mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
vds: drop pubrayx1.zeroq.su from SNI map — Xray now served under pubray1
All Xray REALITY clients already connect to VDS_IP via pubray1.zeroq.su (or any of its subdomains). Removing the explicit pubrayx1.zeroq.su → xray rule means the default route catches it. This way we only have to publish one domain (pubray1.zeroq.su) in subscriptions instead of two. Companion change in x-ui.db (separate runbook step): subURI set to https://pubray1.zeroq.su/subs/ so regenerated subscriptions emit URLs under pubray1.zeroq.su, not x.zeroq.su.
This commit is contained in:
@@ -23,10 +23,15 @@ let
|
|||||||
stream {
|
stream {
|
||||||
ssl_preread on;
|
ssl_preread on;
|
||||||
|
|
||||||
|
# pubray1.zeroq.su SNI → 3x-ui panel (TLS terminated inside the
|
||||||
|
# container using the LE cert mounted from /var/lib/acme/).
|
||||||
|
# Everything else (including any sni the REALITY client uses,
|
||||||
|
# e.g. media.mediavitrina.ru) → Xray. So a single domain
|
||||||
|
# pubray1.zeroq.su serves both panel and Xray — the SNI in the
|
||||||
|
# TLS ClientHello disambiguates.
|
||||||
map $ssl_preread_server_name $sni_backend {
|
map $ssl_preread_server_name $sni_backend {
|
||||||
default xray;
|
default xray;
|
||||||
pubray1.zeroq.su panel;
|
pubray1.zeroq.su panel;
|
||||||
pubrayx1.zeroq.su xray;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
upstream panel {
|
upstream panel {
|
||||||
|
|||||||
Reference in New Issue
Block a user