mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-08-11 22:00:59 +00:00
docs: vendor the documentation site into the monorepo
Fold the standalone 3x-ui-docs project (Next.js 16 + Fumadocs, deployed to docs.sanaei.dev) into docs/ so the panel and its documentation share a single source of truth, the way sing-box keeps its docs in-tree. The old repo becomes redundant and can be retired. - Import the full site under docs/ (app, components, content, lib, public, scripts, config). The self-contained pnpm project sits alongside the existing engineering notes with no filename collisions. - Re-point "Edit on GitHub" links from MHSanaei/3x-ui-docs to this repo's docs/content/docs path (docs/lib/shared.ts, docs/app/.../page.tsx). - Add docs-ci.yml and docs-deploy.yml under .github/workflows/, scoped to docs/** and run with working-directory: docs, since GitHub only runs workflows from the repo-root .github/. deploy-static.yml's GitHub Pages publish (CNAME docs.sanaei.dev) carries over unchanged. Follow-up (outside this commit): attach the docs.sanaei.dev custom domain to this repository's Pages (or set the Vercel project's root directory to docs), confirm the site is live from the monorepo, then delete MHSanaei/3x-ui-docs.
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
// Pure builders for firewall rules (ufw + nftables) from a port list.
|
||||
|
||||
export type PortProtocol = 'tcp' | 'udp' | 'both';
|
||||
|
||||
export interface PortRule {
|
||||
port: number;
|
||||
protocol: PortProtocol;
|
||||
label?: string;
|
||||
}
|
||||
|
||||
export interface FirewallOptions {
|
||||
ports: PortRule[];
|
||||
allowSsh: boolean;
|
||||
sshPort: number;
|
||||
}
|
||||
|
||||
function expand(protocol: PortProtocol): ('tcp' | 'udp')[] {
|
||||
return protocol === 'both' ? ['tcp', 'udp'] : [protocol];
|
||||
}
|
||||
|
||||
export function buildUfwCommands(o: FirewallOptions): string {
|
||||
const lines: string[] = [];
|
||||
if (o.allowSsh) lines.push(`ufw allow ${o.sshPort}/tcp # SSH`);
|
||||
for (const rule of o.ports) {
|
||||
for (const proto of expand(rule.protocol)) {
|
||||
const comment = rule.label ? ` # ${rule.label}` : '';
|
||||
lines.push(`ufw allow ${rule.port}/${proto}${comment}`);
|
||||
}
|
||||
}
|
||||
lines.push('ufw enable');
|
||||
return lines.join('\n');
|
||||
}
|
||||
|
||||
export function buildNftablesRuleset(o: FirewallOptions): string {
|
||||
const accepts: string[] = [];
|
||||
if (o.allowSsh) accepts.push(` tcp dport ${o.sshPort} accept # SSH`);
|
||||
for (const rule of o.ports) {
|
||||
for (const proto of expand(rule.protocol)) {
|
||||
const comment = rule.label ? ` # ${rule.label}` : '';
|
||||
accepts.push(` ${proto} dport ${rule.port} accept${comment}`);
|
||||
}
|
||||
}
|
||||
return `#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
|
||||
table inet filter {
|
||||
chain input {
|
||||
type filter hook input priority 0; policy drop;
|
||||
|
||||
iif "lo" accept
|
||||
ct state established,related accept
|
||||
icmp type echo-request accept
|
||||
${accepts.join('\n')}
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority 0; policy drop;
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority 0; policy accept;
|
||||
}
|
||||
}`;
|
||||
}
|
||||
Reference in New Issue
Block a user