add_vds_configs
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
*
|
||||
!*/
|
||||
!*-example
|
||||
!README.md
|
||||
!.gitignore
|
||||
@@ -0,0 +1,121 @@
|
||||
# vds haproxy + wireguard + ipvs
|
||||
|
||||
L4 балансировщик и шлюз для распределения tcp/udp сервисов во внутреннюю сеть через wireguard с использованием haproxy, ipvs и nftables.
|
||||
|
||||
## Архитектура
|
||||
|
||||
- Вход: публичные порты vds
|
||||
- tcp → haproxy
|
||||
- udp / спец. tcp → nftables (`fwmark`) → `ipvs`
|
||||
- Транспорт → wireguard (`wg0`)
|
||||
- NAT → netmap (1:1 подсети)
|
||||
|
||||
## Компоненты
|
||||
|
||||
### haproxy (tcp)
|
||||
|
||||
Работает в `mode tcp`, проксирует с поддержкой `proxy-protocol`:
|
||||
|
||||
| Порт | Сервис | Backend |
|
||||
| --- | --- | --- |
|
||||
| 80 | HTTP | 10.x.102.3:81 |
|
||||
| 443 | HTTPS | 10.x.102.3:444 |
|
||||
| 22 | Gitea SSH | 10.x.103.3:22 |
|
||||
| 24444 | MCSManager | 10.x.103.3:24445 |
|
||||
|
||||
### xmpp (prosody)
|
||||
|
||||
Прямой tcp проброс:
|
||||
|
||||
| Порт | Сервис |
|
||||
| --- | --- |
|
||||
| 5222, 5223 | client |
|
||||
| 5269 | server |
|
||||
| 5000 | proxy65 |
|
||||
| 5270 | components |
|
||||
| 5280 | BOSH |
|
||||
|
||||
---
|
||||
|
||||
## wireguard
|
||||
|
||||
- Интерфейс: `wg0`
|
||||
- Подсеть: `10.x.200.0/24`
|
||||
|
||||
#### Функции:
|
||||
|
||||
- транспорт между узлами
|
||||
- запуск `nftables` и `ipvs`
|
||||
- включение `ip_forward` и `conntrack`
|
||||
|
||||
## ipvs (fwmark)
|
||||
|
||||
Балансировка по меткам:
|
||||
|
||||
| Марка | Сервис | Backend |
|
||||
| --- | --- | --- |
|
||||
| 10 | coturn | 10.x.103.10 |
|
||||
| 20 | minecraft | 10.x.104.3 |
|
||||
| 30 | steam/valheim | 10.x.104.4 |
|
||||
| 40 | rustdesk | 10.x.200.1 |
|
||||
|
||||
Алгоритм: `rr`
|
||||
|
||||
|
||||
## nftables
|
||||
|
||||
### prerouting
|
||||
|
||||
Классификация трафика:
|
||||
|
||||
- wireguard (51820) → accept
|
||||
- coturn → mark 10
|
||||
- minecraft → mark 20
|
||||
- steam / valheim → mark 30
|
||||
- rustdesk → mark 40
|
||||
- nat (postrouting)
|
||||
|
||||
1:1 netmap через **wg0**:
|
||||
|
||||
```bash
|
||||
10.x.0.0/24 → 10.x.100.0/24
|
||||
10.x.1.0/24 → 10.x.101.0/24
|
||||
10.x.2.0/24 → 10.x.102.0/24
|
||||
10.x.3.0/24 → 10.x.103.0/24
|
||||
10.x.4.0/24 → 10.x.104.0/24
|
||||
10.x.5.0/24 → 10.x.105.0/24
|
||||
192.x.x.0/24 → 10.x.200.0/24
|
||||
```
|
||||
|
||||
## Поток трафика
|
||||
1. Клиент → vds
|
||||
2. haproxy (tcp) или nftables (udp/marked tcp)
|
||||
3. Проставление `fwmark`
|
||||
4. ipvs → выбор backend
|
||||
5. SNAT (netmap) → wireguard
|
||||
6. Доставка в целевую подсеть
|
||||
|
||||
## Цикл жизни
|
||||
|
||||
### PostUp
|
||||
- загрузка модулей: `ip_vs`, `nf_conntrack`
|
||||
- включение `ip_forward`
|
||||
- применение `nftables`
|
||||
- настройка `ipvs` (`fwmark rules`)
|
||||
|
||||
### PostDown
|
||||
- очистка `ipvs`
|
||||
- удаление таблицы `nftables`
|
||||
|
||||
## Особенности
|
||||
- Используется `proxy-protocol` для реального ip
|
||||
- udp балансируется через `ipvs`
|
||||
- Сегментация через netmap (жёсткое соответствие подсетей)
|
||||
- Все сервисы заходят через одну точку (vds)
|
||||
|
||||
## Зависимости
|
||||
|
||||
```bash
|
||||
apt update
|
||||
apt install ipvsadm ufw haproxy wireguard-tools
|
||||
```
|
||||
@@ -0,0 +1,107 @@
|
||||
global
|
||||
log /dev/log local2
|
||||
chroot /var/lib/haproxy
|
||||
maxconn 4000
|
||||
user haproxy
|
||||
group haproxy
|
||||
daemon
|
||||
stats socket /var/lib/haproxy/stats mode 660 level admin
|
||||
|
||||
defaults
|
||||
log global
|
||||
mode tcp
|
||||
option tcplog
|
||||
option dontlognull
|
||||
retries 3
|
||||
timeout connect 5s
|
||||
timeout client 1h
|
||||
timeout server 1h
|
||||
timeout check 10s
|
||||
|
||||
# http
|
||||
frontend http_frontend
|
||||
bind ip:80
|
||||
mode http
|
||||
option httplog
|
||||
|
||||
acl host_host2 hdr_end(host) -m end host2.tld
|
||||
|
||||
use_backend host2_http_srv if is_host2
|
||||
default_backend host1_http_srv
|
||||
|
||||
backend host1_http_srv
|
||||
mode http
|
||||
server host1_srv 10.x.102.3:81 check send-proxy-v2
|
||||
|
||||
backend host2_http_srv
|
||||
mode http
|
||||
server host2_srv 10.x.200.1:81 check send-proxy-v2
|
||||
|
||||
# https
|
||||
frontend https_frontend
|
||||
bind ip:443
|
||||
mode tcp
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_ssl_hello_type 1 }
|
||||
|
||||
acl host_host2 req_ssl_sni -m end host2.tld
|
||||
acl host_host3 req_ssl_sni -i host3.tld
|
||||
|
||||
use_backend host2_https_srv if host_host2
|
||||
use_backend host3_https_srv if host_host3
|
||||
default_backend host1_https_srv
|
||||
|
||||
backend host1_https_srv
|
||||
mode tcp
|
||||
server host1_srv 10.x.102.3:444 check send-proxy-v2
|
||||
|
||||
backend host2_https_srv
|
||||
mode tcp
|
||||
server host2_srv 10.x.200.1:444 check send-proxy-v2
|
||||
|
||||
backend host3_https_srv
|
||||
mode tcp
|
||||
server host3_srv x.x.x.x:443 check
|
||||
|
||||
# gitea
|
||||
listen gitea_ssh_secure
|
||||
bind ip:2211
|
||||
bind 127.0.0.1:2211
|
||||
mode tcp
|
||||
default_backend gitea_ssh_backend
|
||||
|
||||
backend gitea_ssh_backend
|
||||
mode tcp
|
||||
server gitea_srv 10.x.103.3:22 check
|
||||
|
||||
# mcsmanager-daemon
|
||||
listen mcsmanager_service
|
||||
bind ip:24444
|
||||
mode tcp
|
||||
server mcs_srv 10.x.102.3:24445 check send-proxy-v2
|
||||
|
||||
# prosody
|
||||
listen xmpp_c2s
|
||||
bind ip:5222
|
||||
server prosody_srv 10.x.103.9:5222 check
|
||||
|
||||
listen xmpp_legacy_ssl
|
||||
bind ip:5223
|
||||
server prosody_srv 10.x.103.9:5223 check
|
||||
|
||||
listen xmpp_s2s
|
||||
bind ip:5269
|
||||
server prosody_srv 10.x.103.9:5269 check
|
||||
|
||||
listen prosody_proxy65
|
||||
bind ip:5000
|
||||
server prosody_srv 10.x.103.9:5000 check
|
||||
|
||||
listen prosody_components
|
||||
bind ip:5270
|
||||
server prosody_srv 10.x.103.9:5270 check
|
||||
|
||||
listen prosody_bosh_http
|
||||
bind ip:5280
|
||||
server prosody_srv 10.x.103.9:5280 check
|
||||
@@ -0,0 +1,25 @@
|
||||
table ip ipvs_mgr {
|
||||
chain prerouting {
|
||||
type filter hook prerouting priority -150; policy accept;
|
||||
|
||||
# allow wireguard
|
||||
udp dport 51820 counter accept
|
||||
|
||||
# coturn
|
||||
ip daddr #ip udp dport { 3478, 5349, 49152-65535 } counter mark set 10
|
||||
ip daddr #ip tcp dport { 3478, 5349 } counter mark set 10
|
||||
|
||||
# minecraft
|
||||
ip daddr #ip tcp dport 25565 counter mark set 20
|
||||
|
||||
# steam-query
|
||||
ip daddr #ip udp dport 2456 counter mark set 30
|
||||
|
||||
# valheim
|
||||
ip daddr #ip udp dport 2457 counter mark set 30
|
||||
|
||||
# rustdesk
|
||||
ip daddr #ip udp dport 21116 counter mark set 40
|
||||
ip daddr #ip tcp dport 21114-21119 counter mark set 40
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,51 @@
|
||||
[Interface]
|
||||
Address = 10.x.255.200/24
|
||||
ListenPort = 51820
|
||||
PrivateKey =
|
||||
|
||||
# global vars
|
||||
PostUp = modprobe nf_conntrack
|
||||
PostUp = modprobe ip_vs
|
||||
PostUp = modprobe ip_vs_rr
|
||||
PostUp = sysctl -w net.ipv4.ip_forward=1
|
||||
PostUp = sysctl -w net.ipv4.vs.conntrack=1
|
||||
|
||||
# nftables
|
||||
PostUp = nft -f /etc/wireguard/10-marks.nft
|
||||
PostUp = nft -f /etc/wireguard/20-netmap.nft
|
||||
|
||||
# coturn
|
||||
PostUp = ipvsadm -D -f 10 || true
|
||||
PostUp = ipvsadm -A -f 10 -s rr
|
||||
PostUp = ipvsadm -a -f 10 -r 10.x.103.10 -m
|
||||
|
||||
# minecraft
|
||||
PostUp = ipvsadm -D -f 20 || true
|
||||
PostUp = ipvsadm -A -f 20 -s rr
|
||||
PostUp = ipvsadm -a -f 20 -r 10.x.104.3 -m
|
||||
|
||||
# steamcmd
|
||||
PostUp = ipvsadm -D -f 30 || true
|
||||
PostUp = ipvsadm -A -f 30 -s rr
|
||||
PostUp = ipvsadm -a -f 30 -r 10.x.104.4 -m
|
||||
|
||||
# rustdesk
|
||||
PostUp = ipvsadm -D -f 40 || true
|
||||
PostUp = ipvsadm -A -f 40 -s rr
|
||||
PostUp = ipvsadm -a -f 40 -r 10.x.200.1 -m
|
||||
|
||||
# cleanup
|
||||
PostDown = ipvsadm -C
|
||||
PostDown = nft delete table ip ipvs_mgr || true
|
||||
|
||||
# bananawrt
|
||||
[Peer]
|
||||
PublicKey =
|
||||
PresharedKey =
|
||||
AllowedIPs = 10.x.255.1/32, 10.x.100.0/24, 10.x.101.0/24, 10.x.102.0/24, 10.x.103.0/24, 10.x.104.0/24, 10.x.105.0/24
|
||||
|
||||
# xiawrt
|
||||
[Peer]
|
||||
PublicKey =
|
||||
PresharedKey =
|
||||
AllowedIPs = 10.x.255.2/32, 10.x.200.0/24
|
||||
Reference in New Issue
Block a user