restructuring

This commit is contained in:
2026-10-01 15:14:37 +03:00
parent d49fd5a358
commit c05cc88843
9 changed files with 369 additions and 293 deletions
+3 -29
View File
@@ -35,35 +35,9 @@ let
realityPorts = lib.optional config.host."3x-ui".reality443Forwarding "127.0.0.1:15380:443/tcp";
in
{
options.host."3x-ui" = {
# Domain whose LE cert should be mounted into the 3x-ui container at
# /root/cert/fullchain.pem and key.pem. Set null if 3x-ui serves plain
# HTTP and TLS is terminated by an upstream nginx.
certDomain = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
example = "pubray1.zeroq.su";
description = ''
Domain whose LE cert should be mounted into the 3x-ui
container at /root/cert/fullchain.pem and key.pem.
'';
};
# Publish host:15380 → container:443. Only nodes that host an Xray
# REALITY inbound on container:443 need this (so nginx stream can
# forward TLS to Xray via 127.0.0.1:15380 while Xray itself sees
# incoming connections on its configured port 443). Set false on nodes
# that only run the 3x-ui panel.
reality443Forwarding = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When true, publish host:15380 → container:443 so Xray
inside the container can serve REALITY on its real
configured port 443 (nginx stream forwards 443 → 15380).
'';
};
};
# `host."3x-ui"` options are declared in modules/options.nix: they are set
# by modules/server and modules/vds, so this module cannot be the only place
# that knows they exist.
config = {
virtualisation = {
podman = {
+2
View File
@@ -17,6 +17,7 @@ let
with inputs;
[
./essentials
./options.nix
./users.nix
home-manager.nixosModules.home-manager # home-manager module
@@ -45,6 +46,7 @@ let
imports = [
# ./essentials
# ./users.nix
./options.nix
(./. + "/${xlib.device.type}")
# sops-nix.nixosModules.sops
];
+41
View File
@@ -0,0 +1,41 @@
{
lib,
...
}:
# Cross-module options: declared here, not in the module that reads them.
#
# An option belongs in this file when at least one context *sets* it while
# another module *reads* it — the reader cannot be the only place that knows
# the option exists. `modules/essentials/ssh.nix` does not belong here: it
# declares and reads `host.ssh.enable` itself, within one module.
{
options.host."3x-ui" = {
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/)
# gets mounted read-only into the 3x-ui container so the panel
# can terminate TLS itself. Set null if 3x-ui serves plain HTTP
# and TLS is terminated by an upstream nginx.
certDomain = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
example = "pubray1.zeroq.su";
description = ''
Domain whose LE cert should be mounted into the 3x-ui
container at /root/cert/fullchain.pem and key.pem.
'';
};
# Publish host:15380 → container:443. Only nodes that host an
# Xray REALITY inbound on container:443 need this (so nginx
# stream can forward TLS to Xray via 127.0.0.1:15380 while Xray
# itself sees incoming connections on its configured port 443).
# Set false on nodes that only run the 3x-ui panel.
reality443Forwarding = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When true, publish host:15380 → container:443 so Xray
inside the container can serve REALITY on its real
configured port 443 (nginx stream forwards 443 → 15380).
'';
};
};
}