mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
cleaning
This commit is contained in:
@@ -46,7 +46,7 @@ in
|
|||||||
oci-containers = {
|
oci-containers = {
|
||||||
backend = "podman";
|
backend = "podman";
|
||||||
containers."3xui_app" = {
|
containers."3xui_app" = {
|
||||||
image = "ghcr.io/mhsanaei/3x-ui:v3.8.5";
|
image = "ghcr.io/mhsanaei/3x-ui:latest";
|
||||||
environment = {
|
environment = {
|
||||||
"XRAY_VMESS_AEAD_FORCED" = "false";
|
"XRAY_VMESS_AEAD_FORCED" = "false";
|
||||||
"XUI_ENABLE_FAIL2BAN" = "true";
|
"XUI_ENABLE_FAIL2BAN" = "true";
|
||||||
@@ -89,13 +89,13 @@ in
|
|||||||
unitConfig.Description = "Root target generated by compose2nix.";
|
unitConfig.Description = "Root target generated by compose2nix.";
|
||||||
wantedBy = [ "multi-user.target" ];
|
wantedBy = [ "multi-user.target" ];
|
||||||
};
|
};
|
||||||
timers."podman-update-3xui_app" = {
|
# timers."podman-update-3xui_app" = {
|
||||||
wantedBy = [ "timers.target" ];
|
# wantedBy = [ "timers.target" ];
|
||||||
timerConfig = {
|
# timerConfig = {
|
||||||
OnCalendar = "weekly";
|
# OnCalendar = "weekly";
|
||||||
Persistent = true;
|
# Persistent = true;
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
tmpfiles.rules = [
|
tmpfiles.rules = [
|
||||||
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
||||||
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
|
||||||
|
|||||||
@@ -10,6 +10,9 @@
|
|||||||
enable = true;
|
enable = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
port = 61208;
|
port = 61208;
|
||||||
|
extraArgs = [
|
||||||
|
"--bind 100.64.0.0"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,6 @@
|
|||||||
./systemd.nix
|
./systemd.nix
|
||||||
# ./glances.nix
|
# ./glances.nix
|
||||||
# ./netbird.nix
|
# ./netbird.nix
|
||||||
# ./xray.nix
|
|
||||||
];
|
];
|
||||||
# VDS hosts the public-facing Xray REALITY inbound on container:443,
|
# VDS hosts the public-facing Xray REALITY inbound on container:443,
|
||||||
# fronted by nginx stream on host:443 → host:15380 → container:443.
|
# fronted by nginx stream on host:443 → host:15380 → container:443.
|
||||||
|
|||||||
@@ -10,6 +10,9 @@
|
|||||||
enable = true;
|
enable = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
port = 61208;
|
port = 61208;
|
||||||
|
extraArgs = [
|
||||||
|
"--bind 100.64.1.0"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,44 +0,0 @@
|
|||||||
{
|
|
||||||
config,
|
|
||||||
inputs,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
services.xray = {
|
|
||||||
enable = false;
|
|
||||||
settings = inputs.zeroq-credentials.services.xray.config;
|
|
||||||
};
|
|
||||||
|
|
||||||
# networking.firewall = {
|
|
||||||
# allowedTCPPorts = [
|
|
||||||
# 8443
|
|
||||||
# 9443
|
|
||||||
# 13380
|
|
||||||
# ];
|
|
||||||
# allowedUDPPorts = [
|
|
||||||
# 8443
|
|
||||||
# 9443
|
|
||||||
# 13380
|
|
||||||
# ];
|
|
||||||
# };
|
|
||||||
|
|
||||||
environment.systemPackages = [ pkgs.xray ];
|
|
||||||
|
|
||||||
# sops.secrets = {
|
|
||||||
# xray_uuid = {
|
|
||||||
# key = "uuid";
|
|
||||||
# mode = "0444";
|
|
||||||
# format = "yaml";
|
|
||||||
# sopsFile = ./secrets/xray.yaml;
|
|
||||||
# path = "/etc/xray/uuid";
|
|
||||||
# };
|
|
||||||
# xray_private-key = {
|
|
||||||
# path = "/etc/xray/private-key";
|
|
||||||
# key = "private-key";
|
|
||||||
# mode = "0444";
|
|
||||||
# format = "yaml";
|
|
||||||
# sopsFile = ./secrets/xray.yaml;
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user