Files
nixos/modules/options.nix
T
oqyude 07a0437c13 fix(3x-ui): restore reality443Forwarding — T10 removal broke Xray REALITY
Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему
не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.'

T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched
and still routes:
  pubray1.zeroq.su  → 127.0.0.1:2049  (panel)
  pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY)
  default           → 127.0.0.1:15380 (fallback)

Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx
stream forward TLS to a dead port → Xray REALITY unreachable. SSH and
pubray1.zeroq.su kept working because they do NOT depend on 15380.

Restored (exact pre-T10 code from 61b3724):
- modules/options.nix: reality443Forwarding option
- modules/vds/default.nix: reality443Forwarding = true
- modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts
- manifest.json T10 → status 'pending' (reopened with corrected notes)

Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports =
  [..., '127.0.0.1:15380:443/tcp']
2026-10-10 17:54:18 +03:00

82 lines
3.4 KiB
Nix

{
lib,
...
}:
# Cross-module options: declared here, not in the module that reads them.
#
# An option belongs in this file when at least one context *sets* it while
# another module *reads* it — the reader cannot be the only place that knows
# the option exists. `modules/essentials/ssh.nix` does not belong here: it
# declares and reads `host.ssh.enable` itself, within one module.
{
# Remote-builder wiring. A coordinator (e.g. sapphira) sets
# `host.builder.clients` to register remote build machines;
# a builder host (e.g. the WSL on vetymae) sets `host.builder.enable`
# to advertise itself. The two halves are intentionally split so a single
# declaration in configurations/* is enough to flip each side.
options.host.builder = {
enable = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
Advertise this host as a remote Nix builder and accept builds
from other machines in the flake over SSH.
'';
};
clients = lib.mkOption {
type = lib.types.listOf lib.types.attrs;
default = [ ];
description = ''
List of remote Nix build machines this coordinator should
register via `nix.buildMachines`. Each entry matches the NixOS
option schema (hostName, sshUser, sshKey, systems,
supportedFeatures, ...). Two extra attributes are consumed by
modules/server/builder.nix and stripped before reaching
`nix.buildMachines`:
- `proxyCommand` — generates a per-builder Host block in the
system-wide OpenSSH config (the nix-daemon runs as root and
cannot see the user's ~/.ssh/config).
- `hostKeyAlias` — alias used inside that SSH matchBlock.
A builder reachable on its own (no ProxyCommand needed) omits
both and gets no SSH matchBlock. Empty by default — opt in by
setting this list.
'';
};
};
options.host."3x-ui" = {
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/)
# gets mounted read-only into the 3x-ui container so the panel
# can terminate TLS itself. Set null if 3x-ui serves plain HTTP
# and TLS is terminated by an upstream nginx.
certDomain = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
example = "pubray1.zeroq.su";
description = ''
Domain whose LE cert should be mounted into the 3x-ui
container at /root/cert/fullchain.pem and key.pem.
'';
};
# Publish host:15380 → container:443. Only nodes that host an
# Xray REALITY inbound on container:443 need this (so nginx
# stream can forward TLS to Xray via 127.0.0.1:15380 while Xray
# itself sees incoming connections on its configured port 443).
# Set false on nodes that only run the 3x-ui panel.
#
# RESTORED 2026-10-10: this option was wrongly removed by T10/C5.
# modules/vds/nginx.nix still routes pubrayx1.zeroq.su/default →
# 127.0.0.1:15380, so without this mapping the nginx stream points
# at a dead port and Xray REALITY is unreachable.
reality443Forwarding = lib.mkOption {
type = lib.types.bool;
default = false;
description = ''
When true, publish host:15380 → container:443 so Xray
inside the container can serve REALITY on its real
configured port 443 (nginx stream forwards 443 → 15380).
'';
};
};
}