Documentation
¶
Overview ¶
Package config handles TOML configuration parsing.
Index ¶
- func BuildDDSecret(key []byte) string
- func BuildFullSecret(key []byte, host string) string
- func GenerateKey() (string, error)
- func ParseKey(s string) ([]byte, error)
- type Config
- type Duration
- type GeneralConfig
- type MetricsConfig
- type MiddleEndConfig
- type MiddleEndRuntimeConfig
- func (c MiddleEndRuntimeConfig) CloseIdleConnections()
- func (c MiddleEndRuntimeConfig) Frontend(source gproxy.MiddleEndBindingSource) gproxy.MiddleEndFrontendConfig
- func (c MiddleEndRuntimeConfig) FrontendForService(service *middleend.Service) gproxy.MiddleEndFrontendConfig
- func (c MiddleEndRuntimeConfig) GoString() string
- func (MiddleEndRuntimeConfig) String() string
- type PerformanceConfig
- type TLSFrontingConfig
- type UpstreamConfig
- type WebProxyConfig
- type WebProxyRuntimeConfig
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildDDSecret ¶ added in v0.3.3
BuildDDSecret builds the dd secret string: dd + key (no hostname)
func BuildFullSecret ¶
BuildFullSecret builds the full secret string: ee + key + hex(host)
func GenerateKey ¶
GenerateKey generates a new random 16-byte key (returned as 32 hex chars).
Types ¶
type Config ¶
type Config struct {
// Top-level options (can also be set in [general] section)
BindTo string `toml:"bind-to"`
LogLevel string `toml:"log-level"`
ProxyProtocol bool `toml:"proxy-protocol"`
Secrets map[string]string `toml:"secrets"` // name = "secret"
General GeneralConfig `toml:"general"`
TLSFronting TLSFrontingConfig `toml:"tls-fronting"`
Performance PerformanceConfig `toml:"performance"`
Upstream UpstreamConfig `toml:"upstream"`
Metrics MetricsConfig `toml:"metrics"`
WebProxy WebProxyConfig `toml:"web-proxy"`
MiddleEnd MiddleEndConfig `toml:"middle-end"`
}
Config is the TOML configuration structure.
func (*Config) ToGProxyConfig ¶
ToGProxyConfig converts to gproxy.Config.
func (*Config) ToMiddleEndRuntimeConfig ¶ added in v0.6.0
func (c *Config) ToMiddleEndRuntimeConfig() (MiddleEndRuntimeConfig, error)
ToMiddleEndRuntimeConfig validates the optional ME section and derives every nested queue and lifecycle limit. Disabled configuration is ignored.
func (*Config) ToWebProxyRuntimeConfig ¶ added in v0.5.0
func (c *Config) ToWebProxyRuntimeConfig(mtProxyBind string) (WebProxyRuntimeConfig, error)
ToWebProxyRuntimeConfig validates the optional WEB listener and derives its plain and dd profiles from the existing 16-byte [secrets]. Disabled WEB configuration is deliberately ignored so legacy configurations retain their exact startup behavior.
type GeneralConfig ¶ added in v0.1.4
type GeneralConfig struct {
BindTo string `toml:"bind-to"`
LogLevel string `toml:"log-level"` // trace, debug, info, warn, error
ProxyProtocol bool `toml:"proxy-protocol"` // Accept incoming PROXY protocol
MaxConnectionsPerIP int `toml:"max-connections-per-ip"` // Max connections per IP+secret, 0 = unlimited
MaxIPsPerUser int `toml:"max-ips-per-user"` // Max unique IPs per user, 0 = unlimited
IPBlockTimeout Duration `toml:"ip-block-timeout"` // How long blocked IPs stay blocked
HandshakeTimeout Duration `toml:"handshake-timeout"` // Max time for handshake (default 5s)
ClockSyncURL string `toml:"clock-sync-url"` // HTTPS URL whose Date header corrects a skewed server clock at startup
}
GeneralConfig contains general server settings.
type MetricsConfig ¶ added in v0.3.0
type MetricsConfig struct {
BindTo string `toml:"bind-to"` // Address to bind metrics server (empty = disabled)
Path string `toml:"path"` // Metrics path (default: /metrics)
Diagnostics bool `toml:"diagnostics"` // Private on-demand runtime profiles (default: disabled)
}
MetricsConfig configures the Prometheus metrics endpoint.
func (MetricsConfig) Validate ¶ added in v0.6.1
func (c MetricsConfig) Validate() error
Validate rejects diagnostics that can bind beyond a literal loopback address.
type MiddleEndConfig ¶ added in v0.6.0
type MiddleEndConfig struct {
Enabled bool `toml:"enabled"`
ProxyTag string `toml:"proxy-tag"`
SOCKS5 string `toml:"socks5"`
SOCKS5Username string `toml:"socks5-username"`
SOCKS5Password string `toml:"socks5-password"`
ArtifactProxy string `toml:"artifact-proxy"`
NATIP string `toml:"nat-ip"`
MaxConnections int `toml:"max-connections"`
QueueBudgetMB int `toml:"queue-budget-mb"`
}
MiddleEndConfig configures Telegram's official Middle-End transport, which Load enables by default unless the configuration explicitly disables it. Queue, topology, and timeout details are derived by ToMiddleEndRuntimeConfig. The two expert bounds can only reduce the production defaults.
type MiddleEndRuntimeConfig ¶ added in v0.6.0
type MiddleEndRuntimeConfig struct {
Enabled bool
Service middleend.ServiceConfig
ProxyTag *middleend.ProxyTag
MaxConnections int
// contains filtered or unexported fields
}
MiddleEndRuntimeConfig owns the non-network resources needed to construct a complete ME service and frontend. It never exposes proxy credentials or the registered proxy tag through formatting.
func (MiddleEndRuntimeConfig) CloseIdleConnections ¶ added in v0.6.0
func (c MiddleEndRuntimeConfig) CloseIdleConnections()
CloseIdleConnections releases artifact-fetch keepalive sockets after the ME service has stopped.
func (MiddleEndRuntimeConfig) Frontend ¶ added in v0.6.0
func (c MiddleEndRuntimeConfig) Frontend(source gproxy.MiddleEndBindingSource) gproxy.MiddleEndFrontendConfig
Frontend derives policy for a binding source. Use FrontendForService when the source belongs to a service with a shared response pool.
func (MiddleEndRuntimeConfig) FrontendForService ¶ added in v0.6.5
func (c MiddleEndRuntimeConfig) FrontendForService(service *middleend.Service) gproxy.MiddleEndFrontendConfig
FrontendForService shares the service's response pool with every frontend output owner, including output retained after a generation retires.
func (MiddleEndRuntimeConfig) GoString ¶ added in v0.6.0
func (c MiddleEndRuntimeConfig) GoString() string
func (MiddleEndRuntimeConfig) String ¶ added in v0.6.0
func (MiddleEndRuntimeConfig) String() string
type PerformanceConfig ¶
type PerformanceConfig struct {
TCPBufferKB int `toml:"tcp-buffer-kb"`
NumEventLoops int `toml:"num-event-loops"` // gnet event loops (0 = auto, uses all cores)
PreferIP string `toml:"prefer-ip"`
IdleTimeout Duration `toml:"idle-timeout"`
MaxWriteBufferMB int `toml:"max-write-buffer-mb"` // Max pending bytes per connection (0 = 4MB)
// ClientSilenceClose: close a relay whose server reply has gone unanswered by
// the client for this long (breaks the iOS bad_salt "Updating" wedge).
// 0 = off. If enabled, keep it well above your slowest legitimate response;
// ~10-15s is a sane starting point.
ClientSilenceClose Duration `toml:"client-silence-close"`
}
PerformanceConfig configures performance settings.
type TLSFrontingConfig ¶
type TLSFrontingConfig struct {
MaskHost string `toml:"mask-host"` // Domain to mimic (SNI validation, proxy links)
MaskPort int `toml:"mask-port"` // Default port (default: 443)
// Certificate fetching - where to connect to get real TLS cert
// Defaults to mask-host:mask-port if not set
// Useful when cert must be fetched from local nginx bypassing front proxy
CertHost string `toml:"cert-host"`
CertPort int `toml:"cert-port"`
// FakeCertSize sets the exact size of the fake encrypted-certificate record
// in the FakeTLS ServerHello. 0 = auto (match the mask backend's real cert
// record size). Set to the backend's first cert-record size to remove the
// accept-vs-mask cert-record-length tell.
FakeCertSize int `toml:"fake-cert-size"`
// MaskSNISafelist: opt-in extra domains an unauthenticated probe may be
// fronted to when its ClientHello SNI matches. Empty = off (never a relay).
MaskSNISafelist []string `toml:"mask-sni-safelist"`
// Splice target - where to forward unrecognized clients
// Defaults to mask-host:mask-port if not set
SpliceHost string `toml:"splice-host"`
SplicePort int `toml:"splice-port"`
SpliceProxyProtocol int `toml:"splice-proxy-protocol"` // 0=off, 1=v1, 2=v2
SpliceIdleTimeout Duration `toml:"splice-idle-timeout"` // Idle timeout for splice connections (default 30s)
// Anti-DPI record shaping on the proxy->client direction.
// Pointers so an absent TOML key keeps the gproxy.DefaultConfig() default (true).
EnableDRS *bool `toml:"enable-drs"` // Chrome-style probe-then-ramp record sizer
EnableSplitTLS *bool `toml:"enable-split-tls"` // 1-byte first ApplicationData record
}
TLSFrontingConfig configures TLS fronting.
type UpstreamConfig ¶ added in v0.1.3
type UpstreamConfig struct {
Socks5 string `toml:"socks5"` // SOCKS5 proxy address (e.g., "127.0.0.1:1080")
}
UpstreamConfig configures upstream (DC) connection settings.
type WebProxyConfig ¶ added in v0.5.0
type WebProxyConfig struct {
Enabled bool `toml:"enabled"`
BindTo string `toml:"bind-to"`
Hostname string `toml:"hostname"`
BasePath string `toml:"base-path"`
Backend string `toml:"backend"`
Carrier string `toml:"carrier"`
TrustedProxyCIDRs []string `toml:"trusted-proxy-cidrs"`
NumEventLoops int `toml:"num-event-loops"`
}
WebProxyConfig configures the optional private WEB carrier listener. Nginx terminates public TLS and forwards candidate requests to this listener.
type WebProxyRuntimeConfig ¶ added in v0.5.0
type WebProxyRuntimeConfig struct {
Enabled bool
BindAddr string
Hostname string
BasePath string
Backend string
LogicalBackend bool
MTProxyAddr net.Addr
Carrier webproxy.CarrierMode
TrustedProxyCIDRs []string
NumEventLoops int
Profiles []webproxy.Profile
BackendProxyProtocol bool
}
WebProxyRuntimeConfig is the validated, immutable input used to construct the native WEB manager and its private gnet HTTP listener.