feat(mtproto): adopt dolonet/mtg-multi and make MTProto inbounds multi-client

Replace the upstream 9seconds/mtg sidecar with the dolonet/mtg-multi fork so a single MTProto inbound can serve many per-user secrets. Each panel client is now one named FakeTLS secret in the fork's [secrets] section: clients are first-class (attach/detach, limits, expiry, per-client tg:// links) exactly like every other protocol, mirroring the WireGuard multi-client model. Per-client traffic and online status come from the fork's /stats JSON API (its Prometheus output has no per-user label), fed into the existing email-keyed client_traffics accumulator; an optional throttle caps concurrent connections. A one-time seeder converts each legacy single-secret inbound into a one-client inbound.

The fork ships only linux/darwin amd64/arm64 binaries but is pure Go, so provisioning builds it from source for every supported platform (release.yml, DockerInit.sh) while keeping the panel-expected mtg-<os>-<arch> filename and the 'run' verb, so process.go is untouched. Also fixes a pre-existing update.sh gap that never renamed the mtg binary for armv6/armv7 updates.
This commit is contained in:
MHSanaei
2026-07-06 16:04:32 +02:00
parent 5e9606aa4d
commit d97bd8643e
54 changed files with 1160 additions and 453 deletions
+13
View File
@@ -1167,6 +1167,11 @@
"description": "VLESS simple reverse proxy settings",
"nullable": true
},
"secret": {
"description": "MTProto FakeTLS secret",
"example": "ee1234567890abcdef1234567890abcd7777772e636c6f7564666c6172652e636f6d",
"type": "string"
},
"security": {
"description": "Security method (e.g., \"auto\", \"aes-128-gcm\")",
"type": "string"
@@ -1279,6 +1284,9 @@
"type": "integer"
},
"reverse": {},
"secret": {
"type": "string"
},
"security": {
"type": "string"
},
@@ -1317,6 +1325,7 @@
"publicKey",
"reset",
"reverse",
"secret",
"security",
"subId",
"tgId",
@@ -1835,6 +1844,9 @@
"listen": {
"type": "string"
},
"mtprotoDomain": {
"type": "string"
},
"nodeAddress": {
"description": "Share-host resolution inputs, mirroring the subscription's\nresolveInboundAddress so the clients page renders a node-managed WireGuard\nEndpoint that points at the node, not the master panel. NodeAddress is the\nhosting node's externally reachable address (empty for this panel's own\ninbounds); Listen and ShareAddrStrategy/ShareAddr feed the same\nnode→listen→custom fallback the share/QR links already use.",
"type": "string"
@@ -2803,6 +2815,7 @@
"enable": true,
"id": 1,
"listen": "",
"mtprotoDomain": "",
"nodeAddress": "",
"nodeId": null,
"port": 443,