-
Notifications
You must be signed in to change notification settings - Fork 11
Expand file tree
/
Copy pathpoint.sh
More file actions
80 lines (72 loc) · 1.79 KB
/
Copy pathpoint.sh
File metadata and controls
80 lines (72 loc) · 1.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
#!/usr/bin/env bash
set -e
# 1. 监听端口
INTERNAL_PORT="${PORT:-2053}"
EXTERNAL_PORT="443"
# 2. 客户端 ID
if [ -n "$UUID" ]; then
CLIENT_ID="$UUID"
elif [ -f /default_uuid ]; then
CLIENT_ID="$(cat /default_uuid)"
else
CLIENT_ID="$(openssl rand -hex 16)"
fi
# 3. TLS 域名
DOMAIN="${DOMAIN:-vless.cfapps.us10-001.hana.ondemand.com}"
# 4. 目录准备
CERT_DIR="/etc/xray/certs"
CONFIG_DIR="/etc/xray"
mkdir -p "$CERT_DIR" "$CONFIG_DIR"
# 5. 自签证书(如已存在则跳过)
if [ ! -f "$CERT_DIR/privkey.pem" ] || [ ! -f "$CERT_DIR/fullchain.pem" ]; then
openssl req -x509 -nodes -newkey rsa:2048 \
-days 365 \
-subj "/CN=$DOMAIN" \
-keyout "$CERT_DIR/privkey.pem" \
-out "$CERT_DIR/fullchain.pem"
fi
# 6. 生成 Xray 配置
cat > "$CONFIG_DIR/config.json" <<EOF
{
"inbounds": [
{
"port": ${INTERNAL_PORT},
"protocol": "vless",
"settings": {
"clients": [
{
"id": "${CLIENT_ID}",
"flow": "xtls-rprx-direct"
}
],
"decryption": "none"
},
"streamSettings": {
"network": "tcp",
"security": "tls",
"tlsSettings": {
"certificates": [
{
"certificateFile": "${CERT_DIR}/fullchain.pem",
"keyFile": "${CERT_DIR}/privkey.pem"
}
]
}
}
}
],
"outbounds": [
{
"protocol": "freedom",
"settings": {}
}
]
}
EOF
# 7. 拼接并打印完整 VLESS URI(供客户端一键导入)
VLESS_URI="vless://${CLIENT_ID}@${DOMAIN}:${EXTERNAL_PORT}?encryption=none&security=tls&flow=xtls-rprx-direct&type=tcp#${DOMAIN}"
echo "===== VLESS 节点信息 ====="
echo "URI: ${VLESS_URI}"
echo "=========================="
# 8. 启动 Xray
exec xray -c "${CONFIG_DIR}/config.json"