Compare commits

...
7 Commits
Author SHA1 Message Date
oqyude e1d276097d refactoring 2026-08-29 04:05:38 +03:00
oqyude 7f5ea81f37 3x-ui: make module generic via xlib.services.3x-ui options
The 3x-ui container config was hardcoded for vds: it mounted the LE
cert for pubray1.zeroq.su and published host:15380→container:443 for
Xray REALITY. The server imports the same module but for x.zeroq.su
(no REALITY inbound, no cert needed by 3x-ui itself yet).

Add two options so each device picks what it needs:
  - xlib.services.3x-ui.certDomain: domain whose LE cert is mounted
    at /root/cert/{fullchain,key}.pem. null means no cert mount.
  - xlib.services.3x-ui.reality443Forwarding: when true, also publish
    host:15380→container:443 for nginx stream SNI-routed REALITY.

vds sets both. Server sets only certDomain (kept harmless; nginx
still terminates TLS for x.zeroq.su, so the mounted cert is unused
until/unless 3x-ui is reconfigured to terminate TLS itself).
2026-08-28 01:17:59 +03:00
oqyude 11af2c150a vds: drop pubrayx1.zeroq.su from SNI map — Xray now served under pubray1
All Xray REALITY clients already connect to VDS_IP via
pubray1.zeroq.su (or any of its subdomains). Removing the explicit
pubrayx1.zeroq.su → xray rule means the default route catches it.
This way we only have to publish one domain (pubray1.zeroq.su)
in subscriptions instead of two.

Companion change in x-ui.db (separate runbook step): subURI set
to https://pubray1.zeroq.su/subs/ so regenerated subscriptions
emit URLs under pubray1.zeroq.su, not x.zeroq.su.
2026-08-28 00:56:28 +03:00
oqyude 26e53e96bd vds: SNI-route TLS on 443 to Xray (15380→443) and 3x-ui panel (2049)
nginx stream + ssl_preread reads the ClientHello SNI and forwards the
raw TCP stream (no TLS termination) to either:
  - 3x-ui panel on 127.0.0.1:2049 (SNI=pubray1.zeroq.su)
  - Xray on 127.0.0.1:15380 (SNI=pubrayx1.zeroq.su or default)

podman maps host:15380 → container:443 so Xray inside sees the client
on port 443 (matching its REALITY config) even though the host-side
port from podman's perspective is 15380. Host:2049 still maps to
container:2049 — 3x-ui now terminates TLS itself using the Let's
Encrypt cert mounted from /var/lib/acme/pubray1.zeroq.su/.

x-ui.db: webCertFile, webKeyFile and webDomain set so the panel
answers HTTPS on 2049. nginx no longer owns a server block on 443 —
only an ACME-only vhost for cert renewal.

REALITY inbound on container:443 still needs to be created via the
panel UI (the xrayTemplateConfig doesn't have it yet). The host-side
and routing plumbing is ready for it.
2026-08-28 00:36:54 +03:00
oqyude 0c2b45ea6f Revert "vds/nginx: forward real client IP to 3x-ui"
This reverts commit 2cd636b6d4.
2026-08-28 00:12:14 +03:00
oqyude 2cd636b6d4 vds/nginx: forward real client IP to 3x-ui
With podman bridge networking, 3x-ui no longer sees the actual
client IP — it sees the bridge gateway. Without explicit
proxy_set_header directives, subscription URLs, geo-rules, logs
and fail2ban will all treat every request as coming from the same
IP.

Apply Host/X-Real-IP/X-Forwarded-For/X-Forwarded-Proto to all
3x-ui locations so the panel keeps working as if it were on
host network.
2026-08-27 23:28:41 +03:00
oqyude 2bc02c316d podman changes 2026-08-27 23:21:18 +03:00
6 changed files with 262 additions and 403 deletions
+42 -46
View File
@@ -7,6 +7,30 @@
}:
let
panel = "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}/3x-ui";
certDomain = xlib.services."3x-ui".certDomain or null;
certMounts =
if certDomain == null then [ ]
else
# LE cert mounted read-only so 3x-ui can terminate TLS itself.
# The 3x-ui settings table must point webCertFile / webKeyFile at
# /root/cert/fullchain.pem and /root/cert/key.pem.
map (f: "/var/lib/acme/${certDomain}/${f}:/root/cert/${f}:ro") [
"fullchain.pem"
"key.pem"
];
basePorts = [
# 2049/tcp — 3x-ui web panel
# 2096/tcp — subscription endpoint
# 14380-15379/tcp+udp — Xray inbounds (matches firewall open range)
"0.0.0.0:2049:2049/tcp"
"0.0.0.0:2096:2096/tcp"
"0.0.0.0:14380-15379:14380-15379/tcp"
"0.0.0.0:14380-15379:14380-15379/udp"
];
# VDS-only: nginx stream forwards host:443 → host:15380 → container:443,
# so Xray inside the container sees its REALITY inbound on its real
# configured port 443.
realityPorts = lib.optional xlib.services."3x-ui".reality443Forwarding "0.0.0.0:15380:443/tcp";
in
{
virtualisation = {
@@ -30,11 +54,11 @@ in
volumes = [
"${panel}/cert/:/root/cert:rw"
"${panel}/db/:/etc/x-ui:rw"
];
] ++ certMounts;
log-driver = "journald";
extraOptions = [
"--network=host"
];
# Adding a new inbound through the 3x-ui panel on a port outside
# the 14380-15379 range requires extending basePorts and rebuilding.
ports = basePorts ++ realityPorts;
};
};
};
@@ -42,21 +66,12 @@ in
systemd = {
services = {
"podman-3xui_app" = {
serviceConfig = {
Restart = lib.mkOverride 90 "always";
};
partOf = [
"podman-compose-3x-ui-root.target"
];
wantedBy = [
"podman-compose-3x-ui-root.target"
];
serviceConfig.Restart = lib.mkOverride 90 "always";
partOf = [ "podman-compose-3x-ui-root.target" ];
wantedBy = [ "podman-compose-3x-ui-root.target" ];
};
# Update
"podman-update-3xui_app" = {
path = [
pkgs.podman
];
path = [ pkgs.podman ];
serviceConfig = {
Type = "oneshot";
TimeoutSec = 300;
@@ -66,29 +81,10 @@ in
systemctl restart podman-3xui_app.service
'';
};
# Builds
# "podman-build-3xui_app" = {
# path = [
# pkgs.podman
# pkgs.git
# ];
# serviceConfig = {
# Type = "oneshot";
# TimeoutSec = 300;
# };
# script = ''
# cd /mnt/containers/3x-ui
# podman build -t compose2nix/3xui_app -f ./Dockerfile .
# '';
# };
};
# Root service
# When started, this will automatically create all resources and start
# the containers. When stopped, this will teardown all resources.
# Starts/stops together with all 3x-ui compose resources.
targets."podman-compose-3x-ui-root" = {
unitConfig = {
Description = "Root target generated by compose2nix.";
};
unitConfig.Description = "Root target generated by compose2nix.";
wantedBy = [ "multi-user.target" ];
};
timers."podman-update-3xui_app" = {
@@ -98,15 +94,15 @@ in
Persistent = true;
};
};
# Folders
tmpfiles.rules = [
"d ${xlib.dirs.services-mnt-folder} 0755 root root -"
"d ${xlib.dirs.services-nodes-folder} 0755 root root -"
"d ${xlib.dirs.services-nodes-folder}/${xlib.device.hostname} 0755 root root -"
"d ${panel} 0755 root root -"
"d ${panel}/db 0755 root root -"
"d ${panel}/cert 0755 root root -"
"Z ${panel} 0755 root root -"
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" panel "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" "${panel}/cert" "0755" "root" "root")
# Relabel panel dir for SELinux so containers can access it.
(xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root")
];
};
+29
View File
@@ -75,6 +75,35 @@ in
default = helpers;
description = "Shared helper functions (see lib/xlib.nix).";
};
services."3x-ui" = {
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/)
# gets mounted read-only into the 3x-ui container so the panel
# can terminate TLS itself. Set null if 3x-ui serves plain HTTP
# and TLS is terminated by an upstream nginx.
certDomain = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
example = "pubray1.zeroq.su";
description = ''
Domain whose LE cert should be mounted into the 3x-ui
container at /root/cert/fullchain.pem and key.pem.
'';
};
# Publish host:15380 → container:443. Only nodes that host an
# Xray REALITY inbound on container:443 need this (so nginx
# stream can forward TLS to Xray via 127.0.0.1:15380 while Xray
# itself sees incoming connections on its configured port 443).
# Set false on nodes that only run the 3x-ui panel.
reality443Forwarding = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When true, publish host:15380 → container:443 so Xray
inside the container can serve REALITY on its real
configured port 443 (nginx stream forwards 443 → 15380).
'';
};
};
};
};
}
+6
View File
@@ -44,6 +44,12 @@
# ./trilium.nix
# ./zerotier.nix
];
# Server's 3x-ui is the controller panel at x.zeroq.su (nginx HTTP
# terminates TLS upstream, no SNI-routing on 443 needed here because
# there are other vhosts on the same port). Cert is still mounted in
# case 3x-ui is later reconfigured to terminate TLS itself (e.g. for
# direct node-API access); nginx doesn't have to use it.
xlib.services."3x-ui".certDomain = "x.zeroq.su";
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
+123 -321
View File
@@ -5,17 +5,18 @@
xlib,
...
}:
# Standard reverse-proxy: HTTP/S termination upstream, backend on the LAN.
# x.zeroq.su is the 3x-ui controller panel — see 3x-ui.nix for the
# /subs/, /subsjs/, /clash/ routing logic.
let
server = "192.168.1.20";
# Standard TLS proxy vhost: "/" -> http://server:port
# Returns { name = domain; value = vhost; } for builtins.listToAttrs
mkProxy =
{
domain,
port,
addSSL ? false,
body ? false,
extraConfig ? "",
}:
{
name = domain;
@@ -28,20 +29,17 @@ let
}
// lib.optionalAttrs (!addSSL) { forceSSL = true; }
// lib.optionalAttrs addSSL { addSSL = true; }
// lib.optionalAttrs body {
extraConfig = ''
client_max_body_size 5G;
'';
};
// lib.optionalAttrs (extraConfig != "") { inherit extraConfig; };
};
# Simple proxy sites
bigUploads = "client_max_body_size 5G;";
sites = [
{
domain = "immich.zeroq.su";
port = 2283;
addSSL = true;
body = true;
extraConfig = bigUploads;
}
{
domain = "kuma.zeroq.su";
@@ -71,337 +69,141 @@ let
{
domain = "calibre.zeroq.su";
port = 8083;
body = true;
extraConfig = bigUploads;
}
# {
# domain = "mc.zeroq.su";
# port = 25565;
# }
{
domain = "nix-cache.zeroq.su";
port = 5000;
body = true;
extraConfig = bigUploads;
}
{
domain = "pdf.zeroq.su";
port = 8446;
body = true;
extraConfig = bigUploads;
}
];
in
{
services = {
nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts = (builtins.listToAttrs (map mkProxy sites)) // {
"nextcloud.private" = {
forceSSL = false;
enableACME = false;
listen = [
{
addr = "100.64.0.0";
port = 10000;
}
{
addr = "192.168.1.20";
port = 10000;
}
{
addr = "127.0.0.1";
port = 10000;
}
];
};
"office.zeroq.su" = {
forceSSL = true;
enableACME = true;
};
"pdf.private" = {
forceSSL = false;
enableACME = false;
listen = [
{
addr = "0.0.0.0";
port = 80;
}
{
addr = "100.64.0.0";
port = 8446;
}
{
addr = "192.168.1.20";
port = 8446;
}
{
addr = "127.0.0.1";
port = 8446;
}
];
extraConfig = ''
client_max_body_size 5G;
'';
};
"x.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://${server}:2049";
proxyWebsockets = true;
};
"/subs/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
"/subsjs/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
"/clash/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts = (builtins.listToAttrs (map mkProxy sites)) // {
"nextcloud.private" = {
forceSSL = false;
enableACME = false;
listen = [
{
addr = "100.64.0.0";
port = 10000;
}
{
addr = "192.168.1.20";
port = 10000;
}
{
addr = "127.0.0.1";
port = 10000;
}
];
};
"office.zeroq.su" = {
forceSSL = true;
enableACME = true;
};
"pdf.private" = {
forceSSL = false;
enableACME = false;
listen = [
{
addr = "0.0.0.0";
port = 80;
}
{
addr = "100.64.0.0";
port = 8446;
}
{
addr = "192.168.1.20";
port = 8446;
}
{
addr = "127.0.0.1";
port = 8446;
}
];
extraConfig = bigUploads;
};
"x.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://${server}:2049";
proxyWebsockets = true;
};
};
# "talk.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# # locations = {
# # "/" = {
# # proxyPass = "http://127.0.0.1:7880";
# # proxyWebsockets = true;
# # };
# # };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "turn.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations = {
# "/" = {
# proxyPass = "http://127.0.0.1:5349";
# proxyWebsockets = true;
# };
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "ca.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:9000";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "n8n.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://${server}:5678";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "kuma.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:4001";
# proxyWebsockets = true;
# };
# };
# "flux.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:6061";
# proxyWebsockets = true;
# };
# };
# "navidrome.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:4533";
# proxyWebsockets = true;
# };
# };
# "immich.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:2283";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "agent.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://${server}:3000";
# proxyWebsockets = true;
# };
# };
# "node-red.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# kTLS = true;
# locations."/" = {
# proxyPass = "http://${server}:1880";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
"zeroq.su" = {
forceSSL = true;
enableACME = true;
root = pkgs.writeTextDir "index.html" ''
<!doctype html>
<html>
<body>
<pre>What are you doing here?</pre>
</body>
</html>
'';
locations = {
"/guest/" = {
proxyPass = "http://${server}:80";
proxyWebsockets = true;
};
# "/.well-known/discord" = {
# extraConfig = ''
# default_type text/plain;
# return 200 "dh=c2d103553a4cfdaa1b7952a87a7d8120a1e167cc";
# '';
# };
"/subs/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
};
"vetymae.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.86.62.4:4096";
"/subsjs/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
"/clash/" = {
proxyPass = "http://${server}:2096";
proxyWebsockets = true;
};
};
"lamet.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.106.21.39:6061";
};
"zeroq.su" = {
forceSSL = true;
enableACME = true;
root = pkgs.writeTextDir "index.html" ''
<!doctype html>
<html>
<body>
<pre>What are you doing here?</pre>
</body>
</html>
'';
locations."/guest/" = {
proxyPass = "http://${server}:80";
proxyWebsockets = true;
};
};
"vetymae.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.86.62.4:4096";
proxyWebsockets = true;
};
};
"lamet.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.106.21.39:6061";
proxyWebsockets = true;
};
};
"nextcloud.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://${server}:10000";
proxyWebsockets = true;
};
"/whiteboard" = {
proxyPass = "http://${server}:3002";
proxyWebsockets = true;
};
};
# "n8n.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://${server}:5678";
# proxyWebsockets = true;
# };
# };
# "office.zeroq.su" = {
# enableACME = true;
# forceSSL = true;
# locations = {
# "/" = {
# proxyPass = "http://${server}:8090";
# proxyWebsockets = true;
# };
# };
# };
"nextcloud.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://${server}:10000";
proxyWebsockets = true;
};
"/whiteboard" = {
proxyPass = "http://${server}:3002";
proxyWebsockets = true;
};
};
extraConfig = ''
client_max_body_size 5G;
'';
};
# "calibre.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:8083";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "dns.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:53";
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "glances.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:61208";
# };
# };
# "syncthing.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:8384";
# };
# };
# "zeroq.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# root = pkgs.writeTextDir "index.html" ''
# <!doctype html>
# <html>
# <body>
# <pre>This server is running in backend.</pre>
# </body>
# </html>
# '';
# listen = [
# {
# addr = "100.64.0.0";
# port = 80;
# }
# {
# addr = "192.168.1.20";
# port = 80;
# }
# ];
# };
extraConfig = bigUploads;
};
};
};
+6
View File
@@ -13,6 +13,12 @@
# ./netbird.nix
# ./xray.nix
];
# VDS hosts the public-facing Xray REALITY inbound on container:443,
# fronted by nginx stream on host:443 → host:15380 → container:443.
xlib.services."3x-ui" = {
certDomain = "pubray1.zeroq.su";
reality443Forwarding = true;
};
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
+56 -36
View File
@@ -4,49 +4,69 @@
pkgs,
...
}:
# VDS nginx differs from server's in one key way: port 443 is owned
# by an nginx stream block that does SNI-based TCP routing, not by
# http { server {} } blocks. This lets a single host (pubray1.zeroq.su)
# serve both the 3x-ui panel and an Xray REALITY inbound over TLS,
# sharing the same port.
#
# Routing:
# pubray1.zeroq.su → 127.0.0.1:2049 (3x-ui panel; LE cert mounted
# into the container terminates TLS)
# pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY; Xray sees its
# real configured port 443 via DNAT)
# default → 127.0.0.1:15380 (REALITY fallback for any
# other SNI / IP-direct)
#
# ssl_preread reads SNI from the ClientHello and forwards the rest of
# the TLS stream as-is, so Xray sees a real port-443 connection even
# though podman DNATs it via host:15380.
let
server = "100.64.0.0";
# Goes inside the auto-generated `stream {}` block (services.nginx.streamConfig).
# pubray1.zeroq.su → 3x-ui panel; everything else (including any SNI
# a REALITY client uses, e.g. media.mediavitrina.ru) → Xray.
streamConfig = ''
ssl_preread on;
map $ssl_preread_server_name $sni_backend {
default xray;
pubray1.zeroq.su panel;
}
upstream panel {
server 127.0.0.1:2049;
}
upstream xray {
server 127.0.0.1:15380;
}
server {
listen 443;
proxy_pass $sni_backend;
proxy_timeout 600s;
proxy_connect_timeout 5s;
}
'';
in
{
users.users.nginx.extraGroups = [ "acme" ];
services = {
nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts = {
"pubray1.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://localhost:2049";
proxyWebsockets = true;
};
"/subs/" = {
proxyPass = "http://localhost:2096";
proxyWebsockets = true;
};
"/subsjs/" = {
proxyPass = "http://localhost:2096";
proxyWebsockets = true;
};
"/clash/" = {
proxyPass = "http://localhost:2096";
proxyWebsockets = true;
};
};
};
};
};
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
# ACME only — 443 is owned by the stream block, not by http { server {} }.
# Don't add forceSSL: it would generate an HTTPS server block that
# conflicts with the stream listener.
virtualHosts."pubray1.zeroq.su".enableACME = true;
# Lands inside the auto-generated `stream {}` block.
streamConfig = streamConfig;
};
security.acme = {
acceptTerms = true;
defaults = {
email = "oqyude@gmail.com";
};
defaults.email = "oqyude@gmail.com";
};
networking.firewall.allowedTCPPorts = [
80