From ea00e69d4d718b7d5636c395834495d180bd6062 Mon Sep 17 00:00:00 2001 From: Kuzz007 Date: Mon, 27 Jul 2026 01:13:04 +0300 Subject: [PATCH] chore: remove Docker support entirely from this fork Never used by this fork's own distribution (install.sh/x-ui.sh is the only supported install path), AmneziaWG structurally can't run in the Alpine-based image anyway, and Docker Hub publishing was failing on every release for lack of configured credentials. Removed Dockerfile, docker-compose.yml, DockerEntrypoint.sh, DockerInit.sh, .dockerignore, and the docker.yml CI workflow; dropped the now-dead "Docker" README subsection (all 7 languages), the "Docker image"/"Docker Compose" options from the issue/PR templates, and corrected claude-bot.yml's now-stale references to the deleted files, the never-actually-ours ghcr.io/mhsanaei/3x-ui image, and (caught in passing) an already-stale claim that Windows is a supported platform. Left untouched: generic container-runtime adaptations that apply regardless of image source (x-ui.sh's running-in-docker detection, the virtual-interface-name filters, the DNS-over-container-network note) and deploy/test/smoke-noninteractive.sh, which uses Docker only as its own test sandbox, not as something this repo ships. Co-Authored-By: Claude Sonnet 5 --- .dockerignore | 10 --- .github/ISSUE_TEMPLATE/bug_report.yaml | 2 - .github/ISSUE_TEMPLATE/feature_request.yaml | 1 - .github/ISSUE_TEMPLATE/question.yaml | 1 - .github/pull_request_template.md | 1 - .github/workflows/claude-bot.yml | 10 +-- .github/workflows/docker.yml | 60 --------------- DockerEntrypoint.sh | 82 --------------------- DockerInit.sh | 58 --------------- Dockerfile | 74 ------------------- README.ar_EG.md | 17 ----- README.es_ES.md | 17 ----- README.fa_IR.md | 17 ----- README.md | 17 ----- README.ru_RU.md | 17 ----- README.tr_TR.md | 17 ----- README.zh_CN.md | 17 ----- docker-compose.yml | 68 ----------------- docs/architecture.md | 9 +-- install.sh | 5 +- internal/web/job/amneziawg_job.go | 2 +- 21 files changed, 9 insertions(+), 493 deletions(-) delete mode 100644 .dockerignore delete mode 100644 .github/workflows/docker.yml delete mode 100644 DockerEntrypoint.sh delete mode 100755 DockerInit.sh delete mode 100644 Dockerfile delete mode 100644 docker-compose.yml diff --git a/.dockerignore b/.dockerignore deleted file mode 100644 index 0ff86b7a4..000000000 --- a/.dockerignore +++ /dev/null @@ -1,10 +0,0 @@ -.git -**/node_modules -internal/web/dist -build -db -cert -pgdata -x-ui/ -*.db -*.dump diff --git a/.github/ISSUE_TEMPLATE/bug_report.yaml b/.github/ISSUE_TEMPLATE/bug_report.yaml index 52843436d..0bf053feb 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.yaml +++ b/.github/ISSUE_TEMPLATE/bug_report.yaml @@ -92,7 +92,6 @@ body: label: How did you install 3x-ui? options: - install.sh script - - Docker / Docker Compose - Manual build from source - Other (please describe in the bug body) validations: @@ -120,7 +119,6 @@ body: - Statistics / traffic counters - Database / migrations - Install / upgrade script - - Docker image - Multi-node (sub-nodes) - Telegram bot - Other diff --git a/.github/ISSUE_TEMPLATE/feature_request.yaml b/.github/ISSUE_TEMPLATE/feature_request.yaml index 0110f0619..848074bce 100644 --- a/.github/ISSUE_TEMPLATE/feature_request.yaml +++ b/.github/ISSUE_TEMPLATE/feature_request.yaml @@ -73,7 +73,6 @@ body: - Statistics / traffic counters - Database / migrations - Install / upgrade script - - Docker image - Multi-node (sub-nodes) - Telegram bot - Other diff --git a/.github/ISSUE_TEMPLATE/question.yaml b/.github/ISSUE_TEMPLATE/question.yaml index b60212511..c0e8f0c76 100644 --- a/.github/ISSUE_TEMPLATE/question.yaml +++ b/.github/ISSUE_TEMPLATE/question.yaml @@ -55,7 +55,6 @@ body: label: How did you install 3x-ui? options: - install.sh script - - Docker / Docker Compose - Manual build from source - Other validations: diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index d4ae693ad..7ef81b668 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -28,7 +28,6 @@ Link related issues here: "Closes #123", "Refs #456". - [ ] Statistics / traffic counters - [ ] Database / migrations - [ ] Install / upgrade script -- [ ] Docker image - [ ] Multi-node (sub-nodes) - [ ] Telegram bot diff --git a/.github/workflows/claude-bot.yml b/.github/workflows/claude-bot.yml index 32d234d80..8f5c4592f 100644 --- a/.github/workflows/claude-bot.yml +++ b/.github/workflows/claude-bot.yml @@ -117,7 +117,6 @@ jobs: - docs/ extra docs (custom subscription templates) - install.sh, update.sh, x-ui.sh, x-ui.service.* install/upgrade + systemd units - - Dockerfile, docker-compose.yml, DockerEntrypoint.sh, DockerInit.sh - windows_files/, x-ui.rc Windows support files. (A top-level x-ui/ folder, if present, is gitignored local runtime data, not source.) @@ -140,11 +139,8 @@ jobs: - SQLite -> PostgreSQL: `x-ui migrate-db --dsn "postgres://..."`, then set XUI_DB_TYPE/XUI_DB_DSN in /etc/default/x-ui and `systemctl restart x-ui`. The source SQLite file is left in place. - - Docker image: ghcr.io/mhsanaei/3x-ui. PostgreSQL profile: - `docker compose --profile postgres up -d`. Fail2ban IP-limit - enforcement needs NET_ADMIN + NET_RAW (compose grants them via - cap_add; a bare `docker run` must add - `--cap-add=NET_ADMIN --cap-add=NET_RAW`). + - This fork does not build or publish a Docker image; install is + always via install.sh/x-ui.sh on the host. - Protocols (inbound Protocol enum in internal/database/model/model.go): VLESS, VMess, Trojan, Shadowsocks, WireGuard, Hysteria2 (stored as protocol "hysteria" with stream version 2), HTTP, SOCKS @@ -775,7 +771,7 @@ jobs: - tools/openapigen generates the OpenAPI spec and frontend API types. - docs/ holds extra documentation. - Stack and runtime facts: Backend is Go (module github.com/mhsanaei/3x-ui/v3) with Gin and GORM; storage is SQLite by default at /etc/x-ui/x-ui.db or PostgreSQL via XUI_DB_TYPE and XUI_DB_DSN; further env vars include XUI_DB_FOLDER, XUI_DB_MAX_OPEN_CONNS, XUI_DB_MAX_IDLE_CONNS, XUI_INIT_WEB_BASE_PATH, XUI_ENABLE_FAIL2BAN; the installer writes env to /etc/default/x-ui; SQLite to PostgreSQL migration is x-ui migrate-db --dsn followed by a service restart; install uses install.sh and the x-ui menu, generating random initial credentials; Docker image is ghcr.io/mhsanaei/3x-ui and Fail2ban IP-limit enforcement needs NET_ADMIN and NET_RAW; Windows is a supported platform. Do not hardcode a version: for version or is-this-fixed questions, check the latest release and recent commits or closed PRs with gh. + Stack and runtime facts: Backend is Go (module github.com/mhsanaei/3x-ui/v3) with Gin and GORM; storage is SQLite by default at /etc/x-ui/x-ui.db or PostgreSQL via XUI_DB_TYPE and XUI_DB_DSN; further env vars include XUI_DB_FOLDER, XUI_DB_MAX_OPEN_CONNS, XUI_DB_MAX_IDLE_CONNS, XUI_INIT_WEB_BASE_PATH, XUI_ENABLE_FAIL2BAN; the installer writes env to /etc/default/x-ui; SQLite to PostgreSQL migration is x-ui migrate-db --dsn followed by a service restart; install uses install.sh and the x-ui menu, generating random initial credentials; this fork does not build or publish a Docker image; Fail2ban IP-limit enforcement needs NET_ADMIN and NET_RAW; this fork's release CI targets Linux only (amd64/386/arm64/armv5/armv6/armv7/s390x) and does not publish a Windows build, unlike upstream. Do not hardcode a version: for version or is-this-fixed questions, check the latest release and recent commits or closed PRs with gh. Style: professional, courteous, and matter-of-fact; no emoji, no exclamation marks, no filler; lead with the answer in the first sentence; use fenced code blocks for commands and backtick formatting for paths and setting names; distinguish what you confirmed in the source (name the file) from what you infer; never promise fixes, timelines, or releases. Ground every claim in the code or the README and wiki; do not invent features, paths, flags, or commands, and do not stop at the first plausible match. Token cost is not a concern, so investigate as deeply as the question needs. diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml deleted file mode 100644 index ae62e4ab1..000000000 --- a/.github/workflows/docker.yml +++ /dev/null @@ -1,60 +0,0 @@ -name: Release 3X-UI for Docker - -permissions: - contents: read - packages: write - -on: - workflow_dispatch: - push: - tags: - - "v*.*.*" - -jobs: - build: - runs-on: ubuntu-latest - - steps: - - uses: actions/checkout@v7 - with: - submodules: true - - - name: Docker meta - id: meta - uses: docker/metadata-action@v6 - with: - images: | - hsanaeii/3x-ui - ghcr.io/mhsanaei/3x-ui - tags: | - type=ref,event=branch - type=ref,event=tag - type=semver,pattern={{version}} - - - name: Set up QEMU - uses: docker/setup-qemu-action@v4 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v4 - - - name: Login to Docker Hub - uses: docker/login-action@v4 - with: - username: ${{ secrets.DOCKER_HUB_USERNAME }} - password: ${{ secrets.DOCKER_HUB_TOKEN }} - - - name: Login to GHCR - uses: docker/login-action@v4 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - - name: Build and push Docker image - uses: docker/build-push-action@v7 - with: - context: . - push: true - platforms: linux/amd64,linux/arm64/v8,linux/arm/v7,linux/arm/v6,linux/386 - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} diff --git a/DockerEntrypoint.sh b/DockerEntrypoint.sh deleted file mode 100644 index 5b2a1372c..000000000 --- a/DockerEntrypoint.sh +++ /dev/null @@ -1,82 +0,0 @@ -#!/bin/sh - -# Start fail2ban with the 3x-ipl jail -if [ "$XUI_ENABLE_FAIL2BAN" = "true" ]; then - LOG_FOLDER="${XUI_LOG_FOLDER:-/var/log/x-ui}" - mkdir -p "$LOG_FOLDER" - touch "$LOG_FOLDER/3xipl.log" "$LOG_FOLDER/3xipl-banned.log" - - mkdir -p /etc/fail2ban/jail.d /etc/fail2ban/filter.d /etc/fail2ban/action.d - - cat > /etc/fail2ban/jail.d/3x-ipl.conf << EOF -[3x-ipl] -enabled=true -backend=auto -filter=3x-ipl -action=3x-ipl -logpath=$LOG_FOLDER/3xipl.log -maxretry=1 -findtime=32 -bantime=30m -EOF - - cat > /etc/fail2ban/filter.d/3x-ipl.conf << 'EOF' -[Definition] -datepattern = ^%%Y/%%m/%%d %%H:%%M:%%S -failregex = \[LIMIT_IP\]\s*Email\s*=\s*.+\s*\|\|\s*Disconnecting OLD IP\s*=\s*\s*\|\|\s*Timestamp\s*=\s*\d+ -ignoreregex = -EOF - - # Ports to exempt from the ban so an over-limit proxy client can never lock - # the administrator out of SSH or the panel. The ban still covers every other - # TCP port (including all Xray inbounds), so IP-limit keeps working for inbounds - # added later without regenerating these files. - SSH_PORTS=$(grep -oE '^[[:space:]]*Port[[:space:]]+[0-9]+' /etc/ssh/sshd_config 2>/dev/null | grep -oE '[0-9]+' | paste -sd, -) - [ -z "$SSH_PORTS" ] && SSH_PORTS="22" - PANEL_PORT=$(/app/x-ui setting -show true 2>/dev/null | grep -Eo 'port: .+' | awk '{print $2}') - EXEMPT_PORTS="$SSH_PORTS" - [ -n "$PANEL_PORT" ] && EXEMPT_PORTS="$EXEMPT_PORTS,$PANEL_PORT" - - cat > /etc/fail2ban/action.d/3x-ipl.conf << EOF -[INCLUDES] -before = iptables-allports.conf - -[Definition] -actionstart = -N f2b- - -A f2b- -j - -I -j f2b- - -actionstop = -D -j f2b- - - -X f2b- - -actioncheck = -n -L | grep -q 'f2b-[ \t]' - -actionban = -I f2b- 1 -s -p tcp -m multiport ! --dports -j - -I f2b- 1 -s -p udp -m multiport ! --dports -j - echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") BAN [Email] = [IP] = banned for seconds." >> $LOG_FOLDER/3xipl-banned.log - -actionunban = -D f2b- -s -p tcp -m multiport ! --dports -j - -D f2b- -s -p udp -m multiport ! --dports -j - echo "\$(date +"%%Y/%%m/%%d %%H:%%M:%%S") UNBAN [Email] = [IP] = unbanned." >> $LOG_FOLDER/3xipl-banned.log - -[Init] -name = default -chain = INPUT -exemptports = $EXEMPT_PORTS -EOF - - fail2ban-client -x start -fi - -# Certificate auto-renewal: acme.sh (installed by the panel's SSL menu) relies -# on a root crontab entry, but the crontab is lost when the container is -# recreated and crond was never started. Re-register the job and run crond so -# renewals actually fire; mount /root/.acme.sh as a volume to keep acme state. -if [ -f /root/.acme.sh/acme.sh ]; then - /root/.acme.sh/acme.sh --install-cronjob >/dev/null 2>&1 - crond -fi - -# Run x-ui -exec /app/x-ui diff --git a/DockerInit.sh b/DockerInit.sh deleted file mode 100755 index 172180ab9..000000000 --- a/DockerInit.sh +++ /dev/null @@ -1,58 +0,0 @@ -#!/bin/sh -case $1 in - amd64) - ARCH="64" - FNAME="amd64" - ;; - i386) - ARCH="32" - FNAME="i386" - ;; - armv8 | arm64 | aarch64) - ARCH="arm64-v8a" - FNAME="arm64" - ;; - armv7 | arm | arm32) - ARCH="arm32-v7a" - FNAME="arm32" - ;; - armv6) - ARCH="arm32-v6" - FNAME="armv6" - ;; - *) - ARCH="64" - FNAME="amd64" - ;; -esac -MTG_MULTI_VER=$(curl -sfL "https://api.github.com/repos/mhsanaei/mtg-multi/releases/latest" | sed -n 's/.*"tag_name": *"\([^"]*\)".*/\1/p' | head -n 1) -if [ -z "$MTG_MULTI_VER" ]; then - echo "DockerInit: could not resolve the latest mtg-multi release tag" >&2 - exit 1 -fi -mkdir -p build/bin -cd build/bin -curl -sfLRO "https://github.com/XTLS/Xray-core/releases/download/v26.7.11/Xray-linux-${ARCH}.zip" -unzip "Xray-linux-${ARCH}.zip" -rm -f "Xray-linux-${ARCH}.zip" geoip.dat geosite.dat -mv xray "xray-linux-${FNAME}" -# mtg-multi (MTProto sidecar) ships prebuilt release binaries for every target -# we package, so download and unpack the matching one instead of compiling. -case $FNAME in - i386) MTGARCH="386" ;; - arm32) MTGARCH="armv7" ;; - *) MTGARCH="$FNAME" ;; -esac -MTG_PKG="mtg-multi-${MTG_MULTI_VER#v}-linux-${MTGARCH}" -curl -sfLRO "https://github.com/mhsanaei/mtg-multi/releases/download/${MTG_MULTI_VER}/${MTG_PKG}.tar.gz" -tar -xzf "${MTG_PKG}.tar.gz" -mv "${MTG_PKG}/mtg-multi" "mtg-linux-${FNAME}" -rm -rf "${MTG_PKG}" "${MTG_PKG}.tar.gz" -chmod +x "mtg-linux-${FNAME}" -curl -sfLRO https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geoip.dat -curl -sfLRO https://github.com/Loyalsoldier/v2ray-rules-dat/releases/latest/download/geosite.dat -curl -sfLRo geoip_IR.dat https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geoip.dat -curl -sfLRo geosite_IR.dat https://github.com/chocolate4u/Iran-v2ray-rules/releases/latest/download/geosite.dat -curl -sfLRo geoip_RU.dat https://github.com/runetfreedom/russia-v2ray-rules-dat/releases/latest/download/geoip.dat -curl -sfLRo geosite_RU.dat https://github.com/runetfreedom/russia-v2ray-rules-dat/releases/latest/download/geosite.dat -cd ../../ diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 2e889987c..000000000 --- a/Dockerfile +++ /dev/null @@ -1,74 +0,0 @@ -# ======================================================== -# Stage: Frontend (Vite) -# ======================================================== -FROM --platform=$BUILDPLATFORM node:22-alpine AS frontend -WORKDIR /src/frontend -COPY frontend/package.json frontend/package-lock.json ./ -RUN npm ci -COPY frontend/ ./ -COPY internal/web/translation /src/internal/web/translation -RUN npm run build - -# ======================================================== -# Stage: Builder -# ======================================================== -FROM golang:1.26-alpine AS builder -WORKDIR /app -ARG TARGETARCH - -RUN apk --no-cache --update add \ - build-base \ - gcc \ - curl \ - unzip - -COPY . . -COPY --from=frontend /src/internal/web/dist ./internal/web/dist - -ENV CGO_ENABLED=1 -ENV CGO_CFLAGS="-D_LARGEFILE64_SOURCE" -RUN go build -ldflags "-w -s" -o build/x-ui main.go -RUN ./DockerInit.sh "$TARGETARCH" - -# ======================================================== -# Stage: Final Image of 3x-ui -# ======================================================== -FROM alpine -ENV TZ=Asia/Tehran -WORKDIR /app - -RUN apk add --no-cache --update \ - ca-certificates \ - tzdata \ - fail2ban \ - bash \ - curl \ - openssl - -COPY --from=builder /app/build/ /app/ -COPY --from=builder /app/DockerEntrypoint.sh /app/ -COPY --from=builder /app/x-ui.sh /usr/bin/x-ui -COPY --from=builder /app/internal/web/translation /app/internal/web/translation - - -# Configure fail2ban -RUN rm -f /etc/fail2ban/jail.d/alpine-ssh.conf \ - && cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local \ - && sed -i "s/^\[ssh\]$/&\nenabled = false/" /etc/fail2ban/jail.local \ - && sed -i "s/^\[sshd\]$/&\nenabled = false/" /etc/fail2ban/jail.local \ - && sed -i "s/#allowipv6 = auto/allowipv6 = auto/g" /etc/fail2ban/fail2ban.conf - -RUN chmod +x \ - /app/DockerEntrypoint.sh \ - /app/x-ui \ - /usr/bin/x-ui - -ENV XUI_IN_DOCKER="true" -ENV XUI_MAIN_FOLDER="/app" -ENV XUI_ENABLE_FAIL2BAN="true" -ENV XUI_DB_TYPE="" -ENV XUI_DB_DSN="" -EXPOSE 2053 -VOLUME [ "/etc/x-ui" ] -CMD [ "./x-ui" ] -ENTRYPOINT [ "/app/DockerEntrypoint.sh" ] diff --git a/README.ar_EG.md b/README.ar_EG.md index 7a69a43ae..5ba796d4b 100644 --- a/README.ar_EG.md +++ b/README.ar_EG.md @@ -148,23 +148,6 @@ systemctl restart x-ui يبقى ملف SQLite الأصلي دون تغيير؛ احذفه يدويًا بعد التحقق من الخلفية الجديدة. -### Docker - -يستمر الأمر الافتراضي `docker compose up -d` في استخدام SQLite. للتشغيل مع خدمة PostgreSQL المرفقة، أزِل التعليق عن سطري متغيرات البيئة `XUI_DB_*` في `docker-compose.yml` وشغّل باستخدام البروفايل: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> تحتاج اتصالات AmneziaWG الواردة إلى `awg-quick`/`awg` ووحدة نواة AmneziaWG على **المضيف** — وهذا بالضبط ما يوضحه قصد التصميم بدون Docker في قسم [ما الذي يختلف في هذه النسخة](#ما-الذي-يختلف-في-هذه-النسخة-amneziawg). لا يزال تشغيل اللوحة نفسها في Docker يعمل لأي بروتوكول آخر، لكن اتصال AmneziaWG الوارد المُنشأ من لوحة تعمل داخل حاوية ليس لديه مكان لرفع واجهته ما لم تحصل الحاوية على وصول شبكي/نواة على مستوى المضيف، مما يُبطل الغرض من الأساس. إذا كنت تنوي استخدام AmneziaWG، شغّله نيتيفيًا على المضيف. - -تتضمن الصورة Fail2ban (مُفعَّل افتراضيًا) لفرض **حدود IP** لكل عميل. يحظر Fail2ban المخالفين باستخدام `iptables`، الذي يتطلب صلاحية `NET_ADMIN`. يمنح `docker-compose.yml` هذه الصلاحية مسبقًا عبر `cap_add`؛ إذا شغّلت الحاوية باستخدام `docker run` بدلاً من ذلك، فأضِف الصلاحيات بنفسك، وإلا فسيتم تسجيل عمليات الحظر دون تطبيقها أبدًا: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## متغيرات البيئة | المتغير | الوصف | الافتراضي | diff --git a/README.es_ES.md b/README.es_ES.md index b085fe516..09235e487 100644 --- a/README.es_ES.md +++ b/README.es_ES.md @@ -148,23 +148,6 @@ systemctl restart x-ui El archivo SQLite de origen permanece intacto; elimínalo manualmente una vez que hayas verificado el nuevo backend. -### Docker - -El comando predeterminado `docker compose up -d` sigue usando SQLite. Para ejecutarlo con el servicio PostgreSQL incluido, descomenta las dos líneas de variables de entorno `XUI_DB_*` en `docker-compose.yml` e inícialo con el perfil: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> Las entradas AmneziaWG necesitan `awg-quick`/`awg` y el módulo de kernel de AmneziaWG en el **host** — esto es exactamente lo que refleja la intención de diseño sin Docker descrita en la sección [En qué se diferencia este fork](#en-qué-se-diferencia-este-fork-amneziawg). Ejecutar el propio panel en Docker sigue funcionando para cualquier otro protocolo, pero una entrada AmneziaWG creada desde un panel en contenedor no tiene dónde levantar su interfaz, a menos que el contenedor obtenga acceso de red/kernel a nivel de host, lo cual anula el propósito. Si piensas usar AmneziaWG, ejecútalo de forma nativa en el host. - -La imagen incluye Fail2ban (habilitado de forma predeterminada) para aplicar **límites de IP** por cliente. Fail2ban banea a los infractores con `iptables`, lo que requiere la capacidad `NET_ADMIN`. `docker-compose.yml` ya la concede mediante `cap_add`; si en su lugar inicias el contenedor con `docker run`, añade tú mismo las capacidades, de lo contrario los baneos se registran pero nunca se aplican: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## Variables de Entorno | Variable | Descripción | Predeterminado | diff --git a/README.fa_IR.md b/README.fa_IR.md index 06a017663..c55e8f453 100644 --- a/README.fa_IR.md +++ b/README.fa_IR.md @@ -148,23 +148,6 @@ systemctl restart x-ui فایل اصلی SQLite دست‌نخورده باقی می‌ماند؛ پس از اطمینان از صحت بک‌اند جدید، آن را به‌صورت دستی حذف کنید. -### Docker - -دستور پیش‌فرض `docker compose up -d` همچنان از SQLite استفاده می‌کند. برای اجرا با سرویس PostgreSQL همراه، دو خط متغیر محیطی `XUI_DB_*` را در `docker-compose.yml` از حالت کامنت خارج کنید و با پروفایل زیر اجرا کنید: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> اینباندهای AmneziaWG به `awg-quick`/`awg` و ماژول کرنل AmneziaWG روی **هاست** نیاز دارند — این دقیقاً همان هدف طراحی بدون Docker است که در بخش [تفاوت این فورک](#تفاوت-این-فورک-amneziawg) توضیح داده شده. اجرای خودِ پنل در Docker همچنان برای هر پروتکل دیگر کار می‌کند، اما یک اینباند AmneziaWG که از یک پنل کانتینری ساخته شده، جایی برای بالا آوردن اینترفیسش ندارد مگر آن‌که کانتینر دسترسی شبکه/کرنل در سطح هاست داشته باشد، که هدف اصلی را زیر سؤال می‌برد. اگر قصد استفاده از AmneziaWG را دارید، به‌صورت نیتیو روی هاست اجرا کنید. - -این ایمیج، Fail2ban را (که به‌صورت پیش‌فرض فعال است) برای اعمال **محدودیت‌های IP** به‌ازای هر کلاینت همراه دارد. ‏Fail2ban متخلفان را با `iptables` مسدود می‌کند که به مجوز `NET_ADMIN` نیاز دارد. فایل `docker-compose.yml` این مجوز را از قبل از طریق `cap_add` می‌دهد؛ اگر به‌جای آن کانتینر را با `docker run` اجرا می‌کنید، خودتان مجوزها را اضافه کنید، در غیر این صورت مسدودسازی‌ها فقط ثبت می‌شوند اما هرگز اعمال نمی‌شوند: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## متغیرهای محیطی | متغیر | توضیحات | پیش‌فرض | diff --git a/README.md b/README.md index 0d86f2508..0519ce12e 100644 --- a/README.md +++ b/README.md @@ -148,23 +148,6 @@ systemctl restart x-ui The source SQLite file is left untouched; remove it manually once you have verified the new backend. -### Docker - -The default `docker compose up -d` keeps using SQLite. To run with the bundled PostgreSQL service, uncomment the two `XUI_DB_*` env lines in `docker-compose.yml` and start with the profile: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> AmneziaWG inbounds need `awg-quick`/`awg` and the AmneziaWG kernel module on the **host** — that's the whole point of the no-Docker design in [What's different in this fork](#whats-different-in-this-fork-amneziawg). Running the panel itself in Docker still works for every other protocol, but an AmneziaWG inbound created from a containerized panel has nowhere to bring its interface up unless the container has host-level network/kernel access, which defeats the purpose. Run natively on the host if you plan to use AmneziaWG. - -The image bundles Fail2ban (enabled by default) to enforce per-client **IP limits**. Fail2ban bans offenders with `iptables`, which requires the `NET_ADMIN` capability. `docker-compose.yml` already grants it via `cap_add`; if you start the container with `docker run` instead, add the capabilities yourself, otherwise bans are logged but never applied: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## Environment Variables | Variable | Description | Default | diff --git a/README.ru_RU.md b/README.ru_RU.md index 8c0903203..2d4e48c8a 100644 --- a/README.ru_RU.md +++ b/README.ru_RU.md @@ -148,23 +148,6 @@ systemctl restart x-ui Исходный файл SQLite остаётся нетронутым; удалите его вручную после проверки нового бэкенда. -### Docker - -Команда по умолчанию `docker compose up -d` продолжает использовать SQLite. Чтобы запустить со встроенным сервисом PostgreSQL, раскомментируйте две строки переменных окружения `XUI_DB_*` в `docker-compose.yml` и запустите с профилем: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> AmneziaWG-инбаундам нужны `awg-quick`/`awg` и модуль ядра AmneziaWG на **хосте** — в этом весь смысл отказа от Docker, описанного в разделе [Чем этот форк отличается: AmneziaWG](#чем-этот-форк-отличается-amneziawg). Сама панель в Docker по-прежнему прекрасно работает для всех остальных протоколов, но AmneziaWG-инбаунд, созданный из контейнеризированной панели, поднять интерфейс негде, если только у контейнера нет доступа к сети/ядру хоста — а это уже сводит на нет весь смысл. Если планируете использовать AmneziaWG, запускайте панель нативно на хосте. - -Образ включает Fail2ban (включён по умолчанию) для применения **лимитов IP** по каждому клиенту. Fail2ban блокирует нарушителей с помощью `iptables`, что требует возможности `NET_ADMIN`. `docker-compose.yml` уже предоставляет её через `cap_add`; если вы вместо этого запускаете контейнер через `docker run`, добавьте возможности самостоятельно, иначе блокировки будут регистрироваться, но никогда не применяться: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## Переменные окружения | Переменная | Описание | По умолчанию | diff --git a/README.tr_TR.md b/README.tr_TR.md index 2556b99ae..dcb904810 100644 --- a/README.tr_TR.md +++ b/README.tr_TR.md @@ -148,23 +148,6 @@ systemctl restart x-ui Kaynak SQLite dosyasına dokunulmaz; yeni veritabanının düzgün çalıştığını doğruladıktan sonra eski SQLite dosyasını manuel olarak silebilirsiniz. -### Docker - -Varsayılan `docker compose up -d` komutu SQLite kullanmaya devam eder. Birlikte paketlenmiş PostgreSQL servisi ile çalıştırmak için, `docker-compose.yml` dosyasındaki iki `XUI_DB_*` değişken satırının yorumunu kaldırın ve profille başlatın: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> AmneziaWG gelen bağlantıları, **host** üzerinde `awg-quick`/`awg` ve AmneziaWG çekirdek moduline ihtiyaç duyar — bu tam olarak [Bu fork'ta ne farklı](#bu-forkta-ne-farklı-amneziawg) bölümünde açıklanan Docker'sız tasarım amacının yansımasıdır. Panelin kendisini Docker içinde çalıştırmak diğer tüm protokoller için işlemeye devam eder, ancak konteynerize edilmiş bir panelden oluşturulan bir AmneziaWG gelen bağlantısının, konteyner host düzeyinde ağ/çekirdek erişimi almadıkça arabirimini açacak bir yeri yoktur ki bu da temel amacı geçersiz kılar. AmneziaWG kullanmayı planlıyorsanız, host üzerinde yerel (native) olarak çalıştırın. - -Docker imajı, kullanıcı başına **IP limitlerini** zorunlu kılmak için Fail2ban ile (varsayılan olarak etkindir) paketlenmiştir. Fail2ban, ihlalcileri `iptables` ile engeller ve bunun için `NET_ADMIN` yetkisine ihtiyaç duyar. `docker-compose.yml` bunu zaten `cap_add` üzerinden vermektedir; ancak konteyneri bunun yerine `docker run` ile başlatırsanız bu yetkileri kendiniz eklemelisiniz, aksi takdirde yasaklamalar günlüğe kaydedilir ancak uygulanmaz: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## Ortam Değişkenleri (Environment Variables) | Değişken | Açıklama | Varsayılan | diff --git a/README.zh_CN.md b/README.zh_CN.md index f017d58a2..d830eec9f 100644 --- a/README.zh_CN.md +++ b/README.zh_CN.md @@ -148,23 +148,6 @@ systemctl restart x-ui 源 SQLite 文件保持不变;在确认新后端正常工作后,请手动删除它。 -### Docker - -默认的 `docker compose up -d` 仍使用 SQLite。若要使用捆绑的 PostgreSQL 服务运行,请取消注释 `docker-compose.yml` 中的两行 `XUI_DB_*` 环境变量,并使用该 profile 启动: - -```bash -docker compose --profile postgres up -d -``` - -> [!NOTE] -> AmneziaWG 入站需要**宿主机**上的 `awg-quick`/`awg` 和 AmneziaWG 内核模块——这正是[本分支的不同之处](#本分支的不同之处amneziawg)一节中所述的"不使用 Docker"设计初衷所在。将面板本身运行在 Docker 中对其他任何协议仍然有效,但由运行在容器中的面板创建的 AmneziaWG 入站将无法启动其接口,除非该容器获得宿主机级别的网络/内核访问权限,而这会违背整体设计初衷。如果您打算使用 AmneziaWG,请在宿主机上原生运行面板。 - -该镜像捆绑了 Fail2ban(默认启用),用于强制执行按客户端的 **IP 限制**。Fail2ban 使用 `iptables` 封禁违规者,这需要 `NET_ADMIN` 权限。`docker-compose.yml` 已通过 `cap_add` 授予该权限;如果您改用 `docker run` 启动容器,请自行添加这些权限,否则封禁只会被记录而永远不会生效: - -```bash -docker run -d --cap-add=NET_ADMIN --cap-add=NET_RAW ... ghcr.io/mhsanaei/3x-ui -``` - ## 环境变量 | 变量 | 说明 | 默认值 | diff --git a/docker-compose.yml b/docker-compose.yml deleted file mode 100644 index 39757e26d..000000000 --- a/docker-compose.yml +++ /dev/null @@ -1,68 +0,0 @@ -services: - 3xui: - build: - context: . - dockerfile: ./Dockerfile - container_name: 3xui_app - # hostname: yourhostname <- optional - # Optional hard memory cap. When set, the panel derives its Go soft limit - # (GOMEMLIMIT, ~90% of this cap) so it GCs before the OOM killer fires. - # mem_limit: 512m - # The bundled Fail2ban (XUI_ENABLE_FAIL2BAN below) enforces the IP limit - # with iptables, which needs NET_ADMIN. Without these caps a ban is logged - # and shown in fail2ban status but never actually applied. NET_RAW covers - # ip6tables. If you disable Fail2ban, you can drop cap_add. - # - # This does NOT make AmneziaWG inbounds work: the image is Alpine-based, - # and AmneziaWG's own packaging (DKMS module + amneziawg-tools) doesn't - # target Alpine/musl at all, unlike the Debian/Ubuntu/Fedora/Arch paths - # install.sh already handles. The panel itself runs fine either way -- - # IsAwgInstalled() just logs one warning instead of retrying forever -- - # but an AmneziaWG inbound's tunnel will never come up from this - # container, no matter what capabilities or network mode you add. Run - # natively on the host if you plan to use AmneziaWG. - cap_add: - - NET_ADMIN - - NET_RAW - volumes: - - $PWD/db/:/etc/x-ui/ - - $PWD/cert/:/root/cert/ - # Persists acme.sh state so certificate auto-renewal survives container - # recreation (the entrypoint re-registers the renewal cron job from it). - - $PWD/acme/:/root/.acme.sh/ - environment: - XRAY_VMESS_AEAD_FORCED: "false" - XUI_ENABLE_FAIL2BAN: "true" - # Memory tuning. The panel keeps RAM low via GOGC + periodic release; it no - # longer sets a soft limit from total host RAM (no benefit, risks GC thrash). - # XUI_GOGC: "75" # lower = less RAM, slightly more CPU; GOGC env overrides - # XUI_MEMORY_RELEASE_INTERVAL: "10" # minutes between FreeOSMemory; 0 disables - # Go memory soft limit, only applied from an explicit budget below (or a - # real cgroup/mem_limit cap). Pin it with one of: - # XUI_MEMORY_LIMIT: "400" # in MiB - # GOMEMLIMIT: "400MiB" # Go syntax, takes precedence - # XUI_PPROF: "true" # expose pprof on 127.0.0.1:6060 for profiling - # XUI_INIT_WEB_BASE_PATH: "/" - # XUI_PORT: "8080" - # To use PostgreSQL instead of the default SQLite, run: - # docker compose --profile postgres up -d - # and uncomment the two lines below. - # XUI_DB_TYPE: "postgres" - # XUI_DB_DSN: "postgres://xui:xui@postgres:5432/xui?sslmode=disable" - tty: true - ports: - # When XUI_PORT is set, publish the same container port (for example "8080:8080"). - - "2053:2053" - restart: unless-stopped - - postgres: - image: postgres:16-alpine - container_name: 3xui_postgres - profiles: ["postgres"] - environment: - POSTGRES_USER: xui - POSTGRES_PASSWORD: xui - POSTGRES_DB: xui - volumes: - - $PWD/pgdata/:/var/lib/postgresql/data - restart: unless-stopped diff --git a/docs/architecture.md b/docs/architecture.md index 27164966e..1f828b31a 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -274,11 +274,10 @@ node heartbeat every 5s, periodic traffic resets (hourly/daily/weekly/monthly). ├── docs/ # Markdown docs (this file, custom-subscription-templates.md, …) ├── media/ # README images │ -├── Dockerfile / docker-compose.yml / DockerEntrypoint.sh / DockerInit.sh # Container build/run ├── install.sh / update.sh / x-ui.sh # VPS install + management CLI ├── x-ui.service.* / x-ui.rc # systemd units (debian/rhel/arch) + rc script ├── windows_files/ # Windows service support -└── .github/workflows/ # CI: ci.yml, codeql.yml, docker.yml, release.yml, smoke.yml, +└── .github/workflows/ # CI: ci.yml, codeql.yml, release.yml, smoke.yml, # mutation.yml, cleanup_caches.yml, claude-bot.yml ``` @@ -556,11 +555,9 @@ npm run build # gen:api + vite build → outputs to internal/web/dist (th **Full local loop:** `cd frontend && npm run build` (refresh embedded `dist/`) → back to repo root → `go build ./...` / `go run main.go`. -**Docker:** `docker compose up -d` (uses `Dockerfile` + `DockerEntrypoint.sh`). - **CI** (`.github/workflows/`): `ci.yml` (build/test/lint), `codeql.yml` (security scan), -`smoke.yml` (smoke tests), `mutation.yml` (mutation testing), `docker.yml` + `release.yml` -(multi-arch image + release builds), `cleanup_caches.yml`, `claude-bot.yml` (issue bot). +`smoke.yml` (smoke tests), `mutation.yml` (mutation testing), `release.yml` +(multi-arch release builds), `cleanup_caches.yml`, `claude-bot.yml` (issue bot). --- diff --git a/install.sh b/install.sh index 29432813c..57cb8e9dd 100644 --- a/install.sh +++ b/install.sh @@ -1565,9 +1565,8 @@ EOF # setup_fail2ban auto-installs and configures fail2ban for the IP Limit feature # by invoking the freshly installed x-ui CLI. IP Limit is load-bearing on # fail2ban (without it the panel disables the limitIp field and zeroes existing -# limits), so a fresh install should make it work out of the box, just like the -# Docker image already does. Non-fatal by design: a fail2ban failure must never -# abort the panel install. +# limits), so a fresh install should make it work out of the box. Non-fatal by +# design: a fail2ban failure must never abort the panel install. setup_fail2ban() { if [[ -n "${XUI_ENABLE_FAIL2BAN+x}" && "${XUI_ENABLE_FAIL2BAN}" != "true" ]]; then echo -e "${yellow}XUI_ENABLE_FAIL2BAN=${XUI_ENABLE_FAIL2BAN}, skipping Fail2ban auto-setup.${plain}" diff --git a/internal/web/job/amneziawg_job.go b/internal/web/job/amneziawg_job.go index b9ad10772..ddd21ae92 100644 --- a/internal/web/job/amneziawg_job.go +++ b/internal/web/job/amneziawg_job.go @@ -16,7 +16,7 @@ type AmneziaWGJob struct { inboundService service.InboundService // warnedMissing tracks whether the "awg/awg-quick not found" warning has // already been logged, so a host without the AmneziaWG kernel module - // (the Docker image, RHEL, Arch, or a failed install.sh PPA step) logs it + // (RHEL, Arch, a container, or a failed install.sh PPA step) logs it // once instead of every @every-10s tick forever. warnedMissing bool }