mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Owner: 'reality443Forwarding точно ли стоило удалять? xray по прежнему
не работает, несмотря на то, что ssh и pubray1.zeroq.su работают.'
T10/C5 decision (б) was WRONG. modules/vds/nginx.nix was never touched
and still routes:
pubray1.zeroq.su → 127.0.0.1:2049 (panel)
pubrayx1.zeroq.su → 127.0.0.1:15380 (Xray REALITY)
default → 127.0.0.1:15380 (fallback)
Removing the container mapping 127.0.0.1:15380:443/tcp made the nginx
stream forward TLS to a dead port → Xray REALITY unreachable. SSH and
pubray1.zeroq.su kept working because they do NOT depend on 15380.
Restored (exact pre-T10 code from 61b3724):
- modules/options.nix: reality443Forwarding option
- modules/vds/default.nix: reality443Forwarding = true
- modules/containers/3x-ui.nix: realityPorts binding + ports = basePorts ++ realityPorts
- manifest.json T10 → status 'pending' (reopened with corrected notes)
Verified: nix eval .#nixosConfigurations.otreca...3xui_app.ports =
[..., '127.0.0.1:15380:443/tcp']
82 lines
3.4 KiB
Nix
82 lines
3.4 KiB
Nix
{
|
|
lib,
|
|
...
|
|
}:
|
|
# Cross-module options: declared here, not in the module that reads them.
|
|
#
|
|
# An option belongs in this file when at least one context *sets* it while
|
|
# another module *reads* it — the reader cannot be the only place that knows
|
|
# the option exists. `modules/essentials/ssh.nix` does not belong here: it
|
|
# declares and reads `host.ssh.enable` itself, within one module.
|
|
{
|
|
# Remote-builder wiring. A coordinator (e.g. sapphira) sets
|
|
# `host.builder.clients` to register remote build machines;
|
|
# a builder host (e.g. the WSL on vetymae) sets `host.builder.enable`
|
|
# to advertise itself. The two halves are intentionally split so a single
|
|
# declaration in configurations/* is enough to flip each side.
|
|
options.host.builder = {
|
|
enable = lib.mkOption {
|
|
type = lib.types.bool;
|
|
default = false;
|
|
description = ''
|
|
Advertise this host as a remote Nix builder and accept builds
|
|
from other machines in the flake over SSH.
|
|
'';
|
|
};
|
|
clients = lib.mkOption {
|
|
type = lib.types.listOf lib.types.attrs;
|
|
default = [ ];
|
|
description = ''
|
|
List of remote Nix build machines this coordinator should
|
|
register via `nix.buildMachines`. Each entry matches the NixOS
|
|
option schema (hostName, sshUser, sshKey, systems,
|
|
supportedFeatures, ...). Two extra attributes are consumed by
|
|
modules/server/builder.nix and stripped before reaching
|
|
`nix.buildMachines`:
|
|
- `proxyCommand` — generates a per-builder Host block in the
|
|
system-wide OpenSSH config (the nix-daemon runs as root and
|
|
cannot see the user's ~/.ssh/config).
|
|
- `hostKeyAlias` — alias used inside that SSH matchBlock.
|
|
A builder reachable on its own (no ProxyCommand needed) omits
|
|
both and gets no SSH matchBlock. Empty by default — opt in by
|
|
setting this list.
|
|
'';
|
|
};
|
|
};
|
|
|
|
options.host."3x-ui" = {
|
|
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/)
|
|
# gets mounted read-only into the 3x-ui container so the panel
|
|
# can terminate TLS itself. Set null if 3x-ui serves plain HTTP
|
|
# and TLS is terminated by an upstream nginx.
|
|
certDomain = lib.mkOption {
|
|
type = lib.types.nullOr lib.types.str;
|
|
default = null;
|
|
example = "pubray1.zeroq.su";
|
|
description = ''
|
|
Domain whose LE cert should be mounted into the 3x-ui
|
|
container at /root/cert/fullchain.pem and key.pem.
|
|
'';
|
|
};
|
|
# Publish host:15380 → container:443. Only nodes that host an
|
|
# Xray REALITY inbound on container:443 need this (so nginx
|
|
# stream can forward TLS to Xray via 127.0.0.1:15380 while Xray
|
|
# itself sees incoming connections on its configured port 443).
|
|
# Set false on nodes that only run the 3x-ui panel.
|
|
#
|
|
# RESTORED 2026-10-10: this option was wrongly removed by T10/C5.
|
|
# modules/vds/nginx.nix still routes pubrayx1.zeroq.su/default →
|
|
# 127.0.0.1:15380, so without this mapping the nginx stream points
|
|
# at a dead port and Xray REALITY is unreachable.
|
|
reality443Forwarding = lib.mkOption {
|
|
type = lib.types.bool;
|
|
default = false;
|
|
description = ''
|
|
When true, publish host:15380 → container:443 so Xray
|
|
inside the container can serve REALITY on its real
|
|
configured port 443 (nginx stream forwards 443 → 15380).
|
|
'';
|
|
};
|
|
};
|
|
}
|