mirror of
https://github.com/p1neappleXpress/OpenFlux.git
synced 2026-10-02 05:04:39 +08:00
One multi-stage image (golang:1.26-alpine -> alpine:3.22, CGO off) serving both roles via an env-driven entrypoint: - client: SOCKS5 proxy, no special privileges, published on 127.0.0.1:1080 - exit-node: raw sockets + the kernel-RST drop, confined to the container's network namespace (NET_RAW/NET_ADMIN via compose), so the iptables rule can never touch the host — the containerized variant of the scoped rule the README already recommends docker-compose.yml runs the two ends behind separate profiles; .env.example documents TRANSPORT (yandex|vyandex|oneme), DOC_URL, MAX_TOKEN/MAX_UID, etc.
23 lines
751 B
Bash
23 lines
751 B
Bash
# Copy to .env (gitignored) or export inline. All optional except the
|
|
# credentials of whichever transport you run.
|
|
|
|
# Transport channel: yandex (legacy docs editor) | vyandex (new volga editor) | oneme (MAX)
|
|
TRANSPORT=yandex
|
|
|
|
# yandex / vyandex: public Yandex document URL shared by client and exit node.
|
|
DOC_URL=
|
|
|
|
# oneme: MAX Web token + the *other* side's user id (client dials the exit node's uid).
|
|
MAX_TOKEN=
|
|
MAX_UID=
|
|
|
|
# Client only: SOCKS5 listen address inside the container (published as 127.0.0.1:1080).
|
|
SOCKS5_LISTEN=:1080
|
|
|
|
# Exit node only: pin a dedicated egress/alias IP. Usually unnecessary inside
|
|
# the container's own netns — leave empty for auto-detection.
|
|
EXIT_LOCAL_IP=
|
|
|
|
# 1 enables verbose packet-level logging (noisy).
|
|
DEBUG=0
|