Commit Graph
24 Commits
Author SHA1 Message Date
oqyude 417c7abda6 hide ports 2026-09-26 16:07:37 +03:00
oqyude ac561815ed 3x-ui fix 2026-09-24 22:49:52 +03:00
oqyudeandSisyphus 2be5b168ac tape-rotation fix
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-09-24 17:21:58 +03:00
oqyude 1db2b0955b nextcloud fix 2026-09-23 22:23:13 +03:00
oqyude 2912581b99 tape rotation added 2026-09-23 21:58:39 +03:00
oqyude 44b85e1ebc cleaning 2026-09-22 18:05:10 +03:00
oqyude b57ca3eedf 3x-ui next 2026-09-16 16:09:51 +03:00
oqyude 7441e7f98a 3x-ui regress 2026-09-15 00:54:31 +03:00
oqyude 482d32e1a6 microfix 2026-09-02 13:35:58 +03:00
oqyude e1d276097d refactoring 2026-08-29 04:05:38 +03:00
oqyude 7f5ea81f37 3x-ui: make module generic via xlib.services.3x-ui options
The 3x-ui container config was hardcoded for vds: it mounted the LE
cert for pubray1.zeroq.su and published host:15380→container:443 for
Xray REALITY. The server imports the same module but for x.zeroq.su
(no REALITY inbound, no cert needed by 3x-ui itself yet).

Add two options so each device picks what it needs:
  - xlib.services.3x-ui.certDomain: domain whose LE cert is mounted
    at /root/cert/{fullchain,key}.pem. null means no cert mount.
  - xlib.services.3x-ui.reality443Forwarding: when true, also publish
    host:15380→container:443 for nginx stream SNI-routed REALITY.

vds sets both. Server sets only certDomain (kept harmless; nginx
still terminates TLS for x.zeroq.su, so the mounted cert is unused
until/unless 3x-ui is reconfigured to terminate TLS itself).
2026-08-28 01:17:59 +03:00
oqyude 26e53e96bd vds: SNI-route TLS on 443 to Xray (15380→443) and 3x-ui panel (2049)
nginx stream + ssl_preread reads the ClientHello SNI and forwards the
raw TCP stream (no TLS termination) to either:
  - 3x-ui panel on 127.0.0.1:2049 (SNI=pubray1.zeroq.su)
  - Xray on 127.0.0.1:15380 (SNI=pubrayx1.zeroq.su or default)

podman maps host:15380 → container:443 so Xray inside sees the client
on port 443 (matching its REALITY config) even though the host-side
port from podman's perspective is 15380. Host:2049 still maps to
container:2049 — 3x-ui now terminates TLS itself using the Let's
Encrypt cert mounted from /var/lib/acme/pubray1.zeroq.su/.

x-ui.db: webCertFile, webKeyFile and webDomain set so the panel
answers HTTPS on 2049. nginx no longer owns a server block on 443 —
only an ACME-only vhost for cert renewal.

REALITY inbound on container:443 still needs to be created via the
panel UI (the xrayTemplateConfig doesn't have it yet). The host-side
and routing plumbing is ready for it.
2026-08-28 00:36:54 +03:00
oqyude 2bc02c316d podman changes 2026-08-27 23:21:18 +03:00
oqyude 5b3da95fc2 path refactoring 2026-08-09 01:11:23 +03:00
oqyude f2740e87a0 node backup added 2026-07-04 22:54:38 +03:00
oqyude 8ca46a632c nix flake update 2026-06-05 16:50:35 +03:00
oqyude b001652162 bentopdf added 2026-05-31 14:26:24 +03:00
oqyude 86e20597a7 refact, beets 3.14py 2026-04-21 12:24:54 +03:00
oqyude a5a2763f66 new domain 2026-04-10 10:57:20 +03:00
oqyude c4b52f942c try to setup peerix and removed 2026-04-06 15:53:31 +03:00
oqyude 4d54a3b6fb remnawave editing 2026-04-05 02:37:56 +03:00
oqyude c3f8acad12 remnawave init 2026-04-05 02:28:14 +03:00
oqyude 7d731bd1c4 ref 2026-03-29 14:46:01 +03:00
oqyude f1a81a6408 Init 2026-03-09 10:50:12 +03:00