refactor: restructure inventory, split roles and add new services
This commit is contained in:
@@ -1,7 +0,0 @@
|
||||
{
|
||||
"dns": {
|
||||
"tag": "dns-in",
|
||||
"servers": ["localhost"],
|
||||
"queryStrategy": "UseIPv4"
|
||||
}
|
||||
}
|
||||
@@ -1,35 +0,0 @@
|
||||
{
|
||||
"inbounds": [
|
||||
{
|
||||
"port": 61219,
|
||||
"listen": "127.0.0.1",
|
||||
"protocol": "dokodemo-door",
|
||||
"settings": {
|
||||
"followRedirect": true,
|
||||
"network": "tcp,udp"
|
||||
},
|
||||
"streamSettings": {
|
||||
"sockopt": {
|
||||
"tproxy": "tproxy"
|
||||
}
|
||||
},
|
||||
"tag": "tproxy"
|
||||
},
|
||||
{
|
||||
"tag": "socks-in",
|
||||
"ip": "127.0.0.1",
|
||||
"port": 1080,
|
||||
"protocol": "socks",
|
||||
"settings": {
|
||||
"auth": "password",
|
||||
"accounts": [
|
||||
{
|
||||
"user": "embargo",
|
||||
"pass": "moistnes12"
|
||||
}
|
||||
],
|
||||
"udp": true
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,9 +0,0 @@
|
||||
{
|
||||
"log": {
|
||||
"access": "/var/log/xray-core/access.log",
|
||||
"error": "/var/log/xray-core/error.log",
|
||||
"loglevel": "warning",
|
||||
"dnsLog": false,
|
||||
"maskAddress": ""
|
||||
}
|
||||
}
|
||||
@@ -1,23 +0,0 @@
|
||||
{
|
||||
"policy": {
|
||||
"levels": {
|
||||
"0": {
|
||||
|
||||
"handshake": 4,
|
||||
"connIdle": 300,
|
||||
"uplinkOnly": 2,
|
||||
"downlinkOnly": 5,
|
||||
"statsUserUplink": false,
|
||||
"statsUserDownlink": false,
|
||||
"statsUserOnline": false,
|
||||
"bufferSize": 512
|
||||
}
|
||||
},
|
||||
"system": {
|
||||
"statsInboundUplink": false,
|
||||
"statsInboundDownlink": false,
|
||||
"statsOutboundUplink": false,
|
||||
"statsOutboundDownlink": false
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
[Unit]
|
||||
Description=Xray-core Service
|
||||
Documentation=https://github.com/xtls/xray-core
|
||||
After=network.target network-online.target nftables.service
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/xray-core
|
||||
ExecStart=/opt/xray-core/xray -confdir /opt/xray-core/config
|
||||
Restart=on-failure
|
||||
RestartSec=3s
|
||||
LimitNOFILE=65535
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -1,6 +0,0 @@
|
||||
---
|
||||
- name: restart xray-core
|
||||
ansible.builtin.service:
|
||||
name: xray-core
|
||||
state: restarted
|
||||
listen: restart xray-core
|
||||
@@ -1,33 +0,0 @@
|
||||
---
|
||||
- name: ensure /etc/xray-core exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/xray-core/config
|
||||
state: directory
|
||||
mode: "0755"
|
||||
|
||||
- name: ensure /var/log/xray-core exists
|
||||
ansible.builtin.file:
|
||||
path: /var/log/xray-core
|
||||
state: directory
|
||||
mode: "0755"
|
||||
|
||||
- name: deploy static xray-core config
|
||||
ansible.builtin.copy:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/xray-core/config/{{ item }}"
|
||||
mode: "0744"
|
||||
loop:
|
||||
- dns.jsonc
|
||||
- inbounds.jsonc
|
||||
- log.jsonc
|
||||
- policy.jsonc
|
||||
|
||||
- name: deploy dynamic xray-core config
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}.j2"
|
||||
dest: "/etc/xray-core/config/{{ item }}"
|
||||
mode: "0744"
|
||||
loop:
|
||||
- observatory.jsonc
|
||||
- outbounds.jsonc
|
||||
- routing.jsonc
|
||||
@@ -1,5 +1,42 @@
|
||||
---
|
||||
- name: install unbound
|
||||
- name: install unzip
|
||||
ansible.builtin.package:
|
||||
name: unbound
|
||||
name: unzip
|
||||
state: present
|
||||
|
||||
- name: get latest xray-core release info
|
||||
ansible.builtin.uri:
|
||||
url: https://api.github.com/repos/XTLS/Xray-core/releases/latest
|
||||
return_content: yes
|
||||
register: xray_release
|
||||
run_once: true
|
||||
|
||||
- name: set current xray-core version
|
||||
ansible.builtin.set_fact:
|
||||
xray_version: "{{ xray_release.json.tag_name }}"
|
||||
xray_asset_url: "{{ xray_release.json.assets | selectattr('name', 'equalto', 'Xray-linux-64.zip') | map(attribute='browser_download_url') | first }}"
|
||||
|
||||
- name: check xray-core installed version
|
||||
ansible.builtin.command: /opt/xray-core/xray version
|
||||
register: xray_current_version
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
|
||||
- name: ensure xray-core directory exists
|
||||
ansible.builtin.file:
|
||||
path: /opt/xray-core
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: update xray-core
|
||||
ansible.builtin.unarchive:
|
||||
src: "{{ xray_asset_url }}"
|
||||
dest: /opt/xray-core
|
||||
remote_src: yes
|
||||
when: xray_version not in (xray_current_version.stdout | default(''))
|
||||
|
||||
- name: deploy xray-core systemd service unit
|
||||
ansible.builtin.copy:
|
||||
src: xray-core.service
|
||||
dest: /etc/systemd/system/xray-core.service
|
||||
mode: 755
|
||||
|
||||
@@ -1,6 +1,3 @@
|
||||
---
|
||||
#- name: include unbound install
|
||||
# ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include xray-core configurure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
- name: include xray-core install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
@@ -1,8 +0,0 @@
|
||||
{
|
||||
"observatory": {
|
||||
"subjectSelector": ["vless-"],
|
||||
"probeUrl": "https://www.google.com/generate_204",
|
||||
"probeInterval": "30s",
|
||||
"enableConcurrency": true
|
||||
}
|
||||
}
|
||||
@@ -1,67 +0,0 @@
|
||||
{
|
||||
"outbounds": [
|
||||
{% for item in xray_outbounds %}
|
||||
{
|
||||
"tag": "vless-{{ item.tag }}",
|
||||
"protocol": "vless",
|
||||
"settings": {
|
||||
"vnext": [
|
||||
{
|
||||
"address": "{{ item.address }}",
|
||||
"port": 443,
|
||||
"users": [
|
||||
{
|
||||
"id": "{{ xray_id }}",
|
||||
"flow": "xtls-rprx-vision",
|
||||
"encryption": "{{ xray_encryption }}"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"domainStrategy": "UseIPv4"
|
||||
},
|
||||
"streamSettings": {
|
||||
"network": "xhttp",
|
||||
"xhttpSettings": {
|
||||
"path": "{{ xray_xhttp_path }}",
|
||||
"mode": "stream-one"
|
||||
},
|
||||
"security": "tls",
|
||||
"tlsSettings": {
|
||||
"alpn": [
|
||||
"h2",
|
||||
"h3"
|
||||
],
|
||||
"fingerprint": "firefox"
|
||||
},
|
||||
"sockopt": {
|
||||
"mark": 255
|
||||
}
|
||||
}
|
||||
},
|
||||
{% endfor %}
|
||||
{
|
||||
"tag": "direct",
|
||||
"protocol": "freedom",
|
||||
"settings": {
|
||||
"domainStrategy": "UseIPv4"
|
||||
},
|
||||
"streamSettings": {
|
||||
"sockopt": {
|
||||
"mark": 255,
|
||||
"interface": "eth1",
|
||||
"tcpFastOpen": true
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
"tag": "blocked",
|
||||
"protocol": "blackhole",
|
||||
"settings": {
|
||||
"response": {
|
||||
"type": "none"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,41 +0,0 @@
|
||||
{
|
||||
"routing": {
|
||||
"domainStrategy": "IPIfNonMatch",
|
||||
{% if xray_outbounds | length > 1 %}
|
||||
"balancers": [
|
||||
{
|
||||
"tag": "balancer-vless",
|
||||
"selector": ["vless-"],
|
||||
"strategy": {
|
||||
"type": "leastLoad",
|
||||
"settings": {
|
||||
"costs": [
|
||||
{% for item in xray_outbounds %}
|
||||
{
|
||||
"match": "vless-{{ item.tag }}",
|
||||
"value": {{ item.value }}
|
||||
}{{ "," if not loop.last else "" }}
|
||||
{% endfor %}
|
||||
]
|
||||
}
|
||||
}
|
||||
}
|
||||
],
|
||||
{% endif %}
|
||||
"rules": [
|
||||
{
|
||||
"type": "field",
|
||||
"protocol": ["bittorrent"],
|
||||
"outboundTag": "direct"
|
||||
},
|
||||
{
|
||||
"type": "field",
|
||||
"inboundTag": [
|
||||
"tproxy",
|
||||
"socks-in"
|
||||
],
|
||||
"balancerTag": "{{ 'balancer-vless' if xray_outbounds | length > 1 else 'vless-' ~ xray_outbounds[0].tag }}"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user