fix(3x-ui): restore reality443Forwarding — T10 removal broke Xray REALITY

Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему
не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.'

T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched
and still routes:
  pubray1.zeroq.su  → 127.0.0.1:2049  (panel)
  pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY)
  default           → 127.0.0.1:15380 (fallback)

Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx
stream forward TLS to a dead port → Xray REALITY unreachable. SSH and
pubray1.zeroq.su kept working because they do NOT depend on 15380.

Restored (exact pre-T10 code from 61b3724):
- modules/options.nix: reality443Forwarding option
- modules/vds/default.nix: reality443Forwarding = true
- modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts
- manifest.json T10 → status 'pending' (reopened with corrected notes)

Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports =
  [..., '127.0.0.1:15380:443/tcp']
This commit is contained in:
2026-10-10 17:54:18 +03:00
parent 37b4956a25
commit 07a0437c13
4 changed files with 30 additions and 9 deletions
+2 -2
View File
@@ -175,7 +175,7 @@
"id": "T10",
"title": "C5: решить судьбу reality443Forwarding",
"type": "decision",
"status": "completed",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
@@ -184,7 +184,7 @@
],
"files": ["modules/vds/default.nix", "modules/options.nix", "modules/containers/3x-ui.nix"],
"blocks": [],
"notes": "Решение (б): опция погашена. Удалена из options.nix:66-74, realityPorts из 3x-ui.nix:33-35, reality443Forwarding = true из vds/default.nix:19. ADR-note в options.nix (комментарий на месте удаления) + в 3x-ui.nix + vds/default.nix."
"notes": "REVERTED 2026-10-10. Решение (б) оказалось ОШИБОЧНЫМ: modules/vds/nginx.nix (не тронут) всё ещё маршрутизирует pubrayx1.zeroq.su/default → 127.0.0.1:15380, поэтому после удаления маппинга 127.0.0.1:15380:443/tcp nginx stream смотрит в мёртвый порт и Xray REALITY недоступен (владелец: 'xray по прежнему не работает'). Восстановлено: reality443Forwarding в options.nix, reality443Forwarding=true в vds/default.nix, realityPorts в 3x-ui.nix + ports = basePorts ++ realityPorts. Проверено: nix eval показывает [..., \"127.0.0.1:15380:443/tcp\"]. Решение вернуться к (а): опция нужна, её роль — публикация 15380→443 для nginx stream SNI-routing."
},
{
"id": "T11",
+4 -1
View File
@@ -30,6 +30,9 @@ let
"127.0.0.1:2096:2096/tcp"
"0.0.0.0:8443:8443/tcp"
];
# VDS-only: nginx stream forwards host:443 → 127.0.0.1:15380 →
# container:443, so Xray sees its REALITY inbound on port 443.
realityPorts = lib.optional config.host."3x-ui".reality443Forwarding "127.0.0.1:15380:443/tcp";
in
{
# `host."3x-ui"` options are declared in modules/options.nix: they are set
@@ -62,7 +65,7 @@ in
log-driver = "journald";
# Adding a new inbound through the 3x-ui panel on a port outside
# the 14380-15379 range requires extending basePorts and rebuilding.
ports = basePorts;
ports = basePorts ++ realityPorts;
};
};
};
+19 -4
View File
@@ -58,9 +58,24 @@
container at /root/cert/fullchain.pem and key.pem.
'';
};
# reality443Forwarding was removed (T10/C5, 2026-10-10). The
# option's purpose was lost after the c8d4a12 revert (manifest:177-178);
# nginx stream on otreca still works without it. See ADR-0002
# in .agent/decisions/ for the decision record.
# Publish host:15380 → container:443. Only nodes that host an
# Xray REALITY inbound on container:443 need this (so nginx
# stream can forward TLS to Xray via 127.0.0.1:15380 while Xray
# itself sees incoming connections on its configured port 443).
# Set false on nodes that only run the 3x-ui panel.
#
# RESTORED 2026-10-10: this option was wrongly removed by T10/C5.
# modules/vds/nginx.nix still routes pubrayx1.zeroq.su/default →
# 127.0.0.1:15380, so without this mapping the nginx stream points
# at a dead port and Xray REALITY is unreachable.
reality443Forwarding = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When true, publish host:15380 → container:443 so Xray
inside the container can serve REALITY on its real
configured port 443 (nginx stream forwards 443 → 15380).
'';
};
};
}
+5 -2
View File
@@ -14,10 +14,13 @@
];
# VDS hosts the public-facing Xray REALITY inbound on container:443,
# fronted by nginx stream on host:443 → host:15380 → container:443.
# reality443Forwarding removed 2026-10-10 (T10/C5): option's purpose
# was lost after c8d4a12 revert; nginx stream on otreca still works.
# reality443Forwarding MUST stay true here: modules/vds/nginx.nix
# routes pubrayx1.zeroq.su/default → 127.0.0.1:15380, which only
# exists when this mapping is published. (Restored 2026-10-10 after
# T10/C5 wrongly removed it and broke Xray REALITY.)
host."3x-ui" = {
certDomain = "pubray1.zeroq.su";
reality443Forwarding = true;
};
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")