Compare commits

...

43 Commits

Author SHA1 Message Date
mercury ece8fb75d5 Merge branch 'master' into singbox 2024-08-26 23:31:05 +04:00
mercury 75c0a6a294 Merge branch 'master' into singbox 2024-08-21 23:06:02 +04:00
mercury 9e2b0c041a Merge branch 'dev' into singbox 2024-08-21 23:01:27 +04:00
mercury 108a048f5a Merge branch 'dev' into singbox 2024-08-18 11:54:39 +04:00
mercury a6ec5b041c Merge branch 'dev' into singbox 2024-08-18 02:15:42 +04:00
mercury f55bf31c07 Merge branch 'master' into singbox 2024-08-18 02:02:43 +04:00
mercury b5a40fa0cc Merge branch 'master' into singbox 2024-08-16 22:28:46 +04:00
mercury 7e79f591c3 Merge branch 'master' into singbox 2024-08-16 22:27:31 +04:00
mercury 12babef21e Merge branch 'master' into singbox 2024-08-16 12:21:39 +04:00
mercury b6e078adc0 Merge branch 'master' into singbox 2024-08-10 00:00:46 +04:00
mercury 31a5415e1f Merge branch 'dev' into singbox 2024-08-08 17:13:46 +04:00
mercury 7df97c6ca1 update singbox 2024-08-08 12:43:55 +04:00
mercury 638fcf35d7 improve updatepac 2024-08-08 11:26:14 +04:00
mercury 07022b1697 Merge branch 'dev' into singbox 2024-08-06 22:03:22 +04:00
mercury f2bfad7c80 Merge branch 'dev' into singbox 2024-08-05 01:48:39 +04:00
mercury 4d6f59bc06 Merge branch 'master' into singbox 2024-08-03 11:44:17 +04:00
mercury fe42515617 Merge branch 'master' into singbox 2024-07-07 15:38:48 +04:00
mercury 7e05806f6e Merge branch 'dev' into singbox 2024-05-28 14:47:08 +04:00
mercury 149ce068bf Merge branch 'dev' into singbox 2024-05-18 17:20:19 +04:00
mercury 144366ce9d singbox 1.8.13 2024-05-08 18:19:57 +04:00
mercury 12b42d16b9 Merge branch 'dev' into singbox 2024-05-08 00:41:24 +04:00
mercury 2d94504aa3 outbounds auto fill 2024-05-08 00:40:31 +04:00
mercury d99ddc7ad9 Merge branch 'master' into singbox 2024-05-04 13:02:15 +04:00
mercury a1ac552c3e fix start singbox 2024-05-04 12:09:52 +04:00
mercury 95c9d40b00 Merge branch 'dev' into singbox 2024-05-01 18:42:05 +04:00
mercury af88237ddc Merge branch 'master' into singbox 2024-05-01 17:55:56 +04:00
mercury 102ce5b0a5 delete trojan 2024-05-01 16:25:42 +04:00
mercury a72db227f0 Merge branch 'master' into singbox 2024-04-29 23:15:18 +04:00
mercury e52fa68edd Merge branch 'master' into singbox 2024-04-29 22:52:55 +04:00
mercury 8dba00c9f7 improve choice template 2024-04-29 22:44:27 +04:00
mercury 381e6a9dba choice singbox inbound type 2024-04-29 21:25:06 +04:00
mercury 08e001bcb0 chmod +x *.sh 2024-04-29 20:27:26 +04:00
mercury c5a35e43be fix import xray 2024-04-28 23:24:27 +04:00
mercury eb0d0bb59f fix nginx pid 2024-04-28 23:14:29 +04:00
mercury 7316d49af8 timer singbox user fix 2024-04-28 23:08:48 +04:00
mercury c1a637ac29 xray menu improve 2024-04-28 23:03:17 +04:00
mercury 98d1961669 migrate export xray to singbox 2024-04-28 22:55:55 +04:00
mercury 08f0babed6 fix sinbox users actions 2024-04-27 17:46:08 +04:00
mercury f2897d4b07 return proxy_protocol without singbox 2024-04-26 14:45:33 +04:00
mercury b728553db5 fix sshd warp 2024-04-25 15:13:48 +04:00
mercury 9742cecf51 remove proxy_protocol 2024-04-24 17:53:23 +04:00
mercury 2ed3dfb6dd fix links 2024-04-24 12:32:19 +04:00
mercury 0cc49a89e5 singbox core 2024-04-24 01:06:44 +04:00
17 changed files with 448 additions and 474 deletions
+353 -194
View File
@@ -295,6 +295,9 @@ class Bot
case preg_match('~^/setSSL (\w+)$~', $this->input['callback'], $m):
$this->setSSL($m[1]);
break;
case preg_match('~^/setSingboxType (\w+)$~', $this->input['callback'], $m):
$this->setSingboxType($m[1]);
break;
case preg_match('~^/lang (\w+)$~', $this->input['callback'], $m):
$this->setLang($m[1]);
break;
@@ -437,9 +440,6 @@ class Bot
case preg_match('~^/changeFakeDomain$~', $this->input['callback'], $m):
$this->changeFakeDomain();
break;
case preg_match('~^/selfFakeDomain$~', $this->input['callback'], $m):
$this->selfFakeDomain();
break;
case preg_match('~^/changeTGDomain$~', $this->input['callback'], $m):
$this->changeTGDomain();
break;
@@ -534,12 +534,101 @@ class Bot
}
}
public function restartXray($c)
public function restartXray($c = false)
{
$c['inbounds'][0]['settings']['clients'] = array_values($c['inbounds'][0]['settings']['clients']);
$this->ssh('pkill xray', 'xr');
file_put_contents('/config/xray.json', json_encode($c, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
$this->ssh('xray run -config /xray.json > /dev/null 2>&1 &', 'xr');
$c = $c ?: $this->getXray();
$p = $this->getPacConf();
if (!empty($p['xrusers'])) {
$cl = array_filter($p['xrusers'], fn ($e) => empty($e['off']) && (empty($e['time']) || $e['time'] >= time()));
}
switch ($p['xtlsmode']) {
case 'shadow':
if (!empty($cl)) {
foreach ($cl as $v) {
$t[] = [
"name" => $v['name'],
"password" => $v['uuid'],
];
}
}
$c['inbounds'] = [
[
"type" => "shadowtls",
"tag" => "ss-tls-in",
"listen" => "0.0.0.0",
"detour" => "ss-in",
"sniff" => true,
"sniff_override_destination" => false,
"listen_port" => 443,
"version" => 3,
"strict_mode" => true,
"users" => $t ?: [],
"handshake" => [
"server" => $p['xray']['domain'],
"server_port" => 443,
"domain_strategy" => "ipv4_only"
]
],
[
"type" => "shadowsocks",
"tag" => "ss-in",
"listen" => "127.0.0.1",
"network" => "tcp",
"sniff" => false,
"sniff_override_destination" => false,
"method" => "2022-blake3-aes-128-gcm",
"password" => $p['xray']['sspwd'],
"multiplex" => [
"enabled" => true,
"padding" => true,
]
]
];
break;
case 'trojan':
break;
default:
if (!empty($cl)) {
foreach ($cl as $v) {
$t[] = [
"uuid" => $v['uuid'],
"flow" => 'xtls-rprx-vision',
"name" => $v['name'],
];
}
}
$c['inbounds'] = [
[
"type" => "vless",
"tag" => "vless",
"listen" => "0.0.0.0",
"listen_port" => 443,
"sniff" => true,
"sniff_override_destination" => false,
"users" => $t ?: [],
"tls" => [
"enabled" => true,
"server_name" => $p['xray']['domain'],
"reality" => [
"enabled" => true,
"handshake" => [
"server" => $p['xray']['domain'],
"server_port" => 443
],
"private_key" => $p['xray']['private'],
"short_id" => [
$p['xray']['shortid']
]
]
]
]
];
break;
}
$this->ssh('pkill sing-box', 'si');
file_put_contents('/config/singbox.json', json_encode($c, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
$this->ssh('sing-box run -c /config/singbox.json > /dev/null 2>&1 &', 'si');
}
public function linkMtproto()
@@ -1172,8 +1261,8 @@ class Bot
public function shutdownClientXr()
{
try {
$c = $this->getXray();
foreach ($c['inbounds'][0]['settings']['clients'] as $k => $v) {
$p = $this->getPacConf();
foreach ($p['xrusers'] as $k => $v) {
if (!empty($v['time']) && ($v['time'] < time())) {
$this->switchXr($k, 1);
}
@@ -1227,7 +1316,6 @@ class Bot
] : false,
'mtproto' => file_get_contents('/config/mtprotosecret'),
'mtprotodomain' => file_get_contents('/config/mtprotodomain'),
'xray' => $this->getXray(),
'oc' => file_get_contents('/config/ocserv.conf'),
'ocu' => file_get_contents('/config/ocserv.passwd'),
@@ -1289,11 +1377,36 @@ class Bot
if ($this->getPacConf()['wg1_amnezia'] != $json['pac']['wg1_amnezia']) {
$switch_wg1amnezia = 1;
}
unset($json['pac']['subzoneslist']);
unset($json['pac']['reverselist']);
unset($json['pac']['excludelist']);
unset($json['pac']['zapret']);
$this->setPacConf($json['pac']);
$out[] = 'update naiveproxy';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->restartNaive();
$this->pacUpdate('1');
// xray
if (!empty($json['xray']['inbounds'][0]['settings']['clients'])) {
$out[] = 'migrate xray to singbox';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$pac = $this->getPacConf();
foreach ($json['xray']['inbounds'][0]['settings']['clients'] as $v) {
$pac['xrusers'][] = [
'name' => $v['email'],
'uuid' => $v['id'],
];
}
$pac['xray'] = [
"domain" => $json['xray']['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] != $pac['domain'] ? $json['xray']['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] : 'vk.com',
"public" => $json['pac']['xray'],
"private" => $json['xray']['inbounds'][0]['streamSettings']['realitySettings']['privateKey'],
"shortid" => $json['xray']['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0],
"sspwd" => trim($this->ssh('sing-box generate rand --base64 16', 'si')),
];
$this->setPacConf($pac);
}
$this->xrayUpdateRules();
}
// wg
if (!empty($json['wg'])) {
@@ -1345,13 +1458,6 @@ class Bot
file_put_contents('/config/mtprotodomain', $json['mtprotodomain'] ?: '');
$this->restartTG();
}
// xray
if (!empty($json['xray'])) {
$out[] = 'update xray';
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
$this->restartXray($json['xray']);
$this->setUpstreamDomain($json['xray']['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]);
}
// ocserv
if (!empty($json['oc'])) {
$out[] = 'update ocserv';
@@ -2292,43 +2398,19 @@ DNS-over-HTTPS with IP:
{
$c = $this->getPacConf();
$xr = $this->getXray();
$xr['outbounds'] = [
[
"protocol" => "freedom",
"tag" => "direct",
],
[
"protocol" => "blackhole",
"tag" => "block",
],
[
"protocol" => "socks",
"tag" => "warp",
"settings" => [
'servers' => [
[
"address" => "10.10.0.13",
"port" => 4000,
],
],
],
],
];
if (!empty($c['blocklist']) && !empty(array_filter($c['blocklist']))) {
$rules[] = [
"type" => "field",
"outboundTag" => "block",
"domain" => array_keys(array_filter($c['blocklist'])),
"outbound" => "block",
"domain_suffix" => array_keys(array_filter($c['blocklist'])),
];
}
if (!empty($c['warplist']) && !empty(array_filter($c['warplist']))) {
$rules[] = [
"type" => "field",
"outboundTag" => "warp",
"domain" => array_keys(array_filter($c['warplist'])),
"outbound" => "warp",
"domain_suffix" => array_keys(array_filter($c['warplist'])),
];
}
$xr['routing']['rules'] = $rules ?: [];
$xr['route']['rules'] = $rules ?: [];
$this->restartXray($xr);
}
@@ -3739,17 +3821,17 @@ DNS-over-HTTPS with IP:
$si = "$scheme://{$domain}/pac/" . base64_encode(serialize([
'h' => $hash,
't' => 'si',
's' => $c['inbounds'][0]['settings']['clients'][$i]['id'],
's' => $pac['xrusers'][$i]['uuid'],
]));
switch ($s) {
case 1:
return "$scheme://{$domain}/pac?h=$hash&t=s&s={$c['inbounds'][0]['settings']['clients'][$i]['id']}";
return "$scheme://{$domain}/pac?h=$hash&t=s&s={$pac['xrusers'][$i]['uuid']}";
case 2:
return "sing-box://import-remote-profile/?url={$si}#{$c['inbounds'][0]['settings']['clients'][$i]['email']}";
return "sing-box://import-remote-profile/?url={$si}#{$pac['xrusers'][$i]['name']}";
default:
return "vless://{$c['inbounds'][0]['settings']['clients'][$i]['id']}@$domain:443?security=reality&sni={$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]}&fp=chrome&pbk={$pac['xray']}&sid={$c['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0]}&type=tcp&flow=xtls-rprx-vision#{$c['inbounds'][0]['settings']['clients'][$i]['email']}";
return "vless://{$pac['xrusers'][$i]['uuid']}@$domain:443?security=reality&sni={$c['inbounds'][0]['tls']['reality']['handshake']['server']}&fp=chrome&pbk={$pac['xray']['public']}&sid={$c['inbounds'][0]['tls']['reality']['short_id'][0]}&type=tcp&flow=xtls-rprx-vision#{$pac['xrusers'][$i]['name']}";
}
}
@@ -3958,14 +4040,10 @@ DNS-over-HTTPS with IP:
public function delxr($i)
{
$r = $this->getXray();
foreach ($r['inbounds'][0]['settings']['clients'] as $k => $v) {
if ($i == $k) {
unset($r['inbounds'][0]['settings']['clients'][$k]);
$this->restartXray($r);
break;
}
}
$p = $this->getPacConf();
unset($p['xrusers'][$i]);
$this->setPacConf($p);
$this->restartXray();
$this->xray();
}
@@ -3984,50 +4062,51 @@ DNS-over-HTTPS with IP:
public function addxrus($user)
{
$c = $this->getXray();
$uuid = trim($this->ssh('xray uuid', 'xr'));
$c['inbounds'][0]['settings']['clients'][] = [
'id' => $uuid,
$uuid = trim($this->ssh('sing-box generate uuid', 'si'));
$pac = $this->getPacConf();
$pac['xrusers'][] = [
'uuid' => $uuid,
'flow' => 'xtls-rprx-vision',
'email' => $user,
'name' => $user,
];
$this->restartXray($c);
$this->userXr(count($c['inbounds'][0]['settings']['clients']) - 1);
$this->setPacConf($pac);
$this->restartXray($this->getXray());
$this->userXr(count($pac['xrusers']) - 1);
}
public function setTimerXr($time, $i)
{
$c = $this->getPacConf();
if ($time === '0') {
unset($c['xrusers'][$i]['time']);
} else {
$time = strtotime($time);
if ($time === false) {
$this->send($this->input['chat'], 'wrong format');
return;
}
$c = $this->getXray();
if (empty($time)) {
unset($c['inbounds'][0]['settings']['clients'][$i]['time']);
} else {
if (!empty($c['inbounds'][0]['settings']['clients'][$i]['off'])) {
$this->switchXr($i, 1);
$c = $this->getXray();
if (!empty($c['xrusers'][$i]['off'])) {
unset($c['xrusers'][$i]['off']);
}
$c['inbounds'][0]['settings']['clients'][$i]['time'] = $time;
$c['xrusers'][$i]['time'] = $time;
}
file_put_contents('/config/xray.json', json_encode($c, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
$this->setPacConf($c);
$this->restartXray();
$this->userXr($i);
}
public function switchXr($i, $nm = 0)
{
$c = $this->getXray();
unset($c['inbounds'][0]['settings']['clients'][$i]['time']);
if (empty($c['inbounds'][0]['settings']['clients'][$i]['off'])) {
$c['inbounds'][0]['settings']['clients'][$i]['off'] = $c['inbounds'][0]['settings']['clients'][$i]['id'];
$c['inbounds'][0]['settings']['clients'][$i]['id'] = trim($this->ssh('xray uuid', 'xr'));
$p = $this->getPacConf();
unset($p['xrusers'][$i]['time']);
if (empty($p['xrusers'][$i]['off'])) {
$p['xrusers'][$i]['off'] = 1;
} else {
$c['inbounds'][0]['settings']['clients'][$i]['id'] = $c['inbounds'][0]['settings']['clients'][$i]['off'];
unset($c['inbounds'][0]['settings']['clients'][$i]['off']);
unset($p['xrusers'][$i]['off']);
}
$this->restartXray($c);
$this->setPacConf($p);
$this->restartXray();
if (empty($nm)) {
$this->userXr($i);
}
@@ -4035,9 +4114,9 @@ DNS-over-HTTPS with IP:
public function renXrUs($name, $i)
{
$c = $this->getXray();
$c['inbounds'][0]['settings']['clients'][$i]['email'] = $name;
$this->restartXray($c);
$c = $this->getPacConf();
$c['xrusers'][$i]['name'] = $name;
$this->setPacConf($c);
$this->userXr($i);
}
@@ -4091,10 +4170,14 @@ DNS-over-HTTPS with IP:
$this->templates($type);
}
public function downloadTemplate($type, $name)
public function downloadTemplate($type, $name = false)
{
$pac = $this->getPacConf();
if (!empty($name)) {
$f = new \CURLStringFile(json_encode($pac["{$type}templates"][base64_decode($name)], JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES), base64_decode($name) . '.json', 'application/json');
} else {
$f = new \CURLFile("/config/{$type}.json", 'application/json', "$type.json");
}
$this->sendFile($this->input['chat'], $f);
}
@@ -4129,6 +4212,10 @@ DNS-over-HTTPS with IP:
'text' => "origin",
'web_app' => ['url' => "https://$domain/pac?h=$hash&t=te&ty=$type"],
],
[
'text' => $this->i18n('download'),
'callback_data' => "/downloadTemplate $type",
],
[
'text' => $this->i18n($pac["default{$type}template"] && !empty($pac["{$type}templates"][base64_decode($pac["default{$type}template"])]) ? 'off' : 'on'),
'callback_data' => "/defaultTemplate $type",
@@ -4169,23 +4256,54 @@ DNS-over-HTTPS with IP:
);
}
public function setSingboxType($type)
{
$p = $this->getPacConf();
$p['xtlsmode'] = $type;
if (empty($p['xray']['sspwd'])) {
$p['xray']['sspwd'] = trim($this->ssh('sing-box generate rand --base64 16', 'si'));
}
$this->setPacConf($p);
$this->restartXray();
$this->xray();
}
public function xray($page = 0)
{
if (!$this->ssh('pgrep xray', 'xr')) {
$pac = $this->getPacConf();
if (!$this->ssh('pgrep sing-box', 'si') || empty($pac['xray']['private'])) {
$this->generateSecretXray();
$pac = $this->getPacConf();
}
$c = $this->getXray();
$text[] = "Menu -> " . $this->i18n('xray');
$text[] = "fake domain: <code>{$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]}</code>";
$text[] = "\nfake domain: <code>{$pac['xray']['domain']}</code>";
$text[] = "public: <code>{$pac['xray']['public']}</code>";
$text[] = "private: <code>{$pac['xray']['private']}</code>";
$text[] = "shortId: <code>{$pac['xray']['shortid']}</code>";
$text[] = "sspwd: <code>{$pac['xray']['sspwd']}</code>";
$data[] = [
[
'text' => $this->i18n('generateSecret'),
'callback_data' => "/generateSecretXray",
],
[
'text' => $this->i18n('changeFakeDomain'),
'callback_data' => "/changeFakeDomain",
],
];
$data[] = [
[
'text' => $this->i18n('selfFakeDomain'),
'callback_data' => "/selfFakeDomain",
'text' => $this->i18n('reality') . ' ' . ((empty($pac['xtlsmode']) || $pac['xtlsmode'] == 'reality') ? '✅' : ''),
'callback_data' => "/setSingboxType reality",
],
[
'text' => $this->i18n('shadow') . ' ' . ($pac['xtlsmode'] == 'shadow' ? '✅' : ''),
'callback_data' => "/setSingboxType shadow",
],
// [
// 'text' => $this->i18n('trojan') . ' ' . ($pac['xtlsmode'] == 'trojan' ? '✅' : ''),
// 'callback_data' => "/setSingboxType trojan",
// ],
];
$data[] = [
[
@@ -4203,15 +4321,15 @@ DNS-over-HTTPS with IP:
'callback_data' => "/routes",
],
];
foreach ($c['inbounds'][0]['settings']['clients'] as $k => $v) {
$cl = $pac['xrusers'] ?: [];
foreach ($cl as $k => $v) {
if (!empty($v['off'])) {
$off++;
} else {
$on++;
}
}
$type = $this->getPacConf()['xtlslist'];
$clients = array_filter($c['inbounds'][0]['settings']['clients'], fn($e) => !$type ? empty($e['off']) : !empty($e['off']));
$clients = array_filter($cl, fn($e) => !$pac['xtlslist'] ? empty($e['off']) : !empty($e['off']));
uasort($clients, fn($a, $b) => ($a['time'] ?: PHP_INT_MAX) <=> ($b['time'] ?: PHP_INT_MAX));
$all = (int) ceil(count($clients) / $this->limit);
@@ -4222,7 +4340,7 @@ DNS-over-HTTPS with IP:
$time = $v['time'] ? $this->getTime($v['time']) : '';
$data[] = [
[
'text' => "{$v['email']}" . ($time ? ": $time" : ''),
'text' => "{$v['name']}" . ($time ? ": $time" : ''),
'callback_data' => "/userXr $k",
],
];
@@ -4245,11 +4363,11 @@ DNS-over-HTTPS with IP:
'callback_data' => "/addXrUser",
],
[
'text' => $this->i18n('on') . " $on " . (!$type ? "" : ''),
'text' => $this->i18n('on') . " $on " . (!$pac['xtlslist'] ? "" : ''),
'callback_data' => "/listXr 0",
],
[
'text' => $this->i18n('off') . " $off " . ($type ? "" : ''),
'text' => $this->i18n('off') . " $off " . ($pac['xtlslist'] ? "" : ''),
'callback_data' => "/listXr 1",
],
];
@@ -4365,13 +4483,13 @@ DNS-over-HTTPS with IP:
public function choiceTemplate($arg)
{
$arg = explode('_', $arg);
$c = $this->getXray();
$c = $this->getPacConf();
if (!empty($arg[2])) {
$c['inbounds'][0]['settings']['clients'][$arg[1]]["{$arg[0]}template"] = $arg[2];
$c['xrusers'][$arg[1]]["{$arg[0]}template"] = $arg[2];
} else {
unset($c['inbounds'][0]['settings']['clients'][$arg[1]]["{$arg[0]}template"]);
unset($c['xrusers'][$arg[1]]["{$arg[0]}template"]);
}
file_put_contents('/config/xray.json', json_encode($c, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
$this->setPacConf($c);
$this->userXr($arg[1]);
}
@@ -4379,7 +4497,7 @@ DNS-over-HTTPS with IP:
{
$c = $this->getXray();
$pac = $this->getPacConf();
$text[] = "Menu -> " . $this->i18n('xray') . " -> {$c['inbounds'][0]['settings']['clients'][$i]['email']}\n";
$text[] = "Menu -> " . $this->i18n('xray') . " -> {$pac['xrusers'][$i]['name']}\n";
$templates = $pac["{$type}templates"];
$data[] = [
[
@@ -4417,33 +4535,32 @@ DNS-over-HTTPS with IP:
public function userXr($i)
{
$c = $this->getXray()['inbounds'][0]['settings']['clients'][$i];
$pac = $this->getPacConf();
$c = $pac['xrusers'][$i];
$domain = $pac['domain'] ?: $this->ip;
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
$hash = substr(md5($this->key), 0, 8);
$text[] = "Menu -> " . $this->i18n('xray') . " -> {$c['email']}\n";
$text[] = "<code>{$this->linkXray($i)}</code>\n";
$text[] = "Menu -> " . $this->i18n('xray') . " -> {$c['name']}\n";
$text[] = "import subscribe:";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=v&s={$c['id']}#{$c['email']}'>v2rayng</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=si&s={$c['id']}#{$c['email']}'>sing-box</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=st&s={$c['id']}#{$c['email']}'>streisand</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=h&s={$c['id']}#{$c['email']}'>hiddify</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=v&s={$c['uuid']}#{$c['name']}'>v2rayng</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=si&s={$c['uuid']}#{$c['name']}'>sing-box</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=st&s={$c['uuid']}#{$c['name']}'>streisand</a>";
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=h&s={$c['uuid']}#{$c['name']}'>hiddify</a>";
$text[] = "\nv2ray config: <code>$scheme://{$domain}/pac?h=$hash&t=s&s={$c['id']}</code>";
$text[] = "sing-box config: <code>$scheme://{$domain}/pac?h=$hash&t=si&s={$c['id']}</code>";
$text[] = "sing-box windows: <a href='$scheme://{$domain}/pac?h=$hash&t=si&r=w&s={$c['id']}'>windows service</a>";
$text[] = "\nv2ray config: <code>$scheme://{$domain}/pac?h=$hash&t=s&s={$c['uuid']}</code>";
$text[] = "sing-box config: <code>$scheme://{$domain}/pac?h=$hash&t=si&s={$c['uuid']}</code>";
$text[] = "sing-box windows: <a href='$scheme://{$domain}/pac?h=$hash&t=si&r=w&s={$c['uuid']}'>windows service</a>";
$data[] = [
[
'text' => 'v2ray',
'web_app' => ['url' => "https://{$domain}/pac?h=$hash&t=s&s={$c['id']}"],
'web_app' => ['url' => "https://{$domain}/pac?h=$hash&t=s&s={$c['uuid']}"],
],
[
'text' => 'sing-box',
'web_app' => ['url' => "https://{$domain}/pac?h=$hash&t=si&s={$c['id']}"],
'web_app' => ['url' => "https://{$domain}/pac?h=$hash&t=si&s={$c['uuid']}"],
],
];
$data[] = [
@@ -4456,8 +4573,8 @@ DNS-over-HTTPS with IP:
'callback_data' => "/switchXr $i",
],
];
$singtemplate = $c['singtemplate'] ? base64_decode($c['singtemplate']) : 'default(' . ($pac['defaultsingtemplate'] && !empty($pac['singtemplates'][base64_decode($pac['defaultsingtemplate'])]) ? base64_decode($pac['defaultsingtemplate']) : 'origin') . ')';
$v2raytemplate = $c['v2raytemplate'] ? base64_decode($c['v2raytemplate']) : 'default(' . ($pac['defaultv2raytemplate'] && !empty($pac['v2raytemplates'][base64_decode($pac['defaultv2raytemplate'])]) ? base64_decode($pac['defaultv2raytemplate']) : 'origin') . ')';
$singtemplate = $c['singtemplate'] && !empty($pac['singtemplates'][base64_decode($c['singtemplate'])]) ? base64_decode($c['singtemplate']) : 'default(' . ($pac['defaultsingtemplate'] && !empty($pac['singtemplates'][base64_decode($pac['defaultsingtemplate'])]) ? base64_decode($pac['defaultsingtemplate']) : 'origin') . ')';
$v2raytemplate = $c['v2raytemplate'] && !empty($pac['v2raytemplates'][base64_decode($c['v2raytemplate'])]) ? base64_decode($c['v2raytemplate']) : 'default(' . ($pac['defaultv2raytemplate'] && !empty($pac['v2raytemplates'][base64_decode($pac['defaultv2raytemplate'])]) ? base64_decode($pac['defaultv2raytemplate']) : 'origin') . ')';
$data[] = [
[
'text' => $this->i18n('v2ray') . ": $v2raytemplate",
@@ -4506,45 +4623,6 @@ DNS-over-HTTPS with IP:
);
}
public function v2raySubscription($key, $fs = 0)
{
$pac = $this->getPacConf();
$domain = $pac['domain'] ?: $this->ip;
$xr = $this->getXray();
$flag = true;
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
if ($v['id'] == $key) {
if (!empty($fs)) {
return $this->userXr($k, 0, 1);
}
if (empty($v['off'])) {
$flag = false;
}
break;
}
}
if ($flag) {
return;
}
$c = json_decode(file_get_contents('/config/v2ray.json'), true);
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
$c['outbounds'][0]['settings']['vnext'][0]['users'][0]['id'] = $key;
$c['outbounds'][0]['streamSettings']['realitySettings']['serverName'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
$c['outbounds'][0]['streamSettings']['realitySettings']['publicKey'] = $pac['xray'];
$c['outbounds'][0]['streamSettings']['realitySettings']['shortId'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
$c['routing']['rules'][0]['domain'] = array_keys(array_filter($pac['includelist']));
if (empty($c['routing']['rules'][0]['domain'])) {
unset($c['routing']['rules'][0]);
$c['routing']['rules'] = array_values($c['routing']['rules']);
}
echo json_encode($c);
}
public function subscription()
{
$type = $_GET['t'] == 's' ? 'v2ray' : 'sing';
@@ -4555,13 +4633,13 @@ DNS-over-HTTPS with IP:
$hash = substr(md5($this->key), 0, 8);
$flag = true;
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
if ($v['id'] == $_GET['s']) {
foreach ($pac['xrusers'] as $k => $v) {
if ($v['uuid'] == $_GET['s']) {
if (empty($v['off'])) {
$flag = false;
}
$uid = $v['uuid'];
$template = base64_decode($v["{$type}template"]);
$uid = $v['id'];
break;
}
}
@@ -4627,9 +4705,9 @@ DNS-over-HTTPS with IP:
case 's':
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
$c['outbounds'][0]['settings']['vnext'][0]['users'][0]['id'] = $uid;
$c['outbounds'][0]['streamSettings']['realitySettings']['serverName'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
$c['outbounds'][0]['streamSettings']['realitySettings']['publicKey'] = $pac['xray'];
$c['outbounds'][0]['streamSettings']['realitySettings']['shortId'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
$c['outbounds'][0]['streamSettings']['realitySettings']['serverName'] = $pac['xray']['domain'];
$c['outbounds'][0]['streamSettings']['realitySettings']['publicKey'] = $pac['xray']['public'];
$c['outbounds'][0]['streamSettings']['realitySettings']['shortId'] = $pac['xray']['shortid'];
foreach ($c['routing']['rules'] as $k => $v) {
if (array_key_exists('domain', $v) && $v['domain'] == '~pac~') {
@@ -4646,11 +4724,86 @@ DNS-over-HTTPS with IP:
$c['dns']['servers'][0]['address'] = "tls://" . ($pac['adguardkey'] ? "{$pac['adguardkey']}." : '') . "$domain";
}
$c['outbounds'][0]['server'] = $domain;
$c['outbounds'][0]['uuid'] = $uid;
$c['outbounds'][0]['tls']['reality']['public_key'] = $pac['xray'];
$c['outbounds'][0]['tls']['server_name'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
$c['outbounds'][0]['tls']['reality']['short_id'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
switch ($pac['xtlsmode']) {
case 'shadow':
$o = [
[
"type" => "shadowtls",
"tag" => "ss-tls-out",
"server" => $domain,
"server_port" => 443,
"version" => 3,
"password" => $uid,
"tls" => [
"enabled" => true,
"server_name" => $pac['xray']['domain'],
"utls" => [
"enabled" => true,
"fingerprint" => "randomized"
]
]
],
[
"type" => "shadowsocks",
"tag" => "proxy",
"detour" => "ss-tls-out",
"method" => "2022-blake3-aes-128-gcm",
"password" => $pac['xray']['sspwd'],
"network" => "tcp",
"udp_over_tcp" => true,
"multiplex" => [
"enabled" => true,
"padding" => true
]
]
];
break;
case 'trojan':
break;
default:
$o = [
[
"flow" => "xtls-rprx-vision",
"packet_encoding" => "",
"server" => $domain,
"server_port" => 443,
"tls" => [
"enabled" => true,
"insecure" => false,
"reality" => [
"enabled" => true,
"public_key" => $pac['xray']['public'],
"short_id" => $pac['xray']['shortid']
],
"server_name" => $pac['xray']['domain'],
"utls" => [
"enabled" => true,
"fingerprint" => "chrome"
]
],
"uuid" => $uid,
"type" => "vless",
"domain_strategy" => "ipv4_only",
"tag" => "proxy"
]
];
break;
}
$c['outbounds'] = array_merge($o, [
[
"type" => "direct",
"tag" => "direct"
],
[
"type" => "block",
"tag" => "block"
],
[
"type" => "dns",
"tag" => "dns-out"
]
]);
foreach ($c['route']['rules'] as $k => $v) {
if (array_key_exists('domain_suffix', $v) && $v['domain_suffix'] == '~pac~') {
$c['route']['rules'][$k]['domain_suffix'] = array_keys(array_filter($pac['includelist'] ?: []));
@@ -4794,22 +4947,28 @@ DNS-over-HTTPS with IP:
public function getXray()
{
return json_decode(file_get_contents('/config/xray.json'), true);
return json_decode(file_get_contents('/config/singbox.json'), true);
}
public function generateSecretXray()
{
$c = $this->getXray();
$shortId = trim($this->ssh('openssl rand -hex 8', 'xr'));
$keys = $this->ssh('xray x25519', 'xr');
preg_match('~^Private key:\s([^\s]+)~m', $keys, $m);
$shortId = trim($this->ssh('openssl rand -hex 8', 'si'));
$keys = $this->ssh('sing-box generate reality-keypair', 'si');
preg_match('~^PrivateKey:\s([^\s]+)~m', $keys, $m);
$private = trim($m[1]);
preg_match('~^Public key:\s([^\s]+)~m', $keys, $m);
preg_match('~^PublicKey:\s([^\s]+)~m', $keys, $m);
$public = trim($m[1]);
$c['inbounds'][0]['streamSettings']['realitySettings']['privateKey'] = $private;
$c['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0] = $shortId;
$sspwd = trim($this->ssh('sing-box generate rand --base64 16', 'si'));
$pac = $this->getPacConf();
$pac['xray'] = $public;
$pac['xray'] = [
'domain' => !empty($pac['xray']['domain']) ? $pac['xray']['domain'] : 'vk.com',
'public' => $public,
'private' => $private,
'shortid' => $shortId,
'sspwd' => $sspwd,
];
$this->setPacConf($pac);
$this->restartXray($c);
}
@@ -4817,7 +4976,7 @@ DNS-over-HTTPS with IP:
public function setUpstreamDomain($domain)
{
$nginx = file_get_contents('/config/upstream.conf');
$t = preg_replace('~#domain.+#domain~s', "#domain\n$domain reality;\n#domain", $nginx);
$t = preg_replace('~#domain.+#domain~s', "#domain\n$domain singbox;\n#domain", $nginx);
file_put_contents('/config/upstream.conf', $t);
$this->ssh("nginx -s reload 2>&1", 'up');
}
@@ -4953,7 +5112,7 @@ DNS-over-HTTPS with IP:
],
],
[
'text' => $this->i18n('third party browser') . ': ' . $this->i18n($conf['adgbrowser'] ? 'on' : 'off'),
'text' => $this->i18n($conf['adgbrowser'] ? 'on' : 'off') . ' ' . $this->i18n('third party browser'),
'callback_data' => '/adguardChBr'
],
],
@@ -5292,7 +5451,7 @@ DNS-over-HTTPS with IP:
$this->update(
$this->input['chat'],
$this->input['message_id'],
implode("\n", $text ?: ['...']),
implode("\n", ['...']),
$data ?: false,
);
}
@@ -5380,26 +5539,20 @@ DNS-over-HTTPS with IP:
];
}
public function setFakeDomain($domain, $self = false)
public function setFakeDomain($domain)
{
$c = $this->getXray();
$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] = $domain;
$c['inbounds'][0]['streamSettings']['realitySettings']['dest'] = $self ? "10.10.1.2:443" : "$domain:443";
$this->restartXray($c);
$pac = $this->getPacConf();
if ($pac['domain'] == $domain) {
$this->send($this->input['from'], 'wrong domain');
return;
}
$pac['xray']['domain'] = $domain;
$this->setPacConf($pac);
$this->setUpstreamDomain($domain);
$this->restartXray();
$this->xray();
}
public function selfFakeDomain()
{
$c = $this->getPacConf();
if (!empty($c['domain'])) {
$this->setFakeDomain($c['domain'], 1);
} else{
$this->answer($this->input['callback_id'], 'empty domain', true);
}
}
public function setBackup($text)
{
$text = trim($text);
@@ -5477,7 +5630,7 @@ DNS-over-HTTPS with IP:
public function nginxGetTypeCert()
{
$conf = $this->ssh('cat /etc/nginx/nginx.conf', 'ng');
$conf = file_get_contents('/config/nginx.conf');
preg_match("/#~([^\s]+)/", $conf, $m);
return $m[1];
}
@@ -5771,6 +5924,12 @@ DNS-over-HTTPS with IP:
die('нет айпи');
}
echo "$ip\n";
$this->request('deleteWebhook', []);
$this->request('getUpdates', [
'offset' => -1,
'limit' => 1,
'timeout' => 5,
]);
var_dump($r = $this->request('setWebhook', [
'url' => "https://$ip/tlgrm?k={$this->key}",
'certificate' => curl_file_create('/certs/self_public'),
+2 -2
View File
@@ -262,8 +262,8 @@ $i = [
'ru' => 'очистить',
],
'xray' => [
'en' => 'XTLS-Reality',
'ru' => 'XTLS-Reality',
'en' => 'Sing-box',
'ru' => 'Sing-box',
],
'geodb' => [
'en' => 'GeoIp/GeoSite',
+4 -6
View File
@@ -2,7 +2,6 @@ user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
@@ -22,8 +21,8 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
@@ -75,12 +74,11 @@ http {
#-domain
# server {
# listen 10.10.0.2:80;
# listen 80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# listen 443 ssl http2 proxy_protocol;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
+4 -6
View File
@@ -2,7 +2,6 @@ user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
@@ -22,8 +21,8 @@ http {
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
listen 80 default_server;
listen 443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
@@ -75,12 +74,11 @@ http {
#-domain
# server {
# listen 10.10.0.2:80;
# listen 80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# listen 443 ssl http2 proxy_protocol;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
+1 -97
View File
@@ -1,99 +1,3 @@
{
"zapret": false,
"excludelist": {
"(?:v|w)ul(?:c|k)an": true,
"^\\d": true,
"^a\\w-": true,
"^admiral": true,
"^avtomaty": true,
"^azart": true,
"^azimob": true,
"^baltplay": true,
"a(?:s|z)ino": true,
"adrenalin": true,
"alco": true,
"bet": true,
"prostitut": true,
"zenit": true,
"zerkalo": true,
"777": true
},
"includelist": {},
"reverselist": {},
"subzoneslist": {
"3dn": false,
"3nx": true,
"akadns": true,
"appspot": true,
"azurewebsites": true,
"beget": true,
"berlogovo": true,
"biz": true,
"brightcove": true,
"cc": true,
"cloudfront": true,
"co": true,
"com": true,
"cu": true,
"ddns": true,
"deviantart": true,
"dn": true,
"dp": true,
"dyndns": true,
"edgecastcdn": true,
"edu": true,
"eu": true,
"fastly": true,
"force": true,
"github": true,
"google": true,
"googleusercontent": true,
"gov": true,
"herokuapp": true,
"hldns": true,
"ho": true,
"hopto": true,
"hwcdn": true,
"i": true,
"iboards": true,
"in": true,
"info": true,
"int": true,
"itch": true,
"keenetic": true,
"kiev": true,
"kirov": true,
"linode": true,
"livejournal": true,
"maryno": true,
"mil": true,
"msk": true,
"my1": true,
"mybb2": true,
"ne": true,
"net": true,
"netdna-ssl": true,
"nnov": true,
"notion": true,
"nov": true,
"od": true,
"org": true,
"pp": true,
"pximg": true,
"pythonanywhere": true,
"ru": true,
"scaleway": true,
"sl": true,
"sl-reverse": true,
"spb": true,
"tilda": true,
"trafficmanager": true,
"tut": true,
"u-stream": true,
"ucoz": true,
"v": true,
"vercel": true,
"wix": true,
"wixmp": true
}
"includelist": []
}
+1 -45
View File
@@ -54,54 +54,10 @@
"detour": "direct"
}
],
"rules": [
{
"outbound": "any",
"server": "dns-direct",
"disable_cache": false
}
],
"strategy": "ipv4_only",
"independent_cache": true
},
"outbounds": [
{
"flow": "xtls-rprx-vision",
"packet_encoding": "",
"server": "",
"server_port": 443,
"tls": {
"enabled": true,
"insecure": false,
"reality": {
"enabled": true,
"public_key": "",
"short_id": ""
},
"server_name": "",
"utls": {
"enabled": true,
"fingerprint": "chrome"
}
},
"uuid": "",
"type": "vless",
"domain_strategy": "ipv4_only",
"tag": "proxy"
},
{
"type": "direct",
"tag": "direct"
},
{
"type": "block",
"tag": "block"
},
{
"type": "dns",
"tag": "dns-out"
}
],
"outbounds": [],
"route": {
"auto_detect_interface": true,
"override_android_vpn": true,
+26
View File
@@ -0,0 +1,26 @@
{
"inbounds": [],
"log": {
"level": "info"
},
"outbounds": [
{
"type": "direct",
"tag": "direct"
},
{
"type": "block",
"tag": "block"
},
{
"type": "socks",
"tag": "warp",
"server": "10.10.0.13",
"server_port": 4000
}
],
"route" : {
"rules": [],
"final": "direct"
}
}
+14 -5
View File
@@ -15,8 +15,12 @@ stream {
server ng:443;
}
upstream reality {
server xr:443;
upstream si {
server si:443;
}
upstream singbox {
server 127.0.0.1:4443;
}
upstream ocserv {
@@ -30,7 +34,7 @@ stream {
map_hash_bucket_size 128;
map $ssl_preread_server_name $sni_name {
#domain
www.microsoft.com reality;
vk.com singbox;
#domain
#ocserv
@@ -43,17 +47,22 @@ stream {
default other;
}
server {
listen 4443 reuseport proxy_protocol;
proxy_pass si;
}
server {
listen 443 reuseport;
proxy_pass $sni_name;
proxy_protocol on;
ssl_preread on;
proxy_protocol on;
}
server {
listen 443 udp;
proxy_pass $sni_name;
proxy_protocol on;
ssl_preread on;
proxy_protocol on;
}
}
-61
View File
@@ -1,61 +0,0 @@
{
"inbounds": [
{
"port": 443,
"protocol": "vless",
"settings": {
"clients": [
],
"decryption": "none"
},
"sniffing": {
"destOverride": [
"http",
"tls"
],
"enabled": true
},
"streamSettings": {
"network": "tcp",
"realitySettings": {
"dest": "www.microsoft.com:443",
"maxClientVer": "",
"maxTimeDiff": 0,
"minClientVer": "",
"privateKey": "",
"serverNames": [
"www.microsoft.com"
],
"shortIds": [],
"show": false,
"xver": 0
},
"tcpSettings": {
"acceptProxyProtocol": true
},
"sockopt": {
"acceptProxyProtocol": true
},
"security": "reality"
},
"tag": "vless_tls"
}
],
"log": {
"loglevel": "info"
},
"outbounds": [
{
"protocol": "freedom",
"tag": "direct"
},
{
"protocol": "blackhole",
"tag": "block"
}
],
"routing": {
"domainStrategy": "AsIs",
"rules": []
}
}
+12 -21
View File
@@ -10,10 +10,6 @@ networks:
ipam:
config:
- subnet: 10.10.0.0/24
xray:
ipam:
config:
- subnet: 10.10.1.0/24
volumes:
adguard:
@@ -27,9 +23,9 @@ services:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/upstream.conf:/etc/nginx/nginx.conf
- ./scripts/start_upstream.sh:/start_upstream.sh
- ./ssh:/ssh
- ./config:/config
- ./config/sshd_config:/etc/ssh/sshd_config
- ./logs/:/logs/
ports:
@@ -63,9 +59,7 @@ services:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/nginx.conf:/etc/nginx/nginx.conf
- ./config/include.conf:/etc/nginx/include.conf
- ./config/nginx_default.conf:/nginx_default.conf
- ./config:/config
- ./scripts/start_ng.sh:/start_ng.sh
- ./certs/:/certs/
- ./ssh:/ssh
@@ -89,8 +83,6 @@ services:
networks:
default:
ipv4_address: 10.10.0.2
xray:
ipv4_address: 10.10.1.2
logging: *default-logging
php:
image: mercurykd/vpnbot-php:1.5
@@ -187,7 +179,7 @@ services:
- ad
- ss
- tg
- xr
- si
- oc
- np
proxy:
@@ -398,20 +390,21 @@ services:
default:
ipv4_address: 10.10.0.8
logging: *default-logging
xr:
image: mercurykd/vpnbot-xr:1.3
si:
image: mercurykd/vpnbot-sb:1.2
build:
dockerfile: dockerfile/xray.dockerfile
dockerfile: dockerfile/singbox.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./config/xray.json:/xray.json
- ./scripts/start_xray.sh:/start_xray.sh
hostname: xray
container_name: xray-${VER}
- ./config:/config
- ./certs:/certs
- ./scripts/start_sing.sh:/start_sing.sh
hostname: singbox
container_name: singbox-${VER}
depends_on:
php:
condition: service_healthy
@@ -421,12 +414,10 @@ services:
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_xray.sh"]
command: ["/bin/sh", "/start_sing.sh"]
networks:
default:
ipv4_address: 10.10.0.9
xray:
ipv4_address: 10.10.1.9
logging: *default-logging
oc:
image: mercurykd/vpnbot-oc:1.2
+9
View File
@@ -0,0 +1,9 @@
ARG image
FROM $image
RUN apk add openssh openssl jq \
&& mkdir /root/.ssh \
&& wget https://github.com/SagerNet/sing-box/releases/download/v1.9.3/sing-box-1.9.3-linux-amd64.tar.gz \
&& tar -xf sing-box-1.9.3-linux-amd64.tar.gz \
&& mv sing-box-1.9.3-linux-amd64/sing-box /usr/bin \
&& rm sing-box-1.9.3-linux-amd64.tar.gz \
&& rm -rf /sing-box-1.9.3-linux-amd64
-12
View File
@@ -1,12 +0,0 @@
ARG image
FROM $image
RUN apk add openssh openssl jq \
&& mkdir /root/.ssh \
&& wget -O Xray-linux-64.zip $(wget -q -O - https://api.github.com/repos/XTLS/Xray-core/releases/latest | grep browser_download_url | cut -d\" -f4 | egrep 'Xray-linux-64.zip$') \
&& unzip Xray-linux-64.zip \
&& mv xray /usr/bin/ \
&& rm Xray-linux-64.zip \
&& rm geoip.dat \
&& rm geosite.dat \
&& chmod +x /usr/bin/xray
ENV ENV="/root/.ashrc"
+2 -2
View File
@@ -36,8 +36,8 @@ proxy: # консоль сервиса
docker compose exec proxy /bin/sh
tg: # консоль сервиса
docker compose exec tg /bin/sh
xr: # консоль сервиса
docker compose exec xr /bin/sh
si: # консоль сервиса
docker compose exec si /bin/sh
oc: # консоль сервиса
docker compose exec oc /bin/sh
clean:
+5 -5
View File
@@ -1,8 +1,8 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
sed "s/ss:[0-9]\+/ss:$SSPORT/" /nginx_default.conf > change_port
cat change_port > /nginx_default.conf
sed "s/ss:[0-9]\+/ss:$SSPORT/" /etc/nginx/nginx.conf > change_port
cat change_port > /etc/nginx/nginx.conf
nginx -g "daemon off;"
sed "s/ss:[0-9]\+/ss:$SSPORT/" /config/nginx_default.conf > change_port
cat change_port > /config/nginx_default.conf
sed "s/ss:[0-9]\+/ss:$SSPORT/" /config/nginx.conf > change_port
cat change_port > /config/nginx.conf
nginx -g "daemon off;" -c /config/nginx.conf
+5
View File
@@ -0,0 +1,5 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
sing-box run -c /config/singbox.json > /dev/null &
tail -f /dev/null
+1 -1
View File
@@ -1,4 +1,4 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
nginx -g "daemon off;"
nginx -g "daemon off;" -c /config/upstream.conf
-8
View File
@@ -1,8 +0,0 @@
cat /ssh/key.pub > /root/.ssh/authorized_keys
ssh-keygen -A
exec /usr/sbin/sshd -D -e "$@" &
if [ $(cat /xray.json | jq -r '.inbounds[0].settings.clients[0].id' | wc -c) -gt 1 ]
then
xray run -config /xray.json > /dev/null &
fi
tail -f /dev/null