config

package
v0.4.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 23, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package config handles TOML configuration parsing.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildDDSecret added in v0.3.3

func BuildDDSecret(key []byte) string

BuildDDSecret builds the dd secret string: dd + key (no hostname)

func BuildFullSecret

func BuildFullSecret(key []byte, host string) string

BuildFullSecret builds the full secret string: ee + key + hex(host)

func GenerateKey

func GenerateKey() (string, error)

GenerateKey generates a new random 16-byte key (returned as 32 hex chars).

func ParseKey

func ParseKey(s string) ([]byte, error)

ParseKey parses a 16-byte hex-encoded key (32 hex chars).

Types

type Config

type Config struct {
	// Top-level options (can also be set in [general] section)
	BindTo        string `toml:"bind-to"`
	LogLevel      string `toml:"log-level"`
	ProxyProtocol bool   `toml:"proxy-protocol"`

	Secrets map[string]string `toml:"secrets"` // name = "secret"

	General     GeneralConfig     `toml:"general"`
	TLSFronting TLSFrontingConfig `toml:"tls-fronting"`
	Performance PerformanceConfig `toml:"performance"`
	Upstream    UpstreamConfig    `toml:"upstream"`
	Metrics     MetricsConfig     `toml:"metrics"`
}

Config is the TOML configuration structure.

func Load

func Load(path string) (*Config, error)

Load loads configuration from a TOML file.

func (*Config) ToGProxyConfig

func (c *Config) ToGProxyConfig() (gproxy.Config, error)

ToGProxyConfig converts to gproxy.Config.

type Duration

type Duration time.Duration

Duration is a TOML-parseable duration.

func (Duration) Duration

func (d Duration) Duration() time.Duration

func (*Duration) UnmarshalText

func (d *Duration) UnmarshalText(text []byte) error

type GeneralConfig added in v0.1.4

type GeneralConfig struct {
	BindTo              string   `toml:"bind-to"`
	LogLevel            string   `toml:"log-level"`              // trace, debug, info, warn, error
	ProxyProtocol       bool     `toml:"proxy-protocol"`         // Accept incoming PROXY protocol
	MaxConnectionsPerIP int      `toml:"max-connections-per-ip"` // Max connections per IP+secret, 0 = unlimited
	MaxIPsPerUser       int      `toml:"max-ips-per-user"`       // Max unique IPs per user, 0 = unlimited
	IPBlockTimeout      Duration `toml:"ip-block-timeout"`       // How long blocked IPs stay blocked
	HandshakeTimeout    Duration `toml:"handshake-timeout"`      // Max time for handshake (default 5s)
	ClockSyncURL        string   `toml:"clock-sync-url"`         // HTTPS URL whose Date header corrects a skewed server clock at startup
}

GeneralConfig contains general server settings.

type MetricsConfig added in v0.3.0

type MetricsConfig struct {
	BindTo string `toml:"bind-to"` // Address to bind metrics server (empty = disabled)
	Path   string `toml:"path"`    // Metrics path (default: /metrics)
}

MetricsConfig configures the Prometheus metrics endpoint.

type PerformanceConfig

type PerformanceConfig struct {
	TCPBufferKB      int      `toml:"tcp-buffer-kb"`
	NumEventLoops    int      `toml:"num-event-loops"` // gnet event loops (0 = auto, uses all cores)
	PreferIP         string   `toml:"prefer-ip"`
	IdleTimeout      Duration `toml:"idle-timeout"`
	MaxWriteBufferMB int      `toml:"max-write-buffer-mb"` // Max pending bytes per connection (0 = 4MB)
	// ClientSilenceClose: close a relay whose server reply has gone unanswered by
	// the client for this long (breaks the iOS bad_salt "Updating" wedge).
	// 0 = off. If enabled, keep it well above your slowest legitimate response;
	// ~10-15s is a sane starting point.
	ClientSilenceClose Duration `toml:"client-silence-close"`
}

PerformanceConfig configures performance settings.

type TLSFrontingConfig

type TLSFrontingConfig struct {
	MaskHost string `toml:"mask-host"` // Domain to mimic (SNI validation, proxy links)
	MaskPort int    `toml:"mask-port"` // Default port (default: 443)

	// Certificate fetching - where to connect to get real TLS cert
	// Defaults to mask-host:mask-port if not set
	// Useful when cert must be fetched from local nginx bypassing front proxy
	CertHost string `toml:"cert-host"`
	CertPort int    `toml:"cert-port"`

	// FakeCertSize sets the exact size of the fake encrypted-certificate record
	// in the FakeTLS ServerHello. 0 = auto (match the mask backend's real cert
	// record size). Set to the backend's first cert-record size to remove the
	// accept-vs-mask cert-record-length tell.
	FakeCertSize int `toml:"fake-cert-size"`

	// MaskSNISafelist: opt-in extra domains an unauthenticated probe may be
	// fronted to when its ClientHello SNI matches. Empty = off (never a relay).
	MaskSNISafelist []string `toml:"mask-sni-safelist"`

	// Splice target - where to forward unrecognized clients
	// Defaults to mask-host:mask-port if not set
	SpliceHost          string   `toml:"splice-host"`
	SplicePort          int      `toml:"splice-port"`
	SpliceProxyProtocol int      `toml:"splice-proxy-protocol"` // 0=off, 1=v1, 2=v2
	SpliceIdleTimeout   Duration `toml:"splice-idle-timeout"`   // Idle timeout for splice connections (default 30s)

	// Anti-DPI record shaping on the proxy->client direction.
	// Pointers so an absent TOML key keeps the gproxy.DefaultConfig() default (true).
	EnableDRS      *bool `toml:"enable-drs"`       // Chrome-style probe-then-ramp record sizer
	EnableSplitTLS *bool `toml:"enable-split-tls"` // 1-byte first ApplicationData record
}

TLSFrontingConfig configures TLS fronting.

type UpstreamConfig added in v0.1.3

type UpstreamConfig struct {
	Socks5 string `toml:"socks5"` // SOCKS5 proxy address (e.g., "127.0.0.1:1080")
}

UpstreamConfig configures upstream (DC) connection settings.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL