config

package
v0.6.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 12, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Overview

Package config handles TOML configuration parsing.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildDDSecret added in v0.3.3

func BuildDDSecret(key []byte) string

BuildDDSecret builds the dd secret string: dd + key (no hostname)

func BuildFullSecret

func BuildFullSecret(key []byte, host string) string

BuildFullSecret builds the full secret string: ee + key + hex(host)

func GenerateKey

func GenerateKey() (string, error)

GenerateKey generates a new random 16-byte key (returned as 32 hex chars).

func ParseKey

func ParseKey(s string) ([]byte, error)

ParseKey parses a 16-byte hex-encoded key (32 hex chars).

Types

type Config

type Config struct {
	// Top-level options (can also be set in [general] section)
	BindTo        string `toml:"bind-to"`
	LogLevel      string `toml:"log-level"`
	ProxyProtocol bool   `toml:"proxy-protocol"`

	Secrets map[string]string `toml:"secrets"` // name = "secret"

	General     GeneralConfig     `toml:"general"`
	TLSFronting TLSFrontingConfig `toml:"tls-fronting"`
	Performance PerformanceConfig `toml:"performance"`
	Upstream    UpstreamConfig    `toml:"upstream"`
	Metrics     MetricsConfig     `toml:"metrics"`
	WebProxy    WebProxyConfig    `toml:"web-proxy"`
	MiddleEnd   MiddleEndConfig   `toml:"middle-end"`
}

Config is the TOML configuration structure.

func Load

func Load(path string) (*Config, error)

Load loads configuration from a TOML file.

func (*Config) ToGProxyConfig

func (c *Config) ToGProxyConfig() (gproxy.Config, error)

ToGProxyConfig converts to gproxy.Config.

func (*Config) ToMiddleEndRuntimeConfig added in v0.6.0

func (c *Config) ToMiddleEndRuntimeConfig() (MiddleEndRuntimeConfig, error)

ToMiddleEndRuntimeConfig validates the optional ME section and derives every nested queue and lifecycle limit. Disabled configuration is ignored.

func (*Config) ToWebProxyRuntimeConfig added in v0.5.0

func (c *Config) ToWebProxyRuntimeConfig(mtProxyBind string) (WebProxyRuntimeConfig, error)

ToWebProxyRuntimeConfig validates the optional WEB listener and derives its plain and dd profiles from the existing 16-byte [secrets]. Disabled WEB configuration is deliberately ignored so legacy configurations retain their exact startup behavior.

type Duration

type Duration time.Duration

Duration is a TOML-parseable duration.

func (Duration) Duration

func (d Duration) Duration() time.Duration

func (*Duration) UnmarshalText

func (d *Duration) UnmarshalText(text []byte) error

type GeneralConfig added in v0.1.4

type GeneralConfig struct {
	BindTo              string   `toml:"bind-to"`
	LogLevel            string   `toml:"log-level"`              // trace, debug, info, warn, error
	ProxyProtocol       bool     `toml:"proxy-protocol"`         // Accept incoming PROXY protocol
	MaxConnectionsPerIP int      `toml:"max-connections-per-ip"` // Max connections per IP+secret, 0 = unlimited
	MaxIPsPerUser       int      `toml:"max-ips-per-user"`       // Max unique IPs per user, 0 = unlimited
	IPBlockTimeout      Duration `toml:"ip-block-timeout"`       // How long blocked IPs stay blocked
	HandshakeTimeout    Duration `toml:"handshake-timeout"`      // Max time for handshake (default 5s)
	ClockSyncURL        string   `toml:"clock-sync-url"`         // HTTPS URL whose Date header corrects a skewed server clock at startup
}

GeneralConfig contains general server settings.

type MetricsConfig added in v0.3.0

type MetricsConfig struct {
	BindTo      string `toml:"bind-to"`     // Address to bind metrics server (empty = disabled)
	Path        string `toml:"path"`        // Metrics path (default: /metrics)
	Diagnostics bool   `toml:"diagnostics"` // Private on-demand runtime profiles (default: disabled)
}

MetricsConfig configures the Prometheus metrics endpoint.

func (MetricsConfig) Validate added in v0.6.1

func (c MetricsConfig) Validate() error

Validate rejects diagnostics that can bind beyond a literal loopback address.

type MiddleEndConfig added in v0.6.0

type MiddleEndConfig struct {
	Enabled        bool   `toml:"enabled"`
	ProxyTag       string `toml:"proxy-tag"`
	SOCKS5         string `toml:"socks5"`
	SOCKS5Username string `toml:"socks5-username"`
	SOCKS5Password string `toml:"socks5-password"`
	ArtifactProxy  string `toml:"artifact-proxy"`
	NATIP          string `toml:"nat-ip"`
	MaxConnections int    `toml:"max-connections"`
	QueueBudgetMB  int    `toml:"queue-budget-mb"`
}

MiddleEndConfig enables Telegram's official Middle-End transport. Queue, topology, and timeout details are derived by ToMiddleEndRuntimeConfig. The two expert bounds can only reduce the production defaults.

type MiddleEndRuntimeConfig added in v0.6.0

type MiddleEndRuntimeConfig struct {
	Enabled        bool
	Service        middleend.ServiceConfig
	ProxyTag       *middleend.ProxyTag
	MaxConnections int
	// contains filtered or unexported fields
}

MiddleEndRuntimeConfig owns the non-network resources needed to construct a complete ME service and frontend. It never exposes proxy credentials or the registered proxy tag through formatting.

func (MiddleEndRuntimeConfig) CloseIdleConnections added in v0.6.0

func (c MiddleEndRuntimeConfig) CloseIdleConnections()

CloseIdleConnections releases artifact-fetch keepalive sockets after the ME service has stopped.

func (MiddleEndRuntimeConfig) Frontend added in v0.6.0

Frontend derives the fixed production frontend policy for an already-owned service source.

func (MiddleEndRuntimeConfig) GoString added in v0.6.0

func (c MiddleEndRuntimeConfig) GoString() string

func (MiddleEndRuntimeConfig) String added in v0.6.0

func (MiddleEndRuntimeConfig) String() string

type PerformanceConfig

type PerformanceConfig struct {
	TCPBufferKB      int      `toml:"tcp-buffer-kb"`
	NumEventLoops    int      `toml:"num-event-loops"` // gnet event loops (0 = auto, uses all cores)
	PreferIP         string   `toml:"prefer-ip"`
	IdleTimeout      Duration `toml:"idle-timeout"`
	MaxWriteBufferMB int      `toml:"max-write-buffer-mb"` // Max pending bytes per connection (0 = 4MB)
	// ClientSilenceClose: close a relay whose server reply has gone unanswered by
	// the client for this long (breaks the iOS bad_salt "Updating" wedge).
	// 0 = off. If enabled, keep it well above your slowest legitimate response;
	// ~10-15s is a sane starting point.
	ClientSilenceClose Duration `toml:"client-silence-close"`
}

PerformanceConfig configures performance settings.

type TLSFrontingConfig

type TLSFrontingConfig struct {
	MaskHost string `toml:"mask-host"` // Domain to mimic (SNI validation, proxy links)
	MaskPort int    `toml:"mask-port"` // Default port (default: 443)

	// Certificate fetching - where to connect to get real TLS cert
	// Defaults to mask-host:mask-port if not set
	// Useful when cert must be fetched from local nginx bypassing front proxy
	CertHost string `toml:"cert-host"`
	CertPort int    `toml:"cert-port"`

	// FakeCertSize sets the exact size of the fake encrypted-certificate record
	// in the FakeTLS ServerHello. 0 = auto (match the mask backend's real cert
	// record size). Set to the backend's first cert-record size to remove the
	// accept-vs-mask cert-record-length tell.
	FakeCertSize int `toml:"fake-cert-size"`

	// MaskSNISafelist: opt-in extra domains an unauthenticated probe may be
	// fronted to when its ClientHello SNI matches. Empty = off (never a relay).
	MaskSNISafelist []string `toml:"mask-sni-safelist"`

	// Splice target - where to forward unrecognized clients
	// Defaults to mask-host:mask-port if not set
	SpliceHost          string   `toml:"splice-host"`
	SplicePort          int      `toml:"splice-port"`
	SpliceProxyProtocol int      `toml:"splice-proxy-protocol"` // 0=off, 1=v1, 2=v2
	SpliceIdleTimeout   Duration `toml:"splice-idle-timeout"`   // Idle timeout for splice connections (default 30s)

	// Anti-DPI record shaping on the proxy->client direction.
	// Pointers so an absent TOML key keeps the gproxy.DefaultConfig() default (true).
	EnableDRS      *bool `toml:"enable-drs"`       // Chrome-style probe-then-ramp record sizer
	EnableSplitTLS *bool `toml:"enable-split-tls"` // 1-byte first ApplicationData record
}

TLSFrontingConfig configures TLS fronting.

type UpstreamConfig added in v0.1.3

type UpstreamConfig struct {
	Socks5 string `toml:"socks5"` // SOCKS5 proxy address (e.g., "127.0.0.1:1080")
}

UpstreamConfig configures upstream (DC) connection settings.

type WebProxyConfig added in v0.5.0

type WebProxyConfig struct {
	Enabled           bool     `toml:"enabled"`
	BindTo            string   `toml:"bind-to"`
	Hostname          string   `toml:"hostname"`
	Backend           string   `toml:"backend"`
	Carrier           string   `toml:"carrier"`
	TrustedProxyCIDRs []string `toml:"trusted-proxy-cidrs"`
	NumEventLoops     int      `toml:"num-event-loops"`
}

WebProxyConfig configures the optional private WEB carrier listener. Nginx terminates public TLS and forwards candidate requests to this listener.

type WebProxyRuntimeConfig added in v0.5.0

type WebProxyRuntimeConfig struct {
	Enabled              bool
	BindAddr             string
	Hostname             string
	Backend              string
	LogicalBackend       bool
	MTProxyAddr          net.Addr
	Carrier              webproxy.CarrierMode
	TrustedProxyCIDRs    []string
	NumEventLoops        int
	Profiles             []webproxy.Profile
	BackendProxyProtocol bool
}

WebProxyRuntimeConfig is the validated, immutable input used to construct the native WEB manager and its private gnet HTTP listener.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL