refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
-7
View File
@@ -1,7 +0,0 @@
{
"dns": {
"tag": "dns-in",
"servers": ["localhost"],
"queryStrategy": "UseIPv4"
}
}
-35
View File
@@ -1,35 +0,0 @@
{
"inbounds": [
{
"port": 61219,
"listen": "127.0.0.1",
"protocol": "dokodemo-door",
"settings": {
"followRedirect": true,
"network": "tcp,udp"
},
"streamSettings": {
"sockopt": {
"tproxy": "tproxy"
}
},
"tag": "tproxy"
},
{
"tag": "socks-in",
"ip": "127.0.0.1",
"port": 1080,
"protocol": "socks",
"settings": {
"auth": "password",
"accounts": [
{
"user": "embargo",
"pass": "moistnes12"
}
],
"udp": true
}
}
]
}
-9
View File
@@ -1,9 +0,0 @@
{
"log": {
"access": "/var/log/xray-core/access.log",
"error": "/var/log/xray-core/error.log",
"loglevel": "warning",
"dnsLog": false,
"maskAddress": ""
}
}
-23
View File
@@ -1,23 +0,0 @@
{
"policy": {
"levels": {
"0": {
"handshake": 4,
"connIdle": 300,
"uplinkOnly": 2,
"downlinkOnly": 5,
"statsUserUplink": false,
"statsUserDownlink": false,
"statsUserOnline": false,
"bufferSize": 512
}
},
"system": {
"statsInboundUplink": false,
"statsInboundDownlink": false,
"statsOutboundUplink": false,
"statsOutboundDownlink": false
}
}
}
+17
View File
@@ -0,0 +1,17 @@
[Unit]
Description=Xray-core Service
Documentation=https://github.com/xtls/xray-core
After=network.target network-online.target nftables.service
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/xray-core
ExecStart=/opt/xray-core/xray -confdir /opt/xray-core/config
Restart=on-failure
RestartSec=3s
LimitNOFILE=65535
[Install]
WantedBy=multi-user.target
-6
View File
@@ -1,6 +0,0 @@
---
- name: restart xray-core
ansible.builtin.service:
name: xray-core
state: restarted
listen: restart xray-core
-33
View File
@@ -1,33 +0,0 @@
---
- name: ensure /etc/xray-core exists
ansible.builtin.file:
path: /etc/xray-core/config
state: directory
mode: "0755"
- name: ensure /var/log/xray-core exists
ansible.builtin.file:
path: /var/log/xray-core
state: directory
mode: "0755"
- name: deploy static xray-core config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/xray-core/config/{{ item }}"
mode: "0744"
loop:
- dns.jsonc
- inbounds.jsonc
- log.jsonc
- policy.jsonc
- name: deploy dynamic xray-core config
ansible.builtin.template:
src: "{{ item }}.j2"
dest: "/etc/xray-core/config/{{ item }}"
mode: "0744"
loop:
- observatory.jsonc
- outbounds.jsonc
- routing.jsonc
+39 -2
View File
@@ -1,5 +1,42 @@
---
- name: install unbound
- name: install unzip
ansible.builtin.package:
name: unbound
name: unzip
state: present
- name: get latest xray-core release info
ansible.builtin.uri:
url: https://api.github.com/repos/XTLS/Xray-core/releases/latest
return_content: yes
register: xray_release
run_once: true
- name: set current xray-core version
ansible.builtin.set_fact:
xray_version: "{{ xray_release.json.tag_name }}"
xray_asset_url: "{{ xray_release.json.assets | selectattr('name', 'equalto', 'Xray-linux-64.zip') | map(attribute='browser_download_url') | first }}"
- name: check xray-core installed version
ansible.builtin.command: /opt/xray-core/xray version
register: xray_current_version
changed_when: false
failed_when: false
- name: ensure xray-core directory exists
ansible.builtin.file:
path: /opt/xray-core
state: directory
mode: '0755'
- name: update xray-core
ansible.builtin.unarchive:
src: "{{ xray_asset_url }}"
dest: /opt/xray-core
remote_src: yes
when: xray_version not in (xray_current_version.stdout | default(''))
- name: deploy xray-core systemd service unit
ansible.builtin.copy:
src: xray-core.service
dest: /etc/systemd/system/xray-core.service
mode: 755
+2 -5
View File
@@ -1,6 +1,3 @@
---
#- name: include unbound install
# ansible.builtin.include_tasks: install.yml
- name: include xray-core configurure
ansible.builtin.include_tasks: configure.yml
- name: include xray-core install
ansible.builtin.include_tasks: install.yml
@@ -1,8 +0,0 @@
{
"observatory": {
"subjectSelector": ["vless-"],
"probeUrl": "https://www.google.com/generate_204",
"probeInterval": "30s",
"enableConcurrency": true
}
}
@@ -1,67 +0,0 @@
{
"outbounds": [
{% for item in xray_outbounds %}
{
"tag": "vless-{{ item.tag }}",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "{{ item.address }}",
"port": 443,
"users": [
{
"id": "{{ xray_id }}",
"flow": "xtls-rprx-vision",
"encryption": "{{ xray_encryption }}"
}
]
}
],
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"path": "{{ xray_xhttp_path }}",
"mode": "stream-one"
},
"security": "tls",
"tlsSettings": {
"alpn": [
"h2",
"h3"
],
"fingerprint": "firefox"
},
"sockopt": {
"mark": 255
}
}
},
{% endfor %}
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"sockopt": {
"mark": 255,
"interface": "eth1",
"tcpFastOpen": true
}
}
},
{
"tag": "blocked",
"protocol": "blackhole",
"settings": {
"response": {
"type": "none"
}
}
}
]
}
@@ -1,41 +0,0 @@
{
"routing": {
"domainStrategy": "IPIfNonMatch",
{% if xray_outbounds | length > 1 %}
"balancers": [
{
"tag": "balancer-vless",
"selector": ["vless-"],
"strategy": {
"type": "leastLoad",
"settings": {
"costs": [
{% for item in xray_outbounds %}
{
"match": "vless-{{ item.tag }}",
"value": {{ item.value }}
}{{ "," if not loop.last else "" }}
{% endfor %}
]
}
}
}
],
{% endif %}
"rules": [
{
"type": "field",
"protocol": ["bittorrent"],
"outboundTag": "direct"
},
{
"type": "field",
"inboundTag": [
"tproxy",
"socks-in"
],
"balancerTag": "{{ 'balancer-vless' if xray_outbounds | length > 1 else 'vless-' ~ xray_outbounds[0].tag }}"
}
]
}
}