3x-ui server mask

This commit is contained in:
2026-09-17 00:56:41 +03:00
parent b57ca3eedf
commit 5f1496e980
2 changed files with 102 additions and 29 deletions
+8 -6
View File
@@ -44,12 +44,14 @@
# ./trilium.nix
# ./zerotier.nix
];
# Server's 3x-ui is the controller panel at x.zeroq.su (nginx HTTP
# terminates TLS upstream, no SNI-routing on 443 needed here because
# there are other vhosts on the same port). Cert is still mounted in
# case 3x-ui is later reconfigured to terminate TLS itself (e.g. for
# direct node-API access); nginx doesn't have to use it.
xlib.services."3x-ui".certDomain = "x.zeroq.su";
# Server's 3x-ui is the controller panel at x.zeroq.su, wired the same
# way as the VDS node: nginx stream SNI-routes x.zeroq.su → container:2049
# (3x-ui terminates TLS itself with the mounted LE cert), and the default
# SNI → Xray REALITY via host:15380 → container:443 (see nginx.nix).
xlib.services."3x-ui" = {
certDomain = "x.zeroq.su";
reality443Forwarding = true;
};
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")