mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
3x-ui: revert nginx + ports to 543fcc6 (testing) declarative state
Sapphira: HTTP reverse proxy serves panel/sub on x.zeroq.su;
no xray stream on 443 and no 8443 stream either (8443 is directly
exposed by podman as 0.0.0.0:8443:8443/tcp).
Otreca: stream on 443 routes by SNI (panel via pubray1.zeroq.su,
xray default) and 8443 is direct 0.0.0.0:8443.
Modules/containers/3x-ui.nix:
- basePorts restored: '0.0.0.0:8443:8443/tcp' (was '127.0.0.1:15380:8443/tcp')
- realityPorts restored (was 'lib.optional ... "127.0.0.1:15380:443/tcp"')
- image restored: ':latest' (was ':v3.9.0')
Modules/server/nginx.nix:
- removed 8443 streamConfig for xray (the one b0191bc added)
- removed 8443 from allowedTCPPorts
Other files (configurations/{server,vds,wsl}.nix, home/modules/opencode.nix)
left alone — they contain SSH firewall / builder / opencode web changes
unrelated to nginx + ports that the user asked to revert.
This commit is contained in:
@@ -225,26 +225,5 @@ in
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
80
|
||||
443
|
||||
8443
|
||||
];
|
||||
|
||||
# TCP-level proxy for the 3x-ui xray inbound on 8443. nginx doesn't
|
||||
# unwrap TLS here — `proxy_pass` just relays opaque TCP bytes between
|
||||
# the client and the xray inside the 3x-ui container. Podman's
|
||||
# userspace port-forward mangles the Reality ClientHello, so we go
|
||||
# via nginx stream (same pattern as VDS uses for port 443) instead:
|
||||
# client → nginx stream :8443 → 127.0.0.1:15380 → podman → xray :8443.
|
||||
# Reality auth and TLS are preserved end-to-end.
|
||||
services.nginx.streamConfig = ''
|
||||
upstream xray_in_8443 {
|
||||
server 127.0.0.1:15380;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 8443;
|
||||
proxy_pass xray_in_8443;
|
||||
proxy_timeout 600s;
|
||||
proxy_connect_timeout 5s;
|
||||
}
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user