refactoring

This commit is contained in:
2026-08-29 04:05:38 +03:00
parent 7f5ea81f37
commit e1d276097d
3 changed files with 203 additions and 455 deletions
+30 -64
View File
@@ -10,26 +10,27 @@ let
certDomain = xlib.services."3x-ui".certDomain or null;
certMounts =
if certDomain == null then [ ]
else [
# Let's Encrypt cert for the panel domain — mounted read-only so
# 3x-ui can serve the panel over its own TLS. webCertFile /
# webKeyFile in the x-ui settings table must point at
# /root/cert/fullchain.pem and /root/cert/key.pem respectively.
"/var/lib/acme/${certDomain}/fullchain.pem:/root/cert/fullchain.pem:ro"
"/var/lib/acme/${certDomain}/key.pem:/root/cert/key.pem:ro"
];
else
# LE cert mounted read-only so 3x-ui can terminate TLS itself.
# The 3x-ui settings table must point webCertFile / webKeyFile at
# /root/cert/fullchain.pem and /root/cert/key.pem.
map (f: "/var/lib/acme/${certDomain}/${f}:/root/cert/${f}:ro") [
"fullchain.pem"
"key.pem"
];
basePorts = [
# 2049/tcp — 3x-ui web panel
# 2096/tcp — subscription endpoint
# 14380-15379/tcp+udp — Xray inbounds (matches firewall open range)
"0.0.0.0:2049:2049/tcp"
"0.0.0.0:2096:2096/tcp"
"0.0.0.0:14380-15379:14380-15379/tcp"
"0.0.0.0:14380-15379:14380-15379/udp"
];
realityPorts =
# Only vds needs the 15380→443 forwarding that lets nginx stream
# pass-through Xray REALITY while Xray itself sees the connection
# arriving on 443 (matching its REALITY inbound config).
lib.optional xlib.services."3x-ui".reality443Forwarding
"0.0.0.0:15380:443/tcp";
# VDS-only: nginx stream forwards host:443 → host:15380 → container:443,
# so Xray inside the container sees its REALITY inbound on its real
# configured port 443.
realityPorts = lib.optional xlib.services."3x-ui".reality443Forwarding "0.0.0.0:15380:443/tcp";
in
{
virtualisation = {
@@ -55,15 +56,8 @@ in
"${panel}/db/:/etc/x-ui:rw"
] ++ certMounts;
log-driver = "journald";
# Port-forwarded networking (replaces --network=host).
# Common across all nodes that import this module:
# 2049/tcp — 3x-ui web panel
# 2096/tcp — subscription endpoint
# 14380-15379/tcp+udp — Xray inbounds (matches firewall open range)
# Vds-only (xlib.services.3x-ui.reality443Forwarding = true):
# 15380→443/tcp — Xray REALITY inbound (nginx stream on 443 → 15380)
# Adding a new inbound through the 3x-ui panel on a port outside
# this range will require extending this list and rebuilding.
# the 14380-15379 range requires extending basePorts and rebuilding.
ports = basePorts ++ realityPorts;
};
};
@@ -72,21 +66,12 @@ in
systemd = {
services = {
"podman-3xui_app" = {
serviceConfig = {
Restart = lib.mkOverride 90 "always";
};
partOf = [
"podman-compose-3x-ui-root.target"
];
wantedBy = [
"podman-compose-3x-ui-root.target"
];
serviceConfig.Restart = lib.mkOverride 90 "always";
partOf = [ "podman-compose-3x-ui-root.target" ];
wantedBy = [ "podman-compose-3x-ui-root.target" ];
};
# Update
"podman-update-3xui_app" = {
path = [
pkgs.podman
];
path = [ pkgs.podman ];
serviceConfig = {
Type = "oneshot";
TimeoutSec = 300;
@@ -96,29 +81,10 @@ in
systemctl restart podman-3xui_app.service
'';
};
# Builds
# "podman-build-3xui_app" = {
# path = [
# pkgs.podman
# pkgs.git
# ];
# serviceConfig = {
# Type = "oneshot";
# TimeoutSec = 300;
# };
# script = ''
# cd /mnt/containers/3x-ui
# podman build -t compose2nix/3xui_app -f ./Dockerfile .
# '';
# };
};
# Root service
# When started, this will automatically create all resources and start
# the containers. When stopped, this will teardown all resources.
# Starts/stops together with all 3x-ui compose resources.
targets."podman-compose-3x-ui-root" = {
unitConfig = {
Description = "Root target generated by compose2nix.";
};
unitConfig.Description = "Root target generated by compose2nix.";
wantedBy = [ "multi-user.target" ];
};
timers."podman-update-3xui_app" = {
@@ -128,15 +94,15 @@ in
Persistent = true;
};
};
# Folders
tmpfiles.rules = [
"d ${xlib.dirs.services-mnt-folder} 0755 root root -"
"d ${xlib.dirs.services-nodes-folder} 0755 root root -"
"d ${xlib.dirs.services-nodes-folder}/${xlib.device.hostname} 0755 root root -"
"d ${panel} 0755 root root -"
"d ${panel}/db 0755 root root -"
"d ${panel}/cert 0755 root root -"
"Z ${panel} 0755 root root -"
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" panel "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${panel}/cert" "0755" "root" "root")
# Relabel panel dir for SELinux so containers can access it.
(xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root")
];
};