Documentation
¶
Overview ¶
Package config handles TOML configuration parsing.
Index ¶
- func BuildDDSecret(key []byte) string
- func BuildFullSecret(key []byte, host string) string
- func GenerateKey() (string, error)
- func ParseKey(s string) ([]byte, error)
- type Config
- type Duration
- type GeneralConfig
- type MetricsConfig
- type PerformanceConfig
- type TLSFrontingConfig
- type UpstreamConfig
- type WebProxyConfig
- type WebProxyRuntimeConfig
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildDDSecret ¶ added in v0.3.3
BuildDDSecret builds the dd secret string: dd + key (no hostname)
func BuildFullSecret ¶
BuildFullSecret builds the full secret string: ee + key + hex(host)
func GenerateKey ¶
GenerateKey generates a new random 16-byte key (returned as 32 hex chars).
Types ¶
type Config ¶
type Config struct {
// Top-level options (can also be set in [general] section)
BindTo string `toml:"bind-to"`
LogLevel string `toml:"log-level"`
ProxyProtocol bool `toml:"proxy-protocol"`
Secrets map[string]string `toml:"secrets"` // name = "secret"
General GeneralConfig `toml:"general"`
TLSFronting TLSFrontingConfig `toml:"tls-fronting"`
Performance PerformanceConfig `toml:"performance"`
Upstream UpstreamConfig `toml:"upstream"`
Metrics MetricsConfig `toml:"metrics"`
WebProxy WebProxyConfig `toml:"web-proxy"`
}
Config is the TOML configuration structure.
func (*Config) ToGProxyConfig ¶
ToGProxyConfig converts to gproxy.Config.
func (*Config) ToWebProxyRuntimeConfig ¶ added in v0.5.0
func (c *Config) ToWebProxyRuntimeConfig(mtProxyBind string) (WebProxyRuntimeConfig, error)
ToWebProxyRuntimeConfig validates the optional WEB listener and derives its plain and dd profiles from the existing 16-byte [secrets]. Disabled WEB configuration is deliberately ignored so legacy configurations retain their exact startup behavior.
type GeneralConfig ¶ added in v0.1.4
type GeneralConfig struct {
BindTo string `toml:"bind-to"`
LogLevel string `toml:"log-level"` // trace, debug, info, warn, error
ProxyProtocol bool `toml:"proxy-protocol"` // Accept incoming PROXY protocol
MaxConnectionsPerIP int `toml:"max-connections-per-ip"` // Max connections per IP+secret, 0 = unlimited
MaxIPsPerUser int `toml:"max-ips-per-user"` // Max unique IPs per user, 0 = unlimited
IPBlockTimeout Duration `toml:"ip-block-timeout"` // How long blocked IPs stay blocked
HandshakeTimeout Duration `toml:"handshake-timeout"` // Max time for handshake (default 5s)
ClockSyncURL string `toml:"clock-sync-url"` // HTTPS URL whose Date header corrects a skewed server clock at startup
}
GeneralConfig contains general server settings.
type MetricsConfig ¶ added in v0.3.0
type MetricsConfig struct {
BindTo string `toml:"bind-to"` // Address to bind metrics server (empty = disabled)
Path string `toml:"path"` // Metrics path (default: /metrics)
}
MetricsConfig configures the Prometheus metrics endpoint.
type PerformanceConfig ¶
type PerformanceConfig struct {
TCPBufferKB int `toml:"tcp-buffer-kb"`
NumEventLoops int `toml:"num-event-loops"` // gnet event loops (0 = auto, uses all cores)
PreferIP string `toml:"prefer-ip"`
IdleTimeout Duration `toml:"idle-timeout"`
MaxWriteBufferMB int `toml:"max-write-buffer-mb"` // Max pending bytes per connection (0 = 4MB)
// ClientSilenceClose: close a relay whose server reply has gone unanswered by
// the client for this long (breaks the iOS bad_salt "Updating" wedge).
// 0 = off. If enabled, keep it well above your slowest legitimate response;
// ~10-15s is a sane starting point.
ClientSilenceClose Duration `toml:"client-silence-close"`
}
PerformanceConfig configures performance settings.
type TLSFrontingConfig ¶
type TLSFrontingConfig struct {
MaskHost string `toml:"mask-host"` // Domain to mimic (SNI validation, proxy links)
MaskPort int `toml:"mask-port"` // Default port (default: 443)
// Certificate fetching - where to connect to get real TLS cert
// Defaults to mask-host:mask-port if not set
// Useful when cert must be fetched from local nginx bypassing front proxy
CertHost string `toml:"cert-host"`
CertPort int `toml:"cert-port"`
// FakeCertSize sets the exact size of the fake encrypted-certificate record
// in the FakeTLS ServerHello. 0 = auto (match the mask backend's real cert
// record size). Set to the backend's first cert-record size to remove the
// accept-vs-mask cert-record-length tell.
FakeCertSize int `toml:"fake-cert-size"`
// MaskSNISafelist: opt-in extra domains an unauthenticated probe may be
// fronted to when its ClientHello SNI matches. Empty = off (never a relay).
MaskSNISafelist []string `toml:"mask-sni-safelist"`
// Splice target - where to forward unrecognized clients
// Defaults to mask-host:mask-port if not set
SpliceHost string `toml:"splice-host"`
SplicePort int `toml:"splice-port"`
SpliceProxyProtocol int `toml:"splice-proxy-protocol"` // 0=off, 1=v1, 2=v2
SpliceIdleTimeout Duration `toml:"splice-idle-timeout"` // Idle timeout for splice connections (default 30s)
// Anti-DPI record shaping on the proxy->client direction.
// Pointers so an absent TOML key keeps the gproxy.DefaultConfig() default (true).
EnableDRS *bool `toml:"enable-drs"` // Chrome-style probe-then-ramp record sizer
EnableSplitTLS *bool `toml:"enable-split-tls"` // 1-byte first ApplicationData record
}
TLSFrontingConfig configures TLS fronting.
type UpstreamConfig ¶ added in v0.1.3
type UpstreamConfig struct {
Socks5 string `toml:"socks5"` // SOCKS5 proxy address (e.g., "127.0.0.1:1080")
}
UpstreamConfig configures upstream (DC) connection settings.
type WebProxyConfig ¶ added in v0.5.0
type WebProxyConfig struct {
Enabled bool `toml:"enabled"`
BindTo string `toml:"bind-to"`
Hostname string `toml:"hostname"`
Backend string `toml:"backend"`
TrustedProxyCIDRs []string `toml:"trusted-proxy-cidrs"`
NumEventLoops int `toml:"num-event-loops"`
}
WebProxyConfig configures the optional private WEB carrier listener. Nginx terminates public TLS and forwards candidate requests to this listener.
type WebProxyRuntimeConfig ¶ added in v0.5.0
type WebProxyRuntimeConfig struct {
Enabled bool
BindAddr string
Hostname string
Backend string
TrustedProxyCIDRs []string
NumEventLoops int
Profiles []webproxy.Profile
BackendProxyProtocol bool
}
WebProxyRuntimeConfig is the validated, immutable input used to construct the native WEB manager and its private gnet HTTP listener.