initial commit
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{%- macro set_ref(name) -%}
|
||||
{%- if name == 'all' -%}
|
||||
0.0.0.0/0
|
||||
{%- elif name in xray_ip_sets or name in (xray_static_sets | default([])) -%}
|
||||
@{{ name }}_ip
|
||||
{%- elif name in xray_domain_sets -%}
|
||||
@{{ name_dom }}_dom
|
||||
{%- else -%}
|
||||
INVALID_XRAY_SET_{{ name }}
|
||||
{%- endif -%}
|
||||
{%- endmacro -%}
|
||||
|
||||
{%- set rules_list = [] -%}
|
||||
{%- for item in groups[xray_managed_group] | default([]) | sort -%}
|
||||
{%- set client = hostvars[item] -%}
|
||||
{%- if client.xray_policy is defined -%}
|
||||
{%- set src_ip = client.container_ip | default(client.ansible_host | default(item)) -%}
|
||||
{%- for rule in client.xray_policy -%}
|
||||
{%- if rule.bypass is defined -%}
|
||||
{%- set _ = rules_list.append("meta l4proto { tcp, udp } ip saddr " ~ src_ip ~ " ip daddr " ~ set_ref(rule.bypass) ~ " accept") -%}
|
||||
{%- elif rule.proxy is defined -%}
|
||||
{%- set _ = rules_list.append("meta l4proto { tcp, udp } ip saddr " ~ src_ip ~ " ip daddr " ~ set_ref(rule.proxy) ~ " tproxy ip to :" ~ (xray_tproxy_port | default(61219) | string) ~ " meta mark set " ~ (xray_fwmark | default('0x00000001')) ~ " accept") -%}
|
||||
{%- endif -%}
|
||||
{%- endfor -%}
|
||||
{%- endif -%}
|
||||
{%- endfor -%}
|
||||
|
||||
{%- if rules_list | length > 0 -%}
|
||||
{{- rules_list | join('\n') -}}
|
||||
{%- endif -%}
|
||||
@@ -0,0 +1,15 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{%- for id, item in xray_ip_sets.items() -%}
|
||||
set {{ id }}_ip {
|
||||
type ipv4_addr
|
||||
flags interval
|
||||
auto-merge
|
||||
include "{{ xray_lists_global.output_dir }}/{{ id }}.elements.nft"
|
||||
}
|
||||
{% endfor -%}
|
||||
{%- for id, item in xray_domain_sets.items() -%}
|
||||
set {{ id }}_dom {
|
||||
type ipv4_addr
|
||||
flags interval
|
||||
}
|
||||
{% endfor -%}
|
||||
@@ -0,0 +1,47 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
global:
|
||||
cache_dir: {{ xray_lists_global.cache_dir }}
|
||||
output_dir: {{ xray_lists_global.output_dir }}
|
||||
dnsmasq_output: {{ xray_lists_global.dnsmasq_output }}
|
||||
{% if xray_lists_global.proxy is defined %}
|
||||
proxy: "{{ xray_lists_global.proxy }}"
|
||||
{% endif %}
|
||||
{% if xray_lists_global.proxy_user is defined %}
|
||||
proxy_user: "{{ xray_lists_global.proxy_user }}"
|
||||
proxy_pass: "{{ xray_lists_global.proxy_pass }}"
|
||||
{% endif %}
|
||||
http_timeout: {{ xray_lists_global.http_timeout | default(20) }}
|
||||
ip_sets:
|
||||
{% for id, item in xray_ip_sets.items() %}
|
||||
- id: {{ id }}
|
||||
output: {{ id }}_ip.elements.nft
|
||||
{% if item.static is defined %}
|
||||
static:
|
||||
{% for s in item.static %}
|
||||
- {{ s }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% if item.urls is defined %}
|
||||
urls:
|
||||
{% for u in item.urls %}
|
||||
- {{ u }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
domain_sets:
|
||||
{% for id, item in xray_domain_sets.items() %}
|
||||
- id: {{ id }}
|
||||
dnsmasq_target: "4#inet#filter#{{ id }}_dom"
|
||||
{% if item.static is defined %}
|
||||
static:
|
||||
{% for s in item.static %}
|
||||
- {{ s }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% if item.urls is defined %}
|
||||
urls:
|
||||
{% for u in item.urls %}
|
||||
- {{ u }}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
Reference in New Issue
Block a user