branch --depth 1 https://github.com/GetPageSpeed/MTProxy . \
&& make -j$(nproc) \
&& strip objs/bin/mtproto-proxy
# Runtime stage - minimal Ubuntu
FROM ubuntu:22.04
RUN apt-get update && apt-get install -y --no-install-recommends \
libssl3 \
zlib1g \
curl \
openssh-client \
openssh-server \
ca-certificates \
vim-common \
&& rm -rf /var/lib/apt/lists/* \
&& mkdir -p /root/.ssh /var/run/sshd
COPY --from=builder /src/objs/bin/mtproto-proxy /usr/local/bin/mtproto-proxy
ENV PATH="/usr/local/bin:$PATH"
+15 -15
View File
@@ -1,16 +1,16 @@
FROM ubuntu:22.04 AS build
RUN apt update && apt install -y curl gpg lsb-release \
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/cloudflare-client.list \
&& apt update && apt install -y cloudflare-warp
FROM ubuntu:22.04
FROM alpine:3.17
ARG GLIBC_VERSION=2.34-r0
COPY --from=build /usr/bin/warp-cli /usr/bin/warp-svc /usr/local/bin/
RUN apk add --no-cache dbus-libs wget socat openssh-server jq curl \
&& mkdir /tmp/glibc-pkgs \
&& for PKG in glibc-$GLIBC_VERSION.apk glibc-bin-$GLIBC_VERSION.apk; do wget -q --directory-prefix /tmp/glibc-pkgs https://github.com/sgerrand/alpine-pkg-glibc/releases/download/$GLIBC_VERSION/$PKG; done \
&& apk add --no-cache --allow-untrusted --force-overwrite /tmp/glibc-pkgs/* \
&& rm -rf /tmp/glibc-pkgs \
&& /usr/glibc-compat/sbin/ldconfig /lib /usr/glibc-compat/lib \
&& mkdir /root/.ssh
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
gpg \
socat \
jq \
lsb-release \
openssh-server \
ca-certificates \
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" > /etc/apt/sources.list.d/cloudflare-client.list \
&& apt-get update && apt-get install -y --no-install-recommends cloudflare-warp \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
&& mkdir -p /root/.ssh /var/run/sshd
+19 -13
View File
@@ -1,9 +1,9 @@
b:
docker compose build
u: # запуск контейнеров
$(eval IP := $(shell curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me))
$(eval IP := $(shell hostname -I | awk '{print $$1}'))
bash ./update/update.sh &
touch ./override.env ./docker-compose.override.yml
touch ./override.env ./docker-compose.override.yml ./config/location.conf ./config/override.conf
IP=$(IP) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
d: # остановка контейнеров
-kill -9 $(shell cat ./update/update_pid) > /dev/null
@@ -32,24 +32,26 @@ up: # консоль сервиса
ad: # консоль сервиса
docker compose exec ad /bin/sh
wp: # консоль сервиса
docker compose exec wp /bin/sh
docker compose exec wp bash
proxy: # консоль сервиса
docker compose exec proxy /bin/sh
tg: # консоль сервиса
docker compose exec tg /bin/sh
dnstt: # консоль сервиса
docker compose exec dnstt /bin/sh
hy: # консоль сервиса
docker compose exec hy /bin/sh
xr: # консоль сервиса
docker compose exec xr /bin/sh
oc: # консоль сервиса
docker compose exec oc /bin/sh
clean:
docker image prune
docker builder prune
cleanf:
docker image prune -f > /dev/null
docker builder prune -f > /dev/null
cleanall:
docker image prune -a -f
docker builder prune -a -f
service: # консоль сервиса
docker compose exec service /bin/sh
delete:
make d
docker system prune -f -a
docker volume prune -f -a
rm -rf /root/vpnbot
push:
docker compose push
s:
@@ -67,4 +69,8 @@ reset:
docker volume rm vpnbot_adguard vpnbot_warp
make u
backup:
docker compose exec php php backup.php > backup.json
docker compose exec php php backup.php > backup.json
cron: # установка задачи в cron для автозапуска при перезагрузке
@(crontab -l 2>/dev/null | grep -v "cd /root/vpnbot && make r"; echo "@reboot cd /root/vpnbot && make r") | crontab -
uncron: # удаление задачи из cron
@crontab -l 2>/dev/null | grep -v "cd /root/vpnbot && make r" | crontab -
-18
View File
@@ -1,18 +0,0 @@
version: "3"
services:
socat:
build:
dockerfile: ./dockerfile
ports:
- 80:80
- 443:443
- 853:853
- ${TGPORT}:${TGPORT}
- ${SSPORT}:${SSPORT}
- ${SSPORT}:${SSPORT}/udp
- ${WGPORT}:${WGPORT}/udp
volumes:
- ./start_socat.sh:/start_socat.sh
command: /bin/sh /start_socat.sh
stop_grace_period: 1s
-2
View File
@@ -1,2 +0,0 @@
FROM alpine:3.18
RUN apk add socat htop net-tools
-11
View File
@@ -1,11 +0,0 @@
b:
docker compose build --no-cache
u:
docker compose up -d --build
d:
docker compose down
ps:
docker compose ps
e:
docker compose exec socat sh
r: d u
+53 -8
View File
@@ -1,8 +1,53 @@
socat TCP-LISTEN:80,fork TCP:{ip}:80 &
socat TCP-LISTEN:443,fork TCP:{ip}:443 &
socat TCP-LISTEN:853,fork TCP:{ip}:853 &
socat TCP-LISTEN:{tg},fork TCP:{ip}:{tg} &
socat TCP-LISTEN:{ss},fork TCP:{ip}:{ss} &
socat UDP-LISTEN:{ss},fork UDP:{ip}:{ss} &
socat UDP-LISTEN:{wg},fork UDP:{ip}:{wg} &
tail -f /dev/null
#!/bin/bash
# Параметры (можно менять)
PORTS=(80 443 853 ~tg~ ~ss~ ~wg1~ ~wg2~) # Прослушиваемые порты
TARGET="~ip~" # Куда перенаправляем трафик
TCP_CMD="socat TCP-LISTEN:{PORT},fork,reuseaddr TCP:$TARGET:{PORT}"
UDP_CMD="socat UDP-LISTEN:{PORT},fork,reuseaddr UDP:$TARGET:{PORT}"
# Проверяем, установлен ли socat
if ! command -v socat &> /dev/null; then
echo "socat не установлен. Устанавливаем..."
if [[ -f /etc/debian_version ]]; then
sudo apt update && sudo apt install -y socat
elif [[ -f /etc/redhat-release ]]; then
sudo yum install -y socat
else
echo "Ошибка: Неизвестный дистрибутив. Установите socat вручную."
exit 1
fi
fi
# Проверяем, заняты ли порты (TCP и UDP)
for PORT in "${PORTS[@]}"; do
# Проверка TCP
if ss -tulnp | grep -q ":$PORT "; then
PROCESS=$(ss -tulnp | grep ":$PORT " | awk '{print $7}')
echo "Ошибка: Порт $PORT (TCP) занят процессом: $PROCESS"
exit 1
fi
# Проверка UDP
if ss -ulnp | grep -q ":$PORT "; then
PROCESS=$(ss -ulnp | grep ":$PORT " | awk '{print $6}')
echo "Ошибка: Порт $PORT (UDP) занят процессом: $PROCESS"
exit 1
fi
done
# Запускаем socat для каждого порта (TCP и UDP)
for PORT in "${PORTS[@]}"; do
# TCP
CMD_TCP=$(echo "$TCP_CMD" | sed "s/{PORT}/$PORT/g")
echo "Запуск (TCP): $CMD_TCP"
eval "$CMD_TCP &" # Запускаем в фоне
# UDP
CMD_UDP=$(echo "$UDP_CMD" | sed "s/{PORT}/$PORT/g")
echo "Запуск (UDP): $CMD_UDP"
eval "$CMD_UDP &" # Запускаем в фоне
done
echo "socat запущен для портов: ${PORTS[*]} (TCP и UDP)"
echo "Трафик перенаправляется на: $TARGET"
echo "Для остановки выполните: pkill socat"
+4
View File
@@ -0,0 +1,4 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
tail -f /dev/null
+4
View File
@@ -0,0 +1,4 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
tail -f /dev/null
-1
View File
@@ -1,4 +1,3 @@
echo 'root:dummy_passwd'|chpasswd
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
+4 -2
View File
@@ -14,7 +14,8 @@ then
echo "ListenPort = $WG1PORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WG1PORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
sed "s|Address = [0-9\.\/ ]\+|Address = $ADDRESS|" change_port > change_address
cat change_address > /etc/wireguard/wg0.conf
fi
else
if [ $(cat /etc/wireguard/wg0.conf | wc -c) -eq 0 ]
@@ -26,7 +27,8 @@ else
echo "ListenPort = $WGPORT" >> /etc/wireguard/wg0.conf
else
sed "s/ListenPort = [0-9]\+/ListenPort = $WGPORT/" /etc/wireguard/wg0.conf > change_port
cat change_port > /etc/wireguard/wg0.conf
sed "s|Address = [0-9\.\/ ]\+|Address = $ADDRESS|" change_port > change_address
cat change_address > /etc/wireguard/wg0.conf
fi
fi
iptables -t nat -A POSTROUTING --destination 10.10.0.5 -j ACCEPT
+2 -3
View File
@@ -1,9 +1,8 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
service ssh start
off=$(cat /config/pac.json | jq -r .warpoff)
key=$(cat /config/pac.json | jq -r .warp)
if [ "$off" == 'null' ]
if [ "$off" = 'null' ]
then
warp-svc > /dev/null &
sleep 3
+3 -3
View File
@@ -1,8 +1,8 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
if [ $(cat /xray.json | jq -r '.inbounds[0].settings.clients[0].id' | wc -c) -gt 1 ]
then
xray run -config /xray.json > /dev/null &
uuid=$(cat /xray.json | jq -r '.inbounds[0].settings.clients[0].id // empty')
if [ -n "$uuid" ]; then
xray run -config /xray.json > /dev/null 2>&1 &
fi
tail -f /dev/null
Binary file not shown.
+1 -1
View File
@@ -38,7 +38,7 @@ do
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "launching the bot"/')"
> $pwd/update/key
> $pwd/update/curl
IP=$(curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
IP=$(hostname -I | awk '{print $1}') VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
bash $pwd/update/update.sh &
exit 0
fi
+73
View File
@@ -1,3 +1,76 @@
10.03.2026 v2.29
- amnezia 2.0
16.12.2025 v2.28.1
- фикс шаблона mihomo
15.12.2025 v2.28
- новый MTProto
- hysteria
- dnstt (вместо iodine)
- xhttp-vless by legiz
- возможность отключать поддомены для naive и openconnect (через установку поддомена в 0)
- возможность отключать naive и openconnect (через установку пароля в 0)
- возможность указывать айпишники в списках block, warp
- быстрая команда для добавления бота в крон: make cron
- увиличены тайминги пула рулсетов
- увиличен тайминг сбора статы с xray-ядра
- улучшено логирование: ssh не срет в контейнер, а основной процесс пишет в /logs
- улучшены кроны autobackup, autoscan, autoreset
- фикс старта upstream
- фикс шорт-ссылки для амнезии
- фикс папки override для своих заглушек
- фикс сброса страницы в списках route
09.11.2025 v2.27
- фикс reality
08.11.2025 v2.26
- обновлено ядро xray
- обновлен adguardHome
- добавлен iodine(dnstt)
- добавлены кнопки скачивания vless-конфига
- hwid для подписки orion от legiz
19.07.2025 v2.25
- перед запуском обязательно запустить:
<pre>touch ./override.env ./docker-compose.override.yml ./config/location.conf ./config/override.conf</pre>
- для nginx вместо include.conf теперь override.conf, не затирается
- location.conf (by legiz), не затирается
- app/i18n.override.php для собственных названий кнопок, не затирается
16.07.2025 v2.24
- фикс зависания бота из-за пустого статуса warp
- скрипт socat.sh для мостов /mirror
04.07.2025 v2.23
- фикс двойного /id
- фикс отображения статы vless на мобилке
- страница подписок app/subscription.php
18.06.2025 v2.22
- фикс определения айпи при запуске
11.06.2025 v2.21
- пагинация в списках
20.05.2025 v2.20
- коррекция главного меню
- vless: опция обнуления статы ежемесячно
17.05.2025 v2.19
- фикс падения vless при одинаковом имени пользователей
- фикс падения vless при установке таймера для выключенного пользователя
- подсветка в меню работы процесса контейнера
- overwrite=no для импорта клеш подписки (legiz)
18.04.2025 v2.18
- фикс отсутствия ssl при первом старте
- iplimit уведомляет без отключения пользователя
- включение udp в mihomo-шаблоне
- удаление лишнего образа пхп
07.04.2025 v2.17
- фикс циклической перезагрузки панели adguardHome
07.04.2025 v2.16
- фикс warp
07.04.2025 v2.15
- миграция поддоменов np/oc вместе в с бэкапом
02.03.2025 v2.14
- vless ip limit: фикс выключения юзера
22.02.2025 v2.13
- vless: улучшение сбора статы
- vless: фикс добавления правил srs для block outbound
11.02.2025 v2.12
- vless: хранение статы в отдельном файле
- vless ip limit: возможность указать кол-во айпи
08.02.2025 v2.11
- vless: singbox 1.11
07.02.2025 v2.10