refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
+7
View File
@@ -0,0 +1,7 @@
{
"dns": {
"tag": "dns-in",
"servers": ["localhost"],
"queryStrategy": "UseIPv4"
}
}
+35
View File
@@ -0,0 +1,35 @@
{
"inbounds": [
{
"port": 61219,
"listen": "0.0.0.0",
"protocol": "dokodemo-door",
"settings": {
"followRedirect": true,
"network": "tcp,udp"
},
"streamSettings": {
"sockopt": {
"tproxy": "tproxy"
}
},
"tag": "tproxy"
},
{
"tag": "socks-in",
"ip": "127.0.0.1",
"port": 1080,
"protocol": "socks",
"settings": {
"auth": "password",
"accounts": [
{
"user": "embargo",
"pass": "moistnes12"
}
],
"udp": true
}
}
]
}
+9
View File
@@ -0,0 +1,9 @@
{
"log": {
"access": "/var/log/xray-core/access.log",
"error": "/var/log/xray-core/error.log",
"loglevel": "warning",
"dnsLog": false,
"maskAddress": ""
}
}
+23
View File
@@ -0,0 +1,23 @@
{
"policy": {
"levels": {
"0": {
"handshake": 4,
"connIdle": 300,
"uplinkOnly": 2,
"downlinkOnly": 5,
"statsUserUplink": false,
"statsUserDownlink": false,
"statsUserOnline": false,
"bufferSize": 512
}
},
"system": {
"statsInboundUplink": false,
"statsInboundDownlink": false,
"statsOutboundUplink": false,
"statsOutboundDownlink": false
}
}
}
+43
View File
@@ -0,0 +1,43 @@
---
- name: ensure /opt/xray-core/config exists
ansible.builtin.file:
path: /opt/xray-core/config
state: directory
mode: 0755
- name: ensure /var/log/xray-core exists
ansible.builtin.file:
path: /var/log/xray-core
state: directory
mode: 0755
- name: deploy static xray-core config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/opt/xray-core/config/{{ item }}"
mode: 0744
loop:
- dns.jsonc
- inbounds.jsonc
- log.jsonc
- policy.jsonc
register: xray_core_static_config
- name: deploy dynamic xray-core config
ansible.builtin.template:
src: "{{ item }}.j2"
dest: "/opt/xray-core/config/{{ item }}"
mode: 0744
loop:
- observatory.jsonc
- outbounds.jsonc
- routing.jsonc
register: xray_core_dynamic_config
- name: restart xray-core systemd service unit
ansible.builtin.systemd_service:
name: xray-core
daemon_reload: true
state: restarted
enabled: true
when: xray_core_static_config.changed or xray_core_dynamic_config.changed
+3
View File
@@ -0,0 +1,3 @@
---
- name: include xray-core configurure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,8 @@
{
"observatory": {
"subjectSelector": ["vless-"],
"probeUrl": "https://www.google.com/generate_204",
"probeInterval": "30s",
"enableConcurrency": true
}
}
@@ -0,0 +1,67 @@
{
"outbounds": [
{% for item in xray_outbounds %}
{
"tag": "vless-{{ item.tag }}",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "{{ item.address }}",
"port": 443,
"users": [
{
"id": "{{ xray_id }}",
"flow": "xtls-rprx-vision",
"encryption": "{{ xray_encryption }}"
}
]
}
],
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"path": "{{ xray_xhttp_path }}",
"mode": "stream-one"
},
"security": "tls",
"tlsSettings": {
"alpn": [
"h2",
"h3"
],
"fingerprint": "firefox"
},
"sockopt": {
"mark": 255
}
}
},
{% endfor %}
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"sockopt": {
"mark": 255,
"interface": "eth1",
"tcpFastOpen": true
}
}
},
{
"tag": "blocked",
"protocol": "blackhole",
"settings": {
"response": {
"type": "none"
}
}
}
]
}
@@ -0,0 +1,41 @@
{
"routing": {
"domainStrategy": "IPIfNonMatch",
{% if xray_outbounds | length > 1 %}
"balancers": [
{
"tag": "balancer-vless",
"selector": ["vless-"],
"strategy": {
"type": "leastLoad",
"settings": {
"costs": [
{% for item in xray_outbounds %}
{
"match": "vless-{{ item.tag }}",
"value": {{ item.value }}
}{{ "," if not loop.last else "" }}
{% endfor %}
]
}
}
}
],
{% endif %}
"rules": [
{
"type": "field",
"protocol": ["bittorrent"],
"outboundTag": "direct"
},
{
"type": "field",
"inboundTag": [
"tproxy",
"socks-in"
],
"balancerTag": "{{ 'balancer-vless' if xray_outbounds | length > 1 else 'vless-' ~ xray_outbounds[0].tag }}"
}
]
}
}