Repository navigation
Give each site its own VPN exit - #28
Merged
Merged
Conversation
Sites stream to their own country only, and one process-wide HTTPS_PROXY can exit in a single country. -tvp-proxy and -bbc-proxy (MAGNETOWID_TVP_PROXY, MAGNETOWID_BBC_PROXY) take an HTTP proxy's URL or "direct"; unset, a site follows the environment as before. Each site gets its own client, and its streams carry that client's transport, so playlists, segments, subtitles and probes go the same way as the site's API. ffmpeg, for the streams it fetches itself, is given the proxy that transport would use instead of inheriting http_proxy.
magnetowid-vpn@<name> runs a Gluetun container from /etc/magnetowid/vpn-<name>.env and serves its HTTP proxy on a local port, one instance per country. Nothing starts until an instance is enabled, and Docker stays optional. An exit whose file names no provider fails once with status 78 instead of restarting forever; the check sits in the main command because RestartPreventExitStatus ignores ExecStartPre. Removing the package stops and disables the instances. The package smoke test starts an exit against a fake docker on Debian, Fedora and Arch.
docs/vpn.md walks through one exit for one site and then a second, for the Linux service and for Docker Compose, with compose.vpn.yaml as the Compose example.
Gluetun exits with 1 when it is stopped while its proxy has open connections, so every systemctl stop left the exit failed. Count that status as a stop and restart on any exit instead; an unfinished settings file still ends the unit with 78 and no retries. The smoke test's fake docker now exits with 1 on stop, as Gluetun does.
combor
marked this pull request as ready for review
October 1, 2026 16:54
A site with no proxy setting got a transport that follows the environment, and the downloader then settled ffmpeg's proxy from the master playlist's URL alone, dropping no_proxy. A rendition or segment on another host could go direct where the environment asked for the proxy. Such a site now has no transport of its own, as before per-site settings: its streams use the default clients and ffmpeg inherits the environment and applies its rules to each host.
Flags took their defaults from the environment, and usage, printed when a required setting is missing, lists every default: the API key and any password in a proxy URL ended up in the service's log. Those flags now default to empty and read the environment after parsing. A flag still wins over the environment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sites limit their streams to their own country, and a process-wide
HTTPS_PROXYcan exit in only one. This lets every site be reached through its own proxy, packages a systemd unit that runs a VPN exit per country, and adds a guide.What changes
-tvp-proxy/MAGNETOWID_TVP_PROXYand-bbc-proxy/MAGNETOWID_BBC_PROXYtake an HTTP proxy's URL ordirect. Unset, a site follows the environment'sHTTPS_PROXYandNO_PROXYas before.http_proxy. A site without a setting keeps the previous path unchanged: the default clients, and ffmpeg inheriting the environment and applying its rules per host.magnetowid-vpn@.servicein the deb, rpm and AUR packages:magnetowid-vpn@plruns a Gluetun container from/etc/magnetowid/vpn-pl.envand publishes its HTTP proxy on a local port. Nothing runs until an instance is enabled, and Docker stays optional. An exit whose file names no provider fails once with status 78 instead of restarting forever.vpn.env.example, installed as/usr/share/magnetowid/vpn.env.example, andcompose.vpn.yamlfor Compose installs.Notes for review
MAGNETOWID_VPN_PORT,MAGNETOWID_VPN_IMAGE) because Gluetun reads the same file and takes names such asPROXY_PORTfor its own settings.RestartPreventExitStatusdoes not apply toExecStartPre.Restart=always; otherwise everysystemctl stopleaves the exit failed.magnetowid.envis untouched, so upgrades produce no config-file prompt.CONNECTwithTransfer-Encoding: chunked, which ffmpeg does not accept, so the live and encrypted streams ffmpeg fetches itself fail through a Gluetun exit instead of bypassing it.Testing
make test, including a test that runs the binary's usage with secrets in its environment.make package-smokeon Debian, Fedora and Arch, against a fakedockerthat exits with 1 on stop as Gluetun does: the unit and example install; an exit with a blank provider ends failed with status 78 and no restarts; with a provider and a non-default port it runsdockerwith the expected arguments; it stops without failing, restarts when it exits by itself, survives a package upgrade, and is stopped and disabled on removal.docs/vpn.md:magnetowid.servicefound and downloaded a release from that site while the other site kept working on its own connection. With the two settings swapped, both sites' releases came back unavailable. A second exit on another port ran beside the first.http://vpn-pl:8888, with both files selected throughCOMPOSE_FILEin.env.main: two findings (ffmpeg losing the environment's per-host proxy rules for a site without a setting, and proxy passwords in the usage text), both fixed; the second review was clean.