mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
refactoring
This commit is contained in:
@@ -10,26 +10,27 @@ let
|
||||
certDomain = xlib.services."3x-ui".certDomain or null;
|
||||
certMounts =
|
||||
if certDomain == null then [ ]
|
||||
else [
|
||||
# Let's Encrypt cert for the panel domain — mounted read-only so
|
||||
# 3x-ui can serve the panel over its own TLS. webCertFile /
|
||||
# webKeyFile in the x-ui settings table must point at
|
||||
# /root/cert/fullchain.pem and /root/cert/key.pem respectively.
|
||||
"/var/lib/acme/${certDomain}/fullchain.pem:/root/cert/fullchain.pem:ro"
|
||||
"/var/lib/acme/${certDomain}/key.pem:/root/cert/key.pem:ro"
|
||||
];
|
||||
else
|
||||
# LE cert mounted read-only so 3x-ui can terminate TLS itself.
|
||||
# The 3x-ui settings table must point webCertFile / webKeyFile at
|
||||
# /root/cert/fullchain.pem and /root/cert/key.pem.
|
||||
map (f: "/var/lib/acme/${certDomain}/${f}:/root/cert/${f}:ro") [
|
||||
"fullchain.pem"
|
||||
"key.pem"
|
||||
];
|
||||
basePorts = [
|
||||
# 2049/tcp — 3x-ui web panel
|
||||
# 2096/tcp — subscription endpoint
|
||||
# 14380-15379/tcp+udp — Xray inbounds (matches firewall open range)
|
||||
"0.0.0.0:2049:2049/tcp"
|
||||
"0.0.0.0:2096:2096/tcp"
|
||||
"0.0.0.0:14380-15379:14380-15379/tcp"
|
||||
"0.0.0.0:14380-15379:14380-15379/udp"
|
||||
];
|
||||
realityPorts =
|
||||
# Only vds needs the 15380→443 forwarding that lets nginx stream
|
||||
# pass-through Xray REALITY while Xray itself sees the connection
|
||||
# arriving on 443 (matching its REALITY inbound config).
|
||||
lib.optional xlib.services."3x-ui".reality443Forwarding
|
||||
"0.0.0.0:15380:443/tcp";
|
||||
# VDS-only: nginx stream forwards host:443 → host:15380 → container:443,
|
||||
# so Xray inside the container sees its REALITY inbound on its real
|
||||
# configured port 443.
|
||||
realityPorts = lib.optional xlib.services."3x-ui".reality443Forwarding "0.0.0.0:15380:443/tcp";
|
||||
in
|
||||
{
|
||||
virtualisation = {
|
||||
@@ -55,15 +56,8 @@ in
|
||||
"${panel}/db/:/etc/x-ui:rw"
|
||||
] ++ certMounts;
|
||||
log-driver = "journald";
|
||||
# Port-forwarded networking (replaces --network=host).
|
||||
# Common across all nodes that import this module:
|
||||
# 2049/tcp — 3x-ui web panel
|
||||
# 2096/tcp — subscription endpoint
|
||||
# 14380-15379/tcp+udp — Xray inbounds (matches firewall open range)
|
||||
# Vds-only (xlib.services.3x-ui.reality443Forwarding = true):
|
||||
# 15380→443/tcp — Xray REALITY inbound (nginx stream on 443 → 15380)
|
||||
# Adding a new inbound through the 3x-ui panel on a port outside
|
||||
# this range will require extending this list and rebuilding.
|
||||
# the 14380-15379 range requires extending basePorts and rebuilding.
|
||||
ports = basePorts ++ realityPorts;
|
||||
};
|
||||
};
|
||||
@@ -72,21 +66,12 @@ in
|
||||
systemd = {
|
||||
services = {
|
||||
"podman-3xui_app" = {
|
||||
serviceConfig = {
|
||||
Restart = lib.mkOverride 90 "always";
|
||||
};
|
||||
partOf = [
|
||||
"podman-compose-3x-ui-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-3x-ui-root.target"
|
||||
];
|
||||
serviceConfig.Restart = lib.mkOverride 90 "always";
|
||||
partOf = [ "podman-compose-3x-ui-root.target" ];
|
||||
wantedBy = [ "podman-compose-3x-ui-root.target" ];
|
||||
};
|
||||
# Update
|
||||
"podman-update-3xui_app" = {
|
||||
path = [
|
||||
pkgs.podman
|
||||
];
|
||||
path = [ pkgs.podman ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
TimeoutSec = 300;
|
||||
@@ -96,29 +81,10 @@ in
|
||||
systemctl restart podman-3xui_app.service
|
||||
'';
|
||||
};
|
||||
# Builds
|
||||
# "podman-build-3xui_app" = {
|
||||
# path = [
|
||||
# pkgs.podman
|
||||
# pkgs.git
|
||||
# ];
|
||||
# serviceConfig = {
|
||||
# Type = "oneshot";
|
||||
# TimeoutSec = 300;
|
||||
# };
|
||||
# script = ''
|
||||
# cd /mnt/containers/3x-ui
|
||||
# podman build -t compose2nix/3xui_app -f ./Dockerfile .
|
||||
# '';
|
||||
# };
|
||||
};
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
# Starts/stops together with all 3x-ui compose resources.
|
||||
targets."podman-compose-3x-ui-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
unitConfig.Description = "Root target generated by compose2nix.";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
};
|
||||
timers."podman-update-3xui_app" = {
|
||||
@@ -128,15 +94,15 @@ in
|
||||
Persistent = true;
|
||||
};
|
||||
};
|
||||
# Folders
|
||||
tmpfiles.rules = [
|
||||
"d ${xlib.dirs.services-mnt-folder} 0755 root root -"
|
||||
"d ${xlib.dirs.services-nodes-folder} 0755 root root -"
|
||||
"d ${xlib.dirs.services-nodes-folder}/${xlib.device.hostname} 0755 root root -"
|
||||
"d ${panel} 0755 root root -"
|
||||
"d ${panel}/db 0755 root root -"
|
||||
"d ${panel}/cert 0755 root root -"
|
||||
"Z ${panel} 0755 root root -"
|
||||
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
||||
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
|
||||
(xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}" "0755" "root" "root")
|
||||
(xlib.helpers.mkTmpfile "d" panel "0755" "root" "root")
|
||||
(xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root")
|
||||
(xlib.helpers.mkTmpfile "d" "${panel}/cert" "0755" "root" "root")
|
||||
# Relabel panel dir for SELinux so containers can access it.
|
||||
(xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root")
|
||||
];
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user