mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 22:37:25 +03:00
Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему
не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.'
T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched
and still routes:
pubray1.zeroq.su → 127.0.0.1:2049 (panel)
pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY)
default → 127.0.0.1:15380 (fallback)
Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx
stream forward TLS to a dead port → Xray REALITY unreachable. SSH and
pubray1.zeroq.su kept working because they do NOT depend on 15380.
Restored (exact pre-T10 code from 61b3724):
- modules/options.nix: reality443Forwarding option
- modules/vds/default.nix: reality443Forwarding = true
- modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts
- manifest.json T10 → status 'pending' (reopened with corrected notes)
Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports =
[..., '127.0.0.1:15380:443/tcp']
30 lines
847 B
Nix
30 lines
847 B
Nix
{
|
|
lib,
|
|
xlib,
|
|
...
|
|
}:
|
|
{
|
|
imports = [
|
|
../containers/3x-ui.nix
|
|
./nginx.nix
|
|
./samba.nix
|
|
./systemd.nix
|
|
# ./glances.nix
|
|
# ./netbird.nix
|
|
];
|
|
# VDS hosts the public-facing Xray REALITY inbound on container:443,
|
|
# fronted by nginx stream on host:443 → host:15380 → container:443.
|
|
# reality443Forwarding MUST stay true here: modules/vds/nginx.nix
|
|
# routes pubrayx1.zeroq.su/default → 127.0.0.1:15380, which only
|
|
# exists when this mapping is published. (Restored 2026-10-10 after
|
|
# T10/C5 wrongly removed it and broke Xray REALITY.)
|
|
host."3x-ui" = {
|
|
certDomain = "pubray1.zeroq.su";
|
|
reality443Forwarding = true;
|
|
};
|
|
systemd.tmpfiles.rules = [
|
|
(xlib.helpers.mkTmpfile "d" "/mnt" "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
|
];
|
|
}
|