config

package
v0.6.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 22 Imported by: 0

Documentation

Overview

Package config handles TOML configuration parsing.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildDDSecret added in v0.3.3

func BuildDDSecret(key []byte) string

BuildDDSecret builds the dd secret string: dd + key (no hostname)

func BuildFullSecret

func BuildFullSecret(key []byte, host string) string

BuildFullSecret builds the full secret string: ee + key + hex(host)

func GenerateKey

func GenerateKey() (string, error)

GenerateKey generates a new random 16-byte key (returned as 32 hex chars).

func ParseKey

func ParseKey(s string) ([]byte, error)

ParseKey parses a 16-byte hex-encoded key (32 hex chars).

Types

type Config

type Config struct {
	// Top-level options (can also be set in [general] section)
	BindTo        string `toml:"bind-to"`
	LogLevel      string `toml:"log-level"`
	ProxyProtocol bool   `toml:"proxy-protocol"`

	Secrets map[string]string `toml:"secrets"` // name = "secret"

	General     GeneralConfig     `toml:"general"`
	TLSFronting TLSFrontingConfig `toml:"tls-fronting"`
	Performance PerformanceConfig `toml:"performance"`
	Upstream    UpstreamConfig    `toml:"upstream"`
	Metrics     MetricsConfig     `toml:"metrics"`
	WebProxy    WebProxyConfig    `toml:"web-proxy"`
	MiddleEnd   MiddleEndConfig   `toml:"middle-end"`
}

Config is the TOML configuration structure.

func Load

func Load(path string) (*Config, error)

Load loads configuration from a TOML file.

func (*Config) ToGProxyConfig

func (c *Config) ToGProxyConfig() (gproxy.Config, error)

ToGProxyConfig converts to gproxy.Config.

func (*Config) ToMiddleEndRuntimeConfig added in v0.6.0

func (c *Config) ToMiddleEndRuntimeConfig() (MiddleEndRuntimeConfig, error)

ToMiddleEndRuntimeConfig validates the optional ME section and derives every nested queue and lifecycle limit. Disabled configuration is ignored.

func (*Config) ToWebProxyRuntimeConfig added in v0.5.0

func (c *Config) ToWebProxyRuntimeConfig(mtProxyBind string) (WebProxyRuntimeConfig, error)

ToWebProxyRuntimeConfig validates the optional WEB listener and derives its plain and dd profiles from the existing 16-byte [secrets]. Disabled WEB configuration is deliberately ignored so legacy configurations retain their exact startup behavior.

type Duration

type Duration time.Duration

Duration is a TOML-parseable duration.

func (Duration) Duration

func (d Duration) Duration() time.Duration

func (*Duration) UnmarshalText

func (d *Duration) UnmarshalText(text []byte) error

type GeneralConfig added in v0.1.4

type GeneralConfig struct {
	BindTo              string   `toml:"bind-to"`
	LogLevel            string   `toml:"log-level"`              // trace, debug, info, warn, error
	ProxyProtocol       bool     `toml:"proxy-protocol"`         // Accept incoming PROXY protocol
	MaxConnectionsPerIP int      `toml:"max-connections-per-ip"` // Max connections per IP+secret, 0 = unlimited
	MaxIPsPerUser       int      `toml:"max-ips-per-user"`       // Max unique IPs per user, 0 = unlimited
	IPBlockTimeout      Duration `toml:"ip-block-timeout"`       // How long blocked IPs stay blocked
	HandshakeTimeout    Duration `toml:"handshake-timeout"`      // Max time for handshake (default 5s)
	ClockSyncURL        string   `toml:"clock-sync-url"`         // HTTPS URL whose Date header corrects a skewed server clock at startup
}

GeneralConfig contains general server settings.

type MetricsConfig added in v0.3.0

type MetricsConfig struct {
	BindTo      string `toml:"bind-to"`     // Address to bind metrics server (empty = disabled)
	Path        string `toml:"path"`        // Metrics path (default: /metrics)
	Diagnostics bool   `toml:"diagnostics"` // Private on-demand runtime profiles (default: disabled)
}

MetricsConfig configures the Prometheus metrics endpoint.

func (MetricsConfig) Validate added in v0.6.1

func (c MetricsConfig) Validate() error

Validate rejects diagnostics that can bind beyond a literal loopback address.

type MiddleEndConfig added in v0.6.0

type MiddleEndConfig struct {
	Enabled        bool   `toml:"enabled"`
	ProxyTag       string `toml:"proxy-tag"`
	SOCKS5         string `toml:"socks5"`
	SOCKS5Username string `toml:"socks5-username"`
	SOCKS5Password string `toml:"socks5-password"`
	ArtifactProxy  string `toml:"artifact-proxy"`
	NATIP          string `toml:"nat-ip"`
	MaxConnections int    `toml:"max-connections"`
	QueueBudgetMB  int    `toml:"queue-budget-mb"`
}

MiddleEndConfig configures Telegram's official Middle-End transport, which Load enables by default unless the configuration explicitly disables it. Queue, topology, and timeout details are derived by ToMiddleEndRuntimeConfig. The two expert bounds can only reduce the production defaults.

type MiddleEndRuntimeConfig added in v0.6.0

type MiddleEndRuntimeConfig struct {
	Enabled        bool
	Service        middleend.ServiceConfig
	ProxyTag       *middleend.ProxyTag
	MaxConnections int
	// contains filtered or unexported fields
}

MiddleEndRuntimeConfig owns the non-network resources needed to construct a complete ME service and frontend. It never exposes proxy credentials or the registered proxy tag through formatting.

func (MiddleEndRuntimeConfig) CloseIdleConnections added in v0.6.0

func (c MiddleEndRuntimeConfig) CloseIdleConnections()

CloseIdleConnections releases artifact-fetch keepalive sockets after the ME service has stopped.

func (MiddleEndRuntimeConfig) Frontend added in v0.6.0

Frontend derives policy for a binding source. Use FrontendForService when the source belongs to a service with a shared response pool.

func (MiddleEndRuntimeConfig) FrontendForService added in v0.6.5

FrontendForService shares the service's response pool with every frontend output owner, including output retained after a generation retires.

func (MiddleEndRuntimeConfig) GoString added in v0.6.0

func (c MiddleEndRuntimeConfig) GoString() string

func (MiddleEndRuntimeConfig) String added in v0.6.0

func (MiddleEndRuntimeConfig) String() string

type PerformanceConfig

type PerformanceConfig struct {
	TCPBufferKB      int      `toml:"tcp-buffer-kb"`
	NumEventLoops    int      `toml:"num-event-loops"` // gnet event loops (0 = auto, uses all cores)
	PreferIP         string   `toml:"prefer-ip"`
	IdleTimeout      Duration `toml:"idle-timeout"`
	MaxWriteBufferMB int      `toml:"max-write-buffer-mb"` // Max pending bytes per connection (0 = 4MB)
	// ClientSilenceClose: close a relay whose server reply has gone unanswered by
	// the client for this long (breaks the iOS bad_salt "Updating" wedge).
	// 0 = off. If enabled, keep it well above your slowest legitimate response;
	// ~10-15s is a sane starting point.
	ClientSilenceClose Duration `toml:"client-silence-close"`
}

PerformanceConfig configures performance settings.

type TLSFrontingConfig

type TLSFrontingConfig struct {
	MaskHost string `toml:"mask-host"` // Domain to mimic (SNI validation, proxy links)
	MaskPort int    `toml:"mask-port"` // Default port (default: 443)

	// Certificate fetching - where to connect to get real TLS cert
	// Defaults to mask-host:mask-port if not set
	// Useful when cert must be fetched from local nginx bypassing front proxy
	CertHost string `toml:"cert-host"`
	CertPort int    `toml:"cert-port"`

	// FakeCertSize sets the exact size of the fake encrypted-certificate record
	// in the FakeTLS ServerHello. 0 = auto (match the mask backend's real cert
	// record size). Set to the backend's first cert-record size to remove the
	// accept-vs-mask cert-record-length tell.
	FakeCertSize int `toml:"fake-cert-size"`

	// MaskSNISafelist: opt-in extra domains an unauthenticated probe may be
	// fronted to when its ClientHello SNI matches. Empty = off (never a relay).
	MaskSNISafelist []string `toml:"mask-sni-safelist"`

	// Splice target - where to forward unrecognized clients
	// Defaults to mask-host:mask-port if not set
	SpliceHost          string   `toml:"splice-host"`
	SplicePort          int      `toml:"splice-port"`
	SpliceProxyProtocol int      `toml:"splice-proxy-protocol"` // 0=off, 1=v1, 2=v2
	SpliceIdleTimeout   Duration `toml:"splice-idle-timeout"`   // Idle timeout for splice connections (default 30s)

	// Anti-DPI record shaping on the proxy->client direction.
	// Pointers so an absent TOML key keeps the gproxy.DefaultConfig() default (true).
	EnableDRS      *bool `toml:"enable-drs"`       // Chrome-style probe-then-ramp record sizer
	EnableSplitTLS *bool `toml:"enable-split-tls"` // 1-byte first ApplicationData record
}

TLSFrontingConfig configures TLS fronting.

type UpstreamConfig added in v0.1.3

type UpstreamConfig struct {
	Socks5 string `toml:"socks5"` // SOCKS5 proxy address (e.g., "127.0.0.1:1080")
}

UpstreamConfig configures upstream (DC) connection settings.

type WebProxyConfig added in v0.5.0

type WebProxyConfig struct {
	Enabled           bool     `toml:"enabled"`
	BindTo            string   `toml:"bind-to"`
	Hostname          string   `toml:"hostname"`
	BasePath          string   `toml:"base-path"`
	Backend           string   `toml:"backend"`
	Carrier           string   `toml:"carrier"`
	TrustedProxyCIDRs []string `toml:"trusted-proxy-cidrs"`
	NumEventLoops     int      `toml:"num-event-loops"`
}

WebProxyConfig configures the optional private WEB carrier listener. Nginx terminates public TLS and forwards candidate requests to this listener.

type WebProxyRuntimeConfig added in v0.5.0

type WebProxyRuntimeConfig struct {
	Enabled              bool
	BindAddr             string
	Hostname             string
	BasePath             string
	Backend              string
	LogicalBackend       bool
	MTProxyAddr          net.Addr
	Carrier              webproxy.CarrierMode
	TrustedProxyCIDRs    []string
	NumEventLoops        int
	Profiles             []webproxy.Profile
	BackendProxyProtocol bool
}

WebProxyRuntimeConfig is the validated, immutable input used to construct the native WEB manager and its private gnet HTTP listener.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL