3x-ui: revert nginx + ports to 543fcc6 (testing) declarative state

Sapphira: HTTP reverse proxy serves panel/sub on x.zeroq.su;
no xray stream on 443 and no 8443 stream either (8443 is directly
exposed by podman as 0.0.0.0:8443:8443/tcp).

Otreca: stream on 443 routes by SNI (panel via pubray1.zeroq.su,
xray default) and 8443 is direct 0.0.0.0:8443.

Modules/containers/3x-ui.nix:
  - basePorts restored: '0.0.0.0:8443:8443/tcp' (was '127.0.0.1:15380:8443/tcp')
  - realityPorts restored (was 'lib.optional ... "127.0.0.1:15380:443/tcp"')
  - image restored: ':latest' (was ':v3.9.0')

Modules/server/nginx.nix:
  - removed 8443 streamConfig for xray (the one b0191bc added)
  - removed 8443 from allowedTCPPorts

Other files (configurations/{server,vds,wsl}.nix, home/modules/opencode.nix)
left alone — they contain SSH firewall / builder / opencode web changes
unrelated to nginx + ports that the user asked to revert.
This commit is contained in:
2026-10-04 22:05:27 +03:00
parent c854b2cc6d
commit c8d4a12a73
2 changed files with 12 additions and 286 deletions
-21
View File
@@ -225,26 +225,5 @@ in
networking.firewall.allowedTCPPorts = [
80
443
8443
];
# TCP-level proxy for the 3x-ui xray inbound on 8443. nginx doesn't
# unwrap TLS here — `proxy_pass` just relays opaque TCP bytes between
# the client and the xray inside the 3x-ui container. Podman's
# userspace port-forward mangles the Reality ClientHello, so we go
# via nginx stream (same pattern as VDS uses for port 443) instead:
# client → nginx stream :8443 → 127.0.0.1:15380 → podman → xray :8443.
# Reality auth and TLS are preserved end-to-end.
services.nginx.streamConfig = ''
upstream xray_in_8443 {
server 127.0.0.1:15380;
}
server {
listen 8443;
proxy_pass xray_in_8443;
proxy_timeout 600s;
proxy_connect_timeout 5s;
}
'';
}