fix(3x-ui): restore reality443Forwarding — T10 removal broke Xray REALITY

Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему
не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.'

T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched
and still routes:
  pubray1.zeroq.su  → 127.0.0.1:2049  (panel)
  pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY)
  default           → 127.0.0.1:15380 (fallback)

Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx
stream forward TLS to a dead port → Xray REALITY unreachable. SSH and
pubray1.zeroq.su kept working because they do NOT depend on 15380.

Restored (exact pre-T10 code from 61b3724):
- modules/options.nix: reality443Forwarding option
- modules/vds/default.nix: reality443Forwarding = true
- modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts
- manifest.json T10 → status 'pending' (reopened with corrected notes)

Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports =
  [..., '127.0.0.1:15380:443/tcp']
This commit is contained in:
2026-10-10 17:54:18 +03:00
parent 37b4956a25
commit 07a0437c13
4 changed files with 30 additions and 9 deletions
+5 -2
View File
@@ -14,10 +14,13 @@
];
# VDS hosts the public-facing Xray REALITY inbound on container:443,
# fronted by nginx stream on host:443 → host:15380 → container:443.
# reality443Forwarding removed 2026-10-10 (T10/C5): option's purpose
# was lost after c8d4a12 revert; nginx stream on otreca still works.
# reality443Forwarding MUST stay true here: modules/vds/nginx.nix
# routes pubrayx1.zeroq.su/default → 127.0.0.1:15380, which only
# exists when this mapping is published. (Restored 2026-10-10 after
# T10/C5 wrongly removed it and broke Xray REALITY.)
host."3x-ui" = {
certDomain = "pubray1.zeroq.su";
reality443Forwarding = true;
};
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")