From 11af2c150a64bcc039864c9085d475af6aa9c45c Mon Sep 17 00:00:00 2001 From: oqyude Date: Fri, 28 Aug 2026 00:56:28 +0300 Subject: [PATCH] =?UTF-8?q?vds:=20drop=20pubrayx1.zeroq.su=20from=20SNI=20?= =?UTF-8?q?map=20=E2=80=94=20Xray=20now=20served=20under=20pubray1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit All Xray REALITY clients already connect to VDS_IP via pubray1.zeroq.su (or any of its subdomains). Removing the explicit pubrayx1.zeroq.su → xray rule means the default route catches it. This way we only have to publish one domain (pubray1.zeroq.su) in subscriptions instead of two. Companion change in x-ui.db (separate runbook step): subURI set to https://pubray1.zeroq.su/subs/ so regenerated subscriptions emit URLs under pubray1.zeroq.su, not x.zeroq.su. --- modules/vds/nginx.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/modules/vds/nginx.nix b/modules/vds/nginx.nix index 7610861..f44e306 100644 --- a/modules/vds/nginx.nix +++ b/modules/vds/nginx.nix @@ -23,10 +23,15 @@ let stream { ssl_preread on; + # pubray1.zeroq.su SNI → 3x-ui panel (TLS terminated inside the + # container using the LE cert mounted from /var/lib/acme/). + # Everything else (including any sni the REALITY client uses, + # e.g. media.mediavitrina.ru) → Xray. So a single domain + # pubray1.zeroq.su serves both panel and Xray — the SNI in the + # TLS ClientHello disambiguates. map $ssl_preread_server_name $sni_backend { default xray; pubray1.zeroq.su panel; - pubrayx1.zeroq.su xray; } upstream panel {