Commit Graph
112 Commits
Author SHA1 Message Date
oqyude 44b85e1ebc cleaning 2026-09-22 18:05:10 +03:00
oqyude b57ca3eedf 3x-ui next 2026-09-16 16:09:51 +03:00
oqyude 309644eab2 fixes 2026-09-15 21:22:33 +03:00
oqyude 7441e7f98a 3x-ui regress 2026-09-15 00:54:31 +03:00
oqyude 1c3a524b42 iperf3 added 2026-09-08 21:37:38 +03:00
oqyude be064aca66 nix flake update 2026-09-02 23:32:34 +03:00
oqyude 839b97d01a justray and usbtree 2026-09-02 17:08:18 +03:00
oqyude 482d32e1a6 microfix 2026-09-02 13:35:58 +03:00
oqyude e1d276097d refactoring 2026-08-29 04:05:38 +03:00
oqyude 7f5ea81f37 3x-ui: make module generic via xlib.services.3x-ui options
The 3x-ui container config was hardcoded for vds: it mounted the LE
cert for pubray1.zeroq.su and published host:15380→container:443 for
Xray REALITY. The server imports the same module but for x.zeroq.su
(no REALITY inbound, no cert needed by 3x-ui itself yet).

Add two options so each device picks what it needs:
  - xlib.services.3x-ui.certDomain: domain whose LE cert is mounted
    at /root/cert/{fullchain,key}.pem. null means no cert mount.
  - xlib.services.3x-ui.reality443Forwarding: when true, also publish
    host:15380→container:443 for nginx stream SNI-routed REALITY.

vds sets both. Server sets only certDomain (kept harmless; nginx
still terminates TLS for x.zeroq.su, so the mounted cert is unused
until/unless 3x-ui is reconfigured to terminate TLS itself).
2026-08-28 01:17:59 +03:00
oqyude 11af2c150a vds: drop pubrayx1.zeroq.su from SNI map — Xray now served under pubray1
All Xray REALITY clients already connect to VDS_IP via
pubray1.zeroq.su (or any of its subdomains). Removing the explicit
pubrayx1.zeroq.su → xray rule means the default route catches it.
This way we only have to publish one domain (pubray1.zeroq.su)
in subscriptions instead of two.

Companion change in x-ui.db (separate runbook step): subURI set
to https://pubray1.zeroq.su/subs/ so regenerated subscriptions
emit URLs under pubray1.zeroq.su, not x.zeroq.su.
2026-08-28 00:56:28 +03:00
oqyude 26e53e96bd vds: SNI-route TLS on 443 to Xray (15380→443) and 3x-ui panel (2049)
nginx stream + ssl_preread reads the ClientHello SNI and forwards the
raw TCP stream (no TLS termination) to either:
  - 3x-ui panel on 127.0.0.1:2049 (SNI=pubray1.zeroq.su)
  - Xray on 127.0.0.1:15380 (SNI=pubrayx1.zeroq.su or default)

podman maps host:15380 → container:443 so Xray inside sees the client
on port 443 (matching its REALITY config) even though the host-side
port from podman's perspective is 15380. Host:2049 still maps to
container:2049 — 3x-ui now terminates TLS itself using the Let's
Encrypt cert mounted from /var/lib/acme/pubray1.zeroq.su/.

x-ui.db: webCertFile, webKeyFile and webDomain set so the panel
answers HTTPS on 2049. nginx no longer owns a server block on 443 —
only an ACME-only vhost for cert renewal.

REALITY inbound on container:443 still needs to be created via the
panel UI (the xrayTemplateConfig doesn't have it yet). The host-side
and routing plumbing is ready for it.
2026-08-28 00:36:54 +03:00
oqyude 0c2b45ea6f Revert "vds/nginx: forward real client IP to 3x-ui"
This reverts commit 2cd636b6d4.
2026-08-28 00:12:14 +03:00
oqyude 2cd636b6d4 vds/nginx: forward real client IP to 3x-ui
With podman bridge networking, 3x-ui no longer sees the actual
client IP — it sees the bridge gateway. Without explicit
proxy_set_header directives, subscription URLs, geo-rules, logs
and fail2ban will all treat every request as coming from the same
IP.

Apply Host/X-Real-IP/X-Forwarded-For/X-Forwarded-Proto to all
3x-ui locations so the panel keeps working as if it were on
host network.
2026-08-27 23:28:41 +03:00
oqyude 2bc02c316d podman changes 2026-08-27 23:21:18 +03:00
oqyude cbf731495a minecraft: use jdk25 for fabric 26.2 server 2026-08-12 00:22:53 +03:00
oqyude b933436a6e minecraft: use linkFarmFromDrvs for mods 2026-08-11 23:36:28 +03:00
oqyude 0585f234ba minecraft: add 26.2 mods (lithium/ferritecore/krypton) 2026-08-11 23:34:26 +03:00
oqyude 133db71db0 minecraft-server setup 2026-08-11 23:14:16 +03:00
oqyude 411c118500 br v4 2026-08-11 22:13:53 +03:00
oqyude 056e5895fe br v3 2026-08-11 04:03:42 +03:00
oqyude 843f0bafa1 br v2 2026-08-11 03:05:52 +03:00
oqyude 871fad26d4 big refactoring 2026-08-11 02:31:00 +03:00
oqyude cc12ab5bba refactoring 2026-08-10 03:36:19 +03:00
oqyude e66bbef553 3x-ui on server 2026-08-09 23:51:49 +03:00
oqyude 5b3da95fc2 path refactoring 2026-08-09 01:11:23 +03:00
oqyude cedc856a02 server preparing migration 2026-08-08 19:24:14 +03:00
oqyude 5f6288bd15 unused code 2026-08-08 17:48:43 +03:00
oqyude 682ab4aa01 path moving 2026-08-07 20:40:27 +03:00
oqyude f61d45a279 termux-api: set CMAKE_POLICY_VERSION_MINIMUM=3.5
Upstream CMakeLists.txt declares cmake_minimum_required(3.0.0), but modern
CMake removed compatibility with < 3.5 and refuses to configure.
2026-08-07 19:32:08 +03:00
oqyude caad27900b termux: declarative ~/.ssh/config + termux-api package
- home/termux.nix: programs.ssh.settings with the 7 known hosts
  (replaces hand-copied ~/.ssh/config; ssh aliases z-s/z-st/z-o/z-ot
  removed, lamet/pubray-1 kept since they have no Host entry)
- modules/termux/termux-api.nix: build termux-api 0.59.1 (cmake,
  am resolved from PATH, shebangs fixed); adds termux-battery-status,
  termux-notification, termux-clipboard-*, etc. Needs the Termux:API
  Android app (com.termux.api from F-Droid) as the actual backend
- mobile.nix: enable android-integration.am (termux-am backend for am)
2026-08-07 19:28:29 +03:00
oqyude 1841f9394c termux: create channels/nixpkgs under real symlink target (dangling symlink blocks mkdir -p) 2026-08-07 03:37:43 +03:00
oqyude d5d62393e3 termux: create .nix-defexpr/channels/nixpkgs/.keep via activation (home-manager cannot link into symlinked dir) 2026-08-07 03:35:19 +03:00
oqyude 58c6e5d48e termux: drop tailscaled (cannot run in proot, SELinux netlink), export SVDIR=/etc/service in zshenv 2026-08-07 03:31:06 +03:00
oqyude 566bc12f00 supervisor termux 2026-08-07 03:03:47 +03:00
oqyude bc9b2dc792 sshd setup for termux 2026-08-07 01:38:46 +03:00
oqyude af90756661 termux setup 2026-08-06 22:57:19 +03:00
oqyude 6b426eaa55 add termux device type with shared home-manager userspace module 2026-08-06 17:53:11 +03:00
oqyude 38948e0462 small changes 2026-08-05 11:57:07 +03:00
oqyude c9b15dea59 power settings for server 2026-08-04 11:26:31 +03:00
oqyude cb502e8972 coredns server fix 2026-07-31 10:52:24 +03:00
oqyude 5739ccfcaf nextcloud changes 2026-07-28 03:02:52 +03:00
oqyude 1f1b6efdf0 nix flake update 2026-07-25 23:51:36 +03:00
oqyude f1ac4662fd onlyoffice try to deny regress 2026-07-17 12:42:44 +03:00
oqyude 63c46c80ef navidrome setup 2026-07-17 12:32:29 +03:00
oqyude 521d922961 nextcloud update 2026-07-16 23:34:06 +03:00
oqyude e5e9dfd1de samba fixup 2026-07-16 17:33:19 +03:00
oqyude 867a3227b8 calibre fixup 2026-07-16 01:14:47 +03:00
oqyude 69c53ccd65 fixup for onlyoffice (disabling) 2026-07-16 00:12:52 +03:00
oqyude 536bdf801e homebox added 2026-07-15 23:08:18 +03:00