oqyude 26e53e96bd vds: SNI-route TLS on 443 to Xray (15380→443) and 3x-ui panel (2049)
nginx stream + ssl_preread reads the ClientHello SNI and forwards the
raw TCP stream (no TLS termination) to either:
  - 3x-ui panel on 127.0.0.1:2049 (SNI=pubray1.zeroq.su)
  - Xray on 127.0.0.1:15380 (SNI=pubrayx1.zeroq.su or default)

podman maps host:15380 → container:443 so Xray inside sees the client
on port 443 (matching its REALITY config) even though the host-side
port from podman's perspective is 15380. Host:2049 still maps to
container:2049 — 3x-ui now terminates TLS itself using the Let's
Encrypt cert mounted from /var/lib/acme/pubray1.zeroq.su/.

x-ui.db: webCertFile, webKeyFile and webDomain set so the panel
answers HTTPS on 2049. nginx no longer owns a server block on 443 —
only an ACME-only vhost for cert renewal.

REALITY inbound on container:443 still needs to be created via the
panel UI (the xrayTemplateConfig doesn't have it yet). The host-side
and routing plumbing is ready for it.
2026-08-28 00:36:54 +03:00
2026-08-11 22:13:53 +03:00
2026-08-11 02:31:00 +03:00
2026-08-11 22:13:53 +03:00
2026-08-11 22:13:53 +03:00
2026-05-04 20:23:20 +03:00
2026-08-11 02:31:00 +03:00
2026-03-09 10:50:12 +03:00
ref
2026-03-29 14:46:01 +03:00
2026-08-06 11:53:51 +03:00
2026-03-09 10:50:12 +03:00
2026-08-24 01:33:25 +03:00
2026-08-11 22:13:53 +03:00
2026-06-10 12:38:23 +03:00

I'm a super newbie who just posted my stuff here. Now maybe about intermediate

S
Description
My NixOS configuration
Readme
2.2 MiB
Languages
Nix 89.8%
Python 9.1%
Dockerfile 1.1%