Commit Graph
27 Commits
Author SHA1 Message Date
oqyude 11af2c150a vds: drop pubrayx1.zeroq.su from SNI map — Xray now served under pubray1
All Xray REALITY clients already connect to VDS_IP via
pubray1.zeroq.su (or any of its subdomains). Removing the explicit
pubrayx1.zeroq.su → xray rule means the default route catches it.
This way we only have to publish one domain (pubray1.zeroq.su)
in subscriptions instead of two.

Companion change in x-ui.db (separate runbook step): subURI set
to https://pubray1.zeroq.su/subs/ so regenerated subscriptions
emit URLs under pubray1.zeroq.su, not x.zeroq.su.
2026-08-28 00:56:28 +03:00
oqyude 26e53e96bd vds: SNI-route TLS on 443 to Xray (15380→443) and 3x-ui panel (2049)
nginx stream + ssl_preread reads the ClientHello SNI and forwards the
raw TCP stream (no TLS termination) to either:
  - 3x-ui panel on 127.0.0.1:2049 (SNI=pubray1.zeroq.su)
  - Xray on 127.0.0.1:15380 (SNI=pubrayx1.zeroq.su or default)

podman maps host:15380 → container:443 so Xray inside sees the client
on port 443 (matching its REALITY config) even though the host-side
port from podman's perspective is 15380. Host:2049 still maps to
container:2049 — 3x-ui now terminates TLS itself using the Let's
Encrypt cert mounted from /var/lib/acme/pubray1.zeroq.su/.

x-ui.db: webCertFile, webKeyFile and webDomain set so the panel
answers HTTPS on 2049. nginx no longer owns a server block on 443 —
only an ACME-only vhost for cert renewal.

REALITY inbound on container:443 still needs to be created via the
panel UI (the xrayTemplateConfig doesn't have it yet). The host-side
and routing plumbing is ready for it.
2026-08-28 00:36:54 +03:00
oqyude 0c2b45ea6f Revert "vds/nginx: forward real client IP to 3x-ui"
This reverts commit 2cd636b6d4.
2026-08-28 00:12:14 +03:00
oqyude 2cd636b6d4 vds/nginx: forward real client IP to 3x-ui
With podman bridge networking, 3x-ui no longer sees the actual
client IP — it sees the bridge gateway. Without explicit
proxy_set_header directives, subscription URLs, geo-rules, logs
and fail2ban will all treat every request as coming from the same
IP.

Apply Host/X-Real-IP/X-Forwarded-For/X-Forwarded-Proto to all
3x-ui locations so the panel keeps working as if it were on
host network.
2026-08-27 23:28:41 +03:00
oqyude 411c118500 br v4 2026-08-11 22:13:53 +03:00
oqyude cc12ab5bba refactoring 2026-08-10 03:36:19 +03:00
oqyude e66bbef553 3x-ui on server 2026-08-09 23:51:49 +03:00
oqyude 5b3da95fc2 path refactoring 2026-08-09 01:11:23 +03:00
oqyude cedc856a02 server preparing migration 2026-08-08 19:24:14 +03:00
oqyude 63c46c80ef navidrome setup 2026-07-17 12:32:29 +03:00
oqyude 521d922961 nextcloud update 2026-07-16 23:34:06 +03:00
oqyude e5e9dfd1de samba fixup 2026-07-16 17:33:19 +03:00
oqyude 870f36ec9d opencode serve on su 2026-07-10 11:17:45 +03:00
oqyude f2740e87a0 node backup added 2026-07-04 22:54:38 +03:00
oqyude b2b4883627 try to setup gitea 2026-06-10 12:38:23 +03:00
oqyude ebd2e99066 try to fix onlyoffice
now its working in lan)
2026-06-09 23:13:35 +03:00
oqyude b001652162 bentopdf added 2026-05-31 14:26:24 +03:00
oqyude 58d631c0fb something 2026-04-17 20:46:49 +03:00
oqyude 7f1f714e8c glances added 2026-04-11 12:54:52 +03:00
oqyude f5c6d40c89 systemd-mounts...
lix frozen-removed, rovr frozen-removed
2026-04-10 14:07:07 +03:00
oqyude a5a2763f66 new domain 2026-04-10 10:57:20 +03:00
oqyude cf77fa88bf n8n enable 2026-04-01 12:50:28 +03:00
oqyude efcb4232a5 try to setup onlyoffice 2026-03-31 01:47:42 +03:00
oqyude 5909a72654 sops and onlyoffice evolution 2026-03-30 15:50:00 +03:00
oqyude c8c7c68c04 some fix 2026-03-27 17:56:12 +03:00
oqyude 6f278b36e7 disable unused 2026-03-16 18:22:17 +03:00
oqyude f1a81a6408 Init 2026-03-09 10:50:12 +03:00